We use the product to access the internet internally. It helps us to block unnecessary networks.
It architect at DEM
Useful for blocking applications and IPs
Pros and Cons
- "The tool helps us to block IPs and applications."
- "I have faced issues with the tool's blocking aspects. It is hard to open or block web services due to the multitude of cloud centers. I have to do the process manually at times. We have a bug which is hard to solve."
What is our primary use case?
What is most valuable?
The tool helps us to block IPs and applications.
What needs improvement?
I have faced issues with the tool's blocking aspects. It is hard to open or block web services due to the multitude of cloud centers. I have to do the process manually at times. We have a bug which is hard to solve.
For how long have I used the solution?
I have been using Check Point CloudGuard Application Security for ten years.
Buyer's Guide
Check Point CloudGuard WAF
September 2025

Learn what your peers think about Check Point CloudGuard WAF. Get advice and tips from experienced pros sharing their opinions. Updated: September 2025.
868,787 professionals have used our research since 2012.
What do I think about the stability of the solution?
I like the tool's stability.
What do I think about the scalability of the solution?
Check Point CloudGuard Application Security is scalable.
How are customer service and support?
Check Point CloudGuard Application Security's support is sometimes good.
Which solution did I use previously and why did I switch?
We had used Sophos before Check Point CloudGuard Application Security. We switched to the product since Sophos did not have a firewall then.
How was the initial setup?
Check Point CloudGuard Application Security's deployment is not complicated.
What about the implementation team?
The tool's control helped us with the deployment.
What's my experience with pricing, setup cost, and licensing?
Check Point CloudGuard Application Security's pricing is not friendly.
What other advice do I have?
False positives happen occasionally, but it's not a big deal for me. I prefer false positives over the risk of something going undetected. The tool's abilities for preemptively blocking zero-day attacks and detecting hidden anomalies are good. It has helped us reduce the TCO for the web application firewall. I rate it a nine out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Senior Manager at Agriculture Skill Council of India (ASCI)
Offers high performance and improved productivity with a useful chatbot system
Pros and Cons
- "It offers high performance and improved productivity for users."
- "The trial version should be extended further so that QA test engineers can actually test the utilities in a real sense and can provide the maximum amount of feedback for enhancements."
What is our primary use case?
Check Point CloudGuard Application Security enabled us to develop strength and process efficiency coupled with a secure environment in the IT system. We've installed software all over 3rd party dashboards and internet systems. This application security platform helped us put a strong security system in place with an advanced bot prevention system, ensuring end-to-end security across a complete chain of processes. Our cost of the security system was greatly reduced, and it helped us to achieve cost efficiency within six months.
How has it helped my organization?
Check Point CloudGuard Application Security helps to bring the cost down and increase process and cost efficiency. It provides improved productivity in system outcome and output. It is one of the master security solutions in the market for enhancing system security through an intrusion prevention system that restricts entry of malware and any kind of threat attempts on system confidential data and ensures flawless security inside out. The performance efficiency of users and their department increased multifold due to the introduction of the software.
What is most valuable?
The Intrusion Prevention System is an awesome feature with high-end security properties to ensure a sustainable security system across IT assets and software.
It offers high performance and improved productivity for users.
Our organization marks lowered expenses and improved revenue as part of the technical outcome.
The chatbot system is highly advanced with automated security enhancements and enables real-time system security. It helps the users continuously learn about any potential threats on the system and warns them with pop-ups and notifications.
There are end-to-end web applications protecting and securing IT assets from the inside out.
What needs improvement?
The technical team needs to exercise the pilot testing across all kinds of IT hardware and software to ensure the pilot QA testing shows the highest rate of positives while ensuring system protection. The trial version should be extended further so that QA test engineers can actually test the utilities in a real sense and can provide the maximum amount of feedback for enhancements.
There needs to be an improvement in features and utilities now and then as per business demand. It needs to be customized to match market trends and demand.
For how long have I used the solution?
I've used the solution for one year.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
The solution is quite scalable.
Which solution did I use previously and why did I switch?
We were using our own in-house system security solution to prevent any ransomware and malware.
How was the initial setup?
It offers easy onboarding and is not complex at all. The solution has quite structured onboarding for deployment.
What about the implementation team?
We implemented it through a vendor team.
What was our ROI?
The ROI is great.
What's my experience with pricing, setup cost, and licensing?
The solution is low-cost and offers an easy renewal process as well as smooth onboarding for vendor partners.
Which other solutions did I evaluate?
We evaluated a lot many options available in the market, including Trend and McAfee, among others.
What other advice do I have?
It is a must-try security solution for all kinds of businesses. There are awesome features at extremely low cost.
Which deployment model are you using for this solution?
Private Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Check Point CloudGuard WAF
September 2025

Learn what your peers think about Check Point CloudGuard WAF. Get advice and tips from experienced pros sharing their opinions. Updated: September 2025.
868,787 professionals have used our research since 2012.
Soporte técnico superior at Acobo
Help s guarantee that applications are secure, protected, and resistant to attacks
Pros and Cons
- "The solution offers sophisticated security techniques with unique characteristics that can be particularly valuable for the financial sector, which is where we develop apps."
- "Deeper and more transparent integration between Cloud Application Security and analysis monitoring tools could be very valuable - although the solution currently offers integrations with third-party security tools."
What is our primary use case?
As one of the solutions that we need for protection at the API level, we have found the level of attack detection needed to comply with the internal regulations of the corporation.
It protects both financials and identity searches. It is a new generation of security that can help us seek, implement, and select different brands products for enhanced protection. This is important due to the acceleration and development of many applications. It helps us reduce the risk of vulnerability in productive applications.
How has it helped my organization?
The use of CloudGuard Application Security protects the page and online web services against SQL injection attacks. This prevents attackers from accessing our databases and stealing financial information from customers. These services help identify and fix vulnerabilities in our application and allow us to identify when there is a vulnerability, such as a code injection, and click on the site to see recommendations in order to fix issues before attackers can exploit weaknesses.
What is most valuable?
The solution offers sophisticated security techniques with unique characteristics that can be particularly valuable for the financial sector, which is where we develop apps. It helps us to guarantee that financial applications are secure, protected, and resistant to attacks, which is essential to maintain trust and reputational power with any client that is subscribed to our services.
What needs improvement?
Deeper and more transparent integration between Cloud Application Security and analysis monitoring tools could be very valuable - although the solution currently offers integrations with third-party security tools. Still, a deeper integration could provide better visibility of all the threats. It would be ideal if they could be found in real-time, allowing our financial or security team to offer a more effective response to attacks.
For how long have I used the solution?
I've used the solution for two years.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Perimeter Security Administrator at a security firm with 51-200 employees
Easily deployed with good visibility and excellent security capabilities
Pros and Cons
- "By using a cloud application security solution, our company can save costs by reducing the need for additional security hardware and software and improving operational efficiency."
- "A feature we'd like to see in the future is something that could protect against other attack vectors, with a focus on application protection."
What is our primary use case?
We were looking for a solution that met the following criteria:
- A web application security solution that uses real-time attack prevention techniques and vulnerability scanning to protect applications and data running in public or private cloud environments.
- Monitoring and logging of application traffic to detect anomalies and suspicious attacks.
- Integration with automation and orchestration tools for cloud application security management and scalability.
- Detection and prevention of SQL injection attacks, cross-site scripting (XSS), and other types of injection attacks.
How has it helped my organization?
The product benefits my business by giving enhanced protection for useful cloud applications.
Using enhanced visibility and analytics, the product provides visibility into security. By using a cloud application security solution, our company can save costs by reducing the need for additional security hardware and software and improving operational efficiency.
With this product, we are achieving regulatory compliance. CloudGuard Application Security can help businesses meet security regulatory requirements, which makes for an outstanding organization.
What is most valuable?
This cloud web application security solution can be quickly and easily deployed in public or private cloud environments, allowing a company to protect web applications and reduce downtime quickly.
This solution provides us with enhanced visibility, giving us the ability to provide web application security analysis in the cloud.
What needs improvement?
A feature we'd like to see in the future is something that could protect against other attack vectors, with a focus on application protection. We need to protect against other attack vectors like network or device email attacks in order to provide the greatest protection possible. It is very understandable that there are many characteristics of an attack, including if it is from the inside or outside the organization. However, it would be important to validate threats and have all manner of solutions on hand to help protect the company.
For how long have I used the solution?
I've used the solution for one year.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Project Manager at Digitas APAC
Great support, excellent ROI, and good performance
Pros and Cons
- "It provides advanced analytics that gives each team time to prepare for any threat that might occur in the future."
- "The coding configurations can be simplified to save time for IT teams and developers."
What is our primary use case?
This solution safeguards applications that are hosted in the organization's cloud servers.
It monitors the performance of applications from the deployment stage to the implementation of assigned tasks.
Check Point CloudGuard Application Security blocks any cyber attacks channeled to destroy confidential data.
Configuration of this platform with other tools took place efficiently without any challenge. The set security features alert the IT team when there are external threats that can affect workflows. the organization's networking infrastructure is ever secure since we deployed this product.
How has it helped my organization?
The solution has comprehensive security cover for the cloud applications, which has been a great achievement in the organization since we deployed this platform.
It provides advanced analytics that gives each team time to prepare for any threat that might occur in the future.
Enhanced data intelligence helps us to plan and turn provides analytics into actionable insights.
Safeguarding applications has enabled members to focus on more productive activities without fear of being attacked. The set of security tools enables each app to perform its role without external interference.
What is most valuable?
Sensitive data exposure has enabled us to plan and make reliable decisions based on the work environment.
The product has confirmed to each department that the injection of new data into the systems is highly secured to enhance transparency.
Security misconfigurations enable the IT team to rearrange application codes and take full control.
Insecure deserialization provides a comprehensive report of applications that enables the IT team to identify malicious coding and execute it in advance before it affects workflows.
What needs improvement?
The coding configurations can be simplified to save time for IT teams and developers.
Insufficient logging among applications breaches security, and this may lead to undetected malware attacks contributing to data compromise.
The set security tools target known vulnerabilities, and when there is an outbreak of new viruses, it may not be noticed, easily exposing data to cyber attackers.
Broken access control enables members to gain unauthorized access to saved files allowing them to edit accounts to enable other users to gain access. The software has great capability of preventing data with the set organization policies.
For how long have I used the solution?
I've used the solution for nine months.
What do I think about the stability of the solution?
This platform is stable, and the performance is excellent.
What do I think about the scalability of the solution?
I am impressed by the scalability.
How are customer service and support?
There is great support and cooperation from the customer service team.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I have not worked with a similar solution.
How was the initial setup?
The initial setup was straightforward.
What about the implementation team?
The vendor team was responsible for the full deployment.
What was our ROI?
There is increased ROI from improved application security.
What's my experience with pricing, setup cost, and licensing?
The cost and setup are good, depending on the company size.
Which other solutions did I evaluate?
I have no experience with other security products on the market.
What other advice do I have?
This platform is good for safeguarding cloud applications.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Java Developer at EROAD
Guards privacy, protects data, and offers good security configuration
Pros and Cons
- "After integrating AppSec with other applications, team members can easily work without fear of confidential information exposure."
- "The creation of security profiles for each application takes a lot of time."
What is our primary use case?
This security management system allows teams to evaluate the performance of applications and identify vulnerabilities that could affect performance.
It has deployed reliable security measures that can easily detect any potential data leaks and cyber-attacks. Before we develop any application Check Point CloudGuard Application Security provides the best data protection tools that be configured easily with the new application. We have been able to scale down workflows and monitor appropriately the entire production ecosystem.
How has it helped my organization?
We have prevented many potential threats that could be a major setback to our set goals.
After integrating AppSec with other applications, team members can easily work without fear of confidential information exposure. It has really empowered employees with modern online security measures that can affect business progress.
Learning new security coding techniques has been a great opportunity for my team and the entire organization. We have quashed many authentication and code injection attempts by ransomware attacks to secure our networking infrastructure.
What is most valuable?
Sensitive data exposure models have helped in guarding the privacy of company and customer information from landing in unauthorized hands.
Confidential details like bank statements and the financial status of employees is very sensitive and can easily be exposed to cyber-attacks. AppSec has created a secure environment that allows members to create and manage their personal email accounts and related personal data.
Application security configuration gives the IT team and authorized personnel to have full access and control of workflows without fear.
What needs improvement?
The creation of security profiles for each application takes a lot of time. The new release can have a unified security control system that can access the security situation of all applications from one single source.
The system blocks some authorized data entries that are not threats. AppSec could easily deploy a system with set commands that can be used to block unsafe operations and authorize areas of interest based on the user's needs. I have loved the way this software works, and I am impressed by the increased security across the applications.
For how long have I used the solution?
I've used the solution for eight months.
What do I think about the stability of the solution?
It is stable throughout.
What do I think about the scalability of the solution?
This software is good and the performance is excellent.
How are customer service and support?
The customer support staff is dedicated to delivering the best services ever.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We decided to test the performance of this product for the first time, and it impressed the departments.
How was the initial setup?
The setup process was straightforward, and the vendor guided us effectively.
What about the implementation team?
Deployment took place through the vendor team.
What was our ROI?
ROI has increased from 40% to 65% in eight months.
What's my experience with pricing, setup cost, and licensing?
The price is good for all businesses.
Which other solutions did I evaluate?
I did not consider other options.
What other advice do I have?
We could not have prevented many external attacks without AppSec. I am happy due to its great performance.
Which deployment model are you using for this solution?
Private Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Consultant at ITQS
Great API integration, good pricing, and offers good security
Pros and Cons
- "It is a very scalable and stable solution."
- "CloudGuard for Application Security, like the other Check Point applications, has been presenting major latency problems when entering their administrative portal."
How has it helped my organization?
CloudGuard for Application Security came to provide a layer and organization of security to our company. The management of the devices became easier and faster to manage. In addition, the tool had very good reviews since it is the one in the market with the best detection rate of threats.
The solution is scalable, reliable, and does not present many false positives.
In addition, CloudGuard for Application Security helped us with its AI. With the ability to assess vulnerabilities, it helps us with the best practices to implement in the company.
What is most valuable?
CloudGuard for Application Security one of its most valuable features is that it can be integrated into an API more easily and effortlessly.
It is also a very scalable and stable solution. That is one of the points that a company looks for when implementing something like this in an organization.
With this tool, we have been able to release the overload that was being caused in the IT department and be able to focus on other security functions and thus be able to apply all good practices and be able to manage security 100% of the time.
What needs improvement?
CloudGuard for Application Security, like the other Check Point applications, has been presenting major latency problems when entering their administrative portal. That should be one of the priorities to take into account.
They must also improve the support provided to the client and improve the documentation library.
The tool fulfills the functionality very well. Hopefully, the next improvements will surprise us with something new since at present it fulfills the security expectations very well.
For how long have I used the solution?
it was implemented approximately one year ago.
What do I think about the stability of the solution?
The stability it presents is excellent. It goes up to 100%.
What do I think about the scalability of the solution?
The scalability that it presents is very good.
How are customer service and support?
The support must be improved. It presents a lot of deficiency.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
No previous solution was implemented.
How was the initial setup?
The configuration is very simple and the product is easy to implement.
What about the implementation team?
We had an engineer that helped us with the implementation. Overall, it was fast and good.
What was our ROI?
The investment that is made is an investment that will be reflected in the security. It's worth it.
What's my experience with pricing, setup cost, and licensing?
The cost is competitive in the market.
Which other solutions did I evaluate?
We wanted to continue with the same horizon as we have several Check Point solutions in our environment.
What other advice do I have?
The solution works very well. They just need to improve the support and documentation.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Delivery Engineer at a tech services company with 51-200 employees
Offers comprehensive threat prevention capabilities and a user-friendly interface
Pros and Cons
- "The features I have found most valuable are the comprehensive threat prevention capabilities, automated policy management, and seamless integration with cloud environments."
- "For the next release, I would suggest considering features like enhanced threat intelligence integration."
What is our primary use case?
With CloudGuard WAF, I can deploy a cloud-based network protection solution that secures my applications, endpoints, and data.
What is most valuable?
The features I have found most valuable are the comprehensive threat prevention capabilities, automated policy management, and seamless integration with cloud environments.
What needs improvement?
For the next release, I would suggest considering features like enhanced threat intelligence integration.
For how long have I used the solution?
I have been using Check Point CloudGuard WAF for about two years.
What do I think about the stability of the solution?
The stability of the product has been good so far.
How are customer service and support?
Check Point's technical support is helpful and knowledgeable overall, but there can be delays in response, especially regarding licensing issues.
Which solution did I use previously and why did I switch?
The main reasons I chose this vendor for web application security were their ability to consolidate management facilities, their comprehensive features, and their flexibility in addressing different security needs.
What was our ROI?
We have seen ROI from using CloudGuard WAF.
What's my experience with pricing, setup cost, and licensing?
I believe that the pricing or licensing of CloudGuard WAF could be more competitive.
What other advice do I have?
Implementing CloudGuard WAF allowed me to address the challenges of securing my applications and data in a rapidly evolving cloud environment.
Using CloudGuard WAF has brought significant benefits, including improved threat protection, streamlined policy management, and enhanced usability. I noticed these advantages shortly after the first deployment.
It is extremely important to me that CloudGuard optimizes security to protect my applications without solely relying on signatures.
To access the false positive rate, I typically review assessment reports available on platforms like AWS or Azure. By evaluating how effectively the solution preemptively blocks zero-day attacks and minimizes false positives, I can reduce the total cost of ownership for my web application security.
The solution's privacy features, user-friendly web console, virtual deployment options, and physical appliance capabilities have all contributed to reducing my total cost of ownership.
Overall, I would rate CloudGuard WAF as an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller

Buyer's Guide
Download our free Check Point CloudGuard WAF Report and get advice and tips from experienced pros
sharing their opinions.
Updated: September 2025
Popular Comparisons
SonarQube Server (formerly SonarQube)
Checkmarx One
Imperva Application Security Platform
Azure Front Door
CrowdStrike Falcon Cloud Security
Microsoft Azure Application Gateway
F5 Advanced WAF
Fortinet FortiWeb
Cloudflare Web Application Firewall
Radware Alteon
Barracuda Web Application Firewall
Radware Cloud WAF Service
open-appsec
Buyer's Guide
Download our free Check Point CloudGuard WAF Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- If you had to both encrypt and compress data during transmission, which would you do first and why?
- When evaluating Application Security, what aspect do you think is the most important to look for?
- What are the Top 5 cybersecurity trends in 2022?
- What are the threats associated with using ‘bogus’ cybersecurity tools?
- We're evaluating Tripwire, what else should we consider?
- Which application security solutions include both vulnerability scans and quality checks?
- Is SonarQube the best tool for static analysis?
- Why Do I Need Application Security Software?
- Which Email Security enterprise solution would you choose: Cisco Secure Email vs Forcepoint Email Security vs Barracuda Email Security Gateway?
- SAST vs. DAST: Which is better for application security testing?