Try our new research platform with insights from 80,000+ expert users
it_user589365 - PeerSpot reviewer
Senior Analyst at a consultancy with 10,001+ employees
Real User
You don’t need to run scans by logging into different databases. It is monitored through the centralized console.

What is most valuable?

The most valuable feature of this product is vulnerability management since you don’t need to run different scans by logging into different databases. Everything can be done and monitored through the centralized console by a few clicks and without any hassle.

Also, the report generation option on a daily/weekly/monthly basis comes in very handy to the top management.

How has it helped my organization?

Some of the ways in which this product has helped our organization are:

  • All the databases are being monitored.
  • All the compliance requirements can be taken care of through a console.
  • The daily and weekly reports are helpful in understanding the environment.

What needs improvement?

The stability and the ease of use of this product can be improved. I believe the product can be made more flexible and stable.

Additionally, it is very unlikely for a new professional to easily use this tool to its full potential. For this purpose, I believe a few more video tutorials can be uploaded for the newer versions.

For how long have I used the solution?

I have been using this solution for one year.

Buyer's Guide
Imperva SecureSphere Database Security
January 2025
Learn what your peers think about Imperva SecureSphere Database Security. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,265 professionals have used our research since 2012.

What do I think about the stability of the solution?

We have encountered some stability issues. There were situations when sometimes the gateway didn’t work as expected. However, thanks to active-passive mode, none of the information was lost.

What do I think about the scalability of the solution?

Every manager and gateway has a predefined capacity. It is very easy to scale up to that capacity. But, if that is exhausted you have to burn the midnight oil.

How are customer service and support?

The technical support is good in terms of knowledge. However, the replies are not so frequent and hence can be frustrating sometimes.

Which solution did I use previously and why did I switch?

I have not used any other solution before. I have only used Imperva SecureSphere 11.0.

How was the initial setup?

The initial setup was straightforward. Each and every step is clearly mentioned in the manual. After the initial setup, it becomes a bit tricky.

What's my experience with pricing, setup cost, and licensing?

Since this tool is far better than the competitors and manages a lot of compliance requirements, the pricing seems to be fine.

Which other solutions did I evaluate?

We had evaluated other solutions such as McAfee DAM and IBM Guardium.

What other advice do I have?

You should follow both the guide and the tutorials. The tool is handy only if it is implemented properly. Implementation is a bit complicated; hence, it is advisable to create documentation alongside. It would be more beneficial to use the directory present on the Imperva site before logging for any issues.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user531942 - PeerSpot reviewer
it_user531942Director of Product Marketing at a tech company with 1,001-5,000 employees
Real User

Hi Sudarshan, I am no longer at Imperva, but I agree with you that the legacy console works well, but the UI is dated by today's standard. When I left in the Spring of 2017 there was an R&D project for a new centralized server that would take over some of the legacy console's functionality and add some of the modern elements teams are looking for. It might be worth asking your account manager for a roadmap presentation.

See all 3 comments
Network Engineer at CBN
Real User
Top 20
Up-to-date inventory management and compliance
Pros and Cons
  • "The most valuable feature is the automatic reports on new databases, which gives us up-to-date inventory management."
  • "Sometimes the reports are cumbersome, and you have to drill down to get more information."

What is our primary use case?

I use SecureSphere to monitor our core databases and privilege operations by administrators, and to provide compliance reports.

How has it helped my organization?

In terms of regulatory compliance, one of the key requirements is to ensure that our core databases are monitored. SecureSphere allows us to generate details to prove that we're compliant with all requirements.

What is most valuable?

The most valuable feature is the automatic reports on new databases, which gives us up-to-date inventory management.

What needs improvement?

Sometimes the reports are cumbersome, and you have to drill down to get more information. SecureSphere also sometimes needs a lot of maintenance to keep the agents running on the database. In the next release, Imperva should include a preventative solution that will stop an attack before it happens or read the behavior of particular accounts and act on it. They should also make SecureSphere available on mobile so that if an administrator isn't on-prem, he can access the solution via the internet wherever he may be.

For how long have I used the solution?

I've been using this solution for almost three years.

What do I think about the stability of the solution?

SecureSphere has been very stable until recently, due to the addition of new source databases causing performance issues.

What do I think about the scalability of the solution?

SecureSphere is very scalable.

How are customer service and support?

Imperva's technical support has been good. In the past, it sometimes took a long time to resolve an issue, but more recently, the responsiveness has been very impressive.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

Previously, we used Oracle Audit Vault, but its reports were a little complex, and their support was not so impressive.

How was the initial setup?

The initial setup was straightforward, and the deployment took between one and two weeks.

What about the implementation team?

Our deployment was done in-house.

What was our ROI?

SecureSphere has resulted in us receiving audit exceptions, especially from the final details, which is a big deal to my organization since we have to be compliant.

What other advice do I have?

I would recommend SecureSphere to other users and advise making a dedicated team available to work on the solution and configure the correct set of policies so they can get value for their money. I'd give SecureSphere a rating of eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Imperva SecureSphere Database Security
January 2025
Learn what your peers think about Imperva SecureSphere Database Security. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,265 professionals have used our research since 2012.
reviewer1787367 - PeerSpot reviewer
Manager - IT Security
Real User
A straightforward solution for compliance, security, and visibility over data access
Pros and Cons
  • "There are three major main use cases of this solution. The first one is to fulfill compliance regulations. Customers—especially the banks, health sector, and manufacturing—need to comply with the regulations in different countries. They have to fulfill compliance regulations around the privacy of data. In order to fulfill those requirements, they're using Imperva. It helps them to fulfill these requirements, and they are not fined by the regulators. That is the first use case why people buy Imperva."
  • "They can maybe look at its pricing model. Its pricing could be cheaper for the African countries or developing economies."

What is our primary use case?

I'm the product manager for Imperva in Africa for a distributor. I manage it every day, but I don't personally use it. We sell Imperva to customers in 17 countries. 

Its deployment depends on the customer. Some customers have their databases in the cloud, and if they have them in the cloud, we give them the cloud database security of Imperva. If their database is on-premises, then we deploy it on-premises, and the reseller implements the solution on-premises.

What is most valuable?

There are three major main use cases of this solution. The first one is to fulfill compliance regulations. Customers—especially the banks, health sector, and manufacturing—need to comply with the regulations in different countries. They have to fulfill compliance regulations around the privacy of data. In order to fulfill those requirements, they're using Imperva. It helps them to fulfill these requirements, and they are not fined by the regulators. That is the first use case why people buy Imperva.

The second one is for security itself. They don't want a cybercriminal to have access to the data. Imperva is a security solution, and you can use it to block unauthorized access to your data. 

The third one is related to rightful access to the data. They want to know:

  • Who has access to the data internally?
  • What queries were being issued on the database?
  • What time did they log in?
  • What is going on within the environment?
  • Who is touching the data?
  • What are they doing with the data internally? 

Customers or organizations want to have access or have visibility into all these.

What needs improvement?

They can maybe look at its pricing model. Its pricing could be cheaper for the African countries or developing economies.

For how long have I used the solution?

I have been using this solution for three years.

What do I think about the scalability of the solution?

It is very scalable. If a customer wants it for five database servers, he gets licenses for five database servers. Tomorrow, if they want licenses for two extra databases, they can just buy the extra two licenses. It is very scalable and very straightforward.

How are customer service and support?

Their support is fantastic. It is 24/7. You raise a ticket, and you get someone assigned to you immediately.

I would rate them a five out of five. In a worst-case scenario, it would be a four, but it's always very straightforward. We get a very quick response.

How was the initial setup?

It is very easy and very straightforward. There are no complications.

What's my experience with pricing, setup cost, and licensing?

Its pricing could be cheaper for the African countries or developing economies. The British pound is valued way more than the currency of most African countries. A better or cheaper pricing model for Nigerian and African customers would be better.

It has a per-year subscription model. You pay exactly for what you need. That's all. You don't have to buy what you don't need.

What other advice do I have?

It is very straightforward. It is probably the best solution out there in terms of data security. About 90% to 95% of the banks in Nigeria use Imperva. When you have such a success story in Nigeria, Ghana, and of course, many other African countries, you can be sure that you are getting a very good solution. 

I would rate it a nine out of 10.

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner.
PeerSpot user
it_user579513 - PeerSpot reviewer
Senior System Engineer at a financial services firm with 1,001-5,000 employees
Vendor
We found new patterns of user behaviour and corrected authorisations.

How has it helped my organization?

Database auditing has become simple and easy, releasing storage previously used for native database audit processes. We found new patterns of database users' behaviour and corrected some user authorisations.

What needs improvement?

Mainframe mappings/agents/optimization for CPU usage are areas with room for improvement.

Agent on z/OS does not have a limit for CPU usage like on other platforms. If
you specify filter too "wide", the agent would consume too much cpu so that
could cause more cost for your mainframe. Agents are a bit special for
configuration because the logic is different than the one on other
platforms.

That is because mainframe agents were originally from Tomium company that
was acquired by Imperva some time ago. They still run the same code, just
little improved.
At this point, my configuration does not collect what I expected, but that
could be due to bugs, that is expected to be solved in version 12 of the
SecureSphere.

You can say for sure that security audit costs money - in this case, your
mainframe CPU money.

For how long have I used the solution?

I have been using it for 18 months.

What was my experience with deployment of the solution?

We had a problem with mainframe DB2 mappings; incorrect results due to bug. A fix is expected in DAM (Database Activity Monitoring) version 12 in March 2017.

What do I think about the stability of the solution?

I have not encountered any stability issues. Only, you need to optimize the data/events you are receiving. If you have too much input, you will have a stability problem (in that case, lower event throughput and increase manager memory).

What do I think about the scalability of the solution?

I have not encountered any scalability issues. It's flexible.

How are customer service and technical support?

Customer service is excellent, 5/5.

Which solution did I use previously and why did I switch?

We did not previously use a different solution. We had some pilot projects and chose this solution.

How was the initial setup?

Initial setup was straightforward and it was simple/easy to install and customize.

What about the implementation team?

A combination of in-house and local support teams implemented it. We are satisfied with their level of expertise.

What was our ROI?

ROI is good. We needed this system for getting ISO 27001.

What's my experience with pricing, setup cost, and licensing?

Be careful if you have a mainframe. Calculate well...

Which other solutions did I evaluate?

Before choosing this product, we evaluated IBM InfoSphere Guardium.

What other advice do I have?

We are very satisfied with this product. It's simple to use, customize and administer. Installation is simple and easy, even on mainframe.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user249771 - PeerSpot reviewer
Information Security Compliance Manager at a financial services firm with 10,001+ employees
Vendor
This is a very complex solution with a wide range of capabilities.

What is most valuable?

The database activity monitoring module used for real time database monitoring and integrated into the security event and incident monitoring solution. Most importantly for our critical legacy databases that cannot be encrypted and require real time a activity monitoring.

How has it helped my organization?

It provides a more granular monitoring of database activity at the column and row level as opposed to high level database management system logs.

What needs improvement?

The professional services and customer training aspect needs to be improved.

For how long have I used the solution?

I've used it for four years.

What was my experience with deployment of the solution?

The first implementation was not tailored to our specific requirements and the system was basically an expensive log collector until the vendors came to capture our requirements and then made modifications. This was then followed up with training.

What do I think about the stability of the solution?

No issues encountered.

What do I think about the scalability of the solution?

No issues encountered.

How are customer service and technical support?

Customer Service:

It's moderate.

Technical Support:

It's moderate.

Which solution did I use previously and why did I switch?

I used a different solution with a former employer.

How was the initial setup?

We are a large organization with about 100 critical heterogeneous database servers. This means that one configuration does not fit all, and that made the implementation very complex. Combined with protection of sensitive information that could be logged by the solution.

What about the implementation team?

We used a vendor and their level of expertise was between moderate and high.

What was our ROI?

The ROI based on the number of prevented, and detected, information security incidents can be classified as high.

Which other solutions did I evaluate?

We also looked at Sentrigo Hedgehog by McAfee.

What other advice do I have?

Ensure the vendor clearly captures your specific database monitoring requirements and that might include importing the metadata of the database for proper monitoring. Training should be included in the implementation budget as this is a very complex solution with a wide range of capabilities.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user254619 - PeerSpot reviewer
Operations Consultant at a financial services firm with 10,001+ employees
Real User
Sometimes convincing the engineering team that there was a problem was a bit harder than it should have been, but the on-site engineers who supported the implementation were excellent.

What is most valuable?

We utilise the following components:

  1. Database activity monitoring of Oracle/SQL/Sybase databases - we did have UDB running, but that was decommissioned
  2. Assessment scans using mostly custom checks to check for security settings - we did expand this at one point to check for best practise, but this was discontinued

How has it helped my organization?

It hasn't really improved the way we function, but it has allowed us to meet several audit issues that were outstanding for many years. We tried another product, but we found it did not meet our requirements.

What needs improvement?

  • Capacity management of application needs significant improvement
  • Task management functionality is pretty basic, with not a lot of functionality
  • I would also like to be able to replace IP addresses with DNS names for easier recognition of host machines
  • The SOM feature could also be dramatically improved to allow central management of the entire feature set
  • The ability to manage lifecycle of agents could be improved via central deployment of upgraded agents

For how long have I used the solution?

I started using the database auditing/risk areas of the product in mid-2011. We use agents for monitoring database activity. We do not use the gateways for collecting data via the network.

What was my experience with deployment of the solution?

We had several performance issues on high throughput applications due to outdated, old hardware/non-ideal settings in the agents. These were mostly on our end.

What do I think about the stability of the solution?

We had a few minor issues with stability, but it has not impacted our service. We did have an agent cause a reboot of a host server, but this was quickly fixed via an upgrade of the agent.

What do I think about the scalability of the solution?

Capacity management is a major issue with the application. There is no easy way to identify when new hardware is required, or if a modification to the configuration could solve the issue. This may have been due to our method of deployment though.

How are customer service and technical support?

Customer Service:

We had a service provider in-between Imperva and our organisation. It did not make things easy. When dealing directly with Imperva I had good experiences with the vendor, and real issues were escalated quickly and getting access to the relevant engineering sections of the vendor was possible.

Technical Support:

Technical support was hit and miss. Sometimes we received excellent support, and other times it was not so good. Sometimes convincing the engineering team that there was a real problem in the software was a bit harder than it should have been. Overall, compared to other vendors, support was good.

Which solution did I use previously and why did I switch?

We previously used another solution, and that product was different depending on the DBMS that was being monitored. Technical expertise in DBMS technology with that vendor was poor, so we switched..

How was the initial setup?

The initial setup was easy, but some of the specific requirements we had required some work. Deploying the hardware during the initial setup did not require and specific customisation for our organisation. The audit policies and assessments obviously did require customisation, but it was relatively simple. Later on, we did find some issues that were due to the setup of the site hierarchy that was not brought to our attention until one to two years later.

What about the implementation team?

We used on-site vendor engineers to support the internal implementation. Their level of expertise was excellent.

What was our ROI?

This is not relevant to the production selection, as we were required to close off auditing items.

Which other solutions did I evaluate?

We compared IBM Guardium and Imperva SecureSphere via a POC process. We did a paper evaluation of other products to choose two products for the POC.

What other advice do I have?

Go through the POC process and test all ITIL processes to ensure you understand what will be required for the entire lifecycle of implementation/support. Engage with DBA teams to provide DBA support and knowledge. If it's possible, ensure there are people who understand databases on the SecureSphere support team.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer1310718 - PeerSpot reviewer
Tech Lead at a financial services firm with 1,001-5,000 employees
Real User
Great data discovery and sensitive data scanning with helpful activity monitoring
Pros and Cons
  • "The integration is great."
  • "The solution needs local support."

What is our primary use case?

We primarily use the solution  just to monitor database activity on all the in-house databases.

What is most valuable?

I like almost everything about the solution. That includes sensitive data scanning, which is what is the most important. The data discovery is great as well. 

I like the activity monitoring. That was the main reason we purchased the tool.

The integration is great.

They do quite a lot of feature updates. 

What needs improvement?

The solution needs local support.

They need to do a little bit more knowledge-sharing with the tool. Knowledge-sharing is not what you normally get with Microsoft, Symantec, or any other tools that are leaders in their respective spaces. This is more of a closed-group type of solution only, whereby the information is only accessible to certain groups, or maybe in certain countries. It needs a broader, more accessible knowledge base. 

There could be more on the monitoring side of things. They need more monitoring tools within the tool itself. Although it does a good job monitoring databases, in terms of the health of its agent gateways to verify communication and all that, there are basically no utilities available within the tool.

For how long have I used the solution?

I've used the solution for a little over three years. 

What do I think about the stability of the solution?

The stability is average. I'd rate it three and a half out of five in terms of stability. It's not too bad. 

What do I think about the scalability of the solution?

This is a highly scalable product. I'd rate it four out of five in terms of its ability to scale. 

We have 15 people using the solution.

How are customer service and support?

Local companies have limited exposure to the tool There's professional support and support from the providers, however, if they don't know too much about it, they cannot provide adequate help. 

How would you rate customer service and support?

Positive

How was the initial setup?

While I didn't handle the initial deployment myself, from the training I have done, it is my understanding that the implementation process would not be that hard. 

I'm not sure how many people were involved in the deployment. 

I handle any maintenance myself with the sales provider. There might be six people available to maintain the product. There would be about three from the customer side and two from the service provider's side.

What about the implementation team?

We did have a third party assist with the initial setup. They were from the vendor. 

What's my experience with pricing, setup cost, and licensing?

I am not sure how much the licensing is exactly. that said, my understanding is that it is expensive. 

What other advice do I have?

We're customers and end-users.

We are using the latest version of the solution. 

It's pretty good in terms of capabilities. I'd rate it eight out of ten. 

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Arnab - PeerSpot reviewer
Data Analyst at a tech services company with 11-50 employees
Real User
Top 5Leaderboard
The tool has good database reporting features, but setup and licensing are quite expensive
Pros and Cons
  • "Database reporting features are valuable to us."
  • "The GUI is bad."

How has it helped my organization?

The solution helps us with monitoring the databases, servers, and activities.

What is most valuable?

Using the product is a good experience. Database reporting features are valuable to us.

What needs improvement?

The GUI is bad. The product must focus on improving its reporting features and the dashboard.

For how long have I used the solution?

I have been using the solution for nine months.

What do I think about the stability of the solution?

I rate the tool’s stability a five or six out of ten. The glitches and errors have recently been quite high because they allow connection to databases without verifying or discovering the database. We have to keep in mind that we must monitor all the time.

What do I think about the scalability of the solution?

The scalability is pretty good. I rate it a seven out of ten.

How was the initial setup?

The setup can be a little complicated.

What was our ROI?

For the pricing that the solution provides, the return on investment is good for large companies. It's quite expensive for small to medium businesses.

What's my experience with pricing, setup cost, and licensing?

Overheads like physical databases and servers can be a little bit expensive. The setup and license are quite expensive.

What other advice do I have?

I would not recommend the product to small and medium businesses. Overall, I rate the tool a seven out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free Imperva SecureSphere Database Security Report and get advice and tips from experienced pros sharing their opinions.
Updated: January 2025
Product Categories
Database Security
Buyer's Guide
Download our free Imperva SecureSphere Database Security Report and get advice and tips from experienced pros sharing their opinions.