Try our new research platform with insights from 80,000+ expert users
reviewer1670079 - PeerSpot reviewer
Project Manager at a tech services company with 1,001-5,000 employees
Real User
Complex environment, difficult to install, and expensive, but it's reliable
Pros and Cons
  • "The performance could be good because we chose it at the time, but it is too complex for us to appreciate its performance because we lack the necessary skills."
  • "They are not satisfied with the complexity of the solution and the price."

What is most valuable?

The performance could be good because we chose it at the time, but it is too complex for us to appreciate its performance because we lack the necessary skills.

What needs improvement?

They are not satisfied with the complexity of the solution and the price.

To be used, we must have proper skills that require additional support, and the entire potential of the tool is not utilized and addressed. As a result of a lack of skills, it is complex.

Network auditing, which AlgoSec does, could be included, or perhaps Sky Box does but we don't know how to use it.

For how long have I used the solution?

The company has been using Skybox Security Suite for quite a while, and they are thinking about changing the solution.

They have been working with it for at least three years.

What do I think about the scalability of the solution?

We are in a complex environment, and we have three teams, with approximately 30 people using it on various entities.

Buyer's Guide
Skybox Security Suite
February 2025
Learn what your peers think about Skybox Security Suite. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
838,713 professionals have used our research since 2012.

How are customer service and support?

We did not contact technical support. We attempted to have the necessary skills in-house, but it was insufficient. That is why we are seeking alternatives.

Which solution did I use previously and why did I switch?

We also, work with Tufin. We have not been working with it for that long, we are in the POC phase. We are testing the tool.

We are also considering AlgoSec. I believe that is our current favorite, but we don't have a final decision at this time, but it appears to be AlgoSec.

How was the initial setup?

The environment is very complex.

The deployment took a long time. We are considering changing it because it simply did not finish. It's as if we didn't do it properly.

We have a team of two to maintain this solution.

What's my experience with pricing, setup cost, and licensing?

The licensing fee is paid yearly and is approximately $100,000.

Which other solutions did I evaluate?

I am researching firewall security management tools like Tufin, and AlgoSec.

As a product manager, I don't work with any products. I am just assisting team members in finding alternatives. I am a consultant.

What other advice do I have?

I believe it is a management contract. I believe that such solutions should not be handled on-premise, and we must obtain a proper support contract with SLAs from the service provider. When we do install it on-premises, we have no support, no feedback, and no commitment, except to extend the contract.

We are both customers and a partner with Skybox Security Suite.

I would rate Skybox Security Suite a five out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Asst. Manager Finance at a insurance company with 5,001-10,000 employees
Real User
User-friendly, extracts data easily, scales well, and it's easy to install
Pros and Cons
  • "It's very supportive and very user-friendly."
  • "The price could be cheaper."

What is our primary use case?

We use this solution for data encryption.

We provide and deploy this solution for our customers and show them how to extract the reports. Our customers are really happy.

If they run into any issues, we resolve their queries.

What is most valuable?

It's a good product. We can extract the data from it very easily.

It's very supportive and very user-friendly.

What needs improvement?

We are not using the solution and rely on customer feedback. If the customer does not provide any, then we can't recommend what could be better.

If they have had any kind of issues, then we are able to know and have it perform better.

For how long have I used the solution?

I have been using this solution for four months.

We are using the latest version.

What do I think about the stability of the solution?

It's a stable solution. We haven't had any issues with stability in the four months that we have been using it.

What do I think about the scalability of the solution?

It's a scalable product. We scaled our internal projects.

We only have single customers who are using this solution.

How are customer service and technical support?

We have not contacted technical support because we have not any issues.

Our clients have not had any queries. If they do, then we would contact technical support.

How was the initial setup?

It's easy to install and deploy.

It took one month to deploy to all of the branches.

What about the implementation team?

The integration was done by the vendor. We didn't do any kind of integration.

What's my experience with pricing, setup cost, and licensing?

We purchase the license for the product.

Customers do not purchase the license, we take care of that.

When compared with other companies, the license is more costly.

The price could be cheaper.

What other advice do I have?

We have deployed this solution for our clients and have not received any complaints.

I would definitely recommend this solution to others.

I would rate Skybox Security Suite a ten out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Buyer's Guide
Skybox Security Suite
February 2025
Learn what your peers think about Skybox Security Suite. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
838,713 professionals have used our research since 2012.
SeniorIn877a - PeerSpot reviewer
Senior Information Security Analyst at a energy/utilities company with 501-1,000 employees
Real User
Does a great job of reaching into firewalls and network devices to produce risk and compliance recommendations along with a single plane of glass for queries
Pros and Cons
  • "Security review is the most important feature, because it offers a single pane of glass to analyze multiple firewalls."
  • "This type of tool does a great job of reaching into those other devices producing risk recommendations, compliance recommendations, and a single plane of glass to do your queries, so you can find where these rules might exist."
  • "The vendor's support is terrible."

What is our primary use case?

The primary use case is security and network for security.

How has it helped my organization?

It has grown organically and become a full featured suite. If you have the funding, you can make it do all types of great things.

What is most valuable?

Security review is the most important feature, because it offers a single pane of glass to analyze multiple firewalls.

What needs improvement?

The vendor's support is terrible. The rest of the product is fine.

For how long have I used the solution?

More than five years.

What do I think about the stability of the solution?

With certain versions, we have encountered stability.

What do I think about the scalability of the solution?

The stability is fine for my organization.

How are customer service and technical support?

The technical support is not good. I would rate them as a three out of 10.

Which solution did I use previously and why did I switch?

We did not previously use a different solution.

How was the initial setup?

The initial setup is easy.

What's my experience with pricing, setup cost, and licensing?

The pricing has increased exorbitantly in the last few years, so now it is questionable. Now, it makes me want to review other products.

With licensing, the number of network nodes becomes very expensive to the point where you have to rationalize if the tools are warranted anymore.

Fully understand the total cost of ownership. They have gone to a new model where you have to replace the hardware every X amount of years at a very substantial cost and fully understand your intended number of nodes. To operate a firewall, you have to pay two licenses, a firewall node and a network node. If you are a reasonable-sized organization, this gets expensive very quickly.

We go through an evaluated reseller to purchase the product.

Which other solutions did I evaluate?

We did evaluate other options many years ago when Skybox was the leader in this space, but today, there are others that can compete.

I am looking at using other competitive products from other vendors. The reason would be because other people are using them and we need to or consolidate our tools.

What other advice do I have?

I really like the product. I do not have the experience with its competitors, either in function or pricing. It is a very useful tool, especially for those who do not have access to the devices they are monitoring. Because of separation of duties, you often do not have access to the firewalls or network devices. This type of tool does a great job of reaching into those other devices producing risk recommendations, compliance recommendations, and a single plane of glass to do your queries, so you can find where these rules might exist.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Regional Sales Engineer at RedSeal, Inc.
Real User
Rich vulnerability management that is controlled from a single pane of glass, but the network modeling capability needs improvement
Pros and Cons
  • "The most valuable feature is firewall management."
  • "The Network Assurance, which helps to create the network model, is not so rich."

What is our primary use case?

We are a system integrator and this is one of the products that we implement for our clients. This is one of the vendors that we focus on, from a security standpoint.

Skybox has an amazing portfolio that makes up the security solution. You can onboard your network devices with the network assurance module. This includes layer three, layer two switches, load balancers, and so on. This partially builds the network model for the infrastructure and the entire security platform is built off of that.

How has it helped my organization?

With the combination of the vulnerability management database and third-party integration, vulnerability management is very rich. When you add the network model, Skybox can tell you exactly which vulnerabilities in the infrastructure are exploitable. I have seen examples where there are 7,000 vulnerabilities exposed at one time. This includes highlighting things that are open, or exposed.

What is most valuable?

The most valuable feature is firewall management. It is excellent. It works by onboarding different firewall vendors and together with network assurance, builds a complete network model.

Vulnerability management is very good and it has its own vulnerability database. It gives you the ability to integrate with vulnerability management tools like Nessus, which is used by Tenable, Rapid7, and Qualys. The vulnerability software also integrates with endpoint software such as Symantec, Trend Micro, and McAfee. This is important because in this era, the biggest threat is from the endpoint. This is where most of the attacks are coming from these days.

Skybox integrates with patch management, which contributes to the broad functionality.

Everything is controlled from a single pane of glass.

The Skybox Suite includes change management, which makes up part of the complete security solution.

Skybox Horizon is a dashboard that shows you all of the modules. It is nice because it can show granularity at the level of interest for the NOC or SOC, but it can also give executive dashboarding for the VP or CTO at a business level that is not as concerned about the details.

The out-of-the-box compliance is very good, as it handles PCI and ISO.

What needs improvement?

The Network Assurance, which helps to create the network model, is not so rich. It tells you the best part, and it gives you the alternate routes that are available based on the configuration and the routing table, but it doesn't give you the analytics. One of the issues with security is that if the network model is incorrect then no matter what I add on top of it, it's going to be of no use. Network modeling is the foundation for vulnerability management, test management, firewall management, and change management.

The focus on risk analytics is not very good and should be improved. It relies on the CVSS (Common Vulnerability Security Score), which gives you a vulnerability score based on the standard. The difficulty with this is that sometimes, risks are based on critical assets, and these can differ between environments. My critical assets, for example, may be different than those of my customers. As such, it doesn't give you a fully-fledged risk score. On top of this, it doesn't give you the flexibility to configure a set of weights to adjust the criticality of the assets, the users, and the entities within the infrastructure.

Another area where Skybox lacks is the calculation for combinations and permutations of traffic from each interface. For example, in RedSeal, if traffic comes in from one interface and doesn't go out the desired interface, you can see what is vulnerable, what the vulnerability is, what is exposed, what is exploitable, whether it is subject to an insider threat or an outside threat, what the criticality is, and so on. It is all related to network modeling and seeing what happens when an interface goes down. In general, it needs to be enhanced.

They have to improve their integration with vulnerability management tools. It is good with some products, such as Tenable, but not really good with Rapid7.

Technical support can be improved in some regards because certain teams are better than others.

There is no dashboard for ISR compliance or NESA compliance.

For how long have I used the solution?

3 years

What do I think about the stability of the solution?

Skybox Suite is an unstable solution.

What do I think about the scalability of the solution?

This is a scalable solution.

In the region that I am working in, the director has indicated that we want to target organizations with a minimum of 15 firewalls and 500 devices. Essentially, the networks are very big, the firewalls and devices might be from different vendors, and the operations teams are having trouble managing them.

Skybox, from a scalability perspective, is only for customers with a very large environment that is complex.

Scalability is also a factor when a customer is migrating to the cloud. Specifically, when transitioning from on-premises to the cloud the customer will need cloud-based firewalls, load balancing, sandboxing, etc. This means that the network map in Skybox needs to include the cloud.

How are customer service and support?

When I am working on a deployment or on a PoC, and I see an issue with the software that is not related to the configuration, I open a ticket with the support team.

I am not always satisfied with the support that they provide. In general, I am satisfied, but there are different teams within Skybox that handle different modules. The firewall management team is the best, the network assurance team is very good, and the vulnerability and threat management team is not so good. Sometimes, I get the wrong person and I have to escalate the ticket to the highest priority and get the engineering team on it. With change management, I have only had technical support in regards to a single client.

How was the initial setup?

The initial setup is straightforward, as you have a template for the network assurance.

This solution can be installed on-premises or as a cloud-based deployment with the virtual edition. The architecture for the latter is very simple. In a small environment with less than 1,000 devices, you can use one server, install the software, and it has a database associated with it. You just have to make sure that it can be accessed by every device across the VLAN.

The tricky part of the configuration has to do with vulnerability management, threat management, and change management. When it comes to difficulty, change management is the hardest one when it comes to configuration. The reason for this is that customers normally have their own change management solution, such as ServiceNow and they are not very comfortable offloading the ITSM to do change management. It's a hard shift and a difficult sell. If it is done properly, however, it can automatically identify the vulnerabilities and threats and mitigate them as per the change management policy. Workflows need to be defined. For example, when a firewall change is needed then it needs to know the chain of approval. Since every customer has their own approval or rejection procedure, it has to be based on their requirements.

When it comes to deployment, we use a "Land and Expand" strategy. We land with network assurance and firewall management, which gives the customer a taste of the product. From there, we onboard vulnerability management and threat management. I don't recommend to anybody that they start with this solution full-fledged because it will not necessarily yield a better ROI.

For a network of perhaps a thousand network devices, if all of the ports are open and the permissions are in place, then it should not take longer than two days. You can take one extra day for fine-tuning, but three days is more than enough. After this, it will take another two days for firewall management. When we consider the vulnerability management and threat management modules, we have to take them on a case-by-case basis.

Sometimes, a customer will not have a vulnerability management tool like Tenable or Rapid7, so we rely solely on the Skybox vulnerability database. We also integrate with endpoint solutions because of the importance of protecting them. As an example, if the customer is using McAfee for the endpoint protection then it will take me around three days to complete the integration. Certain vendors do not provide out of the box integration, so we have to use the API, which adds to the time required for deployment. Often, it can be done in three days.

Finally, change management is a tough thing to do that depends on the use cases. Without this aspect considered, I would say that the deployment can be completed in 15 days. This is all for a typical deployment. If the customer needs customization then it will change the deployment date.

What about the implementation team?

A deployment engineer is a single person and I can do the deployment myself. It is not often very complex, as long as things are done correctly from the beginning. The checklist has to be complete, which means that the image has to be stable and the compute that you requested is there. You also need to ensure that the required port numbers for device accessibility are there from the server, and the database is there. Once all of that is in place, the configuration is not difficult.

When it comes to integration, the other vendor has to be available during the same period. It is sometimes difficult to schedule but it is necessary to complete the deployment in a specified timeframe.

What was our ROI?

The ROI would not be good for a smaller company, which is why Skybox is better for large networks. It may take three or four years for a small company to break even.

All of the firewall vendors have their own firewall manager. Fortinet, for example has FortiManager, whereas Palo Alto has Panorama. If a customer has only four firewalls and they are all from Fortinet then it makes more sense for them just to use FortiManager.

The value really comes in when there are a large number of firewalls and they are from different vendors. This is where 360-degree visibility really starts to help. When you see the amount of time it saves, this is where the ROI becomes obvious.

Which other solutions did I evaluate?

I have been evaluating other options including RedSeal, AlgoSec, Tufin, and FireMon. Each vendor has its own strengths and weaknesses. I think that the network modeling capability in RedSeal is far ahead of the rest. Also, in terms of vulnerability management, RedSeal is amazing.

FireMon is really lacking in terms of network modeling.

My best choice is RedSeal.

What other advice do I have?

My advice to anybody who is implementing this product is to make sure that they utilize it. The usage of it should be mandated for the NOC and SOC. They should use a single dashboard to take care of all of your infrastructure components.

When a Skybox representative visits to discuss this solution, it is important to discuss the use cases properly. Have a good project plan and it is also very important to have the right partner. They should be certified, trained, and involved at all stages.

Overall, it is a pretty good product. When you use it, you will see the benefit of it.

I would rate this solution a seven out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Informat54af - PeerSpot reviewer
Information Security Consultant at a insurance company with 1,001-5,000 employees
Consultant
Helps us make sure that all of our devices are configured as they should be
Pros and Cons
  • "The most valuable feature is the compliance, whether it's access compliance or the configuration compliance, to make sure that all of our devices are configured as they're supposed to be, to limit access as much possible, to follow least-access guidelines."
  • "Reporting. A lot of the reports, out of the box, are limited to a certain number of either configuration violations or access rule violations. So when you first set up a new firewall to be monitored by Skybox, you don't get a real full report. You have to really tweak it to get everything."
  • "I've had issues with licensing where, when they were expiring and I asked for the updated licenses, I would the wrong ones. I think their process needs to be straightened out a little bit - I don't know if they fixed it already, it has been awhile. It wasn't as straightforward as it could have been."

What is our primary use case?

We use it to verify firewall compliance with NIST best practices for access and that our firewalls are configured correctly. We're also getting ready to roll out their Vulnerability Management package.

We mostly use Firewall Assurance and we're getting ready to start using Vulnerability Control.

How has it helped my organization?

What we have done is found a lot of misconfigured stuff on firewalls. Our company, Verisk, is a company that buys other companies. We have 70 or so companies at last count and most of them are founder-based companies we bought. They had little to no idea of how to actually secure a firewall correctly. Using Skybox, when we bring them on we take a look at how their firewalls are configured and then make recommendations as far as what they need to do to tighten it up. That is the main function we've been using it for and that is where we have gotten the most benefit out of it.

From Firewall Assurance, the only other real benefit you get is eliminating shadowed rules and redundant rules. You can optimize a little bit based on real usage to move the rules that are used more towards the top of the access lists so that the firewall processes them a little faster. It's a small benefit but it's definitely something that, depending on your business, may be important to you.

What is most valuable?

The most valuable feature is the compliance, whether it's access compliance or the configuration compliance, to make sure that all of our devices are configured as they're supposed to be, to limit access as much possible, to follow least-access guidelines.

What needs improvement?

Reporting. A lot of the reports, out of the box, are limited to a certain number of either configuration violations or access rule violations. So when you first set up a new firewall to be monitored by Skybox, you don't get a real full report. You have to really tweak it to get everything.

In our business, our company buys a lot of other companies and a lot of them manage themselves. Unfortunately, for Firewall Assurance in particular, if you need a group of people to be able to manage their firewalls and only theirs, it's almost impossible because to add a new firewall you have to be an admin, and you can't limit what an admin sees. If I want a particular company to be able to add their firewalls, they're going to see everybody else's firewalls as well, which is much more access than they need. That is one thing I would love to see fixed.

For how long have I used the solution?

One to three years.

What do I think about the stability of the solution?

Stability is good. They do come out with a lot of patches and the updating process, while not a pain, is pretty frequent.

What do I think about the scalability of the solution?

We had to separate our initial appliance into the server and a separate collector just because we have, at last count, about 120 firewalls in there. Collecting all the firewall information in all the logs daily during off hours, it started to get a little choked up. When we separated the server and the collector onto two different machines that fixed the problem.

How are customer service and technical support?

On a scale of one to 10, I would rate Skybox technical support at about eight. It's not perfect, but good. They are not always able to answer questions on first contact but the questions always get answered. The answer is not always what I want to hear, but they do get answered.

Which solution did I use previously and why did I switch?

I used the AlgoSec. AlgoSec wasn't broken up into modules, it was one solution. It was good; again, not perfect, but then their prices just got ridiculous. The fact that Skybox is broken up into modules and you only have to pay for what you're actually going to use, that was the main reason for switching. The pricing was secondary. AlsoSec doesn't do everything that Skybox does, but they were charging a lot more.

How was the initial setup?

Setup is relatively straightforward. There were a couple of things that I found a little difficult. They have an Add Firewall Wizard, but if you want to create a task list or a task group that runs on a certain schedule, it's almost easier to import the firewall as a task rather than using the wizard. You almost have to do the work twice if you do use the wizard. 

The other difficulty was, it really wasn't made clear that separating the server and the collector, for a certain number of firewalls or over, was a best practice. Having to go back and redo that was a little bit of a surprise.

But overall, it's relatively easy to use. There is a little bit of learning curve to figure out how to get the right information out of the reporting. But once you do it, it works.

What's my experience with pricing, setup cost, and licensing?

As with anything else, I would love it to be less expensive, but do I think pricing is a good value? Sure.

I've had issues with licensing where, when they were expiring and I asked for the updated licenses, I would the wrong ones. I think their process needs to be straightened out a little bit - I don't know if they fixed it already, it has been awhile. It wasn't as straightforward as it could have been. When you get the licenses you just put in the license numbers so it's working. That part is easy. It's getting the correct licenses that can be a little cumbersome.

Which other solutions did I evaluate?

We looked at AlgoSec, but their pricing was too high. And previously I had looked at Tufin but they just didn't have the wealth of features that either Skybox or AlgoSec have. Overall, we evaluated other stuff. It's just that Skybox made the most sense for us.

What other advice do I have?

  • Determine what your needs are.
  • Buy only the products you need, when you need them.
  • Make sure that your sales engineer goes over best practices with you so that you do it right the first time.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Informatb8c7 - PeerSpot reviewer
Information Security Architect at a non-profit with 201-500 employees
Real User
Streamlines reporting on ACL usage and on shadowed and redundant rules on the firewall
Pros and Cons
  • "Key features for us include the firewall change audit every week. Also, being able to track firewall ACL usage, so that we can produce semiannual reports on ACL usage and shadowed and redundant rules on the firewall."
  • "If anything could be improved it would be staying on top of the collector scripts, but I understand that's a very tough challenge."

What is our primary use case?

Auditing firewall changes on a weekly basis. We use the Network and the Firewall modules. Firewall as I said, and we use the Network and Firewall for PCI compliance reporting.

How has it helped my organization?

It has automated things. What was a manual process is now just running a report and delivering it to the people who have to mitigate the issues. A better workflow.

What is most valuable?

It's the firewall change audit every week. Also, being able to track firewall ACL usage, so that we can produce semiannual reports on ACL usage and on shadowed and redundant rules on the firewall.

What needs improvement?

It's tough to say, because the areas of improvement, I understand the difficulty. For example, they pull configs from thousands of types of devices, and it's difficult for them to stay on top of when vendors change the way their commands work. If anything, it would be staying on top of the collector scripts, but I understand that's a very tough challenge.

For how long have I used the solution?

Three to five years.

What do I think about the stability of the solution?

We had an issue one time, but it was related to a major release upgrade. But that happens every now and then with vendors. 

What do I think about the scalability of the solution?

We've had no need to scale it.

How is customer service and technical support?

 Excellent. They're right on top of it. Very reactive.

How was the initial setup?

Straightforward.

What's my experience with pricing, setup cost, and licensing?

The product's pricing is excellent value.

In terms of licensing, make sure you understand your network components, all your hops through your network, thoroughly, before you decide on the total cost. If you want to do point-to-point flow analysis and such, you need to have the configuration of all the devices in between point A and point B. A lot of people don't realize all their network components until they start using this product.

Which other solutions did I evaluate?

We evaluated FireMon versus Skybox when we selected Skybox - they were really the two that were best at doing automated reporting for PCI. It was a compliance issue. We thought Skybox really fit our needs best.

What other advice do I have?

Other than what I said - ensuring that you have a really good understanding of all the network components that you have to ingest configurations from - definitely take it out for a proof of concept for 30 days. There are a lot of features in here that we don't use, Change Management and stuff like that, that you want to take a look at and see if they fit your needs.

I would say the reason I can't go higher than eight out of 10 is that their major release announcements aren't always straightforward. You usually discover that there is a new major release when going to their website and you discover it on your own. So they're not really good at major release announcements. 

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user1140936 - PeerSpot reviewer
Business Consultant. at a tech services company with 11-50 employees
Reseller
Good solution with strong features
Pros and Cons
  • "The features that I have found most valuable with Skybox Security Suite, and this is because I work on the security side, are the firewall assurance, the change manager and the vulnerability control. These three features are the most impressive from Skybox Security."
  • "The initial setup with Skybox Security is hard. You need one or two strong security engineers on your team."

What is our primary use case?

We use the firewall assurance and the network assurance when we use change manager to check any changes in our firewall. We also use FortiGate's firewall for all our company. For six months, until 2020, we used the vulnerability control module to analyze our infrastructure.

For one of my customers, we used firewall assurance, network assurance and change manager - three modules. We optimized the firewall appliance and rules for one of the Ukrainian banks.

How has it helped my organization?

Skybox Security Suite is a great, strong solution. But you need a good engineer with high-level technical skills. For businesses it is a great solution - you look at the pie chart and understand everything. But if we talk about technical expertise, you need one or two technical expertise guys on your team to support this platform. You need to check, understand and discuss all cases and events, analyze these events, and make changes in your infrastructure. In terms of the technical aspect, it's good. For businesses, it is great.

What is most valuable?

The features that I have found most valuable with Skybox Security Suite, and this is because I work on the security side, are the firewall assurance, the change manager and the vulnerability control. These three features are the most impressive from Skybox Security.

In terms of the firewall rules, compliance, and vulnerability control, I need to understand what changes were provided from my IT team. I need to understand how these changes impact our compliance. I need to understand this to make decisions.

In terms of the vulnerability control, we need to understand how changes in our infrastructure impact the security in our company, such as having an open port to LinkedIn or Facebook. This could be very bad for the cybersecurity in our company, because some hackers or some non-loyal employees could make a lot of trouble.

So we need to understand how our changes impact the cybersecurity of our company. And Skybox Security is one of greatest solutions for this because you can see the firewall and the network infrastructure and you understand what's happening and how it could impact your cybersecurity.

What needs improvement?

In terms of what could be improved, I would say support for Cisco Firepower. This is one of the biggest segments in the Ukraine market. Many customers use Cisco Firepower. It is not a good solution for me, but it make sense. The second feature that could be improved is a deeper integration with Palo Alto. One of my customers uses Palo Alto and during the trial period with Skybox Security, we had some issues because when the IT administrator used the rules Skybox Security didn't understand. But it's not really a problem with Skybox Security. This was a problem for the company who used these stupid rules.

For how long have I used the solution?

I have been using Skybox Security Suite for the last 15 months. 

What do I think about the stability of the solution?

In terms of stability, humans write the code. So any solution will have some issues. So yeah, we have one or two issues, but for me, Skybox Security support is one of quicker supports in the world. I am familiar with support from Symantec and from Microsoft, these are bad support-wise. I also know about the support from McAfee and SolarWinds. For me, SolarWinds, Skybox and FireEye have quick, good support.

Support is good for me.

How was the initial setup?

The initial setup with Skybox Security is hard. You need one or two strong security engineers on your team. We have that. One of my colleagues has great experience as a cybersecurity engineer officer. So we deployed, but during deployment we asked the Skybox team for support. You need to understand what you are doing and why you are doing it.

What's my experience with pricing, setup cost, and licensing?

We use an NFR, not for resale, license because we have a strong relationship with Skybox Security. But Skybox Security sent me yearly support for the license, not monthly.

Skybox Security has good pricing.

If you need something like Skybox, you would pay more money than for a cybersecurity platform, because you need FireMon for firewalls. For firewalls, you would need a subscription to Cisco Tetration, for example, or for something else. These are more expensive solutions in collaboration. So if you want to save money and save time, use Skybox Security.

What other advice do I have?

I would absolutely recommend using Skybox Security.

If you need to check compliance and to understand how your IT teams work, use Skybox Security. If you need understand, like a clear glass of water, how your IT infrastructure works, use Skybox.

Tenable or Qualys or Rapid7 vulnerability controls in your infrastructure could be installed for vulnerability scans. But they don't know what kind of attack could be used or what vector of attack could be used. If you use Skybox you will see the impact, all the issues with your infrastructure and your configuration, and you can quickly change the situation to be more protected from outside and inside attacks.

On a scale of one to ten, I would give Skybox Security an eight.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Distributor
PeerSpot user
Syed Rizwan - PeerSpot reviewer
Cyber Security Engineer at Defa3 cyber security
Reseller
Top 5Leaderboard
Has good change management, firewall and network assurance
Pros and Cons
  • "I am impressed with the tool's change management, firewall and network assurance."
  • "The solution needs improvement in firewall configuration checks. I would also like to see more configuration checks for Forcepoint and for other non-supported firewalls."

What is most valuable?

I am impressed with the tool's change management, firewall and network assurance. 

What needs improvement?

The solution needs improvement in firewall configuration checks. I would also like to see more configuration checks for Forcepoint and for other non-supported firewalls. 

For how long have I used the solution?

I have been using the product for three years. 

What do I think about the scalability of the solution?

My company has 20 users for the product. 

How was the initial setup?

I would rate the solution's setup a ten out of ten and is straightforward. The product's deployment takes one week to complete. 

What's my experience with pricing, setup cost, and licensing?

I would rate the tool's pricing an eight out of ten. 

What other advice do I have?

I would rate the product a ten out of ten. 

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free Skybox Security Suite Report and get advice and tips from experienced pros sharing their opinions.
Updated: February 2025
Buyer's Guide
Download our free Skybox Security Suite Report and get advice and tips from experienced pros sharing their opinions.