Check Point CloudGuard Application Security helps us ensure the security of contact devices and meet audit requirements for compliance.
Senior Manager ICT & Innovations at Bangalore International Airport Limited
Performs health checkups but needs to improve integration
Pros and Cons
- "The tool performs device health checkups and updates us. It helps us to be compliant with regulatory policies."
- "Check Point CloudGuard Application Security needs to improve updates on integrations. It also needs to incorporate real-time monitoring features."
What is our primary use case?
What is most valuable?
The tool performs device health checkups and updates us. It helps us to be compliant with regulatory policies.
What needs improvement?
Check Point CloudGuard Application Security needs to improve updates on integrations. It also needs to incorporate real-time monitoring features.
For how long have I used the solution?
I have been using the product for two years.
Buyer's Guide
Check Point CloudGuard WAF
January 2025
Learn what your peers think about Check Point CloudGuard WAF. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,020 professionals have used our research since 2012.
What do I think about the stability of the solution?
We encountered stability issues during the configuration. The tool's stability is good.
What do I think about the scalability of the solution?
Check Point CloudGuard Application Security is scalable. My company has 1000 users for it.
How are customer service and support?
The tool's support is good.
How would you rate customer service and support?
Positive
How was the initial setup?
Check Point CloudGuard Application Security's deployment is easy and completed in six hours. You need two to three resources to handle the deployment. You need proper training to do it.
What's my experience with pricing, setup cost, and licensing?
The tool's licensing costs are yearly and competitive.
What other advice do I have?
I rate Check Point CloudGuard Application Security an eight out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Consultant at ITQS
Great API integration, good pricing, and offers good security
Pros and Cons
- "It is a very scalable and stable solution."
- "CloudGuard for Application Security, like the other Check Point applications, has been presenting major latency problems when entering their administrative portal."
How has it helped my organization?
CloudGuard for Application Security came to provide a layer and organization of security to our company. The management of the devices became easier and faster to manage. In addition, the tool had very good reviews since it is the one in the market with the best detection rate of threats.
The solution is scalable, reliable, and does not present many false positives.
In addition, CloudGuard for Application Security helped us with its AI. With the ability to assess vulnerabilities, it helps us with the best practices to implement in the company.
What is most valuable?
CloudGuard for Application Security one of its most valuable features is that it can be integrated into an API more easily and effortlessly.
It is also a very scalable and stable solution. That is one of the points that a company looks for when implementing something like this in an organization.
With this tool, we have been able to release the overload that was being caused in the IT department and be able to focus on other security functions and thus be able to apply all good practices and be able to manage security 100% of the time.
What needs improvement?
CloudGuard for Application Security, like the other Check Point applications, has been presenting major latency problems when entering their administrative portal. That should be one of the priorities to take into account.
They must also improve the support provided to the client and improve the documentation library.
The tool fulfills the functionality very well. Hopefully, the next improvements will surprise us with something new since at present it fulfills the security expectations very well.
For how long have I used the solution?
it was implemented approximately one year ago.
What do I think about the stability of the solution?
The stability it presents is excellent. It goes up to 100%.
What do I think about the scalability of the solution?
The scalability that it presents is very good.
How are customer service and support?
The support must be improved. It presents a lot of deficiency.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
No previous solution was implemented.
How was the initial setup?
The configuration is very simple and the product is easy to implement.
What about the implementation team?
We had an engineer that helped us with the implementation. Overall, it was fast and good.
What was our ROI?
The investment that is made is an investment that will be reflected in the security. It's worth it.
What's my experience with pricing, setup cost, and licensing?
The cost is competitive in the market.
Which other solutions did I evaluate?
We wanted to continue with the same horizon as we have several Check Point solutions in our environment.
What other advice do I have?
The solution works very well. They just need to improve the support and documentation.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Check Point CloudGuard WAF
January 2025
Learn what your peers think about Check Point CloudGuard WAF. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,020 professionals have used our research since 2012.
Java Developer at EROAD
Guards privacy, protects data, and offers good security configuration
Pros and Cons
- "After integrating AppSec with other applications, team members can easily work without fear of confidential information exposure."
- "The creation of security profiles for each application takes a lot of time."
What is our primary use case?
This security management system allows teams to evaluate the performance of applications and identify vulnerabilities that could affect performance.
It has deployed reliable security measures that can easily detect any potential data leaks and cyber-attacks. Before we develop any application Check Point CloudGuard Application Security provides the best data protection tools that be configured easily with the new application. We have been able to scale down workflows and monitor appropriately the entire production ecosystem.
How has it helped my organization?
We have prevented many potential threats that could be a major setback to our set goals.
After integrating AppSec with other applications, team members can easily work without fear of confidential information exposure. It has really empowered employees with modern online security measures that can affect business progress.
Learning new security coding techniques has been a great opportunity for my team and the entire organization. We have quashed many authentication and code injection attempts by ransomware attacks to secure our networking infrastructure.
What is most valuable?
Sensitive data exposure models have helped in guarding the privacy of company and customer information from landing in unauthorized hands.
Confidential details like bank statements and the financial status of employees is very sensitive and can easily be exposed to cyber-attacks. AppSec has created a secure environment that allows members to create and manage their personal email accounts and related personal data.
Application security configuration gives the IT team and authorized personnel to have full access and control of workflows without fear.
What needs improvement?
The creation of security profiles for each application takes a lot of time. The new release can have a unified security control system that can access the security situation of all applications from one single source.
The system blocks some authorized data entries that are not threats. AppSec could easily deploy a system with set commands that can be used to block unsafe operations and authorize areas of interest based on the user's needs. I have loved the way this software works, and I am impressed by the increased security across the applications.
For how long have I used the solution?
I've used the solution for eight months.
What do I think about the stability of the solution?
It is stable throughout.
What do I think about the scalability of the solution?
This software is good and the performance is excellent.
How are customer service and support?
The customer support staff is dedicated to delivering the best services ever.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We decided to test the performance of this product for the first time, and it impressed the departments.
How was the initial setup?
The setup process was straightforward, and the vendor guided us effectively.
What about the implementation team?
Deployment took place through the vendor team.
What was our ROI?
ROI has increased from 40% to 65% in eight months.
What's my experience with pricing, setup cost, and licensing?
The price is good for all businesses.
Which other solutions did I evaluate?
I did not consider other options.
What other advice do I have?
We could not have prevented many external attacks without AppSec. I am happy due to its great performance.
Which deployment model are you using for this solution?
Private Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Cloud Engineer at ITQS
Great AI, less false positives, and great administration capabilities
Pros and Cons
- "Its main value and what we liked the most is its powerful AI."
- "We would like to have a solution of this type for the administration of applications from mobile devices."
What is our primary use case?
We had the need to protect the computers in the cloud that we were migrating, giving them greater security and having control over the events and tasks that they execute.
This need led us to have and search for a solution that would support us directly with containers and the security of our access APIs.
Above all, we needed something that would give us added value when implementing, and that was where we came to use Check Point AppSec.
Its main value and what we liked the most is its powerful AI.
How has it helped my organization?
With so many tasks that we have at the administration level, as administrators, we find this solution as one of the best recommendations due to its powerful AI. It supports us to be scalable and learn in management with the data it is learning.
Zero-day management and preemptive stop management provide detection in hours, not weeks. These help us to be much more proactive and efficient in our security management and in much of what we have in the cloud and the infrastructure that we have been migrating to the various cloud.
What is most valuable?
Among its most outstanding features is the powerful AI in container security. Above all, it is one of the most powerful and easy-to-manage solutions. It manages to protect itself, and it manages to include its new rules based on what manages to learn. This helps us protect web applications and APIs by eliminating false positives and stops automated attacks against our organization. It eliminates the need to adjust rules manually and create exceptions each time an update is performed.
What needs improvement?
We would like to have a solution of this type for the administration of applications from mobile devices. It would help us to be more portable with management from tablets, iPads, or some cell phones, becoming easier to administer.
We'd lie to see it take on the characteristics of quantum applications and have these solutions all in one, protecting us and giving us even more value than what it is giving us today.
For how long have I used the solution?
I've used the solution for one year.
Which solution did I use previously and why did I switch?
We did not previously use a different solution.
Which other solutions did I evaluate?
We did not evaluate other options.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Chief Technology Officer at a legal firm with 11-50 employees
A robust solution that provides a unified view of connections
Pros and Cons
- "The solution's strongest point is that you can connect everything to it, giving you a full view of what's connected."
- "You need to know exactly the system. You cannot have someone running the system if they don't have the knowledge to do so."
What is most valuable?
The solution's strongest point is that you can connect everything to it, giving you a full view of what's connected. If you configure it right, it works perfectly.
What needs improvement?
You need to know exactly the system. You cannot have someone running the system if they don't have the knowledge to do so.
For how long have I used the solution?
I've been working with the solution for about a year.
What do I think about the stability of the solution?
The solution is stable. It doesn't matter which device is running Check Point. The solution works. It has never gone down. I rate the solution's stability a ten out of ten.
What do I think about the scalability of the solution?
My clients are large, but they are not enterprise-sized or small.
How was the initial setup?
I rate the initial setup a five out of ten because it is easy if you have the required knowledge and difficult if you are new to the system. The challenge isn't installing it: "Next, next, next, finish." Even a less knowledgeable person can do that. The challenge is configuring the system. There are a lot of blades in CloudGuard. You need to keep each type of security in your view, except for the Check Point view.
The initial setup is very fast, but you need to pray that the solution does all the work itself.
Which other solutions did I evaluate?
Other unified platforms like QRadar and Cisco are comparatively easier to use.
What other advice do I have?
You need someone knowledgeable to run the system. Today, with all the technology and everything, the company just wants to buy control and be lazy. "Let Check Point do the work." But this does not happen with Check Point because you need professional eyes. Check Point's price is very low compared to those controlling the system. You have to learn to investigate the solution to work better with it. The knowledge costs more than the system. The solution has a hybrid deployment, and I don't know a company that only chooses one deployment or another.
There is no support available for Check Point. There are things you have to look for, and that's it.
Check Point is the world's first and probably best security company. They might change its face, give it new names, separate into new models, and so on, but in the end, they are the best security company in the world. I rate the solution a ten out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer:
Offers comprehensive security, helps with compliance, and has good monitoring
Pros and Cons
- "The solution offers continuous security monitoring and alerting, which can help organizations detect and respond to security incidents in real time."
- "One of the big problems we found in Check Point, in general, is the support."
What is our primary use case?
The importance and use of this product were required to improve new application deployments made in the Microsoft Azure cloud. They were not one hundred percent secure, however with this CloudGuard application security from Check Point has managed to improve all these requirements to obtain greater security.
The applications are generally internal to the company, however, they are secure thanks to Check Point CloudGuard.
How has it helped my organization?
Check Point CloudGuard Application Security is a cloud-based security solution designed to protect web applications and APIs from various types of cyber threats.
This tool has managed to improve security considerably in our apps and the APIs created for the company. We have not presented problems, threats, or leaks even when some are exposed to the Internet and are more susceptible to attacks. The company is now more secure, thanks to Check Point.
What is most valuable?
The solution is created one hundred percent on the cloud; the portal is easy to manage.
The solution offers continuous security monitoring and alerting, which can help organizations detect and respond to security incidents in real time.
CloudGuard Application Security provides comprehensive visibility into web applications and API traffic
The solution offers support for compliance regulations such as PCI-DSS, HIPAA, and GDPR, helping organizations to meet their regulatory obligations.
What needs improvement?
One of the big problems we found in Check Point, in general, is the support. It is always attended very late or they take a long time to answer.
The cost of this tool is extremely high, which is why it must be analyzed before implementing it.
The support language is only English. This causes some problems in Spanish-speaking countries. They could expand the languages offered to help the client.
For how long have I used the solution?
This excellent security tool, Check Point CloudGuard, has multi-cloud security and is also perfect for secure developments. It's been used in recent years by the company.
Which solution did I use previously and why did I switch?
Previously we did not use a technology like this.
Which other solutions did I evaluate?
We always carry out tests and validations before acquiring a solution.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Security IT at a tech services company with 51-200 employees
Great security tool, intuitive tool
Pros and Cons
- "The portal is quite intuitive."
- "We would like the solution to be more economical since it is not accessible to all clients."
What is our primary use case?
We require the use of a solid security tool for our websites provisioned in Microsoft Azure App Service, which is used for internal use by the company and for external use by the client.
The key requirements that we needed to solve were to have automated protection, to have little administration in addition to providing few false positives, all this was successfully solved or provided through CloudGuard Application Security, in addition to the fact that we were able to centralize everything in the whole family.
How has it helped my organization?
Thanks to the centralized use of Check Point CloudGuard App Security we managed to have protection for our Windows and Linux sites, in addition to having little interaction with exceptions due to having this tool in prevention mode.
This tool does not require a lot of learning time, it is incredible. With other tools, adaptation time is required, which with Check Point is not necessary.
We have also been able to find a sensible implementation of the application, providing confidence and business peace of mind.
What is most valuable?
Check Point CloudGuard Application Security offers us many virtues, the ones we liked the most were:
- Easy and simple implementation from the Check Point Infinity portal
- Very few false positives, which generates a lot of confidence in the product
- The portal is quite intuitive
- The solution does not require much time to adapt to the sites and applications it protects.
In itself, the application really meets our expectations. At the management level, the solution is what was needed to protect this area of the company's infrastructure.
What needs improvement?
This Check Point solution is an extremely complete security solution, it is really amazing. However, there are always improvements that can be made to all of the tools.
We would like the solution to be more economical since it is not accessible to all clients or is a point of consideration.
Regarding the documentation, starting implementation was not so clear. We had to validate several guides until we could do it correctly.
Finally, we would like the Infinity portal perform better.
For how long have I used the solution?
During this last year we have been adding the use of CloudGuard checkpoint for the protection of our infrastructure in Microsoft Azure.
What do I think about the scalability of the solution?
It is a cloud solution, managed by Check Point. So far we have not had performance problems.
Which solution did I use previously and why did I switch?
We previously tested Microsoft Azure Application Gateway with the WAF feature. However, two points led us to switch to Check Point:
1- We wanted a centralized security environment. We already have Check Point solutions based on the infinity checkpoint portal.
2- The WAF solution required more time in detection mode.
What's my experience with pricing, setup cost, and licensing?
Costs are an important issue to discuss with the partner. Validate the documentation and its scope to validate if they meet corporate requirements.
Which other solutions did I evaluate?
We always evaluate the solutions in the market to make the best decision.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Delivery Engineer at a tech services company with 51-200 employees
Offers comprehensive threat prevention capabilities and a user-friendly interface
Pros and Cons
- "The features I have found most valuable are the comprehensive threat prevention capabilities, automated policy management, and seamless integration with cloud environments."
- "For the next release, I would suggest considering features like enhanced threat intelligence integration."
What is our primary use case?
With CloudGuard WAF, I can deploy a cloud-based network protection solution that secures my applications, endpoints, and data.
What is most valuable?
The features I have found most valuable are the comprehensive threat prevention capabilities, automated policy management, and seamless integration with cloud environments.
What needs improvement?
For the next release, I would suggest considering features like enhanced threat intelligence integration.
For how long have I used the solution?
I have been using Check Point CloudGuard WAF for about two years.
What do I think about the stability of the solution?
The stability of the product has been good so far.
How are customer service and support?
Check Point's technical support is helpful and knowledgeable overall, but there can be delays in response, especially regarding licensing issues.
Which solution did I use previously and why did I switch?
The main reasons I chose this vendor for web application security were their ability to consolidate management facilities, their comprehensive features, and their flexibility in addressing different security needs.
What was our ROI?
We have seen ROI from using CloudGuard WAF.
What's my experience with pricing, setup cost, and licensing?
I believe that the pricing or licensing of CloudGuard WAF could be more competitive.
What other advice do I have?
Implementing CloudGuard WAF allowed me to address the challenges of securing my applications and data in a rapidly evolving cloud environment.
Using CloudGuard WAF has brought significant benefits, including improved threat protection, streamlined policy management, and enhanced usability. I noticed these advantages shortly after the first deployment.
It is extremely important to me that CloudGuard optimizes security to protect my applications without solely relying on signatures.
To access the false positive rate, I typically review assessment reports available on platforms like AWS or Azure. By evaluating how effectively the solution preemptively blocks zero-day attacks and minimizes false positives, I can reduce the total cost of ownership for my web application security.
The solution's privacy features, user-friendly web console, virtual deployment options, and physical appliance capabilities have all contributed to reducing my total cost of ownership.
Overall, I would rate CloudGuard WAF as an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
Buyer's Guide
Download our free Check Point CloudGuard WAF Report and get advice and tips from experienced pros
sharing their opinions.
Updated: January 2025
Popular Comparisons
SonarQube Server (formerly SonarQube)
Checkmarx One
Buyer's Guide
Download our free Check Point CloudGuard WAF Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- If you had to both encrypt and compress data during transmission, which would you do first and why?
- When evaluating Application Security, what aspect do you think is the most important to look for?
- What are the Top 5 cybersecurity trends in 2022?
- What are the threats associated with using ‘bogus’ cybersecurity tools?
- Which application security solutions include both vulnerability scans and quality checks?
- We're evaluating Tripwire, what else should we consider?
- Is SonarQube the best tool for static analysis?
- Why Do I Need Application Security Software?
- Which Email Security enterprise solution would you choose: Cisco Secure Email vs Forcepoint Email Security vs Barracuda Email Security Gateway?
- SAST vs. DAST: Which is better for application security testing?