We are using it for cloud security posture management to detect vulnerabilities, misconfigurations, threats, and malware in our cloud environment.
Orca Security CNAPP Cloud Security Platform
Orca Security CNAPPExternal reviews
External reviews are not included in the AWS star rating for the product.
Great visibility
GUI
Documentation
Detect vulnerabilities and compliance issues quickly with flexible filtering and visualization
What is our primary use case?
How has it helped my organization?
Orca has helped us reduce the time it takes to address cloud security alerts because of its risk-based calculation and immediate notifications for critical assets and popular vulnerabilities.
What is most valuable?
One of the valuable features of Orca Security is its design and options that allow flexible filtering and user-friendly visualization.
Additionally, it covers a large scope of vulnerabilities, CVEs, malware, and misconfiguration. It also helps identify compliance issues in our cloud environments like AWS or GCP.
What needs improvement?
Orca needs improvement in snoozing or dismissing specific alarms. Currently, snoozing dismisses all future vulnerabilities related to a CVE. Another improvement is in handling alerts for multiple files with the same CVE; it should provide an option to manage each file separately without affecting others.
For how long have I used the solution?
I have been using Orca Security for around one year.
What do I think about the stability of the solution?
We have experienced some problems with the frontend, which occurred around three times a year, usually when updates introduced new lines of code that disrupted functionality.
What do I think about the scalability of the solution?
Scalability is automatically managed. When you onboard an organization, Orca will find new projects, folders, and resources without any additional effort required.
How are customer service and support?
I contacted support quite often, and they felt like family due to the frequency. I would rate the quality of support as nine stars out of ten due to their quick and helpful responses.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I have used CrowdStrike before but was not happy with its features in the CSPM realm. Many of my friends in cybersecurity use Wyz and are pleased with it.
How was the initial setup?
Seventy percent of the deployment was completed successfully with documentation. However, we needed support from Orca for AWS onboarding. GCP was the easiest to onboard, followed by Azure, with AWS being the most challenging.
What's my experience with pricing, setup cost, and licensing?
Pricing is flexible, depending on the number of licenses, contract duration, and future plans. The initial price seemed high, however, after negotiation, the final price was ideal.
Which other solutions did I evaluate?
I evaluated CrowdStrike and have heard positive feedback about Wyz from peers.
What other advice do I have?
New users should have admin rights and follow Orca's clear documentation and web interface instructions for onboarding.
It's rated eight out of ten for its overall performance.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Orca Security Review
One of the best cloud security tools that deepen your knowledge and keeps you secure in the cloud
Navigation flow is nice as well as the findings that go more in depth.
Also would have been nice to have an onboarding in 3 steps: Control Plane, Data Plane and Scanning of the Managed Databases.
User Friendly
Ups and Downs we faced with Orca Security
The customer support is exceptional; I can get a support representative on a call within five minutes, which only enhances my desire to use it. Their support team has also been incredibly helpful with integrations, which has made the tool even easier to integrate and use frequently. This outstanding support and ease of integration contribute to our high frequency of use, making Orca an invaluable asset in our security toolkit.
We've submitted multiple feature requests, including support for asset scanning on devices like Fortinet and Ivanti, which our organization heavily relies on but aren’t currently detected by Orca. Furthermore, we occasionally encounter issues with hardening scan reports for specific assets, and pulling an inventory report is challenging due to the vast number of assets—over 3 to 4 million. While it's understandable given the scale, it’s still a limitation. Another significant issue is the inability to fetch more than 10,000 alerts through the API when retrieving data for a particular CVE.
Despite these drawbacks, I appreciate Orca’s efforts to adapt to our needs and continuously improve the tool.
Having all our vulnerability data in one place has been a game-changer. With Orca’s centralized dashboard, it’s much easier to see what’s critical and what needs our attention first, helping us to reduce risks more effectively. It’s streamlined our process, making it a lot easier to track and fix vulnerabilities.
Their customer support has also been fantastic. I can reach someone in minutes if there’s an issue, which is so helpful when you’re trying to keep things running smoothly. Plus, their support team has been great with helping us integrate Orca with our other tools, which has improved our workflow and made us more efficient.
Overall, Orca has made a real difference by giving us a stronger grip on cloud security, helping us manage vulnerabilities more easily, and scaling well to fit our organization’s needs. It feels like they’re really working to meet our specific needs, and that’s been invaluable.
Great product
Turnkey Cloud Posture Enhancement
Technical and process implementation support from account team was exceptional and guided rapid adoption and integration to security program.
Platform that provide umbrella solution that we needed
No quick/fast scan to verify immediately the fix
Comprehensive cloud security platform with powerful integrations
One feature we’ve found especially valuable is Orca’s compliance management. The AWS CIS Benchmark tool has been a game changer for us. With Orca’s guidance and insights, we were able to identify compliance gaps we hadn’t even noticed and systematically address them. This took our compliance score from 58% all the way up to 100%. Now we’re not just meeting industry standards but have much more confidence in the security and compliance of our AWS setup.
Also, we found it necessary to adjust the default permissions assigned to the role used by Orca, as the out-of-the-box required permissions were too broad and didn’t align with our organization’s principle of least privilege. By tailoring the permissions more specifically to our needs, we were able to enhance security by limiting access only to what was essential for Orca’s operations in our environment.