Comprehensive web protection has reduced attack impact and supports faster incident decisions
What is our primary use case?
My main use case for Imperva Application Security Platform includes DDoS, cross-site scripting, and SQL injections. This kind of signatures will be detected and blocked by Imperva Application Security Platform.
I used Imperva Application Security Platform to check a particular target and verify what action was taken by Imperva Application Security Platform on multiple bad requests, whether they were suspended, allowed, or blocked. The decision making regarding what is taken by Imperva Application Security Platform, I used to check in the tool. I can conclude that whether it is impactful or not on the target and take a decision to follow the further incident response plan.
What is most valuable?
I interact with Imperva Application Security Platform by checking the action taken by Imperva Application Security Platform and also configuring the rules. It effectively works on blocking according to the rules we specify. It is the best tool for detection and mitigation of current web-related attacks.
In my experience, the best features of Imperva Application Security Platform include blocking malicious requests and checking the status of those requests. Each and every detail taken by Imperva Application Security Platform, I can note down, and I can take decisions.
The level of detail in the status reports from Imperva Application Security Platform is one hundred percent helpful for my work.
Imperva Application Security Platform positively impacts my organization by helping to mitigate web-related attacks. Our clients' web applications are kept very secure and safe.
What needs improvement?
As per my knowledge, everything regarding Imperva Application Security Platform is okay, but I do not have that much level to explain the improvement part. As per my best knowledge, it is a wonderful tool as of now, and nothing major changes are required.
Maybe regular updates that evolve with current situations and integrate with a threat intel base, allowing automatic blocking of the IOCs, could be beneficial.
For how long have I used the solution?
I have been using Imperva Application Security Platform for three years.
What do I think about the stability of the solution?
Imperva Application Security Platform is stable in my experience.
What do I think about the scalability of the solution?
The scalability of Imperva Application Security Platform is pretty much scalable, and it can be used in any environment. It is a very scalable tool.
How are customer service and support?
My experience with Imperva's customer support is that it is very great; they react in a timely manner, so it is good.
Which solution did I use previously and why did I switch?
Previously, I used
Akamai, but
Akamai is difficult to navigate and check the operations. Whereas Imperva Application Security Platform gives precise and concise information about things, so it is a much better tool when compared to Akamai.
What was our ROI?
I have seen a return on investment because it saves money and time as it automatically takes decisions on IOCs and blocks them immediately, which helps us mitigate the IOCs before they exploit the vulnerabilities.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing of Imperva Application Security Platform shows that they are very affordable and also very helpful and needful for the organization. It is a great offer.
Which other solutions did I evaluate?
I did not evaluate other options before choosing Imperva Application Security Platform because it is the best one currently in the market.
What other advice do I have?
I have not seen anything major in terms of specific outcomes or measurable improvements, but it is already taking decisions very effectively and blocking malicious requests, and also helps us gather information about the IOCs and block them in the end. It is a very useful tool for organizations, and I suggest every organization use it.
Imperva Application Security Platform is deployed in my organization in both on-premises and public and private cloud environments.
I would rate Imperva Application Security Platform a ten out of ten because in our environment, it is just a perfect tool. I do not know about the other environments. I give this rating of ten out of ten to Imperva Application Security Platform.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Web defenses have blocked unauthorized access and protect sensitive health data effectively
What is our primary use case?
My main use case for Imperva Application Security Platform is to block unauthorized IPs, users, and source applications, as we configured the Web Application Firewall to monitor internet-based applications during my previous project.
To decide which policies to configure for blocking unauthorized users and sources, we identify authorized users and source IP addresses, ensuring only those belonging to the organization are validated and whitelisted in Imperva Application Security Platform to effectively block unauthorized sources. Imperva Application Security Platform works on a whitelisting concept, meaning only whitelisted users are allowed while others are treated as unauthorized.
We implement multiple policies for sensitive data in the Web Application Firewall because users may attempt to access sensitive health-related information. In a healthcare project, we set up patterns to alert if sensitive data is accessed within the organization and block it if accessed externally.
What is most valuable?
The best features of Imperva Application Security Platform include its ease of use, as it offers both on-premises and cloud options, with minimal maintenance downtime during patching due to the recommended three gateways setup, allowing for resource monitoring while upgrading.
Imperva Application Security Platform positively impacts my organization by reducing CVE-related issues significantly, as we monitor and learn from reports generated during collaboration with respective teams.
We track the reduction in CVE-related issues through weekly and monthly meetings using Imperva Application Security Platform reports. Initially, there were over 1,500 vulnerabilities, but we managed to fix almost all of them within three months, leaving only two low severity issues outstanding.
What needs improvement?
Imperva Application Security Platform can be improved as it currently lacks integration with other tools under the Data Security Fabric, particularly the WAF feature, which would enhance overall functionality.
Generally, I am satisfied with the user experience of Imperva Application Security Platform; however, I would suggest streamlining the patching process for larger environments as it becomes time-consuming when applying multiple patches across many gateways.
For how long have I used the solution?
I have been working in IT security for 10 years out of my overall 17 plus years of experience.
What do I think about the stability of the solution?
Imperva Application Security Platform is always stable, having encountered issues infrequently across my usage of their products.
What do I think about the scalability of the solution?
The scalability of Imperva Application Security Platform is indeed good, effectively accommodating growth for larger organizations despite internal data management policies.
Imperva Application Security Platform handles scalability effectively, allowing for growth when appropriately understood through policies and configurations, although understanding the platform takes time.
How are customer service and support?
Customer support from Imperva has been very good as I have raised over 100 cases, with responsive support addressing urgent needs, even offering early support despite initial SLA challenges.
Which solution did I use previously and why did I switch?
We did not previously use a different solution, starting with DAM and moving directly into a full implementation due to an incident that required rapid deployment.
How was the initial setup?
We utilized AWS for our private cloud environment, finding it satisfactory, although I only used Imperva Application Security Platform Cloud once for DAM, not WAF.
What was our ROI?
While I would not say we have saved money, we have certainly saved time through effective documentation and support for compliance-related issues, streamlining the necessary processes with fewer employees.
What's my experience with pricing, setup cost, and licensing?
We faced challenges with high costs, as the customer perceived pricing for gateways to be excessive, but we handled multiple billing instances with sophisticated setups.
Which other solutions did I evaluate?
We did not evaluate other options before choosing Imperva Application Security Platform, opting for it directly because it fit our needs for an on-premises solution.
What other advice do I have?
Beyond the WAF, Imperva DAM is beneficial because it features Imperva Security Fabric and Data Security Fabric, including tools like File Access Activity Monitoring, though the WAF is still using previous functionalities.
I can confirm that Imperva Application Security Platform is stable, though we have not purchased Imperva Application Security Platform cloud environment from the AWS Marketplace.
It is important to decide the purpose for using Imperva Application Security Platform; I recommend it for monitoring internet-based applications, while for internal tasks, it may not be worthwhile due to its costs. I would rate this review as a 9.
Which deployment model are you using for this solution?
Private Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Continuous monitoring has strengthened our web defenses and has reduced malicious incidents
What is our primary use case?
My main use case for
Imperva Application Security Platform is the
Web Application Firewall, which I use for firewall protection and monitoring 24/7 for suspicious activity.
Regarding my main use case, I first log into the WAF applications, then access the Alerts section. In that section, I can see different types of activity happening in the firewall. I review each alert to determine whether it is legitimate or suspicious activity. I can also view the target IP address and locations, target servers, and the payload that the attacker was using in that alert. I can see the OWASP Top 10 alerts and the event timing to identify when the attack occurred.
What is most valuable?
Imperva Application Security Platform offers impressive features. I am using the WAF, which blocks each alert based on signature-based attacks. That is the most impressive aspect I have experienced.
There are many alerts in Imperva Application Security Platform. For example, there is an OWASP Top 10 alert called SSRF, which is server-side request forgery. If someone attempts to access the server, the WAF blocks that SSRF alert, or RCE, Remote Code Execution alert, blocking immediately based on the signature, not only by the payload or the IP address. That is very effective.
Imperva Application Security Platform has positively impacted my organization because every time an attacker uses a malicious payload or malicious signature that is already included in the signature database of the WAF application or Imperva application, the application directly blocks that particular signature immediately. This capability can help any organization achieve better security outcomes.
What needs improvement?
I believe Imperva Application Security Platform can be improved because cybersecurity is a field that changes every day, and different types of signatures are being invented. The WAF team should add more signatures, including basic and advanced signatures, on a daily basis. They need to understand this requirement and update their signature database daily.
For how long have I used the solution?
I have been using Imperva Application Security Platform for almost one year and four months.
What do I think about the stability of the solution?
Imperva Application Security Platform is stable.
How are customer service and support?
The customer support for Imperva Application Security Platform is very good.
Which solution did I use previously and why did I switch?
I did not previously use a different solution; I have been using the WAF Imperva application for the last five years.
What was our ROI?
Imperva Application Security Platform has helped reduce incidents, save time, and improve my organization's security posture with specific measurable outcomes and metrics.
What other advice do I have?
I would rate Imperva Application Security Platform a 10 on a scale of one to 10.
I gave it a 10 because it is useful for private organizations and it is very safe to have WAF applications, particularly Imperva Application Security Platform.
The advice I would give to others looking into using Imperva Application Security Platform is that it is safer to use or to have it. My overall rating for this product is 10 out of 10.