Try our new research platform with insights from 80,000+ expert users

Akamai Guardicore Segmentation vs Check Point CloudGuard CNAPP comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 9, 2024
 

Categories and Ranking

SentinelOne Singularity Clo...
Sponsored
Ranking in Cloud and Data Center Security
5th
Ranking in Cloud Workload Protection Platforms (CWPP)
4th
Average Rating
8.6
Reviews Sentiment
8.0
Number of Reviews
99
Ranking in other categories
Vulnerability Management (6th), Container Security (3rd), Cloud Security Posture Management (CSPM) (4th), Cloud-Native Application Protection Platforms (CNAPP) (3rd), Compliance Management (3rd)
Akamai Guardicore Segmentation
Ranking in Cloud and Data Center Security
1st
Ranking in Cloud Workload Protection Platforms (CWPP)
13th
Average Rating
8.2
Reviews Sentiment
6.8
Number of Reviews
18
Ranking in other categories
Breach and Attack Simulation (BAS) (4th), Microsegmentation Software (2nd)
Check Point CloudGuard CNAPP
Ranking in Cloud and Data Center Security
9th
Ranking in Cloud Workload Protection Platforms (CWPP)
6th
Average Rating
8.6
Reviews Sentiment
7.5
Number of Reviews
67
Ranking in other categories
Vulnerability Management (8th), Container Security (6th), Cloud Security Posture Management (CSPM) (5th), Cloud-Native Application Protection Platforms (CNAPP) (5th), Data Security Posture Management (DSPM) (4th), Compliance Management (5th)
 

Featured Reviews

Andrew W - PeerSpot reviewer
Tells us about vulnerabilities as well as their impact and helps to focus on real issues
Looking at all the different pieces, it has got everything we need. Some of the pieces we do not even use. For example, we do not have Kubernetes Security. We are not running any K8 clusters, so it is good for us. Overall, we find the solution to be fantastic. There can be additional education components. This may not be truly fair to them because of what the product is going for, but it would be great to see additional education for compliance. It is not a criticism of the tool per se, but anything to help non-development resources understand some of the complexities of the cloud is always appreciated. Any additional educational resources are always helpful for security teams, especially those without a development background.
Matthias Kropf - PeerSpot reviewer
The tool's most valuable feature is visibility but needs improvement in Kubernetes
We use the product in the production environment of server infrastructure.  The tool's most valuable feature is its visibility.  Kubernetes is not installed in the way we need it.  I have been using the product since October.  We faced some minor issues, but overall, the product is stable. I…
Yokesh Mani - PeerSpot reviewer
Easy to write custom rules and policies in the UI with limited coding knowledge
The user interface could be improved. Sometimes, the visibility is not immediately available for the environment. We have the native servers that come with the solutions, but we cannot see them in the Check Point log. Another issue is with the integrated file monitoring. It would make sense to have stuff like file integrity monitoring and malware scanning available within this module because we don't want to integrate another product. For example, let's say it's showing a process violation. It should be able to do some additional malware scanning in that particular bucket to get some additional information. I don't want to integrate with another third-party tool or go to the native server to check something. It would be helpful to have integrated monitoring and malware scanning for the file types. There are a few flaws with the security management portal where I have limited visibility into the workload protection features. There is no error visibility where I can see the communication and workflow between services. Some of the dashboards need to be fine-tuned if they are not customized. For example, I cannot customize anything on the effective risk management dashboard. Some of the information is not correct for my tenant. With respect to passwords and user management, there are no policies I can measure at the user level. If the user was created more than six months ago, you don't need to worry about that password or do anything like two-factor authentication associated with that user. They can still log in after six months or one year. It's also a challenge to use CloudGuard's agentless workload posture with AWS. An Azure storage is summed up with a CNAPP encryption by default. We tried onboarding this data, but the problem is the attachment is not done. After a few days, we identified that it was impossible to do the encryption detection. But CloudGuard's default rules say that this has to be encrypted. The AWS module says that we cannot access this volume with this encryption, so we cannot use an agentless workload posture with AWS because of this. It is a best practice to ensure that all the volumes are being encrypted. Without the encryption, how can I do this? It is a big challenge for CloudGuard.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Cloud Native Security's evidence-based reporting allows us to prioritize issues by understanding their impact, helping us resolve the most important problems first."
"PingSafe's most valuable feature is its unified console."
"The most valuable features of PingSafe are cloud misconfiguration, Kubernetes, and IaC scanning."
"Singularity Cloud Security's most valuable features are its ease of scalability and comprehensive security measures."
"The UI is very good."
"The remediation process is good."
"Support has been very helpful and provides regular feedback and help whenever needed. They've been very useful."
"The management console is highly intuitive to comprehend and operate."
"From day one, you get threat intelligence. It will immediately block active threats, which has been useful."
"Application Ring-Fencing and Deception Server, which is basically like a honeypot, are pretty useful features."
"Guardicore makes its own rule set automatically, so we can work fast when creating a rule set."
"The tool is a complete package that offers many features like visibility. You can get a graph with real-time workflows and visibility into server-to-server communication. We get visibility into many things happening within our environment."
"Its deception features are great, providing a rich telemetry of lured origins, and are a great resource for any active defense strategy."
"The label-based segmentation is the most valuable feature."
"We like the centralized management of the firewalls. Until we installed Guardicore Centra, we managed all our firewalls individually, so making changes was complicated, difficult, and time-consuming."
"The most valuable features of the solution are the maps and ring fencing that help monitor events."
"The most valuable feature is posture management, which gives you complete visibility of all your assets in the cloud and allows you to do governance and compliance."
"The CloudGuard for Cloud Intelligence tool has several significant features that provide security to our company."
"Good interface and visibility."
"The solution's main benefit is that it automates all the patching and reporting parts and generates an automated report."
"Check Point CloudGuard CNAPP's initial configuration is very easy. It is plug-and-play. It also gives regular updates."
"The posture management and remediation features are the most valuable. We use GSL Builder to build custom rules in alignment with our organization's policies. CloudGuard has canned rules using multiple standard frameworks, but we also have additional rules."
"The solution has intelligence that integrates with a range of threat intelligence feeds, including Check Point's ThreatCloud, to provide real-time intelligence on emerging threats."
"The automatic learning and an AI engine help to find more modern vulnerability problems."
 

Cons

"They need more experienced support personnel."
"After closing an alert in Cloud Native Security, it still shows as unresolved."
"There should be more documentation about the product."
"The reporting works well, but sometimes the severity classifications are inaccurate. Sometimes, it flags an issue as high-impact, but it should be a lower severity."
"The area of improvement is the cost, which is high compared to other traditional endpoint protections."
"SentinelOne currently lacks a break glass account feature, which is critical for implementing Single Sign-On."
"We had a glitch in PingSafe where it fed us false positives in the past."
"There's an array of upcoming versions with numerous features to be incorporated into the roadmap. Customers particularly appreciate the service's emphasis on intensive security, especially the secret scanning aspect. During the proof of concept (POC) phase, the system is required to gather logs from the customer's environment. This process entails obtaining specific permissions, especially in terms of gateway access. While most permissions for POC are manageable, the need for various permissions may need improvement, especially in the context of security."
"The product needs a few features like enhanced user policies and payload-level inspection to improve the offering."
"Supports become difficult when it's for a big organization. For a small organization, medium organization, it still makes sense, however, for a big organization, it makes life difficult."
"It doesn't support a PAAC solution (Platforma as a service) in the cloud."
"The long-term management of the security policies could be improved with some kind of automation platform, something like Chef or Puppet or Ansible, to help you manage the policies after day-one... to then manage the policies and changes to those policies, going forward, through some type of automation process is not turning out to be really easy."
"Needs more customization of honeypots and a vaster catalog of systems able to be mimicked."
"Kubernetes is not installed in the way we need it."
"Guardicore Centra should incorporate automation so that we don't require to write custom scripts and APIs. The tool also has limitations on rules where it allows only sixty thousand rules. Our clients have also commented that there are too many manual clicks and effort to do changes. I think that the incorporation of automation can help our clients make changes with confidence and without the possibility of human error."
"I would rate the stability a six out of ten, where one is low and ten is high stability."
"One feature of the product that I would like to enhance is the possibility to connect to vulnerability management platforms so that the issues that emerge from the scans can then be ingested directly into the vulnerability management process."
"The accuracy of its remediation is a 7.5 out of 10. Before, I would have given it a ten but now, to handle remediation for fully qualified domain names, it's not working as it did in the past. We're finding some difficulties there."
"Their service needs improvement."
"Reporting should have more options."
"The security of Check Point CloudGuard Posture Management could improve. There are always new security issues coming out."
"Sometimes, the solution provides us with false alerts of vulnerabilities that are not present in our cloud environment."
"Currently, worldwide, there are many companies of all sizes that do not understand the value that their data has, but even with all existing clouds, they also do not understand what the shared responsibility model is. They only assume that by having a cloud, the provider must ensure safety, when the truth is that the providers only secure their sites. Everything we do in the cloud and how we configure it is actually our responsibility."
"Improvements can be made to the user interface."
 

Pricing and Cost Advice

"I am personally not taking care of the pricing part, but when we moved from CrowdStrike to PingSafe, there were some savings. The price of CrowdStrike was quite high. Compared to that, the price of PingSafe was low. PingSafe is charging based on the subscription model. If I want to add an AWS subscription, I need to pay more. It should not be based on subscription. It should be based on the number of servers that I am scanning."
"Pricing is based on modules, which was ideal for us."
"It's a fair price for what you get. We are happy with the price as it stands."
"I understand that SentinelOne is a market leader, but the bill we received was astronomical."
"The features included in PingSafe justify its price point."
"I would rate the cost a seven out of ten with ten being the most costly."
"While I'm slightly out of touch with pricing, I know SentinelOne is much cheaper than other products."
"It is not that expensive. There are some tools that are double the cost of PingSafe. It is good on the pricing side."
"Guardicore Centra provides better value for money than NSX, was the other solution that we looked at, which was too expensive for what it does."
"Akamai Guardicore Segmentation is expensive."
"Compared to the pricing we were seeing from both Illumio and Edgewise, Guardicore was very competitive."
"The price is the same as other products in the market. There's no price argument to choose one or the other product, it will cost the customer approximately the same."
"The customer would complain about the cost."
"The pricing is too high."
"The solution is reasonably priced and I would rate it a six out of ten. The tool's licensing costs are yearly."
"GuardiCore has made some new changes to the license now. We've seen monthly and annual licenses based on a subscription. We have a few clients that pay anywhere from $25,000 a year."
"​They support either annual licensing or hourly. At the time of our last negotiation, it was either one or the other, you could not mix or match. I would have liked to mix/match. ​"
"The licensing and costs are straightforward, as they have a baseline of 100 workloads (number of instances) within one license with no additional nor hidden charges. If you want to have 200 workloads under Dome9, then you need to take out two licenses for that. Also, it does not have any impact on cloud billing, as data is shared using the API call. This is well within the limit of free API calls provided by the cloud provider."
"We have the enterprise-level license and we renew it annually because it is worth the cost."
"The price is on the higher end."
"The license fee is high."
"The pricing is extremely competitive."
"The solution’s pricing is a little bit high."
"Right now, we have licenses on 500 machines, and they are not cheap."
report
Use our free recommendation engine to learn which Cloud and Data Center Security solutions are best for your needs.
823,795 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
19%
Financial Services Firm
15%
Manufacturing Company
10%
Government
5%
Financial Services Firm
19%
Computer Software Company
15%
Manufacturing Company
7%
Insurance Company
6%
Financial Services Firm
15%
Computer Software Company
14%
Manufacturing Company
9%
Security Firm
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about PingSafe?
The dashboard gives me an overview of all the things happening in the product, making it one of the tool's best featu...
What is your experience regarding pricing and costs for PingSafe?
SentinelOne provided competitive pricing compared to other vendors, and we are satisfied with the deal.
What needs improvement with PingSafe?
To enhance the notification system's efficiency, resolved issues should be promptly removed from the portal. Currentl...
What is your experience regarding pricing and costs for Guardicore Centra?
I would rate the pricing a six out of ten, where one is cheap and ten is expensive. I know other micro-segmentation t...
What do you like most about Guardicore Infection Monkey?
Initially, I liked the telemetry part. But later, we used the microsegmentation features that we were able to deploy ...
What needs improvement with Guardicore Infection Monkey?
When we have more than one interface, we can only have one policy for both interfaces. Normally, you have assets with...
 

Also Known As

PingSafe
Guardicore Centra, GuardiCore
Check Point CloudGuard Posture Management, Dome9, Check Point CloudGuard Workload Protection, Check Point CloudGuard Intelligence
 

Overview

 

Sample Customers

Information Not Available
Santander, Frontier Airlines, OpenLink, Intermountain Healthcare, Cellcom, BancoBASE
Symantec, Citrix, Car and Driver, Virgin, Cloud Technology Partners
Find out what your peers are saying about Akamai Guardicore Segmentation vs. Check Point CloudGuard CNAPP and other solutions. Updated: December 2024.
823,795 professionals have used our research since 2012.