The solution's strongest point is that you can connect everything to it, giving you a full view of what's connected. If you configure it right, it works perfectly.
Chief Technology Officer at a legal firm with 11-50 employees
A robust solution that provides a unified view of connections
Pros and Cons
- "The solution's strongest point is that you can connect everything to it, giving you a full view of what's connected."
- "You need to know exactly the system. You cannot have someone running the system if they don't have the knowledge to do so."
What is most valuable?
What needs improvement?
You need to know exactly the system. You cannot have someone running the system if they don't have the knowledge to do so.
For how long have I used the solution?
I've been working with the solution for about a year.
What do I think about the stability of the solution?
The solution is stable. It doesn't matter which device is running Check Point. The solution works. It has never gone down. I rate the solution's stability a ten out of ten.
Buyer's Guide
Check Point CloudGuard WAF
November 2024
Learn what your peers think about Check Point CloudGuard WAF. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
815,854 professionals have used our research since 2012.
What do I think about the scalability of the solution?
My clients are large, but they are not enterprise-sized or small.
How was the initial setup?
I rate the initial setup a five out of ten because it is easy if you have the required knowledge and difficult if you are new to the system. The challenge isn't installing it: "Next, next, next, finish." Even a less knowledgeable person can do that. The challenge is configuring the system. There are a lot of blades in CloudGuard. You need to keep each type of security in your view, except for the Check Point view.
The initial setup is very fast, but you need to pray that the solution does all the work itself.
Which other solutions did I evaluate?
Other unified platforms like QRadar and Cisco are comparatively easier to use.
What other advice do I have?
You need someone knowledgeable to run the system. Today, with all the technology and everything, the company just wants to buy control and be lazy. "Let Check Point do the work." But this does not happen with Check Point because you need professional eyes. Check Point's price is very low compared to those controlling the system. You have to learn to investigate the solution to work better with it. The knowledge costs more than the system. The solution has a hybrid deployment, and I don't know a company that only chooses one deployment or another.
There is no support available for Check Point. There are things you have to look for, and that's it.
Check Point is the world's first and probably best security company. They might change its face, give it new names, separate into new models, and so on, but in the end, they are the best security company in the world. I rate the solution a ten out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer:
Offers comprehensive security, helps with compliance, and has good monitoring
Pros and Cons
- "The solution offers continuous security monitoring and alerting, which can help organizations detect and respond to security incidents in real time."
- "One of the big problems we found in Check Point, in general, is the support."
What is our primary use case?
The importance and use of this product were required to improve new application deployments made in the Microsoft Azure cloud. They were not one hundred percent secure, however with this CloudGuard application security from Check Point has managed to improve all these requirements to obtain greater security.
The applications are generally internal to the company, however, they are secure thanks to Check Point CloudGuard.
How has it helped my organization?
Check Point CloudGuard Application Security is a cloud-based security solution designed to protect web applications and APIs from various types of cyber threats.
This tool has managed to improve security considerably in our apps and the APIs created for the company. We have not presented problems, threats, or leaks even when some are exposed to the Internet and are more susceptible to attacks. The company is now more secure, thanks to Check Point.
What is most valuable?
The solution is created one hundred percent on the cloud; the portal is easy to manage.
The solution offers continuous security monitoring and alerting, which can help organizations detect and respond to security incidents in real time.
CloudGuard Application Security provides comprehensive visibility into web applications and API traffic
The solution offers support for compliance regulations such as PCI-DSS, HIPAA, and GDPR, helping organizations to meet their regulatory obligations.
What needs improvement?
One of the big problems we found in Check Point, in general, is the support. It is always attended very late or they take a long time to answer.
The cost of this tool is extremely high, which is why it must be analyzed before implementing it.
The support language is only English. This causes some problems in Spanish-speaking countries. They could expand the languages offered to help the client.
For how long have I used the solution?
This excellent security tool, Check Point CloudGuard, has multi-cloud security and is also perfect for secure developments. It's been used in recent years by the company.
Which solution did I use previously and why did I switch?
Previously we did not use a technology like this.
Which other solutions did I evaluate?
We always carry out tests and validations before acquiring a solution.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Check Point CloudGuard WAF
November 2024
Learn what your peers think about Check Point CloudGuard WAF. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
815,854 professionals have used our research since 2012.
Consultant at ITQS
Great API integration, good pricing, and offers good security
Pros and Cons
- "It is a very scalable and stable solution."
- "CloudGuard for Application Security, like the other Check Point applications, has been presenting major latency problems when entering their administrative portal."
How has it helped my organization?
CloudGuard for Application Security came to provide a layer and organization of security to our company. The management of the devices became easier and faster to manage. In addition, the tool had very good reviews since it is the one in the market with the best detection rate of threats.
The solution is scalable, reliable, and does not present many false positives.
In addition, CloudGuard for Application Security helped us with its AI. With the ability to assess vulnerabilities, it helps us with the best practices to implement in the company.
What is most valuable?
CloudGuard for Application Security one of its most valuable features is that it can be integrated into an API more easily and effortlessly.
It is also a very scalable and stable solution. That is one of the points that a company looks for when implementing something like this in an organization.
With this tool, we have been able to release the overload that was being caused in the IT department and be able to focus on other security functions and thus be able to apply all good practices and be able to manage security 100% of the time.
What needs improvement?
CloudGuard for Application Security, like the other Check Point applications, has been presenting major latency problems when entering their administrative portal. That should be one of the priorities to take into account.
They must also improve the support provided to the client and improve the documentation library.
The tool fulfills the functionality very well. Hopefully, the next improvements will surprise us with something new since at present it fulfills the security expectations very well.
For how long have I used the solution?
it was implemented approximately one year ago.
What do I think about the stability of the solution?
The stability it presents is excellent. It goes up to 100%.
What do I think about the scalability of the solution?
The scalability that it presents is very good.
How are customer service and support?
The support must be improved. It presents a lot of deficiency.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
No previous solution was implemented.
How was the initial setup?
The configuration is very simple and the product is easy to implement.
What about the implementation team?
We had an engineer that helped us with the implementation. Overall, it was fast and good.
What was our ROI?
The investment that is made is an investment that will be reflected in the security. It's worth it.
What's my experience with pricing, setup cost, and licensing?
The cost is competitive in the market.
Which other solutions did I evaluate?
We wanted to continue with the same horizon as we have several Check Point solutions in our environment.
What other advice do I have?
The solution works very well. They just need to improve the support and documentation.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Senior Manager ICT & Innovations at Bangalore International Airport Limited
Performs health checkups but needs to improve integration
Pros and Cons
- "The tool performs device health checkups and updates us. It helps us to be compliant with regulatory policies."
- "Check Point CloudGuard Application Security needs to improve updates on integrations. It also needs to incorporate real-time monitoring features."
What is our primary use case?
Check Point CloudGuard Application Security helps us ensure the security of contact devices and meet audit requirements for compliance.
What is most valuable?
The tool performs device health checkups and updates us. It helps us to be compliant with regulatory policies.
What needs improvement?
Check Point CloudGuard Application Security needs to improve updates on integrations. It also needs to incorporate real-time monitoring features.
For how long have I used the solution?
I have been using the product for two years.
What do I think about the stability of the solution?
We encountered stability issues during the configuration. The tool's stability is good.
What do I think about the scalability of the solution?
Check Point CloudGuard Application Security is scalable. My company has 1000 users for it.
How are customer service and support?
The tool's support is good.
How would you rate customer service and support?
Positive
How was the initial setup?
Check Point CloudGuard Application Security's deployment is easy and completed in six hours. You need two to three resources to handle the deployment. You need proper training to do it.
What's my experience with pricing, setup cost, and licensing?
The tool's licensing costs are yearly and competitive.
What other advice do I have?
I rate Check Point CloudGuard Application Security an eight out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Java Developer at EROAD
Guards privacy, protects data, and offers good security configuration
Pros and Cons
- "After integrating AppSec with other applications, team members can easily work without fear of confidential information exposure."
- "The creation of security profiles for each application takes a lot of time."
What is our primary use case?
This security management system allows teams to evaluate the performance of applications and identify vulnerabilities that could affect performance.
It has deployed reliable security measures that can easily detect any potential data leaks and cyber-attacks. Before we develop any application Check Point CloudGuard Application Security provides the best data protection tools that be configured easily with the new application. We have been able to scale down workflows and monitor appropriately the entire production ecosystem.
How has it helped my organization?
We have prevented many potential threats that could be a major setback to our set goals.
After integrating AppSec with other applications, team members can easily work without fear of confidential information exposure. It has really empowered employees with modern online security measures that can affect business progress.
Learning new security coding techniques has been a great opportunity for my team and the entire organization. We have quashed many authentication and code injection attempts by ransomware attacks to secure our networking infrastructure.
What is most valuable?
Sensitive data exposure models have helped in guarding the privacy of company and customer information from landing in unauthorized hands.
Confidential details like bank statements and the financial status of employees is very sensitive and can easily be exposed to cyber-attacks. AppSec has created a secure environment that allows members to create and manage their personal email accounts and related personal data.
Application security configuration gives the IT team and authorized personnel to have full access and control of workflows without fear.
What needs improvement?
The creation of security profiles for each application takes a lot of time. The new release can have a unified security control system that can access the security situation of all applications from one single source.
The system blocks some authorized data entries that are not threats. AppSec could easily deploy a system with set commands that can be used to block unsafe operations and authorize areas of interest based on the user's needs. I have loved the way this software works, and I am impressed by the increased security across the applications.
For how long have I used the solution?
I've used the solution for eight months.
What do I think about the stability of the solution?
It is stable throughout.
What do I think about the scalability of the solution?
This software is good and the performance is excellent.
How are customer service and support?
The customer support staff is dedicated to delivering the best services ever.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We decided to test the performance of this product for the first time, and it impressed the departments.
How was the initial setup?
The setup process was straightforward, and the vendor guided us effectively.
What about the implementation team?
Deployment took place through the vendor team.
What was our ROI?
ROI has increased from 40% to 65% in eight months.
What's my experience with pricing, setup cost, and licensing?
The price is good for all businesses.
Which other solutions did I evaluate?
I did not consider other options.
What other advice do I have?
We could not have prevented many external attacks without AppSec. I am happy due to its great performance.
Which deployment model are you using for this solution?
Private Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
CEO at a tech services company with 11-50 employees
Easy deployment, good reporting, and excellent support
Pros and Cons
- "The first valuable feature is that it is not a complex process to get it up and running. It was not complex at all. We were in a close relationship with the team that developed the app, and it worked in a few hours. The second valuable feature is the information that comes out of it."
- "I do not know if it is already there, but I would like to have complete visibility between the posture management and firewall as a service."
What is our primary use case?
We use AppSec. The primary use case was for our client's app. We did a successful project with the biggest university in Mexico. It was a big survey for all the former students. There were thousands of them, and it needed to be completed based on some specifications from the security team.
How has it helped my organization?
The service was available for the client on time. They had a go-to-market or a due date to start sending the app to various students to apply. We were there 24/7 hoping and waiting for everything to be fine, and it worked perfectly and smoothly.
The client was very happy with the performance of Check Point on this project. When comparing it with Imperva, we strongly feel that the formula that Check Point delivers on WAF was what the client needed.
Check Point CloudGuard works perfectly for preemptively blocking Zero Day attacks and detecting hidden anomalies. Check Point is all about prevention. We strongly believe that if you want to prevent threats, Check Point is the one. There is no one else.
What is most valuable?
There are two main features. The first valuable feature is that it is not a complex process to get it up and running. It was not complex at all. We were in a close relationship with the team that developed the app, and it worked in a few hours.
The second valuable feature is the information that comes out of it. With the dashboard or the information that came from it, we made some executive reports for the client. They were very happy with it.
What needs improvement?
I do not know if it is already there, but I would like to have complete visibility between the posture management and firewall as a service. I would like the complete visibility of every product for the client to see in an executive way. I do not want it in a very complex way with so many warnings and threats. They should focus on the main things in all the products. I would like to see that.
For how long have I used the solution?
We started using it six months ago.
What do I think about the stability of the solution?
Its stability is perfect. We have had no issues.
What do I think about the scalability of the solution?
It is made for scalability. We have no issues on the matter.
How are customer service and support?
Check Point helped us a lot with the project. We interacted with Check Point engineers. They knew it was our first project, and we came across as one strong team in front of the client. I would rate their customer service and support a ten out of ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
The client had Imperva, but for this project, they used Check Point. They have some current contracts and some expiration dates. We are hoping to have more deals with them.
They went for this solution for multiple reasons. The first reason was our service as a partner. The client needed somebody to handle the solution. They are not specialists in handling WAF or security. The second reason was that Check Point has authority over security. We were not delivering a solution that was new in the market. We were not an underdog. The third reason was that when we did the workshop, not a POV, the client saw that the solution was intuitive. The dashboards were executive. They liked it a lot. It provided visibility to focus on the efforts. It gave a list of all the threats. It was focused on the main ideas and threats.
Check Point CloudGuard WAF can reduce the total cost of ownership for your web application firewall, but in this case, it was not a big deal.
What was our ROI?
Our client could see that they can have a great solution that does not cost much more than Imperva.
What's my experience with pricing, setup cost, and licensing?
It is not cheap, but it is worth it. For this project, our channel manager and our territory manager helped us a lot. We got a lot of flexibility on the license. I do not know how much discount there was, but it was big enough to win the opportunity.
What other advice do I have?
For those evaluating WAF solutions, there are so many options, but I would recommend relying on a company like Check Point that has a great ecosystem. Their solutions are not only made for the cloud. They also have specialization in all types of security. With their AI and ThreatCloud, you have information about what is happening in the security world. The information that they provide is very useful, so rely on a company that is big enough to provide the security that you deserve.
In this project, there were a lot of technical issues that we had to manage through our engineers. It was our first project and the interaction with the development teams was important. It was very important to get the due dates and stay on track. For a successful project, you need to have a close interaction with the client, especially if the client is not a specialist in security. Check Point also helped us a lot with this project.
Overall, I would rate Check Point CloudGuard WAF a ten out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Last updated: Mar 26, 2024
Flag as inappropriateAdministrative Assistant at Tecapro
Great security and more visibility but needs more AI capabilities
Pros and Cons
- "It offers good functionality of the application that is currently running."
- "I would like to be able to integrate the theme of Artificial Intelligence to help review issues and to monitor and view the security issue while also suggesting and interpreting and additionally configuring solutions - basically, acting as an interpreter."
What is our primary use case?
We have had the need to ensure the development of each of our applications based on the fact that the applications must be safe, fast, and efficient. We want to prevent an injection of a vulnerability attack by broken authentication, exposure of confidential data, or external entities that can inject us with xml services via broken access control. All these characteristics cause insecurity. We have looked for solutions that can guide us and establish a safe and concise baseline.
How has it helped my organization?
It has given us greater security at an organizational level. It has allowed us to use components with known vulnerabilities, which have been prevented based on their multiple databases that have correlated incidents, helping the development of applications to be fast, efficient, and safe, which is what we were looking for. Thus giving us the possibility to register, monitor, and identify technological insufficiencies or absent capacities in the development of the application.
What is most valuable?
Its most outstanding feature is the registry and the possibility of monitoring everything. When it comes to simplifying or establishing an error, an infraction, or a detection due to a breach of unauthorized access, it gives us an overview of each one of the capabilities and a segmented control over the development. It offers good functionality of the application that is currently running. It's giving us the ability to test based on vulnerable interfaces, and anomalous requests and responses. All these types of characteristics give us a reference point as to whether they are secure or insecure. We get logging monitoring and general visibility of the application.
What needs improvement?
The application allows us to have control over its activities, the management, and the interconnection of monitoring which takes advantage of computing power, is exceptional. That said, I would like to be able to integrate the theme of Artificial Intelligence to help review issues and to monitor and view the security issue while also suggesting and interpreting and additionally configuring solutions - basically, acting as an interpreter.
For how long have I used the solution?
We've used the solution for about six or seven months. That was when established applications at the cloud level.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Security IT at a tech services company with 51-200 employees
Great security tool, intuitive tool
Pros and Cons
- "The portal is quite intuitive."
- "We would like the solution to be more economical since it is not accessible to all clients."
What is our primary use case?
We require the use of a solid security tool for our websites provisioned in Microsoft Azure App Service, which is used for internal use by the company and for external use by the client.
The key requirements that we needed to solve were to have automated protection, to have little administration in addition to providing few false positives, all this was successfully solved or provided through CloudGuard Application Security, in addition to the fact that we were able to centralize everything in the whole family.
How has it helped my organization?
Thanks to the centralized use of Check Point CloudGuard App Security we managed to have protection for our Windows and Linux sites, in addition to having little interaction with exceptions due to having this tool in prevention mode.
This tool does not require a lot of learning time, it is incredible. With other tools, adaptation time is required, which with Check Point is not necessary.
We have also been able to find a sensible implementation of the application, providing confidence and business peace of mind.
What is most valuable?
Check Point CloudGuard Application Security offers us many virtues, the ones we liked the most were:
- Easy and simple implementation from the Check Point Infinity portal
- Very few false positives, which generates a lot of confidence in the product
- The portal is quite intuitive
- The solution does not require much time to adapt to the sites and applications it protects.
In itself, the application really meets our expectations. At the management level, the solution is what was needed to protect this area of the company's infrastructure.
What needs improvement?
This Check Point solution is an extremely complete security solution, it is really amazing. However, there are always improvements that can be made to all of the tools.
We would like the solution to be more economical since it is not accessible to all clients or is a point of consideration.
Regarding the documentation, starting implementation was not so clear. We had to validate several guides until we could do it correctly.
Finally, we would like the Infinity portal perform better.
For how long have I used the solution?
During this last year we have been adding the use of CloudGuard checkpoint for the protection of our infrastructure in Microsoft Azure.
What do I think about the scalability of the solution?
It is a cloud solution, managed by Check Point. So far we have not had performance problems.
Which solution did I use previously and why did I switch?
We previously tested Microsoft Azure Application Gateway with the WAF feature. However, two points led us to switch to Check Point:
1- We wanted a centralized security environment. We already have Check Point solutions based on the infinity checkpoint portal.
2- The WAF solution required more time in detection mode.
What's my experience with pricing, setup cost, and licensing?
Costs are an important issue to discuss with the partner. Validate the documentation and its scope to validate if they meet corporate requirements.
Which other solutions did I evaluate?
We always evaluate the solutions in the market to make the best decision.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Download our free Check Point CloudGuard WAF Report and get advice and tips from experienced pros
sharing their opinions.
Updated: November 2024
Popular Comparisons
SonarQube Server (formerly SonarQube)
Checkmarx One
Microsoft Azure Application Gateway
Azure Front Door
F5 Advanced WAF
Fortinet FortiWeb
Imperva Web Application Firewall
Radware Cloud WAF Service
open-appsec
Buyer's Guide
Download our free Check Point CloudGuard WAF Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- If you had to both encrypt and compress data during transmission, which would you do first and why?
- When evaluating Application Security, what aspect do you think is the most important to look for?
- What are the Top 5 cybersecurity trends in 2022?
- What are the threats associated with using ‘bogus’ cybersecurity tools?
- Which application security solutions include both vulnerability scans and quality checks?
- We're evaluating Tripwire, what else should we consider?
- Is SonarQube the best tool for static analysis?
- Why Do I Need Application Security Software?
- Which Email Security enterprise solution would you choose: Cisco Secure Email vs Forcepoint Email Security vs Barracuda Email Security Gateway?
- SAST vs. DAST: Which is better for application security testing?