Web defenses have blocked unauthorized access and protect sensitive health data effectively
What is our primary use case?
My main use case for Imperva Application Security Platform is to block unauthorized IPs, users, and source applications, as we configured the Web Application Firewall to monitor internet-based applications during my previous project.
To decide which policies to configure for blocking unauthorized users and sources, we identify authorized users and source IP addresses, ensuring only those belonging to the organization are validated and whitelisted in Imperva Application Security Platform to effectively block unauthorized sources. Imperva Application Security Platform works on a whitelisting concept, meaning only whitelisted users are allowed while others are treated as unauthorized.
We implement multiple policies for sensitive data in the Web Application Firewall because users may attempt to access sensitive health-related information. In a healthcare project, we set up patterns to alert if sensitive data is accessed within the organization and block it if accessed externally.
What is most valuable?
The best features of Imperva Application Security Platform include its ease of use, as it offers both on-premises and cloud options, with minimal maintenance downtime during patching due to the recommended three gateways setup, allowing for resource monitoring while upgrading.
Imperva Application Security Platform positively impacts my organization by reducing CVE-related issues significantly, as we monitor and learn from reports generated during collaboration with respective teams.
We track the reduction in CVE-related issues through weekly and monthly meetings using Imperva Application Security Platform reports. Initially, there were over 1,500 vulnerabilities, but we managed to fix almost all of them within three months, leaving only two low severity issues outstanding.
What needs improvement?
Imperva Application Security Platform can be improved as it currently lacks integration with other tools under the Data Security Fabric, particularly the WAF feature, which would enhance overall functionality.
Generally, I am satisfied with the user experience of Imperva Application Security Platform; however, I would suggest streamlining the patching process for larger environments as it becomes time-consuming when applying multiple patches across many gateways.
For how long have I used the solution?
I have been working in IT security for 10 years out of my overall 17 plus years of experience.
What do I think about the stability of the solution?
Imperva Application Security Platform is always stable, having encountered issues infrequently across my usage of their products.
What do I think about the scalability of the solution?
The scalability of Imperva Application Security Platform is indeed good, effectively accommodating growth for larger organizations despite internal data management policies.
Imperva Application Security Platform handles scalability effectively, allowing for growth when appropriately understood through policies and configurations, although understanding the platform takes time.
How are customer service and support?
Customer support from Imperva has been very good as I have raised over 100 cases, with responsive support addressing urgent needs, even offering early support despite initial SLA challenges.
Which solution did I use previously and why did I switch?
We did not previously use a different solution, starting with DAM and moving directly into a full implementation due to an incident that required rapid deployment.
How was the initial setup?
We utilized AWS for our private cloud environment, finding it satisfactory, although I only used Imperva Application Security Platform Cloud once for DAM, not WAF.
What was our ROI?
While I would not say we have saved money, we have certainly saved time through effective documentation and support for compliance-related issues, streamlining the necessary processes with fewer employees.
What's my experience with pricing, setup cost, and licensing?
We faced challenges with high costs, as the customer perceived pricing for gateways to be excessive, but we handled multiple billing instances with sophisticated setups.
Which other solutions did I evaluate?
We did not evaluate other options before choosing Imperva Application Security Platform, opting for it directly because it fit our needs for an on-premises solution.
What other advice do I have?
Beyond the WAF, Imperva DAM is beneficial because it features Imperva Security Fabric and Data Security Fabric, including tools like File Access Activity Monitoring, though the WAF is still using previous functionalities.
I can confirm that Imperva Application Security Platform is stable, though we have not purchased Imperva Application Security Platform cloud environment from the AWS Marketplace.
It is important to decide the purpose for using Imperva Application Security Platform; I recommend it for monitoring internet-based applications, while for internal tasks, it may not be worthwhile due to its costs. I would rate this review as a 9.
Which deployment model are you using for this solution?
Private Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Continuous monitoring has strengthened our web defenses and has reduced malicious incidents
What is our primary use case?
My main use case for
Imperva Application Security Platform is the
Web Application Firewall, which I use for firewall protection and monitoring 24/7 for suspicious activity.
Regarding my main use case, I first log into the WAF applications, then access the Alerts section. In that section, I can see different types of activity happening in the firewall. I review each alert to determine whether it is legitimate or suspicious activity. I can also view the target IP address and locations, target servers, and the payload that the attacker was using in that alert. I can see the OWASP Top 10 alerts and the event timing to identify when the attack occurred.
What is most valuable?
Imperva Application Security Platform offers impressive features. I am using the WAF, which blocks each alert based on signature-based attacks. That is the most impressive aspect I have experienced.
There are many alerts in Imperva Application Security Platform. For example, there is an OWASP Top 10 alert called SSRF, which is server-side request forgery. If someone attempts to access the server, the WAF blocks that SSRF alert, or RCE, Remote Code Execution alert, blocking immediately based on the signature, not only by the payload or the IP address. That is very effective.
Imperva Application Security Platform has positively impacted my organization because every time an attacker uses a malicious payload or malicious signature that is already included in the signature database of the WAF application or Imperva application, the application directly blocks that particular signature immediately. This capability can help any organization achieve better security outcomes.
What needs improvement?
I believe Imperva Application Security Platform can be improved because cybersecurity is a field that changes every day, and different types of signatures are being invented. The WAF team should add more signatures, including basic and advanced signatures, on a daily basis. They need to understand this requirement and update their signature database daily.
For how long have I used the solution?
I have been using Imperva Application Security Platform for almost one year and four months.
What do I think about the stability of the solution?
Imperva Application Security Platform is stable.
How are customer service and support?
The customer support for Imperva Application Security Platform is very good.
Which solution did I use previously and why did I switch?
I did not previously use a different solution; I have been using the WAF Imperva application for the last five years.
What was our ROI?
Imperva Application Security Platform has helped reduce incidents, save time, and improve my organization's security posture with specific measurable outcomes and metrics.
What other advice do I have?
I would rate Imperva Application Security Platform a 10 on a scale of one to 10.
I gave it a 10 because it is useful for private organizations and it is very safe to have WAF applications, particularly Imperva Application Security Platform.
The advice I would give to others looking into using Imperva Application Security Platform is that it is safer to use or to have it. My overall rating for this product is 10 out of 10.
Strong policies and bot defenses have secured critical APIs and have reduced attack noise
What is our primary use case?
My main use case is regarding
API Security, specifically trying to do some schema enforcement. I would say that is my main use case, so having to make sure the schema enforcement is done and also some DDoS protection in the aspect of web application firewalls and making sure DDoS protection is done also for bot protection, as well as some of the use cases I have had in recent projects.
In a recent project, we had one of our clients, a major financial institution in Eastern Europe. They were trying to resolve some issues with bots having access to some tangible data in their application. They had an external firewall they were using, but it was not backing up whatever alerts that needed to be obtained to make sure things are well secured. We came in and configured Imperva Application Security Platform on the web application. We made sure the DDoS protection feature was activated, so the admin is also alerted to whatever attack is coming in and then they are able to do the right measures to make sure it is stopped.
What is most valuable?
Some of the best features are the policy tuning, where you are able to tune policies the right way without stress or much hassle. The DDoS protection, the OWASP Top 10 feature, and the bot protection feature are also excellent. The API security feature is particularly valuable because most attackers do not try to come in from where it is expected. Most attackers attack the API that is being used on a platform.
The policy tuning is one of the easiest features that I know. Once you are trying to customize a policy, you just need to understand what kind of policy you are trying to customize, go through the right place from the security to policies, then create a policy. For example, you might be trying to set a policy to make sure that it does not save credit cards on a particular platform or website. That is basically one of the simplest ways of ensuring policy tuning works fine. It is one of the easiest features and I believe it has done a great deal for me in the aspect of operating Imperva Application Security Platform.
What needs improvement?
From my research regarding the
IAM space that Imperva Application Security Platform is trying to look into, I believe they still need to do a lot of modeling and modification to make sure that also helps. There are several competitors in the
IAM space, so Imperva would do well if they can do some basic modeling and modifications from my own personal research and my own experience in the
IAM space. Alternatively, they could actually just focus on trying to be stronger in the web application space and the database activity monitoring space.
The main reason it is not a perfect ten is regarding support. At times, having to reach the support team takes eight hours to ten hours maximum. There are times when clients could have urgent issues to attend to. The support team could do more by having a faster response rate.
For how long have I used the solution?
I have been working for over three years in this space.
What do I think about the stability of the solution?
Imperva Application Security Platform is very stable, very, very stable.
What do I think about the scalability of the solution?
The scalability of Imperva Application Security Platform is easy and well organized, so you can easily upgrade the version of the model you are using. It is easy to always scale to add more users. It is easy to always scale to add more endpoints and apps you are trying to secure.
How are customer service and support?
For the customer support, the reason I rated Imperva nine over ten is basically because of the customer support. They need to work faster on the response time because of issues of urgent replies. They need to work perfectly on the faster response. Overall, it is a good customer experience with them. It has not really been hectic, but they can do better.
Which solution did I use previously and why did I switch?
We did not use any previous solution regarding that. We were always on Imperva Application Security Platform because Imperva is one of the leading organizations regarding
WAF and
DAM.
How was the initial setup?
Regarding licensing, it was a smooth experience. I had to reach out to the salesperson at Imperva who helped us with setting up costs and understanding what the client needs, and making sure the pricing and licensing is done. Licensing is always for a year. There are times when most of our clients do not actually remember where they do their licensing. The licensing certificate helps to understand the date and then gives the client the proper time to renew when necessary.
What was our ROI?
I was able to save over seven million dollars last year as return on investment in the company. Regarding fewer employees needed, we are able to employ more hands because we were one of the organizations that actually brought Imperva to Africa. We needed more Imperva engineers and from the way it is, Imperva engineers have not been that much in Africa. Training new employees and making sure they are attended to with Imperva is also an issue that we are trying to resolve in Africa.
What's my experience with pricing, setup cost, and licensing?
We have noticed faster response times and fewer security alerts because after doing some custom policy tuning, everything seemed to be aligned and we have fewer attacks to monitor and fewer alerts to monitor. It was possible where we were able to integrate a
SIEM solution that we were using with Imperva Application Security Platform. That is one of the features I enjoy about Imperva. You can stimulate and integrate whatever
SIEM platform you are using to Imperva. Imperva sends over the logs and alerts to the SIEM, so it is easier for the blue team of your organization to read the alert and provide adequate measures to stop whatever is happening in the enterprise.
Which other solutions did I evaluate?
We evaluated Trendis and we also evaluated Check Point.
What other advice do I have?
My basic advice would be to make your evaluations properly. It is okay to do demos as much as you can to fully see if it is going to work with whatever challenges you are trying to solve. I believe in thorough and proper evaluation of solutions. I can give a solid approval of Imperva Application Security Platform because it has really done a lot in helping my clients and giving them the best. Imperva is one of the best, if not the best. Almost every feature in Imperva Application Security Platform works really fine and it is what enterprises are battling, and what Imperva does in shaping the security culture of the digital world. Overall, I am going to rate Imperva Application Security Platform a nine out of ten, being one of the leading solution providers in the
WAF space and the
DAM space.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Advanced threat detection has improved real-time traffic protection and mitigates DDoS attacks
What is our primary use case?
Clients can use Imperva Application Security Platform for various purposes, and as a reseller, I believe the best advantage in the product is its features that stand out for the client.
What is most valuable?
I have experience with the real-time traffic inspection feature of Imperva Application Security Platform, and it helps with network security.
I believe the reputational analysis in Imperva Application Security Platform is effective for blocking security threats before impact. I also believe that behavioral and signature-based techniques help to improve threat detection accuracy.
I see valuable benefits from advanced detection and traffic profiling during DDoS attacks, and I track some metrics related to DDoS protection performance.
What needs improvement?
I see some areas for improvement in Imperva Application Security Platform, especially regarding price. Regarding return on investment, ROI, I can say it is noticeable with Imperva Application Security Platform, and I see some significant differences compared to other firewalls such as Palo Alto, where there are pros and cons between Imperva Application Security Platform and some competitors.
As for the deployment of Imperva Application Security Platform, I would say it can be a complex process, and I ask this because we are partners with AWS. I have not purchased a solution from AWS Marketplace or deployed it on AWS Cloud for a client.
For how long have I used the solution?
I have been working and selling it for three years so far.
What do I think about the stability of the solution?
Regarding the scalability of Imperva Application Security Platform, I would say it is a scalable product with some limitations, but it is also a stable product without much glitch or downtime.
How are customer service and support?
My experience with technical support from Imperva Application Security Platform was good when I reached out to them.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
I have been in this domain with firewalls longer than three years, overall in this sphere with firewalls and security solutions.
What was our ROI?
I see some areas for improvement in Imperva Application Security Platform, especially regarding price. Regarding return on investment, ROI, I can say it is noticeable with Imperva Application Security Platform, and I see some significant differences compared to other firewalls such as Palo Alto, where there are pros and cons between Imperva Application Security Platform and some competitors.
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)