Try our new research platform with insights from 80,000+ expert users
Cloud & DevOps Team Leader at a tech company with 501-1,000 employees
Real User
Wraps our FTP infrastructure with network security and allows us to monitor FTP activity
Pros and Cons
  • "Dome9 wraps our FTP infrastructure with its network security configurations, and this also gives us the ability to monitor FTP activity."
  • "Gives us centralized firewall management for both Windows and Linux distros. Also provides a clear view of the security configurations and connections across environments (DMZ, external and internal networks)."
  • "The user interface is responsive and quite intuitive; when selecting an object it automatically shows the relevant actions."
  • "I’d like to see more integration with third-party tools. For example, it would be helpful to have an integration between Dome9 and ServiceNow to manage security incidents and security changes."

How has it helped my organization?

We have an FTP infrastructure that is accessed by customers. As FTP service is quite vulnerable if not secured properly, before implementing Dome9 we had to apply multiple security solutions on the FTP servers.

Dome9 wrapped the FTP infrastructure with its network security configurations. This gives us the ability to monitor FTP activity as well.

What is most valuable?

  • Centralized firewall management for both Windows and Linux distros - This is something that everyone is looking for. The initial version of Dome9 was one where you managed all the rules centrally in Linux and Windows, which was quite challenging. Now, to see in a single pane of glass, all the agents, all the rules, everything that is going on in out datacenters, is quite valuable.
  • Visibility of the security configurations
  • Clear view of the security configurations and connections across environments (DMZ, external and internal networks)
  • The user interface is responsive and quite intuitive; when selecting an object it automatically shows the relevant actions

What needs improvement?

I’d like to see more integration with third-party tools. For example, it would be helpful to have an integration between Dome9 and ServiceNow to manage security incidents and security changes.

For how long have I used the solution?

Three to five years.
Buyer's Guide
Check Point CloudGuard CNAPP
January 2025
Learn what your peers think about Check Point CloudGuard CNAPP. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,020 professionals have used our research since 2012.

What do I think about the stability of the solution?

I don’t recall any stability issue from the first time we used it. It has been solid and reliable.

What do I think about the scalability of the solution?

I didn’t encounter any scalability challenges. According to the vendor, we are far from the limit that has been tested by the vendor so far.

How are customer service and support?

The technical support has been very professional and helpful. They are knowledgeable and answer our questions in a timely fashion.

Which solution did I use previously and why did I switch?

We had been using iptables on Linux servers but it was missing centralized management. Also, configuring firewall security rules was quite a nightmare, especially testing.

How was the initial setup?

The initial setup was straightforward, as the solution is quite intuitive.

What's my experience with pricing, setup cost, and licensing?

In order to obtain better pricing, I would advise taking into account the existing number of devices and add a forecast of the number of devices to be added in the coming year or two. The company has multiple modules that you purchase independently or in groups, depending on your needs.

Which other solutions did I evaluate?

When we did market research five years ago, there were not many alternatives in the market for our purposes. We looked at Kaspersky Lab and Trend Micro but they didn’t address our needs.

We ran a PoC with Dome9 and it was transformed quickly into production.

What other advice do I have?

My advice would be:

  • Share your project goal(s) with the vendor to help you map the functionalities and modules needed, to be implemented in phases, during implementation.
  • Map your existing security configurations and create a lab to test them with and without Dome9.
  • Implement the solution progressively and look at the logs in the Dome9 application to learn about the network activity.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
PeerSpot user
CEO at a tech vendor with 11-50 employees
Real User
Top 20
Has amazing coverage and a very sophisticated way of building new queries
Pros and Cons
  • "The most valuable features of CloudGuard CNAPP are its compliance engine and auto-remediation features."
  • "There are opportunities for improvement that can be addressed through a roadmap."

What is our primary use case?

I use it for cloud visibility detection and remediation. I also use it for reporting and dashboarding.

What is most valuable?

The most valuable features of CloudGuard CNAPP are its compliance engine and auto-remediation features.

What needs improvement?

CloudGuard CNAPP is a great tool that justifies its investment. Like any other tool, there are opportunities for improvement that can be addressed through a roadmap.

For how long have I used the solution?

I have been using Check Point CloudGuard CNAPP for six years.

What do I think about the scalability of the solution?

I would rate the scalability of the solution as a ten out of ten.

How are customer service and support?

I would rate the technical support as seven out of ten. It is good when we get attention, but sometimes it is a bit difficult to get the attention we need.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

We opted for CloudGuard CNAPP over other solutions mostly due to its flexibility.

How was the initial setup?

The implementation of the solution was easy.

What was our ROI?

There has been a significant ROI for me because now I can reduce risks effectively, and every risk I mitigate is a return on investment for the platform.

What other advice do I have?

CloudGuard CNAPP has been crucial in giving us visibility into our cloud setup and has significantly lowered our risks by enabling better control over our cloud security.

I find that CloudGuard CNAPP 's cloud security posture management is exceptional for addressing both physical and digital security concerns. It offers extensive coverage and provides a straightforward yet sophisticated method for creating and implementing new security queries.

My advice would be to define your use cases very well when considering this solution.

Overall, I would rate CloudGuard CNAPP as an eight out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Buyer's Guide
Check Point CloudGuard CNAPP
January 2025
Learn what your peers think about Check Point CloudGuard CNAPP. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,020 professionals have used our research since 2012.
LucianoMiguel - PeerSpot reviewer
Security Consultant at a consultancy with 501-1,000 employees
Real User
Top 5
Easy to manage, great visibility, all from a single dashboard
Pros and Cons
  • "The most valuable feature is the single dashboard that enables us to manage the entire cloud environment from one place."
  • "The dashboard customization has room for improvement."

What is our primary use case?

We utilize Check Point CloudGuard Posture Management to gain visibility into our cloud environments and their configurations. The cloud services we employ include AWS, Azure, and GCP.

How has it helped my organization?

A while back, we deployed Kubernetes, and it was exposed to the internet, resulting in the environment being affected by malware. Check Point CloudGuard Posture Management has helped our organization prevent such attacks from occurring in our environment.

What is most valuable?

The most valuable feature is the single dashboard that enables us to manage the entire cloud environment from one place.

What needs improvement?

The dashboard customization has room for improvement.

For how long have I used the solution?

I have been using Check Point CloudGuard Posture Management for four years.

What do I think about the stability of the solution?

Check Point CloudGuard Posture Management is highly stable. There was only one instance when the solution experienced downtime.

How are customer service and support?

The technical support is good.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup is straightforward.

What's my experience with pricing, setup cost, and licensing?

Check Point CloudGuard Posture Management is expensive.

What other advice do I have?

I give Check Point CloudGuard Posture Management a ten out of ten.

Check Point CloudGuard Posture Management is an important component of a cloud environment that enables us to gain visibility across all areas and configure easily. I highly recommend this solution.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Real User
Top 10
Provides detailed information, and is stable, but the rules are not well-tuned
Pros and Cons
  • "The ability to drill down to individual hosts on an account and see which ones are affected is valuable."
  • "The rules are not well-tuned, and many of them generate false positives or nonsensical results."

What is our primary use case?

We review CloudGuard results and generate tickets to contact the owners.

How has it helped my organization?

Check Point CloudGuard Posture Management will improve the organization. Currently, it is operating as a stopgap measure to address these issues. This is because there are a lot of them being generated. They are working on automation to automatically create tickets and track when issues are remediated. So, hopefully, when that comes into play, it will be a much more valuable tool.

What is most valuable?

The ability to drill down to individual hosts on an account and see which ones are affected is valuable. This is because we have a lot of cases where people remediate part of the solution on half of their hosts, but don't realize that they have more hosts that need to be addressed.

What needs improvement?

The rules are not well-tuned, and many of them generate false positives or nonsensical results. For example, they might flag port 443 as open, even though it is supposed to be open for a public web server. There needs to be a better way to exclude certain hosts that are compliant and are supposed to be open.

For how long have I used the solution?

I have been using Check Point CloudGuard Posture Management for three months.

What do I think about the stability of the solution?

The solution has not crashed yet, and there are a lot of findings, so that is a good sign of its stability.

What do I think about the scalability of the solution?

The solution is able to handle a large number of vulnerabilities, so it seems to be able to scale well.

What was our ROI?

We've only been using the solution for a few months, but we're already starting to see the numbers go down. This is encouraging, but it's important to be aware of any vulnerabilities that may exist so that we can take steps to address them.

What's my experience with pricing, setup cost, and licensing?

I'm glad I don't have to pay the licensing fee. Everything in this field is very expensive. I don't have a say in the matter.

What other advice do I have?

I give Check Point CloudGuard Posture Management a six out of ten. It could be better once fully tuned and properly deployed.

My usage is rather difficult because the client has not spent much time tuning the solution, as they are planning to automate a lot of it. As a result, I am currently the manual.

The solution actually created more work for the staff because it made them aware of all the vulnerabilities. As a result, their priority is now to fix them, which created a lot of work and a lot of tickets.

I wish I had been involved in the deployment because I would have done it differently.

At the RSA conference, we receive a lot of promotional items.

The RSA conference does not impact our organization's cybersecurity purchases.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Support at a security firm with 51-200 employees
User
Top 5Leaderboard
Great management, good security, and offers automated compliance checks
Pros and Cons
  • "Helps identify and correct misconfigurations in cloud environments, ensuring that infrastructure and applications are secure and optimized."
  • "The Check Point solution is somewhat expensive."

What is our primary use case?

Check Point CloudGuard Posture Management has helped us a lot with generating a more secure public cloud. It tries to verify and apply improvements in order to seek to avoid vulnerabilities in environments such as Azure.

The tool is really robust. It allows us, through evaluations, to verify our compliance, detecting and correcting it in a timely manner.

The integration with the intelligence tool helps us a lot to detect and prevent threats in a timely and effective manner.

How has it helped my organization?

At a business level, Check Point CloudGuard Posture Management helps us a lot with the management, security, control, and prevention of cyber threats in multi-cloud environments. In our case, our environments are both in Microsoft Azure and local environments.

Another great help is in identity. It helps us to manage your protection in a timely manner. Compliance evaluations are great for all security.

In addition, the Check Point Infinity Portal is quite good and centralized.

What is most valuable?

The key features of Check Point CloudGuard Posture are:

  • The ability to provide automated compliance checks.
  • Helps identify and correct misconfigurations in cloud environments, ensuring that infrastructure and applications are secure and optimized.
  • Provides visibility into cloud infrastructure, applications, and security posture.
  • Automates security policies and remediation actions to ensure cloud environments remain secure and compliant.               

What needs improvement?

Some CloudGuard Check Point positions are not required by the company, however, if we do not apply it, it affects our score.

The support SLA is not met. Sometimes they don't seem to like solving cloud issues or modern security applications.

The Check Point solution is somewhat expensive. It must be validated first before purchasing it. 

For how long have I used the solution?

We used the solution for our public cloud environment with Azure, over the last year.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
PeerSpot user
Security IT at a tech services company with 51-200 employees
Real User
Top 5Leaderboard
Very easy to use with good security and others
Pros and Cons
  • "We really liked its ease of implementation against our Microsoft Azure environment."
  • "The support must be more effective."

What is our primary use case?

We required a centralized, modern, and easy-to-use tool. After validating the technology of the available security applications, we found the correct tool in Check Point CloudGuard.

It helped us with the security posture to follow best practices. The recommendations and the automated implementations are through a multi-cloud portal that was easily linked with the cloud that we manage. All those previous virtues plus an effective dashboard full of graphs have helped us with decision making. It's been very helpful for the company's security requirements.

We have been able to comply with the recommendations and improvements in our cloud infrastructure using this product.

How has it helped my organization?

Thanks to the best practices recommended in the CloudGuard Posture Management, we were able to provide an incredible layer of security to our Microsoft Azure environment. We required a great layer of security to be able to certify ourselves with security regulations.

Also, all its reports are very useful to be able to carry out good work of improvements and avoid vulnerability within the multi-cloud perimeter.

Another requirement was not to have different security environments. The CloudGuard Posture Management correctly met the business needs.

What is most valuable?

We really liked its ease of implementation against our Microsoft Azure environment.

In addition, its centralized portal, which showcases multiple security solutions in one place, is very helpful.

Another feature that we really liked is the score function for improvements and good practices. You can take a security posture that complies with regulations or company policies.

What needs improvement?

Areas that can be improved are few. However, some can be mentioned, such as the costs for this solution going down a bit. Not all clients, despite the great power of the tool, can afford it.

The support must be more effective. Sometimes they take several days to resolve an issue. However, it must be mentioned, they always resolve it correctly.

Finally, I think that the solution meets all expectations but can also improve the performance of the administrator portal a little so that it does not sometimes stop.

For how long have I used the solution?

This is a very good cloud tool and has been used in the last quarter with surprising results.

What do I think about the stability of the solution?

We have witnessed very good performance with the solution.

What do I think about the scalability of the solution?

The solution offers excellent performance.

Which solution did I use previously and why did I switch?

We have not found a more centralized, powerful, or complete solution than Check Point Cloud Guard Posture Management, neither before nor now.

What's my experience with pricing, setup cost, and licensing?

It is essential to validate the costs and have a good representative for Check Point that can provide security in the tools. They need to be able to understand your needs as clients.

Which other solutions did I evaluate?

We continuously evaluate various options and manufacturers, however, on its own merits, the Check Point solution became our first choice.

What other advice do I have?

It's an excellent tool that is a bit expensive yet worth it.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
PeerSpot user
Security IT at a tech services company with 51-200 employees
Real User
Top 5Leaderboard
CloudGuard Intelligence - Infinity Portal
Pros and Cons
  • "The ability to integrate it with Microsoft Azure Sentinel allows us to validate the logs in an even more complex and meaningful way."

    What is our primary use case?

    We required a tool for our Microsoft Azure environment to validate and find threats under machine learning, forensic validations, and extremely important reports for the company to determine possible vulnerabilities and change the infrastructure to improve the security posture of our public cloud environment.

    We also needed an environment that could show us monitoring and dashboards of value to improve our security easily.

    One of the most important details to monitor is the network in our infrastructure, based on those requirements, we look for a tool, in this case, Check Point.

    How has it helped my organization?

    The Check Point CloudGuard Intelligence tool helped us perfectly with the search for a cloud security posture for our environments and security in the Microsoft Azure cloud, a centralized environment, and has great features within the tool, such as forensic analysis. In case of any vulnerability, we had to determine what happened.

    As for the reports, we could help determine what happened, valuable details which allowed us to generate greater security according to the values shown.

    What is most valuable?

    The most important features that we like in Check Point CloudGuard Intelligence are the centralization of the security environment within the Check Point Infinity Portal, which already has other security tools that we have and that can also be managed from this site.

    Forensic analysis is one of the features we liked a lot since it is easy to understand and helps us improve security.

    The ability to integrate it with Microsoft Azure Sentinel allows us to validate the logs in an even more complex and meaningful way.

    What needs improvement?

    Something that needs to be improved little by little in tools like Check Point CloudGuard Intelligence is the lowering of costs as some customers can't buy such a solution. They could also sell it based on various versions for different customers and various business needs.

    It is also important to improve performance issues at the Infinity Portal level, which is sometimes slow, yet not always.

    We would like there to be more public documentation to generate implementations with best practices.

    For how long have I used the solution?

    We started using the application no more than a year ago. It's excellent for the analysis of the public cloud infrastructure.

    What do I think about the stability of the solution?

    This is a really stable solution.

    What do I think about the scalability of the solution?

    The solution is incredibly scalable and managed by Check Point Infinity Portal infrastructure.

    Which solution did I use previously and why did I switch?

    We had never used or known a tool like Check Point CloudGuard.

    What's my experience with pricing, setup cost, and licensing?

    The best option is to have a partner who helps them with support in addition to helping with cost issues since pricing is not public.

    Which other solutions did I evaluate?

    We always value various issues such as centralized environments, costs, and support, among other details to make the best decision. Even so, with this validation, the best option for our company is Check Point.

    Which deployment model are you using for this solution?

    Hybrid Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Microsoft Azure
    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    PeerSpot user
    Security IT at a tech services company with 51-200 employees
    Real User
    Top 5Leaderboard
    Excellent dashboards - automations
    Pros and Cons
    • "The tool is also very intuitive; its dashboards are very complete and provide a lot of valuable information for decision-making to improve security."
    • "The Check Point Infinity admin portal sometimes freezes."

    What is our primary use case?

    Our developers work in our Microsoft Azure public cloud environment, where they build applications and app service sites. These developments did not always avoid vulnerabilities, so we required a tool to guarantee that these environments complied with robust security measures to avoid attacks including identity theft, and denial of services, among others. We needed to protect from damage to the operation or hijacking of our data which would prevent the internal operation of the company. Thanks to this tool, we could cover ourselves and our environment safely.

    How has it helped my organization?

    The importance of having a security tool for our developers' workloads; most of the time, our apps services use identities to log in against databases, generating a possible loss of data and credentials. 

    Thanks to Check Ppoint CloudGuard Workload Protection, we were able to provide assessments to verify security problems, best practices, and changes that were listed from the solution portal to be able to correct them both automatically and manually, achieving safe environments.

    What is most valuable?

    Check Point CloudGuard Workload Protection is a very important tool for the company and developers. The characteristic that caught our attention the most was that it is a native solution and was created for cloud application protection that was automated.

    This solution not only provides recommendations or best practices for applications that are already finished or productive. However, we can protect from the beginning of development to testing and production, having recommendations and improvements throughout the process.

    The tool is also very intuitive; its dashboards are very complete and provide a lot of valuable information for decision-making to improve security.

    What needs improvement?

    Check Point CloudGuard Workload Protection is a very powerful, comprehensive, centralized tool but also a very expensive solution. It is worth it, however, it is not available to everyone.

    The Check Point Infinity admin portal sometimes freezes.

    There is little documentation for the implementation and start-up of some configurations. They could improve the public documentation to be able to generate the help that the client requires to be able to generate the correct and effective provisioning.

    For how long have I used the solution?

    This is an excellent security tool for the workload of the company's internal developers; we have used this technology in the last year with very encouraging results.

    What do I think about the stability of the solution?

    I really like the solution.

    What do I think about the scalability of the solution?

    This product offers excellent availability; its scaling is managed by the manufacturer.

    Which solution did I use previously and why did I switch?

    A centralized tool with the potential of Check Point CloudGuard Workload Protection is not found in other manufacturers. We have not had such a solid and secure solution.

    What's my experience with pricing, setup cost, and licensing?

    The recommendation is always to have a provider or a partner that can generate and answer all questions about the solutions and provide costs and analysis to see if the solutions are what the company needs.

    Which other solutions did I evaluate?

    Before implementing this solution, we validated solutions from other manufacturers such as Fortinet and Cisco. However, the benefits provided by Check Point exceeded the validations, and we chose CloudGuard.

    What other advice do I have?

    It is an excellent security tool for dev departments and the entire company.

    Which deployment model are you using for this solution?

    Hybrid Cloud
    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    Buyer's Guide
    Download our free Check Point CloudGuard CNAPP Report and get advice and tips from experienced pros sharing their opinions.
    Updated: January 2025
    Buyer's Guide
    Download our free Check Point CloudGuard CNAPP Report and get advice and tips from experienced pros sharing their opinions.