I am primarily using Orca Security for cloud security. Being part of the vulnerability management team, I utilize Orca Security for generating vulnerability alerts on cloud assets.
Orca Security CNAPP Cloud Security Platform
Orca Security CNAPPExternal reviews
External reviews are not included in the AWS star rating for the product.
Seamless integration and side scanning optimize cloud security management
What is our primary use case?
What is most valuable?
One aspect that stands out is the seamless integration. Once our organization is configured, any cloud account under that organization is automatically detected in Orca Security, along with all the assets associated with it.
Another valuable feature is the side scanning technology using a snapshot mechanism. This technology allows for coverage of almost all cloud assets without interrupting their operations.
What needs improvement?
Orca Security could improve its ticket creation process. Currently, it allows for creating tickets in only one bucket, which requires monitoring to redirect tickets to the appropriate team. It would be beneficial to have segregation for different projects.
Additionally, Orca Security could improve in reporting OS package vulnerabilities, such as missing MS patches or Linux patches.
For how long have I used the solution?
I have been using Orca Security for one year.
What do I think about the stability of the solution?
I would rate the stability as nine out of ten. I personally have not encountered any bugs or issues with the console. It runs almost 24/7.
What do I think about the scalability of the solution?
I would rate the scalability as nine out of ten. The seamless integration allows us to automatically reflect any connected project from our cloud into the console.
How are customer service and support?
I would rate customer service between eight and nine out of ten. The support team assists with issues and provides information on new updates, helping us understand the product better.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Previously, we used Rapid7 for vulnerability management. We switched because we moved from on-premises to the cloud, which required a cloud security solution.
What's my experience with pricing, setup cost, and licensing?
I am not sure about the pricing, as all decisions related to pricing and configuration were made by a different department.
What other advice do I have?
I recommend Orca Security to others looking for a cloud security solution due to its seamless integration and side-scanning technology that does not hamper cloud asset performance. It also offers automation for ticket creation directly from alerts.
I'd rate the solution eight out of ten.
Great tool for measuring and improving cloud security posture
Security engineer's perspective
New Orca Cloud Security User
Consolidating security tools with comprehensive cloud visibility
What is our primary use case?
We used Orca Security for Cloud Security Posture Management (CSPM), vulnerability assessment, and several other security controls, including Shimless Security. It helped us consolidate our security tools and provided a central view for organization-wide visibility.
What is most valuable?
The best features of Orca Security include its ability to perform a lot of security controls without requiring any installation of agents, making it very easy to set up. This feature allowed us to replace a lot of tools with one comprehensive platform, enhancing our ability to consolidate the security footprint on a large scale.
It provided us with visibility from a central point, increasing our view from the previous thirty percent to a full one hundred percent of our cloud environment. This comprehensive view facilitated improvements in our security posture.
What needs improvement?
The documentation for Orca Security could be improved. The compliance framework also needs enhancements, especially concerning integrations with other tools like ServiceNow's vulnerability modules, which are not as mature as expected.
It should also increase its capability to ingest data from other security tools like CloudSight for endpoint detection and provide real-time monitoring.
For how long have I used the solution?
I was an administrator of Orca Security in my previous organization for almost two years.
What do I think about the stability of the solution?
There were some stability issues in the initial months of using Orca Security, but overall, it has room for improvement and is rated seven out of ten.
What do I think about the scalability of the solution?
Orca Security's scalability is rated nine out of ten due to its challenge in scaling Kubernetes workloads, which require additional steps on top of connecting cloud accounts.
How are customer service and support?
The technical support has room for improvement. The expertise levels could be improved, and on a scale from one to ten, I rate the support as six or seven out of ten.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
We used several other tools before Orca, such as Microsoft Defender, Twistlock (Prisma Cloud), Rapid7, and AlgoSec. Orca Security replaced these by consolidating their functionalities into a single platform, which helped us save significant costs.
How was the initial setup?
The initial setup of Orca Security was easy. We started with the cloud accounts we already had visibility and control over, then presented its value to the organization.
What was our ROI?
Orca Security significantly improved our visibility from 30% to 100%, enabling better security posture improvements rather than just general cost savings.
What's my experience with pricing, setup cost, and licensing?
The cost of Orca Security is competitive compared to other market solutions.
What other advice do I have?
I would recommend Orca Security to other users and rate it eight out of ten.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
I have been supporting and learning the Orca product to deploy the VM alerting.
Orca has already pre-selected the best practice alerts for your company to focus on, by pulling them in from all of the most pertienent compliance frameworks enabling you meet understand and meet your compliance needs.
Great & smooth experience
Orca CNAPP
Orca's compliance reporting and automated inventory give us excellent insights across our assets, which is invaluable for audit preparation.
The contextual alerting and prioritization features in Orca are also standout advantages. It cuts through the noise by correlating security issues to highlight the most critical risks in the environment, saving time and reducing alert fatigue.
Excellent customer support from our account team.
In-Depth Cloud Security Monitoring and Vulnerability Detection
Great cloud security platform
I really like the attack path feature it helps us closing gaps in our environments, also it provides as with a lot of the needed information about the resource or the alert that was triggered.
Also I think the UI can be improved a little bit, with some alerts it can be overwhelming with the amount of details presented in the screen.