What is our primary use case?
We use IBM Security Guardium Data Encryption for the testing of our systems in the UAT environment. When providing data outside of the organization, we use Guardium encryption. We also use the tool when we have to share data with our external bodies.
Moreover, when developing systems within our organization, we use data masking for Oracle and data masking solutions from IBM for testing purposes.
What is most valuable?
The key management functionality in Guardium performs well and integrates easily with SIEM, which is a positive aspect. The encryption features help in complying with the Encryption Technology Governance Framework issued by the State Bank, fulfilling our regulatory needs.
What needs improvement?
There is a need for an improvement in native masking functionality, especially for databases like Oracle. We face challenges with masking features that require developing kernels and take a long time. Enhancing ease of integration with various databases and reducing the time taken for support are areas for improvement.
For how long have I used the solution?
We deployed the solution in 2021, however, regarding data encryption, we started implementing it in mid-2023.
What do I think about the stability of the solution?
From 2021 to 2024, we have faced continuous issues with implementation, requiring frequent contact with IBM for support. We experience stability issues particularly when our databases are changed or upgraded.
What do I think about the scalability of the solution?
The solution is scalable, and I would rate its scalability eight out of ten.
How are customer service and support?
IBM's customer service is supportive but slow, with response times taking up to forty days for developing plugins or parsers. This delay is risky, especially in the financial sector.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
We chose IBM because it was among the top rated solutions on the Gartner website, and we aimed to opt for solutions among the top ten.
How was the initial setup?
Installation was pretty simple, but integrating the solution with our large database systems and going through the approval process took three to four months.
What about the implementation team?
Cross-functional teams including the SIEM team, the office of the CISO team, and the IT team were involved. Around twenty people participated in deployment and implementation.
What was our ROI?
Being a government bank, we prioritize finding the best solution over cost savings. We have not explicitly evaluated the return on investment.
What's my experience with pricing, setup cost, and licensing?
Upon purchasing CP4S, which includes IBM Guardium, we had to purchase additional plugins for encryption, leading to extra costs. I would rate the cost effectiveness seven out of ten.
Which other solutions did I evaluate?
Peer banks in our country using IBM played a role in our decision to choose them. We looked at top-rated solutions from Gartner's rankings.
What other advice do I have?
Overall, Guardium is a good solution. However, given the challenges with encryption, we have started considering other solutions. IBM should work on enhancing integration and usability with different databases.
I can recommend this solution, however, our organization has faced implementation challenges, leading to a rating of six out of ten.
Which deployment model are you using for this solution?
On-premises