Try our new research platform with insights from 80,000+ expert users

BMC Helix Cloud Security vs IBM Turbonomic comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

SentinelOne Singularity Clo...
Sponsored
Average Rating
8.6
Reviews Sentiment
8.1
Number of Reviews
92
Ranking in other categories
Vulnerability Management (6th), Cloud and Data Center Security (5th), Container Security (3rd), Cloud Workload Protection Platforms (CWPP) (4th), Cloud Security Posture Management (CSPM) (4th), Cloud-Native Application Protection Platforms (CNAPP) (3rd), Compliance Management (3rd)
BMC Helix Cloud Security
Average Rating
8.0
Number of Reviews
5
Ranking in other categories
Cloud Workload Protection Platforms (CWPP) (24th), Cloud Security Posture Management (CSPM) (31st)
IBM Turbonomic
Average Rating
8.8
Number of Reviews
205
Ranking in other categories
Cloud Migration (5th), Cloud Management (4th), Virtualization Management Tools (3rd), Cloud Analytics (1st), Cloud Cost Management (1st)
 

Mindshare comparison

Cloud Workload Protection Platforms (CWPP)
Virtualization Management Tools
 

Featured Reviews

Andrew W - PeerSpot reviewer
Aug 29, 2024
Tells us about vulnerabilities as well as their impact and helps to focus on real issues
Looking at all the different pieces, it has got everything we need. Some of the pieces we do not even use. For example, we do not have Kubernetes Security. We are not running any K8 clusters, so it is good for us. Overall, we find the solution to be fantastic. There can be additional education components. This may not be truly fair to them because of what the product is going for, but it would be great to see additional education for compliance. It is not a criticism of the tool per se, but anything to help non-development resources understand some of the complexities of the cloud is always appreciated. Any additional educational resources are always helpful for security teams, especially those without a development background.
GregoireSoukiassian - PeerSpot reviewer
Oct 20, 2023
Effectively addresses security concerns but could use enhancement in terms of integration
BMC Helix Cloud Security has room for improvement in terms of integrating its various features. It currently consists of separate point solutions that don't flow together as seamlessly as they could. This lack of integration, unlike platforms like ServiceNow, may be due to historical factors. Enhancing this integration would make it a more compelling choice from a business perspective and offer a smoother user experience. In the next release of BMC Helix Cloud Security, I would like to see additional features, particularly AI integration, which has already been announced. AI integration could bring more precision to the platform, making it even more interesting and effective.
SubashSubbiah - PeerSpot reviewer
Dec 10, 2022
It can tell us where performance is lagging on the hardware layer, but the reporting on the application layer is lacking
The automation area could be improved, and the generic reports are poor. We want more details in the analysis report from the application layer. The reports from the infrastructure layer are satisfactory, but Turbonomic won't provide much information if we dig down further than the application layer. I would like them to add some apps for physical device load resourcing and physical-to-virtual calculation. It gives excellent recommendations for the virtual layer but doesn't have the capabilities for physical-to-virtual analysis. Automated deployment is something else they could add. Some built-in automation features are helpful, but we aren't effectively using a few. We want a few more automated features, like autoscaling and automatic performance optimization testing would be useful.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"They're responsive to feature requests. If I suggest a feature for Prisma, I will need to wait until the next release on their roadmap. Cloud Native Security will add it right away."
"PingSafe provides email alerts and ranks issues based on severity, such as high, critical, etc., that help us prioritize issues."
"The UI is very good."
"We noted immediate benefits from using the solution."
"The offensive security feature is valuable because it publicly detects the offensive and vulnerable things present in our domain or applications. It checks any applications with public access. Some of the applications give public access to certain files or are present over a particular domain. It detects and lets us know with evidence. That is quite good. It is protecting our infrastructure quite well."
"We really appreciate the Slack integration. When we have an incident, we get an instant notification. We also use Joe Sandbox, which Singularity can integrate with, so we can verify if a threat is legitimate."
"Cloud Native Security is a tool that has good monitoring features."
"It is fairly simple. Anybody can use it."
"Role-based security is a valuable feature."
"The features that I've found most valuable are its container security aspect. I also like its vulnerability management tools."
"The most valuable aspects of BMC Helix Cloud Security are its security features and regulatory compliance capabilities."
"The best feature is time to value. With very minimal effort, you are able to have a cohesive view into your security posture on one or multiple cloud accounts, particularly if you are dealing with multicloud. If you have Azure and AWS deployments, you might have multiple subscriptions in Azure and usually multiple accounts in AWS. You may even be doing some GCP work (around Google Cloud Platform). It's very difficult to manage a common set of policies, even less reporting, across multiple subscriptions, accounts, and cloud environments. What BMC Helix Cloud Security does is provide a unified view or single pane of glass as to your baseline. Then, it also facilitates the ability for Level 1 or 2 operations support to take action and report on security vulnerabilities."
"It's also multi-cloud. You can look at several cloud providers: AWS, Azure, or GCP."
"The cool feature of Helix Cloud Security is that you can do all that — understand and remediate issues — in one dashboard, based on the different policies that are available for security, out-of-the-box."
"With over 2500 ESX VMs, including 1500+ XenDesktop VDI desktops, hosted over two datacentres and 80+ vSphere hosts, firefighting has become something of the past."
"The recommendation of the family types is a huge help because it has saved us a lot of money. We use it primarily for that. Another thing that Turbonomic provides us with is a single platform that manages the full application stack and that's something I really like."
"I like Turbonomic's automation and AI machine learning features. It shows you what it can do, but it can also act on recommendations automatically. Integration with an APM system makes the AI/ML features truly effective. Understanding what the application is doing and the trends of application behavior can help you make real-world decisions and act on that information."
"The solution has a good optimization feature."
"The automated memory balancing, where it looks at whether it's being used in the most efficient way and adds or takes away memory, is the best part. If it didn't do that, it would be something that I would have to do. We have too many machines for one person to do that. The automation helps me in that it is done in a really efficient way and a balanced way because of the policies. It really helps."
"Turbonomic can show us if we're not using some of our storage volumes efficiently in AWS. For example, if we've over-provisioned one of our virtual machines to have dedicated IOPs that it doesn't need, Turbonomic will detect that and tell us."
"The feature for optimizing VMs is the most valuable because a number of the agencies have workloads or VMs that are not really being used. Turbonomic enables us to say, 'If you combine these, or if you decide to go with a reserve instance, you will save this much.'"
"The primary features we have focused on are reporting and optimization."
 

Cons

"Currently, we would have to export our vulnerability report to an .xlsx file, and review it in an Excel spreadsheet, and then we sort of compile a list from there. It would be cool if there was a way to actually toggle multiple applications for review and then see those file paths on multiple users rather than only one user at a time or only one application at a time."
"For vulnerabilities, they are showing CVE ID. The naming convention should be better so that it indicates the container where a vulnerability is present. Currently, they are only showing CVE ID, but the same CVE ID might be present in multiple containers. We would like to have the container name so that we can easily fix the issue."
"In some cases, the rules are strictly enforced but do not align with real-world use cases."
"They can work on policies based on different compliance standards."
"Crafting customized policies can be tricky."
"The Kubernetes scanning on the Oracle Cloud needs to be improved. It's on the roadmap. AWS has this capability, but it's unavailable for Oracle Cloud."
"The reporting works well, but sometimes the severity classifications are inaccurate. Sometimes, it flags an issue as high-impact, but it should be a lower severity."
"There's an array of upcoming versions with numerous features to be incorporated into the roadmap. Customers particularly appreciate the service's emphasis on intensive security, especially the secret scanning aspect. During the proof of concept (POC) phase, the system is required to gather logs from the customer's environment. This process entails obtaining specific permissions, especially in terms of gateway access. While most permissions for POC are manageable, the need for various permissions may need improvement, especially in the context of security."
"The UI could be more user-friendly."
"BMC Helix Cloud Security has room for improvement in terms of integrating its various features."
"I want the role-based security feature to be improved."
"We've had some with issues connectors. The connectors have seemed to have caused a little bit of trouble, perhaps with the APIs trying to scan the environment. The only time I've had to reach out to tech support was for that. It seems it may not have been scanning correctly or I wasn't seeing data within a specific time. But we've set up a couple of connectors in the past couple of weeks and they actually scanned the AWS environment and we had data within about 10 minutes. It's working a lot faster and I think they're making improvements as they go."
"Every organization out there doesn't rely on just one control body. They use FISMA control. They may use HIPAA, CIS, PCI, or SOX, then blend them. One of the things that is now in big demand for BMC Helix Cloud Security is content. That's the next journey in its lifespan, making it easier for the community to share and collaborate on content for security controls that can be measured and remediated."
"It would be good for Turbonomic, on their side, to integrate with other companies like AppDynamics or SolarWinds or other monitoring softwares. I feel that the actual monitoring of applications, mixed in with their abilities, would help. That would be the case wherever Turbonomic lacks the ability to monitor an application or in cases where applications are so customized that it's not going to be able to handle them. There is monitoring that you can do with scripting that you may not be able to do with Turbonomic."
"We're still evaluating the solution, so I don't know enough about what I don't know. They've done a lot over the years. I used Turbonomics six or seven years ago before IBM bought them. They've matured a lot since then."
"It would be nice for them to have a way to do something with physical machines, but I know that is not their strength Thankfully, the majority of our environment is virtual, but it would be nice to see this type of technology across some other platforms. It would be nice to have capacity planning across physical machines."
"It sometimes does get false positives. Sometimes, it'll move something when it really wasn't a performance metric. I've seen it do that, but it's pretty much an automated tool for performance. We've only got about 500 virtual machines, so lots of times, I'm able to manage it physically, but it's definitely a nice tool for a larger enterprise that might be managing 2,000 or 3,000 virtual machines."
"In Azure, it's not what you're using. You purchase the whole 8 TB disk and you pay for it. It doesn't matter how much you're using. So something that I've asked for from Turbonomic is recommendations based on disk utilization. In the example of the 8 TB disk where only 200 GBs are being used, based on the history, there should be a recommendation like, "You can safely use a 500 GB disk." That would create a lot of savings."
"Turbonomic doesn't do storage placement how I would prefer. We use multiple shared storage volumes on VMware, so I don't have one big disk. I have lots of disks that I can place VMs on, and that consumes IOPS from the disk subsystem. We were getting recommendations to provision a new volume."
"After running this solution in production for a year, we may want a more granular approach to how we utilize the product because we are planning to use some of its metrics to feed into our financial system."
"Remove the need for special in-house knowledge and development."
 

Pricing and Cost Advice

"Singularity Cloud Workload Security's pricing is good."
"The features included in PingSafe justify its price point."
"I am personally not taking care of the pricing part, but when we moved from CrowdStrike to PingSafe, there were some savings. The price of CrowdStrike was quite high. Compared to that, the price of PingSafe was low. PingSafe is charging based on the subscription model. If I want to add an AWS subscription, I need to pay more. It should not be based on subscription. It should be based on the number of servers that I am scanning."
"PingSafe is affordable."
"Its pricing is okay. It is in line with what other providers were providing. It is not cheap. It is not expensive."
"The pricing for PingSafe in India was more reasonable than other competitors."
"PingSafe falls somewhere in the middle price range, neither particularly cheap nor expensive."
"Pricing is based on modules, which was ideal for us."
"It is a subscription model with term licensing that is usually yearly. This includes, not only the product, but support and maintenance. It is based on cloud assets. Therefore, if you have 100 cloud assets, those cloud assets are measured based on evaluation or transactions. For example, if I'm evaluating that cloud asset for CIS compliance, PCI compliance, and AWS best practices, that asset gets evaluated three times, as those are three transactions. However, the license model is based on peak asset usage. So, over a year, if you deploy 100, 1000, 500, and then 2000 assets, you will be charged for the 2000 peak of assets managed by Helix Cloud Security."
"The pricing is based on an annual subscription, upfront, and it's based on cloud assets. Whether your assets are in Azure and AWS combined, the tool tells you how many assets are being scanned and that's the number used for pricing."
"The pricing and licensing are fair. We purchase based on benchmark pricing, which we have been able to get. There are no surprise charges nor hidden fees."
"It was an annual buy-in. You basically purchase it based on your host type stuff. The buy-in was about 20K, and the annual maintenance is about $3,000 a year."
"The product is fairly priced right now. Given its capabilities, it is excellently priced. We think that the product will become self-funding because we will be able to maximize our resources, which will help us from a capacity perspective. That should save us money in the long run."
"Everybody tells me the pricing is high. But the ROIs are great."
"Price is a big one. VMTurbo was very competitively priced."
"I have not seen Turbonomic's new pricing since IBM purchased it. When we were looking at it in my previous company before IBM's purchase, it was compatible with other tools."
"I consider the pricing to be high."
"I know there have been some issues with the billing, when the numbers were first proposed, as to how much we would save. There was a huge miscommunication on our part. Turbonomic was led to believe that we could optimize our AWS footprint, because we didn't know we couldn't. So, we were promised savings of $750,000. Then, when we came to implement Turbonomic, the developers in AWS said, "Absolutely not. You're not putting that in our environment. We can't scale down anything because they coded it." Our AWS environment is a legacy environment. It has all these old applications, where all the developers who have made it are no longer with the company. Those applications generate a ton of money for us. So, if one breaks, we are really in trouble and they didn't want to have to deal with an environment that was changing and couldn't be supported. That number went from $750,000 to about $450,000. However, that wasn't Turbonomic's fault."
report
Use our free recommendation engine to learn which Cloud Workload Protection Platforms (CWPP) solutions are best for your needs.
814,649 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
19%
Financial Services Firm
16%
Manufacturing Company
10%
Insurance Company
5%
Financial Services Firm
26%
Computer Software Company
18%
Manufacturing Company
8%
Real Estate/Law Firm
8%
Financial Services Firm
16%
Computer Software Company
14%
Manufacturing Company
11%
Healthcare Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

What do you like most about PingSafe?
The dashboard gives me an overview of all the things happening in the product, making it one of the tool's best featu...
What is your experience regarding pricing and costs for PingSafe?
I am personally not taking care of the pricing part, but when we moved from CrowdStrike to Singularity Cloud Native S...
What needs improvement with PingSafe?
They can provide some kind of alert when a new type of risk is there. There can be a specific type of alert showing t...
What do you like most about BMC Helix Cloud Security?
The most valuable aspects of BMC Helix Cloud Security are its security features and regulatory compliance capabilities.
What is your experience regarding pricing and costs for BMC Helix Cloud Security?
I would rate the price of BMC Helix Cloud Security as a seven in terms of costliness. It is not the cheapest option a...
What needs improvement with BMC Helix Cloud Security?
BMC Helix Cloud Security has room for improvement in terms of integrating its various features. It currently consists...
What is your experience regarding pricing and costs for Turbonomic?
It offers different scenarios. It provides more capabilities than many other tools available. Typically, its price is...
What needs improvement with Turbonomic?
The implementation could be enhanced.
What is your primary use case for Turbonomic?
We use IBM Turbonomic to automate our cloud operations, including monitoring, consolidating dashboards, and reporting...
 

Also Known As

PingSafe
TrueSight Cloud Security, SecOps Policy Service
Turbonomic, VMTurbo Operations Manager
 

Learn More

Video not available
 

Interactive Demo

Demo not available
Demo not available
 

Overview

 

Sample Customers

Information Not Available
NHS, Vodafone, Kansas City Life, SKY Italia, Cybera
IBM, J.B. Hunt, BBC, The Capita Group, SulAmérica, Rabobank, PROS, ThinkON, O.C. Tanner Co.
Find out what your peers are saying about Palo Alto Networks, Wiz, Microsoft and others in Cloud Workload Protection Platforms (CWPP). Updated: October 2024.
814,649 professionals have used our research since 2012.