


Imperva Application Security Platform and Barracuda WAF-as-a-Service compete in web application security. Imperva stands out with more extensive features, while Barracuda is preferred for its ease of setup.
Features: Imperva Application Security Platform provides advanced security analytics, automated vulnerability protection, and integrated threat intelligence. Barracuda WAF-as-a-Service is known for its simplicity, efficient DDoS protection, and ease of use.
Room for Improvement: Imperva could enhance the user interface and reduce initial complexity. Additionally, improving customization options and reducing pricing complexity would benefit users. Barracuda could benefit from extending feature capabilities, offering more in-depth security analytics, and enhancing integration with third-party tools.
Ease of Deployment and Customer Service: Barracuda offers a cloud-based model for quick deployment supported by responsive customer service. Imperva, while more complex, supports users with extensive documentation and expert consultation.
Pricing and ROI: Imperva generally has higher initial costs due to its feature set but offers substantial ROI with scalable security. Barracuda’s transparent pricing and lower setup costs attract organizations seeking faster returns on investment.
My experience with the pricing or licensing of Cloudflare Web Application Firewall is that many features can be accessed for free, so the pricing is definitely reasonable.
Barracuda WAF-as-a-Service has positively impacted our organization by reducing cyber threats like ransomware and phishing by ninety-five percent.
For us, the biggest value comes from improved security and the reduced workload on the team, which makes the investment feel justified.
From an ROI and impact perspective, there is a 20 to 35% reduction in day-to-day administrative effort.
They know how much money they are losing while the system is down, so by increasing the possibility of not having a down website or web application, return on investment can be calculated easily.
I was able to save over seven million dollars last year as return on investment in the company.
I have seen a return on investment with Imperva Application Security Platform, as it is generally associated with time savings, because the review of alerts and the visibility it gives saves us significant operational time.
I would rate the technical support with Cloudflare as excellent every time I've had to contact them.
The technical support of Cloudflare Web Application Firewall rates between five and seven at maximum.
We had an incident requiring direct support, and the representatives were really helpful, resolving our query within forty-five minutes.
The engineers were helpful and knowledgeable, and we were able to get the guidance we needed.
I would rate Barracuda WAF-as-a-Service customer support as a nine on a scale of one to ten.
I would rate the technical support of Imperva DDoS as ten.
They need to work faster on the response time because of issues of urgent replies.
Responsive support addressing urgent needs.
The scalability of Cloudflare Web Application Firewall rates between 8 to 9, as it depends upon the use cases and what exactly the client needs.
Scalability is good for Barracuda WAF-as-a-Service; we can scale up or down based on our needs.
As our needs have grown and we have added more applications, it has handled this expansion without creating extra management overhead.
99% of customers are using the cloud version of Imperva DDoS protection, so they just purchase the new license and scale as needed.
I have not even needed support after deployment, since it has remained stable.
It is easy to always scale to add more users.
The stability of Cloudflare Web Application Firewall deserves a perfect 10 out of 10.
We have not faced any downtime, crashes, or lag.
Barracuda WAF-as-a-Service is extremely accurate in detection and reporting, and I find very few false positives.
Barracuda WAF-as-a-Service has been stable in our experience, and we have not faced any major downtime or service-impacting issues.
It is also a stable product without much glitch or downtime.
One notable drawback is that, unlike Fortinet, which offers fast track labs and continuous enablement, Imperva Application Security Platform lacks lab access and fast track labs for enablement and product advertising.
We experienced downtime or crashes with Imperva Application Security Platform when traffic went really strong or fast because people tried to get tickets.
The product can improve by having more multitenancy capability, which is currently not available.
I think they're doing a good job with DNS and as support for any domains that I create or that my clients create, it's mandatory for me to ensure they have Cloudflare as their DNS provider.
And maybe something similar to Pushpin that Fastly has, which is an option where you can push messages that then can be scaled globally over the network.
The ROI they have given us is tremendous, and they are doing really well in terms of product, scalability, and service.
Modernizing the UI further, simplifying packaging and licensing clarity, enhancing the executive reporting and risk dashboard, and expanding broader cloud-native integration would be beneficial improvements.
There is one issue regarding local data storage, as they do not have that capability, and we are storing the data in another foreign country, which is against the law.
To convince my clients, a purely on-prem solution would be ideal since they are financial institutions.
Maybe Imperva DDoS could use endpoints to get information about the attacks before they commence from the endpoint level or establish cooperation with endpoint vendors to share this information.
Regarding return on investment, ROI, I can say it is noticeable with Imperva Application Security Platform.
This system allows us to pay only for what we use, saving a lot of money, so I give it a ten out of ten as it is both a money and time saver for the organization.
Barracuda service is customizable but external references note that licensing and cost planning can become complex.
While it may not be the cheapest solution available, we believe the security, ease of management, and operational benefits provide good value for the investment.
I would rate the pricing of Imperva DDoS as five, where one is very cheap and ten is very expensive.
the setup cost was high, with the hardware installation in the data center being particularly expensive.
We have noticed faster response times and fewer security alerts because after doing some custom policy tuning, everything seemed to be aligned and we have fewer attacks to monitor and fewer alerts to monitor.
The custom rules and the geo-redundant geographical rule feature, which allows me to implement geographical rules for customers, add significant value.
The best features of Cloudflare Web Application Firewall are multiple, including the WAF, rate limiter, and bot attack protection.
Cloudflare Web Application Firewall's advanced reporting and analytics tools add a layer that we're able to visualize and see before it actually hits the local firewall.
The centralized dashboard is helping us streamline visibility across our admin panels and provides site-to-site visibility deployed directly to our AWS environment, securing VPC traffic and ensuring the firewall is in place.
One of the strongest points is the speed of deployment, which features a three-step deployment wizard, pre-built templates, and quick onboarding, making it suitable for teams that want protection fast without complex infrastructure setup.
I particularly appreciate its ability to automatically detect and block common web attacks such as SQL injection, XSS, and bot-based threats without requiring manual intervention.
The API security feature is particularly valuable because most attackers do not try to come in from where it is expected.
If someone attempts to access the server, the WAF blocks that SSRF alert, or RCE, Remote Code Execution alert, blocking immediately based on the signature, not only by the payload or the IP address.
It reduces the DDoS attacks and reduces the attacks from threat actors, including SQL Injection and zero-day attacks, by using dynamic application profiling from Imperva.
| Product | Mindshare (%) |
|---|---|
| Imperva Application Security Platform | 7.4% |
| Cloudflare Web Application Firewall | 4.5% |
| Barracuda WAF-as-a-Service | 1.0% |
| Other | 87.1% |

| Company Size | Count |
|---|---|
| Small Business | 16 |
| Midsize Enterprise | 6 |
| Large Enterprise | 6 |
| Company Size | Count |
|---|---|
| Small Business | 12 |
| Midsize Enterprise | 2 |
| Large Enterprise | 6 |
| Company Size | Count |
|---|---|
| Small Business | 88 |
| Midsize Enterprise | 25 |
| Large Enterprise | 70 |
Cloudflare Web Application Firewall integrates DDoS protection, load balancing, and firewall capabilities. Its ease of use, configurability, and robust security measures make it a versatile choice for protecting web applications.
Cloudflare Web Application Firewall provides a comprehensive defense against threats with advanced reporting and robust security measures. It includes DNS integration, rate limiting, and extensive rule sets, all within a SaaS model that allows API configurability. Users value its caching, scalability, and pricing, although enhancements are needed in rate-limiting and third-party integration. Improvements in customer support, especially in India, real-time controls, and user documentation are also desired. Users seek a more intuitive dashboard, better log management, and improved alert systems, along with multitenancy capabilities and enhanced reporting.
What are the key features of Cloudflare Web Application Firewall?Cloudflare Web Application Firewall finds application in industries like banking and retail by acting as a comprehensive security gateway, managing authentication and authorization while protecting web applications from malicious Layer 7 traffic. It also implements load balancing, CDN, and zero-trust policies, supported by advanced reporting, analytics tools, and threat scoring to meet specific industry needs.
Barracuda WAF-as-a-Service streamlines cloud security with features like automatic updates, real-time detection, and bot protection. It enhances AWS environments with simplified management and threat intelligence.
Barracuda WAF-as-a-Service provides robust application security, leveraging automatic security updates and real-time attack detection to defend against threats. Its centralized dashboard offers an intuitive management experience, complemented by automated policies. Real-time threat intelligence, application control, and VPN support contribute to its security efficacy. Its capabilities to detect and prevent DDoS, application, and unknown OS attacks ensure comprehensive protection. Although licensing complexity, high costs, stability concerns, and regional compliance issues pose challenges, it effectively secures websites and email systems against malware, phishing, and ransomware, and simplifies cloud migration.
What are the key features of Barracuda WAF-as-a-Service?In industries like e-commerce and finance, Barracuda WAF-as-a-Service is implemented for its effectiveness in securing cloud-based applications while reducing the need for on-premises equipment. Its strength in protecting both websites and email systems makes it a preferred choice for businesses migrating to cloud solutions.
Imperva Application Security Platform delivers comprehensive and continuous web threat protection. Renowned for its ease of use, it shields web applications and databases from various cyber threats while integrating seamlessly with cloud and on-premises environments.
Imperva Application Security Platform protects web environments by offering advanced security measures against threats like DDoS attacks, SQL injections, and cross-site scripting. As a robust web application firewall, it provides extensive monitoring and bot management capabilities. The platform integrates content delivery networks for enhanced performance and scalability, while real-time traffic analysis ensures consistent protection. Despite its strengths, improvements can be made in policy management and customization options. Users seek better integration with third-party tools and more competitive pricing models. The inclusion of AI for enhanced analytics is also anticipated.
What are the key features of Imperva Application Security Platform?Imperva Application Security Platform is implemented in industries needing strong database and application protection. Companies use it to enforce geolocation restrictions and manage bots, benefiting sectors like finance and e-commerce where data security and threat monitoring are critical. Its ability to protect and ensure data accessibility makes it integral to business operations prioritizing cyber resilience.
We monitor all Web Application Firewall (WAF) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.