Try our new research platform with insights from 80,000+ expert users

Akamai Guardicore Segmentation vs Check Point CloudGuard CNAPP comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 9, 2024
 

Categories and Ranking

SentinelOne Singularity Clo...
Sponsored
Ranking in Cloud and Data Center Security
5th
Ranking in Cloud Workload Protection Platforms (CWPP)
4th
Average Rating
8.6
Reviews Sentiment
8.1
Number of Reviews
93
Ranking in other categories
Vulnerability Management (6th), Container Security (3rd), Cloud Security Posture Management (CSPM) (4th), Cloud-Native Application Protection Platforms (CNAPP) (3rd), Compliance Management (3rd)
Akamai Guardicore Segmentation
Ranking in Cloud and Data Center Security
2nd
Ranking in Cloud Workload Protection Platforms (CWPP)
12th
Average Rating
8.2
Number of Reviews
18
Ranking in other categories
Breach and Attack Simulation (BAS) (4th), Microsegmentation Software (2nd)
Check Point CloudGuard CNAPP
Ranking in Cloud and Data Center Security
9th
Ranking in Cloud Workload Protection Platforms (CWPP)
6th
Average Rating
8.6
Number of Reviews
69
Ranking in other categories
Vulnerability Management (8th), Container Security (6th), Cloud Security Posture Management (CSPM) (5th), Cloud-Native Application Protection Platforms (CNAPP) (5th), Data Security Posture Management (DSPM) (4th), Compliance Management (5th)
 

Featured Reviews

Andrew W - PeerSpot reviewer
Aug 29, 2024
Tells us about vulnerabilities as well as their impact and helps to focus on real issues
Looking at all the different pieces, it has got everything we need. Some of the pieces we do not even use. For example, we do not have Kubernetes Security. We are not running any K8 clusters, so it is good for us. Overall, we find the solution to be fantastic. There can be additional education components. This may not be truly fair to them because of what the product is going for, but it would be great to see additional education for compliance. It is not a criticism of the tool per se, but anything to help non-development resources understand some of the complexities of the cloud is always appreciated. Any additional educational resources are always helpful for security teams, especially those without a development background.
Matthias Kropf - PeerSpot reviewer
Jan 16, 2024
The tool's most valuable feature is visibility but needs improvement in Kubernetes
We use the product in the production environment of server infrastructure.  The tool's most valuable feature is its visibility.  Kubernetes is not installed in the way we need it.  I have been using the product since October.  We faced some minor issues, but overall, the product is stable. I…
Yokesh Mani - PeerSpot reviewer
Jan 23, 2024
Easy to write custom rules and policies in the UI with limited coding knowledge
The user interface could be improved. Sometimes, the visibility is not immediately available for the environment. We have the native servers that come with the solutions, but we cannot see them in the Check Point log. Another issue is with the integrated file monitoring. It would make sense to have stuff like file integrity monitoring and malware scanning available within this module because we don't want to integrate another product. For example, let's say it's showing a process violation. It should be able to do some additional malware scanning in that particular bucket to get some additional information. I don't want to integrate with another third-party tool or go to the native server to check something. It would be helpful to have integrated monitoring and malware scanning for the file types. There are a few flaws with the security management portal where I have limited visibility into the workload protection features. There is no error visibility where I can see the communication and workflow between services. Some of the dashboards need to be fine-tuned if they are not customized. For example, I cannot customize anything on the effective risk management dashboard. Some of the information is not correct for my tenant. With respect to passwords and user management, there are no policies I can measure at the user level. If the user was created more than six months ago, you don't need to worry about that password or do anything like two-factor authentication associated with that user. They can still log in after six months or one year. It's also a challenge to use CloudGuard's agentless workload posture with AWS. An Azure storage is summed up with a CNAPP encryption by default. We tried onboarding this data, but the problem is the attachment is not done. After a few days, we identified that it was impossible to do the encryption detection. But CloudGuard's default rules say that this has to be encrypted. The AWS module says that we cannot access this volume with this encryption, so we cannot use an agentless workload posture with AWS because of this. It is a best practice to ensure that all the volumes are being encrypted. Without the encryption, how can I do this? It is a big challenge for CloudGuard.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Singularity Cloud Workload Security provides us with better security detection and more visibility. It is another resource that we can use to detect vulnerabilities in our company's systems. For example, it can help us detect new file processes that we are not familiar with, which could be used by attackers to exploit our systems. Singularity Cloud Workload Security can also help us diagnose and analyze data to determine whether it is malicious or not. Singularity Cloud Workload Security is like another pair of eyes that can help us protect our systems from cyberattacks."
"We mostly use alerts. That has been pretty good. If we use the alert system from Amazon, it is much costlier to us, so we use PingSafe."
"The most valuable feature is the ability to gain deep visibility into the workloads inside containers."
"The most valuable features of PingSafe are the asset inventory and issue indexing."
"The mean time to detect has been reduced."
"The real-time detection and response capabilities overall are great."
"PingSafe can integrate all your cloud accounts and resources you create in the AWS account, We have set it up to scan the AWS transfer services, EC2, security groups, and GitHub."
"The multi-cloud support is valuable. They are expanding to different clouds. It is not restricted to only AWS. It allows us to have different clouds on one platform."
"The tool is a complete package that offers many features like visibility. You can get a graph with real-time workflows and visibility into server-to-server communication. We get visibility into many things happening within our environment."
"The most valuable features of the solution are the maps and ring fencing that help monitor events."
"From day one, you get threat intelligence. It will immediately block active threats, which has been useful."
"The tool's most valuable feature is its visibility."
"The real bonus is the fact that we can secure applications, all the way down to the individual services, on each host. It's actually more granular security than we can get out of a traditional firewall."
"The interface and dashboard are amazing."
"The label-based segmentation is the most valuable feature."
"Initially, I liked the telemetry part. But later, we used the microsegmentation features that we were able to deploy and found that they really stood out from other vendors. It allows us to see microsegmentation as distributed services."
"The most valuable feature is the CloudBots for auto-remediation of security findings."
"It provides complete visibility of workload hosted on different cloud platforms including AWS and Azure, along with multiple tenants."
"The new scanning function is a valuable feature that wasn't available until recently."
"It offers security insights and recommendations to assist organizations in acting and remediating issues swiftly."
"The reporting is quite good. It is the most powerful aspect of this solution."
"The product enables us to check the information that goes out of the company."
"The rulesets and the findings are valuable. The actual core functionality of it and the efficacy of events are great."
"It provides the most useful tools for protecting our financial account records from hackers."
 

Cons

"It does not bring much threat intel from the outside world. All it does is scan. If it can also correlate things, it will be better."
"There's an array of upcoming versions with numerous features to be incorporated into the roadmap. Customers particularly appreciate the service's emphasis on intensive security, especially the secret scanning aspect. During the proof of concept (POC) phase, the system is required to gather logs from the customer's environment. This process entails obtaining specific permissions, especially in terms of gateway access. While most permissions for POC are manageable, the need for various permissions may need improvement, especially in the context of security."
"We repeatedly get alerts on the tool dashboard that we've already solved on our end, but they still appear. That is somewhat irritating."
"In terms of ease of use, initially, it is a bit confusing to navigate around, but once you get used to it, it becomes easier."
"The application module focuses on the different codes and libraries that can be run on the machines. It is very important for Singularity EDR to detect what type of codes and what type of libraries can run in the machine. If they can implement a white list or a black list of codes or libraries that can be used in the machine, it would be very helpful. They can focus more on the application module."
"The Infrastructure as Code service available in PingSafe and the services available in AWS cloud security can be merged so that we can get the security data directly from AWS cloud in PingSafe. This way, all the data related to security will be in one single place. Currently, we have to check a couple of things on PingSafe, and we have to validate that same data on the AWS Cloud to be sure. If they can collaborate like that, it will be great."
"We don't get any notifications from PingSafe when the clusters are down."
"I would like PingSafe's detections to be openly available online instead of only accessible through their portal. Other tools have detections that are openly available without going through the tool."
"It doesn't support a PAAC solution (Platforma as a service) in the cloud."
"In our version, when using the terminal server, we cannot exclude user tasks for each session."
"Incident tagging could be improved. Other vendors offer semi-automatic tagging, which Guardicore doesn't yet have."
"The long-term management of the security policies could be improved with some kind of automation platform, something like Chef or Puppet or Ansible, to help you manage the policies after day-one... to then manage the policies and changes to those policies, going forward, through some type of automation process is not turning out to be really easy."
"The dashboard needs improvement. It should be more flexible so that I can easily see what I want or need to see."
"They can maybe improve their customer service just because they are kind of a small organization, and customer service isn't as big as others such as VMware."
"I would rate the stability a six out of ten, where one is low and ten is high stability."
"The product needs a few features like enhanced user policies and payload-level inspection to improve the offering."
"The main issue that we found with Dome9 is that we have a default rule set with better recommendations that we want to use. So, you do a clone of that rule set, then you do some tweaks and customizations, but there is a problem. When they activate the default rule set with the recommendations and new security measures, it doesn't apply the new security measures to your clones profile. Therefore, you need to clone the profile again. We are already writing a report to Check Point."
"You do need to pay extra in order to get better support."
"I would like to see Test B functions at the application access level."
"The user interface could be improved. Sometimes, the visibility is not immediately available for the environment. We have the native servers that come with the solutions, but we cannot see them in the Check Point log. Another issue is with the integrated file monitoring. It would make sense to have stuff like file integrity monitoring and malware scanning available within this module because we don't want to integrate another product."
"The technical support could be better, but I do not know of any other needed improvements."
"Down the road, we would like to see automation. That is probably a feature that most people want. If they can automate patching a vulnerability, it will be much easier."
"Their service needs improvement."
"It does not support on-premise deployments such as VMware Tanzu, and this has been a major drawback when it comes to integrations with some applications."
 

Pricing and Cost Advice

"PingSafe's primary advantage is its ability to consolidate multiple tools into a single user interface, but, beyond this convenience, it may not offer significant additional benefits to justify its price."
"The features included in PingSafe justify its price point."
"I understand that SentinelOne is a market leader, but the bill we received was astronomical."
"PingSafe is less expensive than other options."
"The pricing is fair. It is not inexpensive, and it is also not expensive. When managing a large organization, it is going to be costly, but it meets the business needs. In terms of what is out there on the market, it is fair and comparable to what I have seen, so I do not have any complaints about the cost"
"It's a fair price for what you get. We are happy with the price as it stands."
"PingSafe's pricing is good because it provides us with a solution."
"Its pricing is okay. It is in line with what other providers were providing. It is not cheap. It is not expensive."
"Guardicore Centra provides better value for money than NSX, was the other solution that we looked at, which was too expensive for what it does."
"This is not a cheap solution but you have to consider the bigger picture, which is what it is giving you."
"Compared to the pricing we were seeing from both Illumio and Edgewise, Guardicore was very competitive."
"The pricing is too high."
"The customer would complain about the cost."
"Akamai Guardicore Segmentation is expensive."
"GuardiCore has made some new changes to the license now. We've seen monthly and annual licenses based on a subscription. We have a few clients that pay anywhere from $25,000 a year."
"The solution is reasonably priced and I would rate it a six out of ten. The tool's licensing costs are yearly."
"Right now, we have licenses on 500 machines, and they are not cheap."
"​They support either annual licensing or hourly. At the time of our last negotiation, it was either one or the other, you could not mix or match. I would have liked to mix/match. ​"
"Everything in this field is very expensive."
"Check Point CloudGuard Posture Management is always known as a good solution but an expensive one. When you're using Cisco, Check Point, or Palo Alto, you know that you will pay more, but you know that it will work."
"Its pricing is competitive."
"CloudGuard is fairly priced."
"Check Point CloudGuard Posture Management is expensive."
"The pricing is extremely competitive."
report
Use our free recommendation engine to learn which Cloud and Data Center Security solutions are best for your needs.
815,854 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
19%
Financial Services Firm
16%
Manufacturing Company
10%
Insurance Company
5%
Financial Services Firm
18%
Computer Software Company
16%
Manufacturing Company
7%
Insurance Company
6%
Financial Services Firm
15%
Computer Software Company
14%
Manufacturing Company
9%
Security Firm
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about PingSafe?
The dashboard gives me an overview of all the things happening in the product, making it one of the tool's best featu...
What is your experience regarding pricing and costs for PingSafe?
SentinelOne provided competitive pricing compared to other vendors, and we are satisfied with the deal.
What needs improvement with PingSafe?
Sometimes, I am not able to see the flow when there is an issue. When anyone complains and I have to troubleshoot it,...
What do you like most about Guardicore Centra?
Guardicore Centra offers the best coverage specifically in backward compatibility with legacy operating systems.
What is your experience regarding pricing and costs for Guardicore Centra?
I would rate the pricing a six out of ten, where one is cheap and ten is expensive. I know other micro-segmentation t...
What needs improvement with Guardicore Centra?
Customers would want to see the cost improved.
 

Also Known As

PingSafe
Guardicore Centra, GuardiCore
Check Point CloudGuard Posture Management, Dome9, Check Point CloudGuard Workload Protection, Check Point CloudGuard Intelligence
 

Overview

 

Sample Customers

Information Not Available
Santander, Frontier Airlines, OpenLink, Intermountain Healthcare, Cellcom, BancoBASE
Symantec, Citrix, Car and Driver, Virgin, Cloud Technology Partners
Find out what your peers are saying about Akamai Guardicore Segmentation vs. Check Point CloudGuard CNAPP and other solutions. Updated: October 2024.
815,854 professionals have used our research since 2012.