As a cyber security analyst, my main use case for SentinelOne Singularity Cloud Security is front line support. I use SentinelOne Singularity Cloud Security in my daily work for detection through our endpoints for any ingress on our clients.
External reviews
External reviews are not included in the AWS star rating for the product.
Centralized threat insight has improved frontline detection but support still needs faster, clearer help
What is our primary use case?
What is most valuable?
The best features SentinelOne Singularity Cloud Security offers include the data lake where I can ingest data from all other applications that I use into one central location, making managing alerts much easier and more responsive.
SentinelOne Singularity Cloud Security has positively impacted our organization as it allows us to be more proactive on the alerts that we get and any threats that we receive. The data lake feature helps me day-to-day by ingesting all the information from Darktrace and Defender into one single point of reference, which makes it easier to locate information.
Being able to get information from one central source helps to streamline processes and security in my daily workflow.
What needs improvement?
I find the platform somewhat clunky at times, and SentinelOne Singularity Cloud Security does not always give me accurate data, which could also be due to fine tuning on our end.
SentinelOne Singularity Cloud Security needs to be more reliable for the information it is pulling, as I am not always confident that the data coming through is accurate and immediate. We have had a few issues with the configuration setup at our location, which will be resolved; however, some of the configurations have taken a long time to resolve, and the back and forth with support has been frustrating.
Regarding needed improvements, support can be more proactive, faster in responsiveness, and come back with workable solutions rather than just steering me back to online knowledge bases all the time.
For how long have I used the solution?
I have been using SentinelOne Singularity Cloud Security for about 18 months.
What do I think about the stability of the solution?
SentinelOne Singularity Cloud Security appears to be stable at the moment.
What do I think about the scalability of the solution?
I am not really sure how the scalability of SentinelOne Singularity Cloud Security plays out in our current position.
How are customer service and support?
The customer support for SentinelOne Singularity Cloud Security is about a 5 out of 10, and I think they need to be more interactive with their clients rather than just steering clients back to knowledge bases.
SentinelOne Singularity Cloud Security's unified platform experience has helped streamline our security operations, as it has definitely allowed us to get more accurate information faster.
How would you rate customer service and support?
Positive
What other advice do I have?
For others looking into using SentinelOne Singularity Cloud Security, I would definitely recommend it as worth a look for your current environment to see whether it would have a place, and also compare it against other products out there.
My only other thought about SentinelOne Singularity Cloud Security is that support needs to be enhanced with their clients, requiring more interaction with their customer base rather than online pushing clients to knowledge bases all the time.
I gave this review a rating of 6 out of 10.
Cloud risk visibility has improved security operations but onboarding still needs refinement
What is our primary use case?
SentinelOne Singularity Cloud Security was implemented across our multi-cloud infrastructure, with all of these infrastructures integrated into the platform. The solution pulled all accounts and subscriptions from AWS and Azure, providing a consolidated view of our entire infrastructure. Within those infrastructures, it ran agentless scanning and could identify any vulnerabilities, malware, or risks associated with our infrastructure resources.
SentinelOne Singularity Cloud Security was user-friendly and not difficult to understand in terms of how the application works. The integration process was pretty straightforward. We integrated with AWS, Azure, and Google, though integration with Google required significant workarounds involving Terraform. Once the integration was completed, the process became straightforward. The onboarding process for accounts was somewhat tedious, but apart from that aspect, everything was straightforward.
What is most valuable?
From a security operations perspective, SentinelOne Singularity Cloud Security played an important role. I work with the infrastructure team and closely work with the Infosec team, which is the primary security team. They relied on all the risks and alerts from the platform and worked on how to remediate them and determine whether patching was required. All remediation decisions were based on the initial visibility of any infrastructure risk provided by this application.
The secret scanning feature in SentinelOne Singularity Cloud Security is very important. When we create new accounts or onboard new accounts for any business unit, we gain visibility into what exactly that team is doing and what risks are associated with their activities. As a platform engineer, I work with multiple business units who want to work on Kubernetes or Docker solutions in test environments or sandboxes. When we create an account for a business unit without segmentation around what connects to what, SentinelOne Singularity Cloud Security runs scanning and provides visibility. For example, if a developer creates a vulnerable Jenkins instance, the SOC team and I get a better view of the risks associated with instances that the developer team is working on, even though the developers themselves may not be aware of those risks.
What needs improvement?
Drift detection with respect to infrastructure code is important. When somebody makes changes to infrastructure code, it creates a drift and lets you know what changes have been made at the infrastructure level.
The first downside of SentinelOne Singularity Cloud Security was the onboarding process, which was very challenging and took a lot of time. We faced many challenges around onboarding accounts. However, once we got past that initial phase, everything became pretty straightforward and we did not have any issues.
For how long have I used the solution?
What do I think about the stability of the solution?
What do I think about the scalability of the solution?
How are customer service and support?
The speed of opening a ticket with SentinelOne Singularity Cloud Security support is good. However, there were some cases where getting a support agent on a call was a little difficult.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
The company went with Prisma because within multiple operating companies, there is a significant footprint of Palo Alto devices for firewalls and endpoint firewalls on-premise. Since Prisma is also a Palo Alto product, it integrates natively with their existing applications. SentinelOne Singularity Cloud Security operated through the cloud, while Prisma also provides risk assessment for on-premise devices, which is an additional capability. This is the reason why Prisma is preferred currently.
How was the initial setup?
What other advice do I have?
It is user-friendly and helps reduce false positives, but the log search is limited to 14 days
What is our primary use case?
SentinelOne Singularity Cloud Security is deployed on all our servers except for user machines. When Singularity identifies a downloaded application as malicious, it triggers an alert sent to our SIEM console. We can then investigate the alert details, including associated logs, to determine if the malware is static or actively malicious. We can also investigate suspicious IP addresses or domains. Additionally, Singularity monitors process creation and can provide forensic data on security incidents, including information about backdoor connections and the applications involved, like Chrome or other browsers.
How has it helped my organization?
SentinelOne Singularity Cloud Security stands out for its user-friendliness compared to competitors like CrowdStrike, FireEye HX, and Microsoft Defender. Unlike these tools, which can be cumbersome for tasks like running queries or searching for logs, Singularity offers intuitive interfaces and delivers results in seconds, even for complex searches across various hash formats, like MD5, SHA256, etc., without needing conversion.
Our existing SIEM console allows us to analyze alerts triggered by the SOC team. We can investigate potential false positives or conduct tests directly within the console. Additionally, the console facilitates quick searches for IOCs to identify malicious communications. Furthermore, Singularity Cloud Security offers a central management console for automated machine reboots, containment, and even self-maintenance in response to high-severity security alerts. This eliminates the need for manual intervention.
We saw the benefits of SentinelOne Singularity Cloud Security within the first two months of transitioning from FireEye HX. Singularity was easy to manage, and we were able to identify vulnerabilities.
SentinelOne Singularity Cloud Security has helped reduce the false positives we receive by 15 percent compared to FireEye HX.
Singularity has helped reduce our mean time to detect. The automatic containment of the infected machine is done within the first ten seconds of detection.
Singularity has helped reduce our mean time to remediate.
What is most valuable?
The user-friendliness is the most valuable feature.
What needs improvement?
SentinelOne Singularity Cloud Security offers a custom search function with a default 14-day limit. Extending this period to 30 days requires an additional license. A two-month grace period for extended searches would be a valuable improvement. Additionally, enhancements to the threat-hunting capabilities of the hunter module are recommended.
For how long have I used the solution?
I have been using SentinelOne Singularity Cloud Security for two years.
How are customer service and support?
We had an incident in which they pushed a patch without notifying us and without testing, damaging all of our security controls.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
We previously used FireEye HX but shifted to Singularity because we saw the potential while the POC was going on. The top three endpoint security solutions are SentinelOne Singularity, Microsoft Defender, and CrowdStrike. FireEye HX is not one of them.
How was the initial setup?
The initial deployment's complexity was moderate. The entire deployment took six months to complete.
What about the implementation team?
The implementation was completed with the help of the vendor.
What other advice do I have?
I would rate SentinelOne Singularity Cloud Security seven out of ten. The lack of a 60-day search option for the log source lowers the overall score.
The endpoint security team does the maintenance.
SentinelOne Singularity Cloud Security is a good product that is easy to use.
Gives us better visibility into our resources and enables faster resolution
What is our primary use case?
We use Singularity Cloud Security to monitor our infrastructure and ensure it meets all security and compliance standards. The solution helps us maintain and strengthen our security posture. Singularity covers our AWS environment, Kubernetes clusters, and some of our GitHub repositories.
How has it helped my organization?
Our organization is growing steadily, so our infrastructure is expanding, and we're managing more technical resources. Singularity Cloud Security helps us track our resources so that we don't get lost in the overwhelming volume of things and ensures we follow best practices. The solution gives us better visibility into our resources and enables faster resolution.
Another advantage of Singularity is compliance. I work in the payments industry, where regulations are strict. Maintaining everything and ensuring all the resources meet compliance standards is challenging, but Singularity Cloud Security enables us to do that while saving a lot of time.
Singularity has helped us reduce false positives, but it has also introduced some. Still, it's significantly less than many of the other tools we use. If we deal with fewer false positives, the technicians have more bandwidth to work on real issues. We don't need to spend time on the analysis and can focus on fixing the vulnerabilities and ensuring compliance.
The solution has improved our security posture considerably. In the finance industry, we can't function if we aren't compliant. The better our security posture is, the more compliant we are. By reducing vulnerabilities, we have eliminated risk factors in our systems.
Our remediation time is shorter. It's easier to identify vulnerabilities. We don't need to do much analysis before fixing vulnerabilities. About 90 percent of the time, we can identify the correct problem instantly and begin remedying the finding. It has saved a lot of time. It takes us only one or two days to remedy critical issues, whereas it previously took two weeks. Our mean detection time has dropped from about a week to one or two days.
The solution has given us a lot of insight into cloud security. It shows us some best practices that many people in the company do not know. Singularity finds those weak spots and educates us on the latest best practices to follow. The next time we deploy changes to our infrastructure, we change our policies and designs based on the recommendations.
What is most valuable?
Singularity Cloud Security's UI is clean, simple, and easy to use. When I started using it, I found it easy to learn what things are. Everything is explained in detail. It's always up to date with the latest technologies, such as AWS Kubernetes. They keep on top of trends with new features and updates.
The solution has a mapping feature that allows me to write my own queries and better understand my resources. It also offers some help with security controls on their end, suggesting best practices that you can use to write custom queries or standards. We have the flexibility to customize our infrastructure based on our needs.
Singularity's evidence-based reporting rates my alerts so I can see which ones to prioritize and identify the critical vulnerabilities. It provides a highly detailed description of each vulnerability and the resolution steps. I can triage all the findings from one place and apply different filters based on my preferences.
The offensive security engine is another major feature. We use it for our infrastructure and machines to see if we have an exposure or liability. It takes some time, but the vulnerability reports are highly accurate. It saves us some time because we don't need to verify all the vulnerabilities. We just have to go fix them.
What needs improvement?
The detection time could be better. It takes a long time to scan. I'm not sure how long other tools take for the same amount of scanning, so I cannot compare it with other tools, but it takes us half a day to a full day to complete the scan. I want to get the reports faster so we can start fixing the problems.
The proof of exploitability is another area for improvement. While I have all the information to troubleshoot the problem, it isn't detailed enough for an administrator. It has sufficient information for a general user, but an administrator would like to know all the ins and outs of the vulnerabilities that have been reported.
I would like to see the map feature improve. It's good, but it isn't fully developed. It lets us use custom resources and policies but does not allow us to perform some actions. I would also like more custom integration and runtime security for Kubernetes.
For how long have I used the solution?
We have used Singularity Cloud Security for about eight months.
What do I think about the stability of the solution?
I haven't seen any major stability problems. There are some minor issues but they are rare. Overall, it has been a smooth experience.
What do I think about the scalability of the solution?
Singularity is scalable. It has one UI that can be integrated easily with multiple backends, so we have all the data in one place and we can do whatever we want with it.
How are customer service and support?
I rate SentinelOne support eight out of 10. Their support team is proactive. It has been a while since I connected with them. They helped me with all my questions quickly. It was an excellent experience.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I have worked on other infrastructure-as-code tools and other tools for various functions that Singularity performs, such an AWS Inspector, but now we use Singularity for most of it.
How was the initial setup?
The initial setup is not a very complex process. Because of the large number of resources, we have so many places where we need to integrate the solution repeatedly. It's easy to set up new places or add integrations. The initial setup took two to four weeks. That was how long it took to go back and forth and cover everything.
We did a PoC first, which wasn't very hard. Our deployment team consisted of three or four people. The vendor team was very helpful when they deployed everything on our infrastructure. They helped us set up all the necessary permissions.
What was our ROI?
The return on investment has been good. Singularity offers a lot of flexibility to focus on different aspects because it gives us a lot of information and helps us maintain the observability of all our resources. That is something that we value because of the sheer volume of resources we have. We couldn't do that manually or using some other tools.
What other advice do I have?
I rate SentinelOne Singularity seven out of 10. It's a solid product and I recommend checking it out. It has some excellent features, observability, metrics, etc. It's very cool.
Helps reduce the number of false positives, and improves risk posture, but cloud filtering has a limitation
What is our primary use case?
We leverage SentinelOne Singularity Cloud Security for cloud security posture management, which continuously monitors our cloud configuration for vulnerabilities. When SentinelOne Singularity Cloud Security detects an issue, we prioritize the alert from our cloud-native security solution and route it directly to the DevOps team for remediation.
We have SentinelOne Singularity Cloud Security deployed on AWS, Azure, and GCP.
How has it helped my organization?
SentinelOne Singularity Cloud Security has significantly reduced the number of false positives in our cloud-native security environment from 30 percent down to five percent. This is especially helpful since we receive notifications and alerts from various sources like AWS and Cloudflare, all with their own security policies. With SentinelOne Singularity Cloud Security, I feel confident that these alerts are accurate, reducing the workload on our security team and giving us peace of mind for the past two years.
The threat detection capabilities have improved our overall security by safeguarding our cloud data transfers, and protecting both incoming and outgoing files.
With a large number of domains under our management, SentinelOne Singularity Cloud Security's incident response feature is crucial for identifying and swiftly addressing any data corruption issues that may arise within them.
SentinelOne Singularity Cloud Security has a user-friendly interface, making it a breeze to learn the fundamentals and navigate the dashboard.
Our Infrastructure as Code effectively identifies potential problems in templates and configuration files during the preproduction phase. This information is then relayed to our support team who can address these issues proactively.
Before implementing SentinelOne Singularity Cloud Security, our cloud security was inadequate, resulting in inaccurate data visibility. To ensure complete data encryption and client invisibility, we adopted SentinelOne Singularity Cloud Security, which successfully secured our cloud environment.
Reducing false positives has strengthened our security posture. While we transitioned from Prisma Cloud to SentinelOne Singularity Cloud Security for our GCP and AWS environments, Prisma offered more advanced features. However, SentinelOne Singularity Cloud Security prioritizes customer requests, addressing security needs faster than Prisma's release cycle, ultimately improving our security efficiency.
SentinelOne Singularity Cloud Security has strengthened our risk posture by implementing access controls to ensure only authorized personnel can reach our data, and by safeguarding it to minimize security risks.
SentinelOne Singularity Cloud Security has reduced our mean time to detection by 15 percent.
The implementation of SentinelOne Singularity Cloud Security has improved collaboration between our cloud security application developers and AppSec teams. By granting those teams write access, SentinelOne Singularity Cloud Security streamlines interaction and fosters a more efficient working environment.
Our engineering time has been saved thanks to the visibility that SentinelOne Singularity Cloud Security provides.
What is most valuable?
The visibility SentinelOne Singularity Cloud Security provides into the Cloud environment is a valuable feature.
The user interface is well-designed and easy to use, and retrieving data is smooth and effortless.
What needs improvement?
SentinelOne Singularity Cloud Security's cloud filtering has a limitation: implementing single sign-on requires a pre-class account feature, which is currently not available.
For how long have I used the solution?
I have been using SentinelOne Singularity Cloud Security for one year.
What do I think about the stability of the solution?
I would rate the stability of SentinelOne Singularity Cloud Security seven out of ten. It is stable when it comes to securing our data.
What do I think about the scalability of the solution?
I would rate the scalability of SentinelOne Singularity Cloud Security eight out of ten. We have scaled many times.
How are customer service and support?
The technical support team is both responsive and efficient, promptly resolving our issues.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
While Prisma Cloud initially managed our cloud security, their slow feature implementation ultimately led us to switch to SentinelOne Singularity Cloud Security. SentinelOne Singularity Cloud Security's responsiveness in delivering the features we need has been a major improvement. Also, the visibility and dashboard of SentinelOne Singularity Cloud Security are superior.
How was the initial setup?
The deployment of SentinelOne Singularity Cloud Security spanned several weeks as each cloud platform we deployed it on required one to two weeks for the process to complete.
What's my experience with pricing, setup cost, and licensing?
SentinelOne Singularity Cloud Security is affordable.
What other advice do I have?
I would rate SentinelOne Singularity Cloud Security seven out of ten.
We have around 20,000 users and have SentinelOne Singularity Cloud Security deployed in multiple locations.
While SentinelOne Singularity Cloud Security does require maintenance, our engineering team prioritizes keeping it up-to-date to ensure the accuracy and security of the data that underpins our cloud security posture.
I recommend SentinelOne Singularity Cloud Security to others.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
It gives you a consolidated view of compliance and vulnerabilities
What is our primary use case?
We use SentinelOne Singularity Cloud Security to secure our IT infrastructure and fix vulnerabilities. For example, it tells us if our resources have been inappropriately made public. We provision our infrastructure on AWS and GitHub. SentinelOne Singularity Cloud Security finds vulnerabilities across our entire network and secrets in our GitHub repositories. It also helps us manage our cloud configurations and security groups.
SentinelOne Singularity Cloud Security is integrated with Metabolic, Opsgenie, and Slack for notifications. It's also integrated with our security team. They are using a script to correlate the data from SysTrack.
How has it helped my organization?
When I joined the organization, we didn't have this kind of security tool in our infrastructure. SentinelOne Singularity Cloud Security helps us secure any resources that were mistakenly made public and other vulnerabilities. Initially, we were primarily focused on projects, not on the security side, but we were dealing with some system vulnerabilities that hackers could exploit, like publicly accessible resources. The detection is highly granular. It gives you small vulnerabilities and very new types.
The SentinelOne Singularity Cloud Security team will help you reduce false positives quickly. When we first used SentinelOne Singularity Cloud Security, false positives were high, so we contacted the team. They did some testing and modifications, and the problem was solved in one or two days.
The mean detection time has drastically reduced. The detection time varies depending on what we're scanning. When we're scanning GitHub, it takes 7 to 10 minutes. On the cloud platforms, it depends on resource availability. It takes 10 minutes on the high end, but the mean is about 1 or 2. Overall, it has been reduced by about 10 percent.
The remediation time is up to us. SentinelOne Singularity Cloud Security just detects it, but it gives us an assessment and recommendations, making it easier to resolve. When we fix a vulnerability for a particular resource, the issue will not occur again.
What is most valuable?
SentinelOne Singularity Cloud Security can integrate all your cloud accounts and resources you create in the AWS account, We have set it up to scan the AWS transfer services, EC2, security groups, and GitHub. Using SentinelOne Singularity Cloud Security's evidence-based reporting, we can rank the severity of issues as critical, high, medium, etc. Having the ability to prioritize security issues is crucial for any organization.
One good thing about SentinelOne Singularity Cloud Security is that it gives you a consolidated view of compliance and vulnerabilities. We can follow SentinelOne Singularity Cloud Security's guidance and comply with those use cases. When you get an alert, they explain how to resolve those issues.
The user interface is excellent because we see everything in a single panel and can manage all the operations from one portal. It's integrated with Slack, so we can coordinate on the open tickets. We can also mute notifications. The interface is straightforward and easy to use. Anyone can use it.
The offensive security engine is a helpful feature in cases like when a developer leaves some API element exposed, and we can view the potential exploit path. It's helpful when we are deploying any AWS account or service because all our systems depend on AWS. When the service is initially deployed, we can see what happens and get all the details about anything that depends on it.
What needs improvement?
When you find a vulnerability and resolve it, the same issue will not occur again. I want SentinelOne Singularity Cloud Security to block the same vulnerability from appearing again. I want something like a playbook where the steps that we take to resolve an issue are repeated when that issue happens again.
For how long have I used the solution?
We have used SentinelOne Singularity Cloud Security for more than 2 years.
What do I think about the stability of the solution?
I rate SentinelOne Singularity Cloud Security 9 out of 10 for stability. We've never had any glitches.
What do I think about the scalability of the solution?
We've had no issues with scalability. We've onboarded about 6 or 7. There is no digital investment. You can integrate multiple accounts from various providers.
How are customer service and support?
The support team was valuable during the initial stages. SentinelOne Singularity Cloud Security contacted us every three weeks. They checked our infrastructure and reviewed all the issues that we were incorporating into the system. They took direct responsibility for the system and could solve queries quickly.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Previously, we were using the native tools of each cloud provider. For example, we used GuardDuty on the AWS.
How was the initial setup?
Deploying SentinelOne Singularity Cloud Security is straightforward. You can onboard new AWS accounts in five to 10 minutes, and it will start scanning very quickly. They give you a script to run on AWS. You can enroll your accounts based on the template, and it starts collecting data. We onboarded six or seven accounts. It hardly took any time. It's a SaaS solution so we don't need to maintain it. We only need to do the onboarding.
What other advice do I have?
I rate SentinelOne Singularity Cloud Security 7 out of 10. SentinelOne Singularity Cloud Security isn't a unique solution. Other solutions have the same features, but I like SentinelOne Singularity Cloud Security because it's simpler to use. It doesn't require any maintenance and the scalability is good. However, I think other solutions can give the same level of detail and insight.
Helps save time, and is user-friendly, but the security rules need better definitions
What is our primary use case?
We use SentinelOne Singularity Cloud Security as our CSPM. Integrated with our environment, SentinelOne Singularity Cloud Security scans for vulnerabilities and recommends remediation.
We implemented SentinelOne Singularity Cloud Security to monitor our cloud security for vulnerabilities in the configuration.
How has it helped my organization?
SentinelOne Singularity Cloud Security is easy to use.
The evidence-based reporting provides details of the vulnerability and the steps we need to take to resolve it.
The SentinelOne Singularity Cloud Security scanning engine provides valuable evidence by identifying and reporting vulnerabilities that could be attacker targets. This evidence of exploitability is crucial because it allows us to prioritize and patch vulnerabilities effectively. Without this information, we might not be able to address critical vulnerabilities promptly.
Thanks to SentinelOne Singularity Cloud Security, our security posture has improved significantly. Our team has been able to effectively address all critical and high vulnerabilities identified by the platform.
SentinelOne Singularity Cloud Security has improved our mean time to detection. Without a CSPM tool, we would not be able to identify vulnerabilities.
SentinelOne Singularity Cloud Security facilitated collaboration between our cloud security, application development, and AppSec teams. The evidence provided by SentinelOne Singularity Cloud Security streamlines collaboration and vulnerability resolution across these teams.
The collaboration has saved engineering time by up to 40 percent.
SentinelOne Singularity Cloud Security's improved compliance monitoring capabilities have helped us achieve a more secure posture.
What is most valuable?
All the features we use are equal and get the job done.
What needs improvement?
We encountered issues with some of the configured security rules. The vulnerability recommendations provided by SentinelOne Singularity Cloud Security were inaccurate. In some cases, the rules are strictly enforced but do not align with real-world use cases. To address this, I recommend revising the security rule definitions to better reflect practical scenarios and provide clearer explanations.
We encountered a problem with SentinelOne Singularity Cloud Security. They required a broad security policy, but we requested that they implement least privileged access and grant fewer permissions than they initially required. It took them over six months to respond to our request.
For how long have I used the solution?
I have been using SentinelOne Singularity Cloud Security for 1.5 years.
What do I think about the stability of the solution?
I would rate the stability of SentinelOne Singularity Cloud Security 8 out of 10.
What do I think about the scalability of the solution?
I would rate the scalability of SentinelOne Singularity Cloud Security 9 out of 10.
How are customer service and support?
The technical support teams' response time was good but they were lacking a deep understanding of the different environments which caused delays in resolving our issues.
How would you rate customer service and support?
Neutral
How was the initial setup?
The initial deployment was straightforward and took 2 days to complete.
Two people from our team were involved in the deployment.
What other advice do I have?
I would rate SentinelOne Singularity Cloud Security 7 out of 10.
Four people in our organization utilize SentinelOne Singularity Cloud Security.
No maintenance is required from our end.
I recommend SentinelOne Singularity Cloud Security to others for CSPM.
A simple solution with multi-cloud support, but it needs better reporting and scalability
What is our primary use case?
We use it in different ways. The number one use case is related to vulnerabilities, which includes cloud misconfiguration, the Offensive Security Engine, and the management screen itself. That is our primary use case. Then comes the graphical representation of interfaces, and the third use case is the inventory that it allows, which is very nice.
By implementing this solution, we wanted to watch the security vulnerabilities in our organization. We wanted to watch them in the code that gets checked in. We wanted the latest and refreshed list of vulnerabilities in, for example, Log4j or any other software to be highlighted. SentinelOne Singularity Cloud Security keeps updating its database and highlighting any issues.
How has it helped my organization?
We use agentless vulnerability scanning. It is cool. It operates on our cloud. All we need to do is authenticate and authorize our agents to read from our cloud infrastructure, which is cool.
SentinelOne Singularity Cloud Security includes proof of exploitability in its evidence-based reporting. This is very important because it gives the entry point to the entire process.
We use SentinelOne Singularity Cloud Security's Infrastructure as Code (IaC) scanning. All of our Terraform code and Git repositories are checked in, identified, and scanned. It helps us identify any issues way before production.
SentinelOne Singularity Cloud Security has not reduced the number of false positives. We have very few false positives in our organization. We have a very specific structure.
SentinelOne Singularity Cloud Security has reduced our mean time to detect. It has helped us a lot. It is quite quick, and that is why we put it in our sprint at every agile site. In terms of its effect on the mean time to remediate, we have not crossed the remediation phase. Remediation is okay. I would want it to go a little bit more specific on remediation, but I understand that it is just an engine that can scan.
We were able to realize the benefits of SentinelOne Singularity Cloud Security in about a month.
SentinelOne Singularity Cloud Security has not affected the collaboration among our cloud security, application developers, and app sec teams. The access to SentinelOne Singularity Cloud Security is less. The number of roles that SentinelOne Singularity Cloud Security provides is very low. I cannot segregate a particular account or a particular user. It is difficult for a lot of people to get. It is just the development, operations, and infrastructure teams that are currently working with it.
What is most valuable?
It is pretty simple. It is very straightforward. It is not complicated. For the information that it provides, it does a pretty good job.
What needs improvement?
Its reporting is bad. I export CSV. I cannot export graphs. Restricting it to the CSV format has its own disadvantages. These are all machine IP addresses and information. I cannot change it to the JSON format. The export functionality can be improved.
The graphical representation of different resources is super cool, but the problem is that you cannot do anything with it. For example, if you just take the subnets and VPN and put them in a diagram, it becomes so big. I pretty much cannot use it. There is no point. If I am drawing a graph or bringing up a graph, but I am not able to show it to a person, what is the use of that? It is pointless.
Its scalability can be improved.
For how long have I used the solution?
In this organization, I have been using SentinelOne Singularity Cloud Security for 6 months. Overall, I have about 4.5 years of experience.
What do I think about the stability of the solution?
I have not had any issues. I have been lucky enough to not notice any issues.
What do I think about the scalability of the solution?
We have a parent organization, and then we have child accounts, but they have to be configured separately in SentinelOne Singularity Cloud Security, which makes it difficult to add accounts. You have different pages, so a comparative study about account usage is not possible. I am not a fan of its scalability. Its scalability can be better.
How are customer service and support?
I have interacted with them a couple of times. They have been very helpful. Their speed is pretty good. They are faster than AWS support. They are quick. The support quality is good. I did not see any lack of quality. I do not have anything bad to say about them.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We have CloudFront, which is a security measure by AWS for a very specific purpose. I have used SonarQube. It is pretty decent. It is code-specific, whereas SentinelOne Singularity Cloud Security falls under code and IaC. I have used the Trivy scanning mechanism. Semgrep is an open-source tool. GitLab has its own set of static code analysis and static infrastructure analysis tools. These are some of the tools that I have used before.
SentinelOne Singularity Cloud Security is very specific to the cloud-native environment. It lets you plug in more than one cloud. My organization has a multi-cloud strategy. With SentinelOne Singularity Cloud Security, we can have Google Cloud and AWS under the same umbrella, which is cool. It has its own unique place, and I like it.
How was the initial setup?
It was very easy. The only problem was getting the RBAC roles. After we had the roles, it was straightforward. It was very simple.
We have a 47-cluster environment. It took about 1.5 hours. It is quick enough. It is as good as CloudFormation.
It does not require any maintenance from our side. Because it is fully managed on the cloud SA, we do not have to do anything.
What about the implementation team?
It was implemented in-house. We have a development and operations team with 5 people.
What's my experience with pricing, setup cost, and licensing?
Its pricing is constant. It has been constant over the previous year, so I am happy with it. However, price distribution can be better explained. That is the only area I am worried about. Otherwise, the pricing is very reasonable. As the cloud vendors change their pricing, SentinelOne Singularity Cloud Security also has to change its pricing. I understand that. I am happy with it, but the split up can be better explained.
What other advice do I have?
To those evaluating SentinelOne Singularity Cloud Security, I would advise understanding SentinelOne Singularity Cloud Security's licensing metrics. You should understand how SentinelOne Singularity Cloud Security calculates. That is very important because it is not straightforward. You should understand that, and you can talk to the support people. They are very good. They clearly explain it. The person who is dealing with it should have a technical background. He cannot be a business analyst.
Make sure that you put in all the configurations on day one. You will find it difficult to compare if you keep building on top of it.
Overall, I would rate SentinelOne Singularity Cloud Security a 7 out of 10.
Easy to use with good monitoring but support could be more responsive
What is our primary use case?
We use the solution for security posture management. It's a safeguard for our cloud. It helps flag misconfiguration or any kind of vulnerability. There are also remediation capabilities, although we're only subscribed to alerts.
How has it helped my organization?
It's a safeguard tool for our cloud. When I'm using my cloud I need to make sure whatever I'm doing is secure. So we needed a gatekeeper or something acting as a gatekeeper, to keep an eye out since people can sometimes make mistakes. If there is any kind of event error, it helps us get alerted.
What is most valuable?
It's a real-time monitoring tool that runs 24/7.
I like the security capabilities. The availability and stability are very good.
It is very easy to use, and the graphical user interface is nice. It's great that they provide information regarding issues on the front end. The evidence-based reporting is good. There is some heavy investment there. The user interface and ease of use for security operations are very helpful. Everything is easily available, and that's very impressive.
It works within a certain set of rules. It has enough information to cover 100% of the services we are using. For most of my expectations, the product has covered my needs. They are also adding new features and functionality.
We use the infrastructure as code scanning, which is good. There's very good security scanning. We can scan non-production environments and get a report. We get notifications of issues immediately. Before moving to production, we always look at reports to check for issues.
We're almost 99% compliant based on the compliance regulations we follow. It's helpful to have good compliance scanning.
We've been dealing with fewer false positives. It's improved over time. It's too early to say, percentage-wise, how many fewer we're seeing; however, it is noticeable.
It's lowered our risk posture. We have been satisfied so far. It covers what we need to be covered.
The mean time to remediate has been lowered by about 20% to 30%.
We now have very good collaboration between our cloud security, application developers, and AppSec teams. There's better communication in terms of response. We haven't calculated if it's saved us any engineering time, however.
What needs improvement?
They could improve their mean time to detect. It's good, however, it could be lowered further. Detection should be in near real-time. We need these alerts fast as security is our greatest concern.
They could improve reporting and offer better, faster notifications.
For how long have I used the solution?
I've used the solution for almost 2 years.
What do I think about the stability of the solution?
I'd rate the stability 8 out of 10.
What do I think about the scalability of the solution?
We have 10 to 15 people using the solution.
I'd rate the ability to scale 8 out of 10.
How are customer service and support?
We've had our support directly reach out to theirs. Sometimes they address items slowly; sometimes they are faster. The support response time could be improved.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We did use something prior to PingSafe. We had a few things on-premises and on our private cloud. We liked the pricing and feature offering of PingSafe and decided to implement it.
How was the initial setup?
The initial setup was pretty straightforward. We had to do some integration and it was simple. The deployment itself hardly took an hour. It's integrated with our AWS and that was pretty seamless.
I don't worry about maintenance. I don't take care of that aspect. However, PingSafe works in the background, maintaining and upgrading the system directly.
What about the implementation team?
We had a few people from PingSafe involved in the implementation.
What other advice do I have?
I'm a customer and end-user.
It's a 100% available solution. It covers most of our cloud security requirements and has a nice interface. Support could be faster, though. When we're dealing with security, we don't want lots of time between responses.
I'd rate the solution 7 out of 10.
I like the security engine, but it needs a break-glass account feature
What is our primary use case?
My company uses Cloud Native Security as our CSPM solution to discover vulnerabilities in cloud-based configurations. We take alerts from Cloud Native Security and forward them to the DevOps team to remediate them manually.
How has it helped my organization?
Cloud Native Security helps reduce the number of false positives we receive. We receive notifications and alerts from various channels, such as AWS CloudTrail and Microsoft Defender. These products generate alerts based on their policies. I can feel confident that Cloud Native Security isn't giving any false positives. We get a few, but they are rare, and I can immediately alert the team to redefine their policies.
What is most valuable?
Cloud Native Security's most valuable feature is its offensive security engine. I have worked with many CSPM solutions. What sets Cloud Native Security apart is the security engine's ability to provide evidence about the potential for vulnerabilities to be exploited or endpoints exposed with credentials.
The evidence-based reporting is helpful. It shows us all these details that help us do more research. We are working with various stakeholders to remediate those misconfigurations immediately. No other solutions provide this feature. We can research other resources affected by the same kind of vulnerabilities or misconfigurations. We can prioritize fixing them and work on them immediately. That's beneficial to everyone on the team, and they are learning a lot with this feature from Cloud Native Security itself.
What needs improvement?
While Cloud Native Security is mostly easy to use, the interface has a few trouble areas. We have faced some challenges with filtering. The Cloud Native Security team is working on that, and they're fixing it immediately. They take feedback seriously. There is no break-glass account feature. They should implement this as soon as possible because we can't implement SSO without a break-glass feature.
For how long have I used the solution?
We have been using Cloud Native Security for one year.
What do I think about the stability of the solution?
Cloud Native Security is stable.
What do I think about the scalability of the solution?
I rate Cloud Native Security 9 out of 10 for scalability. There is no lag, and the application doesn't break down.
How are customer service and support?
I rate Cloud Native Security support 8 out of 10. We contacted them about adding some policies and creating plugins based on our requirements.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We previously used Prisma Cloud. Each has its own feature set. Prisma is on a higher level, and Cloud Native Security is a startup that's building its feature set and taking feedback from all the customers. That's one advantage Cloud Native Security has. They're responsive to feature requests. If I suggest a feature for Prisma, I will need to wait until the next release on their roadmap. Cloud Native Security will add it right away.
How was the initial setup?
Deploying Cloud Native Security wasn't too easy or difficult. It was manageable. I did the deployment by myself. I'm the Cloud Native Security admin for my organization responsible for onboarding all the cloud accounts for AWS, GCP, and Azure.
Which other solutions did I evaluate?
We also looked at Orca Security. Like Prisma, Orca is one of the top solutions on the market. Most of the CSPM solutions have the same features. Cloud Native Security stood out for two reasons: One is the offensive security engine. That is the main thing. The second thing Cloud Native Security offers is evidence-based reporting. That helps us a lot. These two features are unique, which is why we chose Cloud Native Security.
What other advice do I have?
I rate Cloud Native Security 7 out of 10.