Try our new research platform with insights from 80,000+ expert users
Cloud Security SME at a computer software company with 1-10 employees
Real User
Top 20
Provides a single pane of glass and good value for money, but the account onboarding has room for improvement
Pros and Cons
  • "The most valuable feature is the ability to apply common tools across all accounts."
  • "The integration process could be enhanced by enabling integration at the organizational level rather than requiring the manual setup of individual accounts."

What is our primary use case?

We use Check Point CloudGuard Posture Management to maintain our organization's security posture.

How has it helped my organization?

With a bit of upscaling, it is possible to write custom rules and policies using the GSL Builder. We used the GSL Builder to build the rules for our playground environment and internet-facing environments.

It takes a couple of weeks for a nontechnical person to learn how to use GSL Builder.

The Unified Security Management console is helpful because it provides a single pane of glass. 

From a control plane perspective, the solution offers excellent visibility into our framework, enabling the identification of non-compliance.

CloudGuard provides good value for money in terms of automating our security across multiple clouds.

The agentless workload posture analysis, which primarily focuses on our cloud platform, provided valuable insights into our organization's overall security posture.

CloudGuard helped to eliminate some manual processes for a few teams, freeing up some of their time.

Our organization's security operations were able to save time by using CloudGuard's unified platform.

What is most valuable?

The most valuable feature is the ability to apply common tools across all accounts.

What needs improvement?

The integration process could be enhanced by enabling integration at the organizational level rather than requiring the manual setup of individual accounts. The current workflow of creating and linking each role is time-consuming and labor-intensive. Streamlining account onboarding by allowing CloudGuard to identify and integrate at the organizational level would significantly simplify the process.

Buyer's Guide
Check Point CloudGuard CNAPP
December 2024
Learn what your peers think about Check Point CloudGuard CNAPP. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
823,875 professionals have used our research since 2012.

For how long have I used the solution?

I have been using Check Point CloudGuard Posture Management for one year.

What do I think about the stability of the solution?

Check Point CloudGuard Posture Management is stable.

What do I think about the scalability of the solution?

CloudGuard Posture Management is scalable, as it is a SaaS product.

Which solution did I use previously and why did I switch?

Before implementing Check Point CloudGuard Posture Management, we relied on the native CSPM of AWS Config.

For beginners in the field, AWS might be a good starting point due to its simplicity. However, for more experienced users who require more advanced features, CloudGuard offers a more mature and comprehensive solution.

What other advice do I have?

I would give Check Point CloudGuard Posture Management a rating of seven out of ten. Consolidating additional capabilities into CloudGuard, along with Fusion, would create a comprehensive package offering for customers. This, along with maintaining compatibility with the evolving AWS service, would help to avoid complicating any integration issues.

While developing our tools, there is always a need for ongoing review and updates. However, compared to AWS, the maintenance required for CloudGuard is minimal.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer2514357 - PeerSpot reviewer
Technical Analyst (Cyber Security) at a consultancy with 51-200 employees
Real User
Top 20
Patches cloud vulnerabilities and automates all the patching and reporting
Pros and Cons
  • "The solution's main benefit is that it automates all the patching and reporting parts and generates an automated report."
  • "Sometimes, the solution provides us with false alerts of vulnerabilities that are not present in our cloud environment."

What is our primary use case?

I work with the solution for patching over all the cloud vulnerabilities. We have a different monitoring team that monitors all the alerts on the solution. They send us a report, and we work on that report to patch all the vulnerabilities of our cloud environment, such as Azure and AWS.

What is most valuable?

The solution's main benefit is that it automates all the patching and reporting parts and generates an automated report. The solution automatically notifies you whenever any alert comes into your cloud environment via mail or message.

What needs improvement?

Sometimes, the solution provides us with false alerts of vulnerabilities that are not present in our cloud environment. The solution should include an auto-remediation feature, which most tools currently provide.

For how long have I used the solution?

I have been using the solution for three years.

What do I think about the stability of the solution?

Apart from the occasional false positives in the reports, we haven't had any issues with the solution's performance or stability.

What do I think about the scalability of the solution?

Check Point CloudGuard CNAPP is a scalable solution.

The solution is implemented in multiple locations, and each location has around 300 users.

How are customer service and support?

We contacted the technical support team during the deployment phase, and their support was very good and responsive.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We previously used CrowdStrike. We switched to Check Point CloudGuard CNAPP because CrowdStrike lacked many features. Check Point CloudGuard CNAPP is a more advanced version of CrowdStrike, integrated with AI capabilities. It also provides different automatic reports, such as compliance reports.

How was the initial setup?

Around three to four people were involved in the solution's deployment. Since there are multiple environments in the cloud, it takes an entire day to deploy the tool.

What other advice do I have?

The solution's cloud security posture management scans your cloud environment and cloud-configured policies and gives you a report of all the loopholes in your cloud environment. You can also get compliance reports from the solution, and I am completely satisfied with its effectiveness.

The solution's cloud security posture management identifies risks most critical to the business and segregates them into low, medium, and high categories. The solution's workload protection capabilities provide protection for VMs. The scanning provided by the solution's workload protection capabilities helps us identify problems before they go live.

We can schedule the solution to scan our cloud environment daily for vulnerabilities. The solution takes 20 to 25 minutes to scan the entire cloud environment. Earlier, it used to take an entire day because we had to perform all the manual tasks to find out all the loopholes in our cloud environment.

Before using the solution, we used to spend an entire day finding all the loopholes in our cloud environment. Check Point CloudGuard CNAPP automated most of our tasks by providing automatic reports to our security team. We also use the solution's CDR capabilities.

The visibility we get from the solution's CDR capabilities helps simplify incident investigation time or process. After providing all the loopholes in our cloud environment, the solution provides a step-by-step remediation plan to fix particular vulnerabilities. We extract the report from the tool and work on the patching part.

We perform intrusion detection and threat hunting from the same console. Check Point CloudGuard CNAPP is a SaaS-based solution. All the configurations have gone through the secret key we fetch from the cloud environment and integrate with the solution. From there, it fetches all the configurations for the entire cloud environment.

I would recommend the solution to other users.

Overall, I rate the solution ten out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
PeerSpot user
Buyer's Guide
Check Point CloudGuard CNAPP
December 2024
Learn what your peers think about Check Point CloudGuard CNAPP. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
823,875 professionals have used our research since 2012.
Evans Vs - PeerSpot reviewer
Engineer at Digitaltrack
User
Top 5Leaderboard
Excellent efficiency and accuracy with very good cost-effectiveness
Pros and Cons
  • "The valuable features of Checkpoint CloudGuard CNAPP include its automation capabilities."
  • "Improvements can be made to the user interface."

What is our primary use case?

Check Point CloudGuard CNAPP is primarily designed to protect cloud-native applications and their underlying infrastructure from cyber threats. The primary use cases of this solution are comprehensive cloud security, workload protection, cloud security posture management, DevSecOps integration, threat detection and response, compliance and risk management.

How has it helped my organization?

Checkpoint CloudGuard Cnapp has improved efficiency, accuracy, cost-effectiveness, data-driven decision making and customer satisfaction.

What is most valuable?

The valuable features of Checkpoint CloudGuard CNAPP are automation capabilities, integration with existing systems, real-time analytics and reporting, customization and flexibility, security and compliance, scalability and growth support and a user-friendly interface.

What needs improvement?

Improvements can be made to the user interface, performance and reliability, security and compliance, and customer support.

For how long have I used the solution?

I've used the solution for the past year.

What do I think about the stability of the solution?

The stability is good.

What do I think about the scalability of the solution?

The scalability is nice.

How are customer service and support?

Technical support is good.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

No, I did not previously use a different solution. 

What about the implementation team?

The solution was set up via our in-house team.

What was our ROI?

The ROI is okay.

What's my experience with pricing, setup cost, and licensing?

The pricing and licensing can be improved.

Which other solutions did I evaluate?

No, I did not evaluate another solution. 

Which deployment model are you using for this solution?

Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
PeerSpot user
Adrian Cambronero - PeerSpot reviewer
Consultant at ITQS
Reseller
Top 5Leaderboard
Robust, complete, and offers good visibility
Pros and Cons
  • "It presents great visibility of the traffic flow of our cloud, providing information on what data and users are circulating and in the event of a threat, it immediately identifies them by providing detailed and granular information from our entire environment."
  • "It should have some options to activate API calls to the platform in the cloud, another improvement would be that when the rules are colonized and they want to be published."

What is our primary use case?

We pull all of our cloud platforms into Microsoft Azure. We needed a tool that would provide us with provides policy compliance to be able to monitor our environment. In the case something is in violation of one of those rules, it will let us know and we can correct it. 

It is also very flexible to configure users, and authentication methods and thus be able to control the activities of each of the system administrators and users, another one of the functionalities it presents is that it allows us to monitor the records of our environment in the Azure Cloud and be able to take the necessary measures if there is a problem.

How has it helped my organization?

One of the reasons we were able to implement this solution is that it gives us complete visibility into the workload that we have hosted on our Microsoft Azure platform. This tool came to help improve our security environment in the cloud and provide more detail through reports such as compliance and security, as it shows us complete visibility of the traffic that is flowing to our Azure platform.

Another reason we implemented it and it caught our attention was the access control to our Azure cloud. Every time a policy is created for each purpose, it immediately blocks the access for which it was designed. Dome9 provides excellent visibility.

What is most valuable?

Check Point CloudGuard Posture Management presents great values, such as the IAM role control, since if it does not meet the established parameters, these controls will not allow the creation of users, and policies that are not allowed.

It presents great visibility of the traffic flow of our cloud, providing information on what data and users are circulating and in the event of a threat, it immediately identifies them by providing detailed and granular information from our entire environment. 

It also has and provides the ability to provide recommendations of the errors that exist and thus be able to correct them as soon as possible

What needs improvement?

The service is very complete for the functionality that it was created for, however, they can make a couple of improvements such as the validation of policies that must be available before they are implemented in the production environment. It should have some options to activate API calls to the platform in the cloud, another improvement would be that when the rules are colonized and they want to be published. They do not update as they should and the new rules are not applied. They can also try to reduce the false positives generated by the tool.

For how long have I used the solution?

This solution has been used for approximately five years in the company.

What do I think about the stability of the solution?

One of the reasons why we chose to do the implementation with Check Point was its stability. Its performance is very good.

What do I think about the scalability of the solution?

My impression was that the scalability was very good. It is a super scalable product.

How are customer service and support?

On some occasions, we have had problems as they do not send the meetings on time or it takes a long time to resolve a case. However, on other occasions, they resolve very quickly.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Check Point was always our first option as many security teams are from Check Point.

How was the initial setup?

The configuration was very simple. The application is a very user-friendly tool - apart from training and courses for implementation.

What about the implementation team?

A Check Point engineer who had a lot of experience helped us with the implementation.

What was our ROI?

When making an investment with these tools you are taking care of an important patrimony that will double your profits.

What's my experience with pricing, setup cost, and licensing?

Check Point always manages good prices and costs in the tools they sell.

Which other solutions did I evaluate?

We do not evaluate other options. We wanted to continue implementing the same brand since the other products have helped us a lot in the security of our company.

What other advice do I have?

Users can fully rely on Check Point products as they are robustly designed for security.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Microsoft Azure
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Adrian Cambronero - PeerSpot reviewer
Consultant at ITQS
Reseller
Top 5Leaderboard
Agentless, fast, and precise
Pros and Cons
  • "It has great scalability."
  • "They take time to respond or coordinate a meeting since they maintain a schedule that does not fit Latin America very well."

What is our primary use case?

As an organization, we have implemented Azure Microsoft and AWS for some applications. Most of the workloads are managed in the cloud. Therefore we needed a tool that could protect us against some type of cyber threat that would generate losses in the apps that are being used. We apply CloudGuard Workload that comes to us to cover all those security breaches that we could see presenting. In the beginning, we used the free trial to do some tests, and it worked for what we needed it for, and then we acquired it with all the functionalities

How has it helped my organization?

CloudGuard Workload Protection came to help us a lot in the organization in the application development part since it is one of the areas where there is more workflow and vital generation of the company since applications are generated and modified daily. With this tool, IT came to us to help provide a series of security layers to all these flows by providing us with different types of security options such as alerts and improvements. One of the characteristics that we liked very much is that it can be coupled with different public clouds.

What is most valuable?

One of the CloudGuard Workload Protection features that we liked a lot is the security it handles in containers. 

Another interesting thing is that it works without an agent involved. 

It also offers great complete visibility of all devices, and assets in the cloud, which allows us to control all those assets, thus generating complete analysis of the infrastructure in real-time. In this way, we've been able to attack the points where there is some vulnerability in our infrastructure and being able to be at the forefront of security.

What needs improvement?

It cost us a little to find some information about CloudGuard Workload Protection. It cost us to find information about the tool and recommendations.

The configuration administration documentation is not very available on the web, or it is not completely updated. They should also improve the support so that we can create a case and they can respond faster. They take time to respond or coordinate a meeting since they maintain a schedule that does not fit Latin America very well. It is sometimes difficult to coordinate support hours. 

They do not provide a concrete and rapid solution which causes security implementations to be delayed.

For how long have I used the solution?

The solution was implemented a¿twoo ago.

What do I think about the stability of the solution?

So far, the stability of the product has remained excellent. We have not presented any failures.

What do I think about the scalability of the solution?

It has great scalability. It's very fast and precise.

How are customer service and support?

The support offered by Check Point in general is very regular.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

No other solution has been implemented.

How was the initial setup?

Like all setup-type software, it is very easy to install.

What about the implementation team?

The implementation was done in conjunction with a support team from the company and the supplier.

What was our ROI?

The implementation of a security tool is always an excellent investment. One thing outweighs the other.

What's my experience with pricing, setup cost, and licensing?

The installation of the product is very reliable, and fast, and it is a very competitive cost in the market.

Which other solutions did I evaluate?

Check Point was the first solution we used. It was recommended by third parties.

What other advice do I have?

It is a very complete tool for workflows. It provides excellent security.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Adrian Cambronero - PeerSpot reviewer
Consultant at ITQS
Reseller
Top 5Leaderboard
Great centralized monitoring, alerts, and helpful integration
Pros and Cons
  • "The CloudGuard for Cloud Intelligence tool has several significant features that provide security to our company."
  • "Check Point tools need to improve the latency in the portal since they take a long time to load."

What is our primary use case?

Currently, the company I work for has implemented several cloud solutions such as Azure and AWS, in which they are migrating from AWS to Azure to have everything unified in a single environment. 

At the moment, we have different applications in both clouds, which have their own system of security in the environments. Recently, in the country there were several ransomware attacks on government companies they were the target due to this we decided to expand security a little more and it was where we made use of Check Point tools that will help us comply with a more centralized security that is more robust on all our end devices.

How has it helped my organization?

We have made the decision to centralize our security infrastructure via that CloudGuard for Cloud Intelligence tool. It has contributed a lot to security since many companies were having security problems. We decided we could be one of the few that was not violated with this tool as it gave us a lot of security and helped us avoid vulnerabilities. We were able to counteract attacks with the recommendations that the tool gave us since each point of vulnerability that we found told us how to increase security. That is how our organization was able to survive even an attack.

What is most valuable?

The CloudGuard for Cloud Intelligence tool has several significant features that provide security to our company. These are helping us to prevent misfortune. Some of these features are centralized monitoring, alerts that indicate some type of vulnerability, recommendations on how to reduce these vulnerabilities, and configuration and monitoring of policies, all based on real-time monitoring with excellent efficiency. They are very effective.

One of the most effective functionalities is integration with the cloud since a match can also be done between the two. 

What needs improvement?

Check Point tools need to improve the latency in the portal since they take a long time to load. 

They also need to improve the support a little or hire more staff since the response time is slow or the solutions take a long time to implement.

Check Point should give added value to all those customers who purchase their product by providing training so that they can certify in the tool. That way, the customer stops depending so much on support and can solve incidents themselves.

For how long have I used the solution?

I've used the solution for approximately Three year.

What do I think about the stability of the solution?

The stability is very good. Even when updates are made, it has not presented any type of failure.

What do I think about the scalability of the solution?

The tool has excellent scalability.

How are customer service and support?

The support must improve the level of service and must train their staff a bit more.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Currently, we only had other Check Point tools.

How was the initial setup?

Making the investment is a bit high, however, it is very effective to make the acquisition of the tool.

What about the implementation team?

The implementation was done with the help of the vendor and an engineer.

What was our ROI?

Here it will be reflected in the long term since it is not something tangible but by making the investment in security we can have a company always working

What's my experience with pricing, setup cost, and licensing?

The cost is a bit high, however, the investment is worth it.

Which other solutions did I evaluate?

We evaluated Palo Alto and Cisco however, they forced us through Check Point at the company.

What other advice do I have?

The solution is very effective. It fulfills perfectly for what it was made to do.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Microsoft Azure
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Nagendra Nekkala - PeerSpot reviewer
Senior Manager ICT & Innovations at Bangalore International Airport Limited
Real User
Top 5Leaderboard
Helps to improve security score with real-time information
Pros and Cons
  • "Check Point CloudGuard CNAPP's initial configuration is very easy. It is plug-and-play. It also gives regular updates."
  • "The tool should incorporate more use cases like improving security scores. It should also improve documentation."

What is our primary use case?

We want network security through machine learning. The product offers threat detection and intelligence for the endpoints. It also provides real-time information on application security. 

What is most valuable?

Check Point CloudGuard CNAPP's initial configuration is very easy. It is plug-and-play. It also gives regular updates. 

What needs improvement?

The tool should incorporate more use cases like improving security scores. It should also improve documentation.  

For how long have I used the solution?

I have been using the product for a year. 

What do I think about the stability of the solution?

The product is stable. 

What do I think about the scalability of the solution?

Check Point CloudGuard CNAPP is scalable. My company has more than 1000 users. 

How are customer service and support?

Check Point CloudGuard CNAPP's support is very good. 

How would you rate customer service and support?

Positive

How was the initial setup?

The tool's deployment is very easy and takes two weeks to complete. We need engineers to install the product. You need to ensure the overall device landscape before the product's installation. Its maintenance is easy. 

What was our ROI?

I can get 50-60 percent ROI with the tool's use. 

What's my experience with pricing, setup cost, and licensing?

The tool's pricing is moderate. Its licensing costs are yearly. 

What other advice do I have?

The solution helps to improve security scores, which is important for auditing and compliance. I rate it a nine out of ten. 

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Mohan Janarthanan - PeerSpot reviewer
Assosiate Vice President at Novac Technology Solutions
Real User
Top 5
Great asset detection, risk assessment, and remediation processes
Pros and Cons
  • "It offers security insights and recommendations to assist organizations in acting and remediating issues swiftly."
  • "Compliance checks on cloud resources against various industry standards and compliance framework templates need to be improved."

What is our primary use case?

CloudGuard constantly monitors cloud systems for misconfigurations and vulnerabilities that attackers could exploit. Many processes associated with cloud security management, such as asset detection, risk assessment, and remediation, are automated by CloudGuard. This allows security teams to concentrate on more strategic efforts. CloudGuard is intended to assist organizations in securing their cloud environments by continuously monitoring and analyzing cloud setups for misconfigurations, vulnerabilities, and compliance violations.

How has it helped my organization?

Many of the duties associated with maintaining cloud security are automated by CloudGuard, including asset detection, risk assessment, and remediation. 

In addition to improving compliance, this frees up security personnel to concentrate on more strategic initiatives and enables organizations to adhere to industry standards and laws like PCI DSS, HIPAA, and GDPR. 

It offers security advice and insights to assist organizations in acting quickly to address concerns. It also has automated remediation capabilities to address found problems and automatically enact security policies.

What is most valuable?

The asset detection, risk assessment, and remediation processes are only a few of the duties that CloudGuard automates while managing cloud security. This improves compliance, enables organizations to adhere to industry standards and laws like PCI DSS, HIPAA, and GDPR, and frees up security personnel to concentrate on more strategic objectives. 

It offers security insights and recommendations to assist organizations in acting and remediating issues swiftly. It also has automated remediation capabilities to address found issues and automatically enforce security policies.

What needs improvement?

Compliance checks on cloud resources against various industry standards and compliance framework templates need to be improved, to ensure that organizations meet regulatory requirements with clear visibility action controls. This can make it difficult to create and manage custom security policies. 

Cloud security posture management is a proprietary solution, which means that there is no open-source community to support it. This can make it difficult to get help with troubleshooting and other issues.

For how long have I used the solution?

We have been adopting the solution for more than a year.

What do I think about the stability of the solution?

CloudGuard is known for being highly scalable and reliable. It handles big cloud workloads with ease and may be implemented in complex cloud infrastructures.

What do I think about the scalability of the solution?

In terms of cloud solutions, the scalability was a fairly simple and entirely software-driven approach.

How are customer service and support?

The customer support is good and offers regularly updated new features and security patches. This ensures that CloudGuard is always protected against the most advanced threats.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We adopted our cloud journey last year, and while developing the cloud, we took all security precautions. CSPM was a priority solution, and we have apt.

How was the initial setup?

We implemented CSPM in 30 days. Since the solution was simple to implement and the transition was painless, we added many of our cloud environments.

What about the implementation team?

We implemented the solution through a partner.

What was our ROI?

CloudGuard's return on investment (ROI) varies based on the organization and its cloud environment.

What's my experience with pricing, setup cost, and licensing?

CSPM is an invaluable resource for any organization that makes use of cloud computing. It can assist organizations in improving their cloud security posture, reducing the risk of cyberattacks, and adhering to industry norms and regulations.

Which other solutions did I evaluate?

We evolved various CSPM tools such as PAN, TRELIX, and Fortinet, however, our management opted to install CloudGuard as a strategic step.

What other advice do I have?

CloudGuard provides a comprehensive set of security solutions for cloud environments.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free Check Point CloudGuard CNAPP Report and get advice and tips from experienced pros sharing their opinions.
Updated: December 2024
Buyer's Guide
Download our free Check Point CloudGuard CNAPP Report and get advice and tips from experienced pros sharing their opinions.