What is our primary use case?
This perimeter firewall provides me control over my perimeter servers and devices. Current Cloud applications are getting good protection from CASB solutions, but are limited to data leakage and application control. Beyond that, I require something to monitor my data that flows inside of my cloud application.
Sophisticated threats like zero-day attacks can't be control by CASB solutions, Instead, we are required to have something that can work using Artificial Intelligence and Machine learning algorithms. This helps to defend my cloud applications against today's attacks.
How has it helped my organization?
Sophisticated attacks can't be prevented by normal SaaS security. Cloud Guard SaaS is a technology that prevents not only Sophisticated attacks but affords protection from Email.
Most attacks are successful because of SPAM emails that effectively cause users to fall into the attacker's trap. As Check Point is a leading technology in the industry, it provides maximum protection against email phishing attacks and provides the identity of users and visibility over shadow IT applications.
Along with the email security solution, Cloud Guard is an additional layer of comprehensive security, so we can completely rely on it.
What is most valuable?
Most organizations that invest in email security opt for MFA. They invest in a Cloud Firewall but they never consider the east-west traffic flow inside their Cloud Applications.
Here, Cloud Guards comes in with the best features, such as protection from zero-day attacks. These are usually reported when we have blades on the perimeter firewall, like Threat Emulation and Extraction or Sandbox. We have complete visibility of email Attacks like spear-phishing, spoofing, etc. Based on domain and URL reputation, it will allow traffic to flow.
Apart from this, we can easily identify users who are going to use cloud applications. These users are logged in via a trusted network or device.
What needs improvement?
Cloud Guard would be a complete solution if Check Point added a comprehensive data loss solution that included capabilities such as bulk data transfer detection.
I would like to see a centralized gateway so that anyone from any geolocation can access the infrastructure with minimum latency.
I would like to see additional work on protecting against phishing emails by adding more filters to minimize risk or to harden the security.
Stability is the main area that Check Point needs to focus on.
Integration with third-party APIs should be supported, as AI and ML can get more inputs to minimize the false rate ratio.
For how long have I used the solution?
I have been using Check Point CloudGuard SaaS for more than a year.
What do I think about the stability of the solution?
Stability is an area that needs to improve.
What do I think about the scalability of the solution?
It can be scale up to maximum limit.
How are customer service and support?
Technical support is good.
Which solution did I use previously and why did I switch?
We did not previously use another solution before this one. However, one of our customers had implemented an on-premises solution by McAfee.
How was the initial setup?
This solution is easy to implement, although it is required that you have knowledge of the Public Cloud domain.
What about the implementation team?
We are vendors and deploy this solution for our clients.
What was our ROI?
We definitely see ROI from this product, and it grows and we have a greater dependency on east-west traffic.
What's my experience with pricing, setup cost, and licensing?
Cost is the main concern that every customer takes into consideration, and Check Point always negotiates a price that is affordable. Pricing is based on the requirements and their relationship.
What other advice do I have?
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: We are the vendors who provide services to other customers.