Has straightforward security automation capabilities
What is our primary use case?
In terms of use cases, we had a single client. This client belonged to the insurance sector here in India, specifically a large insurance chain. We discovered that they had migrated to a cloud environment and had some security controls in place. However, they lacked expertise in understanding the threats associated with the cloud. From a resource and organizational perspective, they didn't possess the necessary skill set to implement a comprehensive governance framework. This client operates within the insurance industry, regulated by the Insurance Regulatory and Development Authority in India, which has revised some pipelines for the current financial year. The IRDA also serves as a regulatory authority for Indian banks. As a result, the client needed to strengthen their controls, particularly those with higher significance.
Their objective was to implement a few security controls to successfully pass an upcoming audit. We recommended that they integrate Prisma into their infrastructure. This would allow them to generate reports promptly whenever required and help fine-tune existing policies or guide the infrastructure development team in implementing new ones. Prisma would scan the entire infrastructure and provide the best recommendations. It was a challenging use case in terms of implementation, as only a few clients were familiar with Prisma's capabilities. Prisma is a cloud service that enables the hosting of applications and infrastructure.
We wanted to address vulnerabilities that we identified from a logging and monitoring perspective, which is why we implemented Prisma Cloud.
How has it helped my organization?
If we discuss a multi-cloud environment or a multi-fleet architecture or implement it as a fleet architecture, Prisma Cloud offers comprehensive functionality. It enables us to obtain complete reports or scanning reports from the tool on an enterprise scale. However, this process takes time. Although it is completed within seconds, if we have a larger infrastructure with multiple running instances, the tool will require more time. Nevertheless, the resulting report will be accurate and provide a comprehensive perspective.
In terms of a multi-cloud environment, our observations indicate that if we implement and configure Prisma Cloud with Azure and AWS, the tool performs well. On the other hand, when performing checks on AWS and GCP, the tool exhibits better performance on AWS. It does not meet the same standards on the GCP side, but it remains accurate. Azure is compatible with AWS and shows promising results. Additionally, we are currently conducting tests on the Azure environment.
Regarding the entire infrastructure, whether it follows an SAP model, PaaS model, or a previous model based on infrastructure, our testing has yielded positive results, particularly when using the SaaS model. AWS achieves 100 percent accuracy. From larger clients to smaller ones, even within internal GCP corridors where Prisma is connected, they are effectively protected.
Prisma's security automation capabilities are straightforward. We need to ensure that we have a clear understanding of our intended automation actions before proceeding. I was engaged with a company in the oil and gas sector that utilizes AWS infrastructure. They adopted Prisma Cloud and we implemented some automation. During testing, the alerts were satisfactory. However, in subsequent attempts, vulnerabilities were detected after the automation was executed. I wouldn't describe it as difficult, but rather as tricky.
Prisma Cloud assists us in adopting a proactive approach to cloud security. It provides us with a comprehensive view of areas that require fine-tuning. This perspective encompasses not only governance and threats but also the overall security landscape.
Prisma Cloud helped us reduce manual effort by up to eighty percent. It fine-tuned policies and implemented security controls for the cloud, including threat and vulnerability management. We no longer need to manually review these aspects. However, we still receive recommendations for mitigation. Prisma Cloud suggests actions to take from a governance and security perspective. For example, if we have an open port that is not in use, it advises disabling it. Previously, I or my team would spend around ten to twelve hours a day fine-tuning Azure or AWS services by accessing different dashboards. Now, with Prisma Cloud, we can accomplish all of this through a single console. We simply log on to the Prisma Cloud console and configure the services. Prisma Cloud integrates all the services and provides us with recommendations for remediation. As a result, our effort has been reduced by eighty percent since implementing Prisma. We were able to see all the benefits within a year and a half.
Prisma Cloud provides the 100 percent visibility and control we need regardless of how complex or distributed our cloud environments become. By utilizing Prisma Cloud, we have significantly reduced our manual effort to nearly eighty posts. Having everything consolidated on a single console greatly enhances the efficiency and productivity of our team. Moreover, from both a practical and financial perspective, it is undoubtedly a more advantageous approach.
Prisma Cloud offers risk clarity in real-time throughout our CI/CD pipeline infrastructure.
Prisma Cloud has reduced runtime alerts. I have only seen two alerts.
Prisma Cloud has reduced alert investigation times.
Prisma Cloud has saved our larger clients around $100,000 per month.
What is most valuable?
What needs improvement?
Prisma needs to regularly update itself because there are regulatory compliance requirements that have already been published, yet they have not been integrated into Prisma. This poses a challenge as we have to manually address these issues in our use cases.
We have discovered that Prisma is not functioning properly with GCP. I am unsure if this is due to the security policies being implemented by Google. There are restrictions in place, but from a GCP perspective, the security scanning is quite limited.
The deployment is a tricky task as it requires thorough configuration checks. There was a scenario where we discovered that the deployment had already been completed. However, during integration, we encountered a configuration issue. As a result, the logs from the cloud area were transformed into incidents, resembling an actual security breach. This caused concern among my team, and we were under the impression that an attack had occurred.
Palo Alto offers a different product, and they have introduced Prisma Cloud for a specific purpose, particularly for individuals who are new to the technology. The idea is, for example, to provide a single platform for accessing various Over-the-Top platforms for watching web series or movies. Instead of purchasing multiple OTT platforms, the concept is to offer one comprehensive platform. By paying for a single platform, users can obtain a subscription for services like Netflix or Amazon Prime, without having to spend thousands of dollars individually. Prisma Cloud follows a similar approach, which is perfectly acceptable. Consider the scenario where a client, using Microsoft or Azure environment, desires to use a third-party tool instead of investing in Microsoft Defender. In this case, Prisma Cloud comes into play. However, at some point, they may realize the need for Microsoft Defender as well, which would cost them a significant amount of fifty thousand dollars. To avoid such expenses, the idea of offering a complete package to the client arises.
This complete package enables the client to use a single tool for scanning, obtaining reports and even automating the fine-tuning process. Consequently, the client can invest fifty thousand dollars to obtain the complete package, rather than searching for and purchasing three separate products, which would cost a significant amount of dollars. The complete package offers the same functionalities at half the price. From a product perspective, it is crucial to integrate certain services that assist clients in deciding to invest in Prisma Cloud. In the Indian market, where we have observed our clients, there is a lack of awareness regarding Prisma Cloud and its functionality. Clients are primarily concerned with whether Prisma Cloud can simply scan their products and provide recommendations. They question whether they can perform these tasks manually or use cloud-native services. This perspective influences the clients' decision-making process.
For how long have I used the solution?
I have been using Prisma Cloud by Palo Alto Networks for two years.
What do I think about the stability of the solution?
The stability of Prisma Cloud depends on how the infrastructure has been configured specifically for that tool, taking into account the load and architecture of our infrastructure. The tool responds well in small-scale infrastructures, functioning perfectly without any issues. However, in larger environments, I have not encountered any crashing or lagging problems but the time it takes to scan the infrastructure varies depending on its size.
What do I think about the scalability of the solution?
Prisma Cloud is 100 percent scalable.
How are customer service and support?
I contacted technical support during deployment because we encountered some challenges. The support was excellent, and the conversation went well. It was crucial to address the issues promptly because the entire infrastructure was at stake due to its complexities. We were uncertain about the potential impact of deploying a new tool in the infrastructure. Unfortunately, we faced some issues at one point, but they were resolved within the designated timeframe.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
As an organization, we possess certain tools, some of which have been developed in-house. However, it is important to note that no tool can be entirely relied upon, as perfection is unattainable. Some abnormalities have arisen and subsequently been addressed. Our main focus in the previous year was on utilizing cloud-native tools. We are now using Prisma Cloud and also looking at Citrix.
How was the initial setup?
The initial setup took some time. It was not straightforward. For a few of the clients we have implemented, it will be straightforward. However, in our organization, it conflicts because we have certain lines of business and restrictions, so it took a bit longer. The deployment took around one month and required 15 people.
What's my experience with pricing, setup cost, and licensing?
In general, Prisma Cloud is much cheaper than cloud-native services.
Which other solutions did I evaluate?
We are having conversations with Citrix to evaluate their solution.
What other advice do I have?
I rate Prisma Cloud by Palo Alto Networks a nine out of ten.
We are the aligned partner for Prisma. We recommend the same tool to our clients, and the entire team is actively involved in training on the Prisma Cloud. In my interactions with various clients and stakeholders, I have noticed that some of them are not familiar with Prisma. However, they prioritize security and want to secure their cloud infrastructure. While some clients may not have the capability to use cloud-native tools, based on my observations, most of them are gradually transitioning to the cloud infrastructure and showing interest in the Prisma Cloud.
From a cloud security standpoint, and specifically as an organization, we are not bound by any specific domain. Our focus lies in securing the infrastructure from the client's perspective. For instance, consider a client who is new to the cloud and has migrated their infrastructure. If we do not have any governance measures in place for this scenario, our recommendation would be to opt for the comprehensive package offered by Prisma Cloud. This ensures that in the future or upcoming days, the client won't need to explore numerous other modules. However, it is worth noting that some clients may prefer to use separate modules. In general, we tailor our governance, security, and threat detection solutions to meet the specific requirements of each client. Internally, we provide a complete package.
In the current scenario, where my team is performing the migration for Prisma Cloud or the deployment area, we haven't yet tested the tool. We are planning to proceed with that testing. However, based on our discussions with the Prisma partner, they will integrate some functionalities because, in the DevOps environment, we haven't achieved the expected results. I wouldn't claim it's a hundred percent comprehensive, but based on our discussions and experiences so far, it's still a work in progress. We have conducted two tests, but the results haven't met our expectations.
From a DevOps standpoint, the CI/CD pipeline is still undergoing testing. I'm unsure about the time it will take, but initially, we are testing what we have learned from a CI/CD standpoint and a DevOps standpoint. We are currently investigating the best course of action and how we can integrate effectively. In some of our engagements, clients are requesting the integration of Prisma Cloud to optimize their DevOps area when deploying. However, currently, from a KPM perspective, this task is still manual. From a development standpoint, it will require time. It won't be accomplished in a single day or month, but rather, it will take time. This is because the configuration is still in progress. Moreover, from a security perspective, there are certain areas where we are uncertain. For instance, when considering GCP, it presents a gray area where we have been unable to identify any solutions from Prisma's standpoint. However, we need to determine how to effectively integrate the GCP infrastructure within the field.
Prisma Cloud can scan and monitor, depending on how it is configured. It can also trigger alerts, but it cannot stop an attack.
Prisma Cloud is maintained by Palo Alto.
Prisma Cloud will undoubtedly assist organizations in comprehending their infrastructure and identifying areas of uncertainty. The solution will streamline and minimize manual efforts. Users can obtain the comprehensive report with a single click, eliminating the need to access various services to retrieve logs. I highly recommend Prisma Cloud as it is cost-effective, and user-friendly, although its configuration can be a bit challenging.
Which deployment model are you using for this solution?
Private Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
A accomplish Platform for Cloud Security
What do you like best about the product?
- a wide range of security services, including threat detection and response, cloud compliance, vulnerability management, and comprehensive cloud security coverage.
- easily expanded by integrating with various cloud providers and third-party security technologies.
_ offers thorough information on cloud activities and assets, making spotting and monitoring security threats simple.
What do you dislike about the product?
- Prisma Cloud is a high-end cloud security platform, which could be pricey for some businesses.
- Some users may find the Prisma Cloud user interface perplexing, particularly those who are unfamiliar with the ideas of cloud security.
- the ability to scan expansive cloud environments can be slow.
What problems is the product solving and how is that benefiting you?
The comprehensive cloud security platform Prisma Cloud provides a variety of capabilities and integrations. It is a fantastic option for businesses that must connect their cloud security with other security technologies and safeguard their cloud environments across various cloud providers. However, Prisma Cloud's user interface might be challenging and costly.
Offers the visibility and control we require, regardless of the complexity or distribution of our cloud environments
What is our primary use case?
We utilize all the modules of Prisma Cloud by Palo Alto Networks, and it is fully integrated into the host control manager on GitHub. We employ this solution to achieve complete visibility from the moment we write our ISE to the actual management of the cloud environment. This approach offers a clear view of our security posture, and the container security component provides valuable insights to assist us in our architectural process.
Our security team is the primary user of the solution, followed by SREs and developers.
How has it helped my organization?
Prisma Cloud by Palo Alto Networks offers security that covers various environments. This is crucial as it provides visibility into running processes, allowing for a better assessment of the current security status and giving our knowledge center peace of mind. Moreover, it enables us to leverage all the available modules.
Prisma Cloud by Palo Alto Networks is highly comprehensive, and I would recommend this solution to anyone due to its complete visibility into the cloud and its efficient deployment process, which makes the solution worth the cost.
The solution's security automation capabilities, if configured correctly using various playbooks, can introduce different security gates. This automated playbook has the potential to save us 70 percent of the work.
I would rate Prisma Cloud by Palo Alto Networks a nine out of ten for its proactive approach to cloud security.
Prisma Cloud by Palo Alto Networks has significantly enhanced the functioning of our organization. Through CIM, we can examine IIM posture to determine the permissions granted to users and the status of all shared entities. Additionally, CSPM provides an accurate inventory of all running elements, which we utilize to bolster our security posture. This allows us to effectively identify various threat levels and obtain a precise overview of the environment.
Prisma Cloud by Palo Alto Networks is one of the most comprehensive solutions for securing the entire cloud-native development lifecycle, including the build, deploy, and run phases. By integrating with various components within my development cycle, I can access data from different data centers and formulate a security strategy to ensure ongoing protection.
The solution offers the visibility and control we require, regardless of the complexity or distribution of our cloud environments. This visibility enables us to enhance our security and compliance posture by adhering to the recommendations.
Prisma Cloud by Palo Alto Networks enables us to integrate security into our CI/CD pipeline and add touchpoints to existing DevOps processes by integrating with the infrastructure code. This allows us to enhance security at various stages of the deployment process. The touchpoints in our DevOps processes are seamless.
The solution provides us with a single tool to protect all our cloud resources and applications without the need to manage and reconcile multiple security and compliance reports. It allows us to have a better understanding of our environment, from the infrastructure code to the cloud, providing a more comprehensive picture.
Prisma Cloud by Palo Alto Networks provides risk clarity at the run and across the entire pipeline showing issues as they are discovered during the build phases. This makes it much easier for our developers to actually take into consideration some of the recommendations that are given.
The solution has helped us reduce run time alerts and shave down a few issues by 40 percent.
The solution has reduced alert investigation times because we can gather all the necessary information for investigation in one place.
Prisma Cloud by Palo Alto Networks has saved us approximately 20 million shillings.
What is most valuable?
Due to the maturity of most companies, security posture management is the most valuable feature.
What needs improvement?
The data container component can be improved since it lacks intuitiveness. Therefore, we need to thoroughly comprehend the tool in order to utilize it effectively.
The number of cloud providers in terms of data security needs improvement. The solution does not currently support servers for GCP.
For how long have I used the solution?
I have been using Prisma Cloud by Palo Alto Networks for around three years.
What do I think about the stability of the solution?
Prisma Cloud by Palo Alto Networks is stable. Any issues we have are usually resolved within a few hours.
What do I think about the scalability of the solution?
Prisma Cloud by Palo Alto Networks is scalable.
Which solution did I use previously and why did I switch?
We transitioned from using EDR solutions, and after testing several options that necessitated extensive configuration, we ultimately switched to Prisma Cloud by Palo Alto Networks, which provided a balanced solution.
How was the initial setup?
The initial setup is straightforward. The first time I deployed the solution, it took around three hours, but now I can do it in under an hour. The deployment is usually done through APIs, and we can also employ the production code to deploy containers.
What about the implementation team?
The implementations are completed in-house.
What's my experience with pricing, setup cost, and licensing?
The licensing structure is highly comprehensive. Although the cost can be high, the value is worth the price tag.
Which other solutions did I evaluate?
What other advice do I have?
I give Prisma Cloud by Palo Alto Networks a nine out of ten for its ease of use, value, and support.
One Prisma engineer or security person with training is able to maintain the solution. For our mature organization, we utilize all of Prisma Cloud by Palo Alto Networks tools.
I recommend Prisma Cloud by Palo Alto Networks. The solution is easy to use and intuitive for the most part. The licensing is comprehensive and straightforward, and the modules can be easily integrated to improve our development.
In Africa, many people do not typically associate the cloud with security due to the prevalence of on-premises security solutions. However, upon utilizing Prisma Cloud by Palo Alto Networks, we have come to realize that it is an excellent and secure tool.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Provides security scanning in multi and hybrid cloud environments and the visibility and control we need
What is our primary use case?
We use Prisma Cloud for the banking sector to check the policies as required.
How has it helped my organization?
Prisma Cloud provides security scanning in multi and hybrid cloud environments. This is important because customers often ask if they need certain services, such as detection, auto-remediation, and policies. AWS has all of these features, but why would a customer use anything else? The answer is that Prisma Cloud is multi-cloud, so it can monitor multiple clouds as well as on-premise networks. This is often a key requirement for customers.
Prisma Cloud can help us take a preventative approach to cloud security. It is built for developers and provides a range of features, including RQL, multi-cloud support, and endpoint detection.
Prisma Cloud provides the visibility and control we need. It properly manages all cloud assets and provides information about assets in our cloud.
Prisma Cloud provides us with a single tool to protect all our cloud resources and applications, eliminating the need to manage and reconcile disparate security and compliance reports.
Prisma Cloud provides risk clarity at runtime and throughout the entire pipeline. It also shows issues as they are discovered during the build phases.
The developers are able to correct issues using the tools they used to code.
The alert investigation time has been reduced by half an hour.
What is most valuable?
Prisma Cloud's most important feature is its auto-remediation. This feature automatically fixes security vulnerabilities in our cloud or on-premises environment. This can help us to improve our security posture and reduce our risk of a security breach.
What needs improvement?
Prisma Cloud lags behind in terms of security automation capabilities. Specifically, the investigation feature is not fully automated and requires users to know the RQL language. This can be a barrier for new users.
Prisma Cloud is not updating the real-time information on the UI for our cloud assets. It takes approximately two to three hours for the information to be updated.
I would like Palo Alto to provide a three-month free trial for Prisma Cloud.
The stability has room for improvement.
For how long have I used the solution?
I have been using Prisma Cloud by Palo Alto Networks for two months.
What do I think about the stability of the solution?
Prisma Cloud is not stable except for our AWS clients.
What do I think about the scalability of the solution?
Prisma Cloud is scalable.
How was the initial setup?
The initial setup is straightforward. The deployment can take anywhere from two days to 15 days. We deploy based on the customer's requirements.
What about the implementation team?
We implement the solution for our clients.
What's my experience with pricing, setup cost, and licensing?
Prisma Cloud is more expensive than Check Point CloudGuard.
What other advice do I have?
I give Prisma Cloud by Palo Alto Networks an eight out of ten.
Based on an organization's basic requirements for auditing and detection, I would recommend Prisma Cloud.
The best thing I have learned about Prisma Cloud is that it is a single platform, like SIEM. This is beneficial for network engineers because it reduces the complexity of finding the cause of an issue. With Prisma Cloud, everything can be found in one place.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Great security posture and workflow protection with a detectable ROI
What is our primary use case?
It's a service that we have acquired for our cybersecurity department. We deployed Prisma Cloud by Palo Alto in all our clouds, which are Amazon, Azure, and Alibaba.
We are doing cloud security compliance as a security posture, and we are also doing workflow protection.
How has it helped my organization?
The solution gives us a lot of visibility across all of our cloud solutions. It helps with the security posture across all of our clouds.
What is most valuable?
The security posture and workflow protection are excellent.
From the initial POC, compared to what we had witnessed with Check Point, it's easier to use.
What needs improvement?
Prisma Cloud is quite a good solution. However, the price is not good.
We'd like to have more native integration with clouds and additional security checks in the future. It will be nice to see a general evolution of the solution.
For how long have I used the solution?
I've been using the solution for about one year.
What do I think about the stability of the solution?
The stability has been good so far after less than a year of use.
What do I think about the scalability of the solution?
We are early in the process in terms of using the solution. We're not expecting to scale in the next few years. The problem there will be the licensing costs.
Right now, the environment we use is quite big already. We have several clouds already and need the visibility the solution provides.
How are customer service and support?
Our consultants deal with technical support. I do not deal with support directly.
Which solution did I use previously and why did I switch?
We did not previously use a different solution. We wanted our partner to validate our security with a tool from time to time. However, it was a service they were providing to us.
How was the initial setup?
My team was involved in the deployment. I was not directly involved. It was straightforward with the help of our consultants.
What about the implementation team?
Our consulting partner helped us with the initial deployment.
What was our ROI?
We witnessed an ROI. It helped reduce risks and sped up threat detection. We avoided human mistakes as well while using this solution.
We noted the value almost immediately once it was deployed.
What's my experience with pricing, setup cost, and licensing?
The price is high. In the future, when there are more competitors at the same level with different clouds, maybe the position will be different.
Which other solutions did I evaluate?
We evaluated Check Point due to the relationship we have with them. Yet, they did not completely support Alibaba. Alibaba was only compatible with Check Point and Prisma. However, Check Point was at a very early stage and not quite as developed.
What other advice do I have?
I'd rate the solution an eight out of ten.
Provides security across multi and hybrid-cloud environments and covers the full cloud-native stack with a single pane of glass
What is our primary use case?
We use the solution for three areas, CSPM, CWPP, and Cloud Security.
We use Prisma Cloud by Palo Alto Networks mostly for CSPM. CSPM helps us identify and fix misconfigurations in our cloud environment. This can help us prevent security breaches and improve our overall cloud security posture.
Prisma Cloud also provides CWPP. CWPP helps us protect our cloud workloads from malware, ransomware, and other threats. This can help us keep our data safe and secure.
Prisma's Cloud security is something we are still working on.
The solution is deployed as SaaS.
How has it helped my organization?
The solution provides security across multi and hybrid-cloud environments. However, we are currently only using it for the public cloud. We do not use it for any hybrid solutions, and we are not running any on-premises solutions on it.
The solution covers the full cloud-native stack with a single pane of glass. If we need a holistic view of our security posture, Prisma Cloud is a good option. It provides a single pane of glass for managing our security across all of our CNCF workloads.
Overall, Prisma Cloud by Palo Alto Networks is a very good product. I have been using it for the past four years, and I found it to be very effective in helping me to understand my cloud security posture.
I will use the CNCF as an example. I really like the complete tool. When we first started to use the cloud, we didn't know what we were doing. Only the admins knew what they were doing wrong and what the threats were in the cloud. Cloud is a shared responsibility between us and the cloud provider. This is true for any cloud provider, such as GCP, Azure, or AWS. We don't have visibility into what admins are doing wrong or right, or how many admins keep our configuration secure. On-premises has parameters, but the cloud does not. The solution provides visibility into what is wrong in our environment, what has been done wrong, and what we can do to correct it. This is because of the configuration and the misconfiguration. From an architectural perspective, if we are doing the first step wrong, there is no point in going to the second step and making it correct. We should make our first step correct. Prisma Cloud provides visibility for us to do this.
Prisma Cloud's comprehensiveness for securing the entire cloud-native development lifecycle across build, deploy, and run is good. The solution provides a single pane of glass for everything, including core security, data security, CSP, CWPP, and EIM security. Other good options are available, but they do not offer a single pane of glass. Instead, they are individual products or modules that must be used separately. Prisma Cloud can improve IM and data security, but if we do not want to use multiple tools, Prisma Cloud is a good option because it offers a single pane of glass for all our security needs.
Prisma Cloud provides the visibility and control we need, regardless of how complex or distributed our cloud environment becomes. We can see how many complaints and alerts we have, which gives us a sense of security.
Prisma Cloud enabled us to integrate security into our CI/CD pipeline and add touchpoints into existing dev ops processes.
Prisma Cloud provides us with a single tool to protect all of our cloud resources and applications without having to manage and reconcile discrete security and compliance reports. For operations, the capability of CSPM works well.
Prisma Cloud provides risk clarity at runtime and across the entire pipeline, showing issues as they are discovered during the build phases. Our developers are able to correct issues using the tools they used to code. Some of the results are false positives but the majority are not.
Prisma Cloud helps reduce some of our runtime alerts by 40 percent.
Prisma Cloud helped reduce our investigation time by up to 60 percent.
What is most valuable?
I find the CSPM area to be a more valuable and flexible feature. We have control in our hands, and we can do anything we want with our cloud security posture management.
What needs improvement?
Prisma covers all the CNCF areas. However, they are not the best in all of them. For example, their identity controls are not the best. They have modules for identity controls, but they are not the best in the market. The same is valid for data security. AWS and Azure have better native data security than Prisma. Individual modules, other than CSPM and CWPP, could be improved.
The security automation capabilities are average. They have a semi-automated remediation policy, but many tools on the market can automatically remediate based on the resource and desired outcome we need. Therefore, I think the automation of alerts could be improved.
The visibility of the reporting data for CI/CD can be improved in our console to make the output visible to management and developers.
For how long have I used the solution?
I have been using Prisma Cloud by Palo Alto Networks for four years.
What do I think about the stability of the solution?
What do I think about the scalability of the solution?
Prisma Cloud is a scalable platform that releases new modules every six months.
How are customer service and support?
The technical support is good.
How would you rate customer service and support?
How was the initial setup?
The initial setup is straightforward for an experienced person who follows the instructions. If we have all the necessary resources, the deployment can be completed in one day.
I first started with the CSPM, then the CSP medium, about a year before moving to computing. I then tried data security for native security and more outside and code security.
What about the implementation team?
We used Palo Alto Networks' Professional Service, which was included in our credit and license. They provided us with assistance with the initial implementation, and we were satisfied with their services.
What was our ROI?
We have seen a return on investment from using Prisma Cloud because it has improved our compliance and security posture.
What's my experience with pricing, setup cost, and licensing?
The pricing is reasonable. However, I think some modules need to be restructured, particularly those related to data security. The licensing model for data security should be compared to the native security offered by AWS and Azure.
Which other solutions did I evaluate?
We evaluated Wiz and CrowdStrike. We initially started with CSPM, so Prisma Cloud was more flexible. The representative of the Prisma Cloud CSPM was better and more user-friendly. It gave us more permissions, more controls, and it wasn't complex. We could still do whatever we wanted if it was not given by Prisma out of the box. Therefore, we chose Prisma Cloud.
What other advice do I have?
I give Prisma Cloud by Palo Alto Networks an eight out of ten.
If you are new to the cloud and you are not sure where to start, I would recommend using Prisma Cloud. It will give you a comprehensive view of your cloud security posture and help you to identify any areas where you may be vulnerable. You can also use Prisma Cloud to test and evaluate different security controls before you deploy them in your production environment.
Our entire company uses Prisma Cloud. Anything we deploy in the cloud is protected by the solution.
Prisma Cloud does not require maintenance from our end.
If someone is new to the cloud and looking for cloud security, I think the best place to start is Prisma Cloud. Prisma Cloud offers a comprehensive set of security capabilities, including CSPM, workload security, and cloud security. We can start by using the CSPM module to assess our cloud security posture and identify any potential vulnerabilities. Once we have addressed any critical vulnerabilities, we can then move on to the other modules.
Everything is a lesson because we started with no knowledge. We did not know that there would be many risks and offenses involved in our cloud security environment. We need to know all of the risks, and we can overcome them with Prisma Cloud.
Which deployment model are you using for this solution?
Public Cloud
Comprehensive Solution for Cloud Security
What do you like best about the product?
Prisma Cloud is an innovative cloud security platform that provides organizations with a comprehensive solution to protect their cloud environments. The platform offers a range of security tools and features, including vulnerability management, compliance monitoring, network security, and threat detection and response.
What sets Prisma Cloud apart from other cloud security solutions is its ability to provide a complete view of an organization's cloud environment, allowing for a more proactive approach to security. The platform also offers automated compliance checks, which can help organizations reduce the risk of non-compliance and associated penalties.
What do you dislike about the product?
There are some undisclosed features and a generic bug in the secret key management service that should be addressed. Additionally, the cost of using the platform may be a downside for some users.
What problems is the product solving and how is that benefiting you?
Prisma Cloud from Palo Alto Networks is solving a number of problems related to cloud security. It secures applications from code to the cloud, enabling security and DevOps teams to work together seamlessly. it helps to solve most of the CI/CD issues that are application-level problems, saving teams time and money. Prisma Cloud also helps organizations to comply with PCI requirements, making it a valuable tool for cloud security.
Good inventory reporting and security posture management
What is our primary use case?
I generally use Prisma Cloud to dive deeper into any security findings generated by Prisma. It's also a good way to get a complete inventory of all our cloud assets spread across different cloud platforms.
How has it helped my organization?
The customers that we work with have really benefited from Prisma Cloud by including it in their workflows and security audits. Prisma Cloud has really helped them improve their security posture.
What is most valuable?
Prisma Cloud's inventory reporting is pretty good. If you have multiple clouds or platforms, you can have a list of all your cloud resources within Prisma. The security posture management is also great.
We continuously work with our security teams to find any issues with their infrastructure. Prisma continuously monitors the infrastructure, which helps us locate those resources and patch those findings.
What needs improvement?
The information presented in the UI sometimes doesn't look intuitive enough. For instance, if I want to look at all the resources that are affected by a certain finding, sometimes it's not easy to locate how to look at all those resources in one place. But that's just a UI quirk. However, API-wise, Prisma Cloud is pretty good for locating what you're looking to find.
For how long have I used the solution?
I have been using Prisma Cloud by Palo Alto Networks for the past six months.
What do I think about the stability of the solution?
It is a stable product. I haven't seen any outages with Prisma Cloud.
What do I think about the scalability of the solution?
It is a scalable product.
How are customer service and support?
Prisma Cloud's customer service is pretty great.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
We used a different solution before switching to Prisma Cloud. The decision to switch to Prisma Cloud was a strategic decision made by the enterprise.
How was the initial setup?
The initial deployment was pretty straightforward. We primarily use it with our AWS cloud, and it's pretty easy to set up cross-account roles to get access to Prisma. Prisma Cloud uses cross-account IAM roles in AWS. You just set those roles up using a stack SAT across your entire set of AWS accounts, and Prisma can access all those accounts immediately.
What about the implementation team?
What was our ROI?
Prisma Cloud has really improved our productivity and freed up resource time from manually hunting for findings to automating it.
Which other solutions did I evaluate?
Before choosing Prisma Cloud, we did a few POCs for products like DivvyCloud, Dome9, and Cisive. All these products pretty much do the same thing with a few differentiating factors, but not enough to really stand out.
What other advice do I have?
I rate Prisma Cloud an eight on a scale of one to ten for ease of use. It is pretty intuitive, except for not being able to locate resources affected by a certain finding individually.
Prisma Cloud has helped free up staff to work on other projects. Previously, we used to do ad hoc scripting to find different resources affected by a certain finding. However, we no longer have to do that because everything is automated.
At least ten hours each week were freed up because of the Prisma Cloud.
Meeting with all the industry professionals at the RSA conference is a great feeling. We get to learn about the latest trends in cybersecurity, all the new products that are coming up to tackle all the challenges, and especially the role of AI and machine learning in cybersecurity.
We've been looking at improving our hybrid connectivity solutions and making them more secure. We explored a few solutions at the RSA conference, which will come into play when we decide.
Overall, I rate Prisma Cloud an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)