What is our primary use case?
The product provides complete visibility of our cloud security posture. It supports servers and Cloud-Native Services. It provides a centralized solution for Cloud Security with risk and compliance management.
We required it to manage various compliance requirements including live ISO, SOC, PCI and it supports everything. Our Organization is in a hybrid structure and in it, we are using various AWS and Azure accounts. Earlier, we managed everything individually, however, after the implementation of it, we now manage everything from a single solution. The single solution helps with the system, network, and security administration.
How has it helped my organization?
The solution provides the complete visibility of Cloud Security, as well as a number of baseline policies and rules. This helps us to manage cloud posture with less effort. After implementation, it reduced administrative effort in terms of managed security over the cloud. Now, we are not dependent on individual tools for each account as well as cloud service providers.
After implementation, the team can generate reports from a single console for all compliance needs.
Auto Remediation is a very effective feature and it improves the need for manual intervention from the security and cloud administrator.
What is most valuable?
The baseline policy and the integration with the public cloud are very easy.
The number of compliance rulesets along with the baseline policy, support of cloud-native services, and license management are easy. Support of the CI/CD pipeline security (Code Security), Kubernetes, et cetera, is useful.
There are very helpful and various types of reports. Reporting features are very good and anyone from the compliance team can view/generate a report according to compliance support.
Auto remediation is a very effective feature that helps ensure less manual intervention.
Support of AWS Lamda and Azure Functions helps for any potential breaches.
What needs improvement?
Almost all features are good, however, they still require improvements to the code security portion on which integration with the major source code repository is required.
Integration with CI/CD is an important aspect as it is needed to secure the environment. Having it will help a lot.
Integration with Docker is also a key feature that needs some improvements.
Integration with other third parties and with SIEM is an important aspect that should be addressed.
Currently, it provides integration with Tenable, but it would be good if it had support other VAPT software as well.
For how long have I used the solution?
We have been using Check Point CloudGuard Posture management for the last 8+ months.
What do I think about the stability of the solution?
The solution is very stable and we have not found any gaps. It provides seamless integration with the public cloud.
What do I think about the scalability of the solution?
It's a highly scalable solution and integration with the public cloud is very good. The way you can centralize the dashboard of entire cloud infra is a very impressive.
How are customer service and support?
Support has been good. We implement it with the help of OEM support and whenever we've required help we've received a good response.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Earlier, we tested other tools as well, however, the features which were available via Check Point are very good and the future roadmap is also very good in regards to cloud security.
How was the initial setup?
The setup is straightforward and seamless.
What about the implementation team?
We implemented it with help of Check Point support. The rest was managed by our internal team as it's easy to handle.
What was our ROI?
Security is very important and gives us ROI from security itself. We also get an ROI as we have less administrative effort. We can see an ROI with the compliance and risk management on offer too.
What's my experience with pricing, setup cost, and licensing?
The setup cost is very affordable and very easy. Integration with the public cloud is very easy. The licensing calculation is also very good and no manual effort is required.
Which other solutions did I evaluate?
We evaluated other tools like Rapid7, Qualys, and AWS native security tools, as well as Azure native security tools.
What other advice do I have?
It's a very strong solution for cloud security posture management and very effective for large and mid-size environments. Any organization moving towards the cloud would benefit from this.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: I am a real user, and this review is based on my own experience and opinions.