No more typing reviews! Try our Samantha, our new voice AI agent.

Check Point Cloud Firewall (formerly CloudGuard Network Security) vs Immuta comparison

Why PeerSpot?
Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Aug 13, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Qualys TotalCloud
Sponsored
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
46
Ranking in other categories
Vulnerability Management (11th), Container Security (11th), Cloud Workload Protection Platforms (CWPP) (8th), Cloud Security Posture Management (CSPM) (8th), SaaS Security Posture Management (SSPM) (2nd), Cloud-Native Application Protection Platforms (CNAPP) (7th)
Check Point Cloud Firewall ...
Average Rating
8.4
Reviews Sentiment
7.3
Number of Reviews
244
Ranking in other categories
Firewalls (8th), Managed Security Services Providers (MSSP) (1st), Vulnerability Management (5th), Software Defined WAN (SD-WAN) Solutions (3rd), Cloud and Data Center Security (3rd), Container Security (6th), Cloud Workload Protection Platforms (CWPP) (5th), WAN Edge (3rd), Unified Threat Management (UTM) (4th), Cloud Security Posture Management (CSPM) (5th), Cloud-Native Application Protection Platforms (CNAPP) (5th), Data Security Posture Management (DSPM) (4th), Compliance Management (5th)
Immuta
Average Rating
7.6
Reviews Sentiment
7.6
Number of Reviews
5
Ranking in other categories
Data Governance (25th), Data Security Posture Management (DSPM) (15th), AI Data Analysis (25th)
 

Featured Reviews

reviewer2859021 - PeerSpot reviewer
Sr Security Engineer at a tech vendor with 5,001-10,000 employees
Risk-based triage has transformed container security and now prioritizes high-impact threats
The best features Qualys TotalCloud offers currently include managing cloud infrastructure and container security while facing major challenges such as alert fatigue. Traditional vulnerability scanners flag hundreds of CVEs on short-lived Kubernetes containers, some of which have no internet exposure or are gone before we can even triage them. I leverage Qualys TotalCloud to move beyond static CVSS. I use it to implement runtime exposure, correlation risk reprioritization, and shift-left integration. This notifies developers to fix a base image upstream rather than patching live ephemeral instances. In my work with cloud and container security, the biggest operational hurdle was alert fatigue. I use Qualys to shift left from static CVSS severity to context-aware risk prioritization. I correlated raw vulnerability data with real-time risk factors such as public network exposure, active runtime execution, or overly permissive IAM roles. This allows us to immediately drop the priority of isolated containers and escalate lower-severity CVEs that sit on an exposed, high-risk path. We can map these findings directly back to our CI/CD pipelines so developers can patch the root base images upstream. We have drastically cut down the signal-to-noise ratio, saved a lot of manual hours doing triage work, and ensured engineering effort goes directly towards high-impact risk reduction.
Oscar Nunez - PeerSpot reviewer
Ingeniero en redes y Telecomunicaciones at K-IT
Centralized management has reduced policy time and provides reliable multitenant protection
What I would like, what I think they should improve a little is the management of objects at large scale. When you work with multiple domains, there are thousands of network objects. Detecting duplicates and consistency across domains is a very manual process that should be more automated. Another thing: the SmartConsole interface is very powerful and very good, but the learning curve, compared to other solutions in the market from other manufacturers, could be modernized. I think it does not necessarily have to be done from a client application; it could be done via web, because via web I know that not all the options you have in SmartConsole are available. So it would be good if it could also be done from the web and all the options were available. Another thing that I would really like is more automation with Ansible or Terraform. I know it has improved in recent versions, but I think it is still not mature enough. Compared to other manufacturers that do have a bit more in terms of automation capabilities in integration flows with Ansible or Terraform, Check Point Cloud Firewall (formerly CloudGuard Network Security) could improve. Another thing that could be improved a little would be the TAC response time, because when there are very complex cases, I think there should be more speed initially, more ownership of those urgent cases, and not leave the customer waiting. This has happened to me: when I have cases open with Check Point Cloud Firewall (formerly CloudGuard Network Security) TAC, sometimes they do not respond and I have to keep insisting, and I think that part should improve. I do not know if it depends on who takes the ticket or on the severity of the ticket, but sometimes I have had to insist a lot, and that would be the only problem. Once they attend to me and become involved in the case, the responses they give are very professional and really help directly resolve the problems when there is a bug or troubleshooting to do. As I said, I would like to see a specific improvement in SmartConsole. I think if they improved it—how to say it—gave it a facelift so you could access all the options directly from a browser, that would be great, because sometimes, for one reason or another, you cannot download SmartConsole or, for some reason, the SmartConsole client does not start correctly, and you could do it directly from the browser. I think that would be a good option to improve. Another thing would be that in multidomain environments, I would like a global search function for objects and rules. That is, you could enter and search across all domains at once, because right now you have to go domain by domain, and in environments with many customers, you spend quite a bit of time; you have to exit one domain and enter another. So those would be the improvements I would like to see.
Dibyajyoti Rath - PeerSpot reviewer
Data Analyst at a consultancy with 10,001+ employees
Centralized access control has secured sensitive data and supports compliant self-service analytics
Immuta is very helpful, but it can be improved in a few areas. The initial setup and policy design can be complex and require a learning curve. The user interface could be more interactive, especially for non-technical users. Policy troubleshooting and debugging could be easier with better visibility into why access was allowed or denied. Performance optimization and deeper integration with more tools could make it even better. Additional improvements would strengthen Immuta further. The documentation and real-world examples would help teams onboard faster. More out-of-the-box policy templates could reduce setup time. Improved policy simulation and testing would help teams understand the impact of changes before applying them. Stronger alerting and monitoring features would help quickly identify access issues. Finally, more end-user training and simplified workflows would make it easier for business users to adopt.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Qualys TotalCloud is an excellent platform, and the beauty of the platform is that we can get all the vulnerabilities, see all the reports in a single dashboard, view them segregated, and easily learn about critical, high, and medium findings with appropriately provided remediation steps."
"I like the web API security and IoT scanning features the most. The user-friendly design of TotalCloud's interface enables customers to navigate it and use its full potential easily"
"If I had to say something positive about the product that brings me the biggest benefit, I would say it has accurate reports, gets new update CVEs, zero-day attack detection, and is easy to manage with its GUI."
"Qualys TotalCloud's most valuable features are its cloud security posture management, Kubernetes, and container security capabilities."
"TotalCloud's best feature is the integration of cloud accounts. It helps with the risk and security posture management of our cloud infrastructure."
"Qualys TotalCloud's most valuable feature is its agent versatility."
"The best features in Qualys TotalCloud include the total asset management of the cloud environment. It is very easy to export the report and see the vulnerabilities related to the cloud specifically."
"I would definitely recommend it because it is easy to handle any cloud resources."
"This product is quick to deploy, scalable, and is a fully functional firewall available in the cloud."
"We're very confident in the secure cloud deployments and migrations."
"It presents a real-time database that is always updated."
"Check Point CloudGuard provides comprehensive security coverage."
"It was very easy to install the solution, and the architecture meant we didn't have to worry about exceeding the solution's capacity."
"The product allows us to enhance the security of the implementations we have, helping resolve several security incidents that we previously had and could not see, since previously we did not have a solution that allowed us to quickly and safely manage each one of the activities."
"The most valuable feature of Check Point CloudGuard Network Security is the increased mail protection including spam."
"Dome9 wraps our FTP infrastructure with its network security configurations, and this also gives us the ability to monitor FTP activity."
"Instead of manually tagging data, Immuta’s auto-discovery capability identifies sensitive information, such as country labels, gender information, and other personal data."
"What I appreciate the most is its user-friendliness."
"The tool's most valuable feature is restriction."
"All features available are good."
"Immuta has had a very positive impact on our organization, helping us strengthen data security by ensuring sensitive data is only accessible to the right users, simplifying compliance with clear audit trails and consistent policy enforcement, reducing manual access management to save time for data and security teams, and enabling safe self-service analytics so our team can access data faster while still meeting governance and regulatory requirements."
 

Cons

"Qualys TotalCloud needs to enhance its scanning capabilities in the IP domain, as it currently lacks the functionality to resolve IPs to their corresponding domain names."
"There is room for improvement in vulnerability scanning, particularly for PaaS environments. Currently, Qualys does not have full access to these instances, which limits its effectiveness."
"Qualys's ticketing system can be confusing when assigning tasks to individuals, and support could be improved by offering instant call solutions with engineers in addition to ticket replies."
"Customer support with Qualys TotalCloud needs a little improvement with the response times."
"In a future release, I suggest that zero-day vulnerabilities should be predicted in advance using AI technologies. The system is not 100% secure yet, so proactive threat hunting could be enhanced to be more proactive than the current system."
"In TotalCloud, I would suggest improvements in policy checks to cater to various inventory types like VPCs, subnets, S3 buckets, or IAMs. There is a lack of data segregation according to criticality or inventory."
"Two areas for improvement in Qualys TotalCloud are the speed of the public cloud platform and vulnerability detection."
"To improve the user experience, reporting could be simplified for better comprehension by end users and project managers, facilitating issue resolution."
"The solution could be improved with a greater analysis of its Microsoft Security score."
"The SD-WAN could be better."
"Sometimes, the support is good, and other times, we are a bit desperate."
"Most of our customers are afraid to deploy any configuration changes because they are afraid something will happen."
"New features have been introduced recently, but they have not yet been integrated into CloudGuard Vsec."
"I think the initial setup of Check Point CloudGuard Network Security can be simpler; onboarding could be more intuitive for new cloud teams, and it could also have more flexible custom reporting and better documentation examples."
"It feels somewhat fractured to me. I haven't grasped all the parts yet, and better integration would make CNAPP most valuable."
"The networking system updates, when delayed, can lead to misconfigurations and data loss."
"Immuta is very helpful, but it can be improved in a few areas."
"Immuta is behind in updating upgrades and software releases."
"We have had some challenges with their support when we were migrating to the cloud version. We we had some issues, and it took us several attempts to get a proper responses as part of that migration."
"There is room for improvement in enhancing the monitoring capabilities."
"The implementation process with Immuta was quite challenging, primarily due to issues related to database handling and the syncing of user groups."
 

Pricing and Cost Advice

"Although Qualys TotalCloud is relatively expensive due to its unique automation features, its cost-effectiveness is rated an eight out of ten, with ten being the most costly."
"While Qualys TotalCloud's pricing is currently acceptable, it is becoming increasingly expensive and may soon be considered overpriced."
"The cost is high, but it meets our organizational needs."
"Qualys TotalCloud is cost-efficient and was selected for its value compared to other products."
"TotalCloud's price is about right where I would expect it to be."
"Qualys TotalCloud is expensive."
"As a middle management member, I do not have direct pricing knowledge, but based on the knowledge from our meetings, its pricing is competitive."
"The pricing is comparable. It is built into our other product, so I cannot piecemeal it. It is a part of our subscription."
"The tool's pricing is good. Customers want it to be cheap. I consider the pricing to be elastic. CloudGuard Network Security is perceived as cost-effective compared to using the built-in tools provided by the cloud."
"The license for CloudGuard Posture Management is about $80 a year, and it's based on your cloud footprint, not the number of users. So you could have a million users, and it doesn't matter."
"You get charged only for what resources you choose and how much traffic actually passes through the firewall, which in turn saves a lot of money."
"The pricing and licensing have been good. We just had to do a license increase for our portion of it. We had that done within a couple of days. Given the fact that it's purely a software-based license, it ends up being even quicker than doing it for an on-prem firewall."
"The tool's pricing is not cheap."
"We have a pretty good partnership with Check Point. We have a global subscription and agreement. They give us a pretty good corporate discount."
"They're a little high in price. The price could be lower."
"I do not know the exact price, but it is fairly priced. It is neither cheap nor costly."
"Immuta's pricing is expensive."
report
Use our free recommendation engine to learn which Data Security Posture Management (DSPM) solutions are best for your needs.
913,806 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Comms Service Provider
16%
Outsourcing Company
12%
Manufacturing Company
11%
Financial Services Firm
10%
Outsourcing Company
16%
Construction Company
13%
Financial Services Firm
9%
Manufacturing Company
7%
Financial Services Firm
16%
Construction Company
11%
Manufacturing Company
10%
Computer Software Company
9%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business14
Midsize Enterprise5
Large Enterprise34
By reviewers
Company SizeCount
Small Business132
Midsize Enterprise53
Large Enterprise144
No data available
 

Questions from the Community

What needs improvement with Qualys TotalCloud?
In terms of improvement, remediation still belongs to the cloud team, which is one of the issues we faced with Qualys...
What is your primary use case for Qualys TotalCloud?
My main use case for Qualys TotalCloud is regarding the cloud visibility that we were not having previously. Previous...
What is your experience regarding pricing and costs for Check Point CloudGuard Network Security?
Since we use a unified standard for using policies and modules in Check Point Cloud Firewall (formerly CloudGuard Net...
What needs improvement with Check Point CloudGuard Network Security?
The main limitations of Check Point Cloud Firewall (formerly CloudGuard Network Security) are not in Check Point itse...
What is your primary use case for Check Point CloudGuard Network Security?
Check Point Cloud Firewall (formerly CloudGuard Network Security) is the main manager that provides network security ...
What needs improvement with Immuta?
Immuta is very helpful, but it can be improved in a few areas. The initial setup and policy design can be complex and...
What is your primary use case for Immuta?
My main use case for Immuta is data governance. In my project, which is a data governance project, I use Immuta as a ...
What advice do you have for others considering Immuta?
My advice for others considering Immuta would be to plan your policies carefully. Think through roles, data sensitivi...
 

Also Known As

Qualys TotalCloud with FlexScan
CloudGuard IaaS, Check Point vSEC, CloudGuard IaaS, Check Point Virtual Systems, Check Point CloudGuard Network Security, Check Point CloudGuard CNAPP
No data available
 

Overview

 

Sample Customers

Information Not Available
Physicians Choice Laboratory Services, Helvetica Insurance
Information Not Available
Find out what your peers are saying about Check Point Cloud Firewall (formerly CloudGuard Network Security) vs. Immuta and other solutions. Updated: August 2026.
913,806 professionals have used our research since 2012.