Sign in
Categories
Your Saved List Become a Channel Partner Sell in AWS Marketplace Amazon Web Services Home Help

Comply

Zilla Security

Reviews from AWS customer

0 AWS reviews
  • 5 star
    0
  • 4 star
    0
  • 3 star
    0
  • 2 star
    0
  • 1 star
    0

External reviews

24 reviews
from and

External reviews are not included in the AWS star rating for the product.


    Information Technology and Services

Access Reviews Made Simple

  • November 08, 2024
  • Review provided by G2

What do you like best about the product?
It's considerably sped up our user access review process and has a nice, modern UI. No more spreadsheets for us!
What do you dislike about the product?
Upkeep and data sanitation can be tedious.
What problems is the product solving and how is that benefiting you?
Primarily user access reviews. Zilla quickly allowed us to automate the process in a few key areas, such as data collection and automating portions of the review itself, significantly reducing the time our stakeholders require to complete reviews. The out-of-the-box integrations are simple and easy to configure, and Zilla offers excellent tools for data collection if API syncs are unavailable for a specific system.


    reviewer2517972

The interface is highly intuitive and much easier for non-technical users than other tools

  • July 24, 2024
  • Review provided by PeerSpot

What is our primary use case?

We are a financial services company that's regulated by the FDIC, so we must complete a SOC 2 report showing evidence that we regularly review our high-risk applications. 

How has it helped my organization?

The solution has been a lifesaver. It has given us a unified platform that allows us to easily demonstrate what we need to do regarding user access reviews for compliance. 

Before Zilla, we were using fairly complicated spreadsheets, and it took a long time for the information security team to update these and send them to the business lines every quarter. We wanted something that was automated and easier for the business lines to review. Ultimately, it ended up saving the InfoSec team 60 hours per quarterly review and the business lines well over 100 hours. 

We had these spreadsheets all over the place, but now we have a library of evidence to consult when needed. Zilla keeps everything in one place. It's not scattered all over anymore. 

Because we must adhere to the SOC 2 framework, we need to manage our user permissions to the least privileged level. Since the spreadsheets were so complicated, many people rubber-stamped permissions. They weren't going to dive into this rat's nest, so they would just say everything is fine. With Zilla, people were able to see more clearly into their permissions, and I feel confident that we're drilling down and adhering to the least privileged rule. 

The manual work needed to track everything on spreadsheets was becoming unsustainable as we added applications. We can import permissions directly into Zilla instead of juggling the data and massaging it so it fits into the spreadsheets. It's probably saved my team about 40 hours per quarter.

Zilla saves us money. We did some calculations during the first quarter and found that some people doing user access reviews were at the VP level, so their time is worth a ton of money. We also found that these folks were spending unnecessary time combing through these spreadsheets. Something that typically took an hour could be completed in 15 minutes with Zilla. 

What is most valuable?

The interface is highly intuitive, and that helps in many ways because we don't need to explain things to the business lines. It's much easier than other identity and management tools. We were looking for something clear-cut that makes sense to non-technical people. It has greatly improved the controls on our audit procedures by giving people something that's clean and makes sense.

It's extremely important that Zilla provides us with a single pane of glass. When the FDIC asks us for a review, it's easier to have it in one portal than to go to all these spreadsheets scattered over SharePoint. Spreadsheets can also be manipulated, but Zilla has an audit trail that we can follow and show without a doubt that we've done what was required. 

What needs improvement?

Maybe this is coming with their AI module, but I would like to see a feature that performs baseline analysis of permissions that may not fit into a role, and it attempts to group them into a role. We've run into problems with applications where someone has not created a role but assigned ad hoc permissions to a user. We still need to do some manual work to identify the group that the user belongs to. It would be amazing to have Zilla streamline that. 

For how long have I used the solution?

I have used Zilla for a year and a half. 

What do I think about the stability of the solution?

Zilla is highly stable. We've had zero problems with it. 

What do I think about the scalability of the solution?

When we were using spreadsheets, we reviewed about eight applications, but since we added Zilla, we've scaled up to more than 40 and we continue to add to it quarterly.

How are customer service and support?

I haven't needed support since the initial setup, but we have a monthly meeting with our customer success rep. We discuss our needs and upcoming features on the roadmap.

Which solution did I use previously and why did I switch?

I have seven years of experience with SailPoint. It had the role-analysis feature and was a full-blown IAM solution, but we were looking for something we could use of the InfoSec team and GRC specifically that would enable us to do user access reviews. If I did an apples-to-apples comparison between Zilla and SailPoint regarding user access reviews, I would say Zilla comes out ahead for intuitiveness. It's easier to import permissions and it's simpler for non-technical people to use.

We use a tool called Saviynt that's run in-house by our identity access and management department. That also has user access management, but they hope to move away from it because support hasn't been great. Rather than wait for the IAM team, we decided to go for our own solution. While doing a deep dive into Saviynt, we came across Zilla. Our IAM team told us that if we wanted to switch, it would take only a week or two to get it set up. 

How was the initial setup?

Deploying Zilla was easier than I expected, based on my experience with SailPoint and Saviynt. With those, it was an arduous process. The initial deployment was short, but it took us a quarter to get the solution up to usability. It doesn't require much maintenance aside from regularly updating permissions. It's more administration than maintenance. 

What about the implementation team?

We received support from Zilla's team, which was very helpful. 

What's my experience with pricing, setup cost, and licensing?

The Zilla license is what we expect to pay for a product like this. 

What other advice do I have?

I rate Zilla Security nine out of 10. I recommend that new users follow the advice of their solution engineer. They knew what they were doing and guided us through the installation. 

Which deployment model are you using for this solution?

Public Cloud


    Hubert Hopkins

Reasonably priced, responsive support, and easy to implement access reviews

  • July 17, 2024
  • Review provided by PeerSpot

What is our primary use case?

We use the tool for access reviews. It is mainly for our regulatory SOX compliance. That was the main use case, and why we purchased Zilla back at the end of 2021.

How has it helped my organization?

The system is pretty self-explanatory and easy to use. It is menu-driven. You can certainly hide the menu and go with icons that describe the menu items. It is easy to locate the things or categories that you need.

They are getting there in terms of the unified identity platform. We were one of the early adopters of Zilla, and I have seen it grow over the past couple of years. They are innovative and forward-thinking in their enhancements and development of the tool. They are adding things onto the tool to expand what it can do, whether it is additional application APIs or security findings and policies. 

I don't know if it has helped to consolidate applications, but it has made it easy to implement access reviews for critical applications. Previously, there was no process at all for an access review. It was a manual process, and now we have been able to automate it. We have not utilized everything that Zilla can do now to its complete ability. We are still growing in terms of the opportunities in the system.

We have looked at some of the policy-based information provided in Zilla but have not yet fully utilized it. I do look at some of the critical policies relevant to our environment that may pop up, and try to utilize them, such as if a terminated privileged user still has access to some systems. Whether that is true or false, it gives me that identification. I can then explore and validate if it is still true or not.

There are prebuilt APIs for many well-known applications. We have a few applications for which they have prebuilt their APIs. Others in our environment require the use of a CSV file upload to import user lists, which Zilla makes easy to do.

For our use case, when we initially purchased it, we did see the benefit right away or within the first few months of using it.

Zilla Security has helped improve controls when automating manual work. Some of these review processes were nonexistent or manual spreadsheet-based types of interactions. Being able to automate the process was a key factor.

Zilla Security has enabled me and one colleague to do more with less. It may have freed up some time for the business users, but it has enabled my smaller team to accomplish a lot more. 

I am sure Zilla Security has helped us save costs. We have been able to use limited resources to do more. We have not had to increase the team to manage the access reviews we perform. I haven't put a quantitative number on savings, but it has streamlined processes.

What is most valuable?

I enjoy the ease of setup and creation of a review. Being a user of the tool or an admin of the tool, the ease of setup of an access review is valuable. End users find out, after they complain about having to do it, how simple and easy it was for them to complete their reviews. It's as simple for them to click on a link in an email, check a few boxes, and submit their review. I tell most reviewers that the process of review, depending on the number of items reviewed, can take you less than 5 minutes to complete. 

The ability to sync applications via an API on a scheduled basis, if you choose, it also valuable in time savings because a admin doesn't have to remember to login and perform the function. 

What needs improvement?

There is still no automated way to de-provision access due to a review completion, but they are getting there in terms of making it unified.

Right now it is just a one-way integration, importing user lists. I believe they working on it. I can pull a user list in, but when I do a review, the results get sent to a ticket which requires a person to execute. As a result of the review, there is no automation for the removal of access. They are going there, and the next step is to continue to streamline the process operationally and resource-wise. The review process is great. The scope for improvement is more at the results end. It would be great if it could systematically communicate with that end system and remove the requested access automatically.

For how long have I used the solution?

We first started using it in 2021.

What do I think about the stability of the solution?

We have had lagging-related issues on very rare occasions accessing the system pages, but I cannot say if it was on the Zilla side or our own network side. If there is a major issue, which over the past 2.5 years I can only think of 1, Zilla proactively communicates that they know about and are working on. 

What do I think about the scalability of the solution?

We have applications with 50 users in them, and we also have applications with 4,000 users that we review. It scales well across all of those applications. 

How are customer service and support?

I have contacted them a bunch of times. They react pretty quickly and they respond fast to take care of things or inquire for clarification of what the issue may be. I have had positive responses from the support team and I would rate them a nine out of ten.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We have not used any other solution besides spreadsheets. I have seen other tools in my career and would say that Zilla still seems the simplest to use and setup when it comes to the review process. 

How was the initial setup?

Zilla is a cloud-based solution. It was fairly easy to set up. We had to pick a primary directory or source of truth for users. 

If you have applications that they don't currently have APIs for, it is a manual input process. But once you have done a manual input file once or twice, it is fairly easy to use.

We purchased Zilla at the end of October or November of 2021. I had it up and running our first access review within a month.

One key is the need for collaboration with others who own applications. One or two people could manage the system, but you have to have that collaboration with others.

In terms of maintenance, I would say that the system mostly can maintain itself. I would call myself the admin user of the system. I am in it every day. I keep an eye on certain things, especially scheduled APIs to ensure they execute.

What about the implementation team?

We implemented it in-house with our teams and Zilla. 

What's my experience with pricing, setup cost, and licensing?

It has been fair because we have been in from the beginning or close to the beginning. I know it is not truly an identity access management system yet, but its price was one of the appealing factors for us to purchase it at the time. It was reasonably priced.

Which other solutions did I evaluate?

We did not, mainly based on the size of our organization at the time. 

What other advice do I have?

I would advise knowing the source of truth that you are going to use upfront. If you need to change, that can be more complicated. Educating end users is always the biggest challenge with any process, but spending time to learn it is worth it.

I would rate Zilla Security a nine out of ten. It has been very easy to use. I have liked working with their team on different things, and they are very responsive.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other


    SYED ZAFFAR M.

Zilla Security- Enhanced automation of access control management.

  • May 25, 2024
  • Review provided by G2

What do you like best about the product?
We integrate Zilla security in our higher education institution to allow authorized students and subscribers access to academic resources, documents, projects and presentations. They frequently share their assignments and updates with group members remotely. This application helps us to monitor and control access management.
What do you dislike about the product?
So far, we have not faced any technical issues with this application.
What problems is the product solving and how is that benefiting you?
It provides the identity and details of all users who access our resources and automates the authorization management. Any misadventures will be detected and barred.


    Ahmad J.

Great Product for Access Reviews

  • March 22, 2024
  • Review provided by G2

What do you like best about the product?
The easy connections to our core applications
What do you dislike about the product?
I wish there could be automated remediation
What problems is the product solving and how is that benefiting you?
Zilla has given us a better more streamlined approach to a previous manual process.


    Nicole B.

Great Product

  • March 19, 2024
  • Review provided by G2

What do you like best about the product?
Zilla automated what my team had to do manually! By managing user identities across various systems and applications within my organization. I found the application had lots of flexibility for our use case.
What do you dislike about the product?
Nothing! Zilla Security works great for us.
What problems is the product solving and how is that benefiting you?
Zilla offers invaluable audit and compliance reports, furnishing irrefutable evidence to uphold our regulatory obligations. With its robust access management feature, Zilla effectively safeguards against unauthorized access to sensitive data and systems, simultaneously reducing application costs per user. Furthermore, Zilla significantly aids in regulatory compliance efforts by securely providing an immutable audit trail, meticulously documenting each stage of our access review process.


    Chris E.

Great for executing user reviews for your financial systems

  • March 19, 2024
  • Review provided by G2

What do you like best about the product?
Zilla allows me to quickly provide leadership the tools to approve the access of many financial systems users. It also confirms that they have enabled Active Directory accounts on the network. I am able to include a lot of information about each user, which makes their job of approving them even easier. The Zilla support team has gone above and beyond to support us and help us better use the product.
What do you dislike about the product?
I haven't found anything that I don't like yet. We are just now continue to expand our use of this product.
What problems is the product solving and how is that benefiting you?
Annual and semi-annual user access reviews required for audit.


    Chase S.

Zilla helps audit access to multiple systems

  • March 18, 2024
  • Review provided by G2

What do you like best about the product?
My favorite aspect of Zilla security is that it is a centralized location for all Vail Health users and the applications that they use. Before Zilla my organization had no way of auditing who had access to certain applications that are not tied to okta/AD.
What do you dislike about the product?
I dislike the fact that some processes in Zilla are manual. For example the mapping of users and integrating applications that are not capable of using the ZUS extension.
What problems is the product solving and how is that benefiting you?
Zilla is helping me with access reviews. Before Zilla we never had a process for reviewing access to applications that are not tied to okta/AD.


    Hubert H.

Have had nothing but positive things to say about using Zilla.

  • March 15, 2024
  • Review provided by G2

What do you like best about the product?
Ease of setup of access reviews.
Ease of use to the reviewer for performing reviews.
Responsiveness of customer support to support requests.
Friendliness of the Zilla team.
Continuous improvements or options in the tool.
What do you dislike about the product?
Some areas allow for the download of a large csv and others do not.
Some screens expand to 500 lines others do not.
What problems is the product solving and how is that benefiting you?
The main use is for compliance requirements. We perform around 15 reviews a quarter using Zilla and the number keeps growing. It has helped the organization maintain compliance with our required regulations and controls.


    Hospital & Health Care

PPFA - Zilla reivew

  • March 14, 2024
  • Review provided by G2

What do you like best about the product?
Zilla Security is easy to use; they have fast and efficient customer services. The implementations are quick and integrations are seamless.
What do you dislike about the product?
Zilla has limitations relating to application reviews, which makes it difficult to manage our admin/user account environment. We also cannot simultaneously review admin users and inactive users t the same time.
What problems is the product solving and how is that benefiting you?
User provision and access governance tolls streamline our processes of managing user access across our organization. This is helpful relating to auditing onboarding and offboarding processes. We also like that we can review appropriate access levels and ensure least privilege.