No more typing reviews! Try our Samantha, our new voice AI agent.

Imperva Data Security Fabric vs Proofpoint Data Security Posture Management comparison

Why PeerSpot?
Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jul 21, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Qualys TotalCloud
Sponsored
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
46
Ranking in other categories
Vulnerability Management (11th), Container Security (11th), Cloud Workload Protection Platforms (CWPP) (8th), Cloud Security Posture Management (CSPM) (8th), SaaS Security Posture Management (SSPM) (2nd), Cloud-Native Application Protection Platforms (CNAPP) (7th)
Imperva Data Security Fabric
Average Rating
8.2
Reviews Sentiment
6.8
Number of Reviews
65
Ranking in other categories
Database Security (2nd), Data Security Posture Management (DSPM) (13th), Data Security Platforms (DSP) (4th)
Proofpoint Data Security Po...
Average Rating
9.0
Reviews Sentiment
3.6
Number of Reviews
1
Ranking in other categories
Data Security Posture Management (DSPM) (21st), Data Security Platforms (DSP) (9th)
 

Featured Reviews

reviewer2859021 - PeerSpot reviewer
Sr Security Engineer at a tech vendor with 5,001-10,000 employees
Risk-based triage has transformed container security and now prioritizes high-impact threats
The best features Qualys TotalCloud offers currently include managing cloud infrastructure and container security while facing major challenges such as alert fatigue. Traditional vulnerability scanners flag hundreds of CVEs on short-lived Kubernetes containers, some of which have no internet exposure or are gone before we can even triage them. I leverage Qualys TotalCloud to move beyond static CVSS. I use it to implement runtime exposure, correlation risk reprioritization, and shift-left integration. This notifies developers to fix a base image upstream rather than patching live ephemeral instances. In my work with cloud and container security, the biggest operational hurdle was alert fatigue. I use Qualys to shift left from static CVSS severity to context-aware risk prioritization. I correlated raw vulnerability data with real-time risk factors such as public network exposure, active runtime execution, or overly permissive IAM roles. This allows us to immediately drop the priority of isolated containers and escalate lower-severity CVEs that sit on an exposed, high-risk path. We can map these findings directly back to our CI/CD pipelines so developers can patch the root base images upstream. We have drastically cut down the signal-to-noise ratio, saved a lot of manual hours doing triage work, and ensured engineering effort goes directly towards high-impact risk reduction.
reviewer1876449 - PeerSpot reviewer
BDM at a comms service provider with 51-200 employees
Has provided wide data coverage and supports flexible implementation for growing database environments
Imperva SecureSphere Database Security offers the most comprehensive coverage range of database types, which is a significant advantage. It has very flexible implementation modes and an understandable console. Even someone who is not a database administrator could work with it, understand the security events, and comprehend the data activity monitoring events.Data is the most important asset in any organization and the primary target of hackers. Imperva SecureSphere Database Security provides one of the best solutions to analyze data, maintain GDPR compliance, and help investigate any incidents. It is user-friendly and can start with a small scope. Unlike competitors such as IBM Guardium and Oracle, customers can start with a small scope and scale every year. This advantage allows them to invest less money initially while learning the solution. Year after year, they can add value scope and cover more databases in their organization with high quality. We have been working with Imperva SecureSphere Database Security for about 10 years. I started working with this project about five years ago.
EO
Senior Solutions Architect at Cyber Knight Technologies FZ LLC
AI classification has transformed data visibility and now simplifies policy‑driven protection
In my opinion, what should be improved about Proofpoint Data Security Posture Management is that it is quite advanced. I think they should ease it up a bit. When it comes to setting of policies, I wish there were a single policy that deals with multiple channels of exfiltration instead of having to do multiple policies to deal with maybe data exfiltration through web upload, data exfiltration through USB, data exfiltration through print, copy and paste, and so forth. It would have been much easier if I had one policy, and then I could turn on the light for all of these different exfiltration channels. A critical example is saying I want to put up a PII policy that will secure social security numbers. That is the condition, social security number. Then in the same policy, I should be able to state that I want this to block exfiltration through USB. However, I want it to allow uploads through web or uploads to a particular website or URL. I want it to allow that kind of granularity where you can flick around things on the same policy. Currently, with Proofpoint Data Security Posture Management, you have to build multiple policies for different channels. Most importantly, the Boolean logic in their policies is incomplete. It just has the AND function. Boolean should carry AND and OR. I am saying if this data contains PII data OR PCI data—either of them—it flags either PCI or PII. But what it has now is AND. For it to fire or trigger, both must be triggered. So if somebody puts only one, maybe PII, and does not put PCI, then it does not trigger. It should have an OR, so that I can have multiple policies and then differentiate them so that if this OR this OR this, either of these triggers. I have flagged that and raised that as a concern to the product team. I expect additional features from them in the next release, specifically the OR feature for the conditions. However, I am happy with the agent, the lightweight agent, the amount of activities it captures. Beyond just the DLP, it looks at the sites and URLs you are going to, it looks at the file renaming, it looks at the attempt to uninstall, and it looks really deep even though it is user mode. I am happy with that. The Boolean logic is what I think is incomplete at the moment.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Qualys TotalCloud fulfills all these needs."
"The vulnerability management feature is the one I like the most because it provides a clear picture of all vulnerabilities."
"I would rate Qualys TotalCloud ten out of ten."
"TotalCloud has been excellent in providing us with immediate access to all the products and features we need, such as CSPM, TruRisk Insights, and compliance reports, including CIS and HIPAA."
"The best features in Qualys TotalCloud include the total asset management of the cloud environment. It is very easy to export the report and see the vulnerabilities related to the cloud specifically."
"The scalability is good as well. I would rate it ten out of ten."
"CSPM is currently the most used feature, and we are enjoying the new feature, FlexScan, which is valuable for Internet-facing VMs."
"Qualys TotalCloud's most valuable features are its security capabilities that help identify and mitigate risk factors."
"The most valuable feature is the automatic reports on new databases, which gives us up-to-date inventory management."
"Excellent ROI using the automated scans, especially comparing it to the manual method proposed by many vendors."
"The most valuable features of Imperva SecureSphere Database Security are the user-friendliness, easy-to-use interface compared to competitors, database operations do not need a specialist, and simple to manage for our security team. Additionally, the solution can show all the databases and the level of sensitivity. It can show what is more sensitive or less sensitive."
"The cyber intelligence feature is the most valuable."
"This tool helped us mitigate audit risks by 100 percent."
"The tool happens to be very intelligent when it comes to processing policies and sounding alerts. It allows us to implement policies and measure actions against them, raising alerts accordingly."
"It allows us to run models against it and do reports against it without understanding the different database technologies."
"All of Imperva’s features are extremely powerful, while a certain degree of knowledge is required to have a solid understanding of the product."
"It has helped my data security strategy very well because one thing is to set static DLP rules, however, how do you start setting rules when you have little or zero visibility as to where your critical or sensitive data resides?"
 

Cons

"Although TotalCloud is a helpful tool, some of its advanced features are still under development."
"One thing that could be improved is the user experience and navigation."
"Areas that need improvement in every solution include the remediation part. The remediation steps should be simple enough for everyone to understand."
"TotalCloud could improve its scanning of niche devices like Wi-Fi dongles and USB modems because they are often untested. It covers everything else, like laptops, mobile devices, and Bluetooth IoT devices. They can improve on the small IoT devices because hackers and testers use these."
"Two areas for improvement in Qualys TotalCloud are the speed of the public cloud platform and vulnerability detection."
"From a downside perspective, the UI is not user-friendly and feels dated compared to other tools like Prisma Cloud."
"To improve the user experience, reporting could be simplified for better comprehension by end users and project managers, facilitating issue resolution."
"TotalCloud could improve the classification of vulnerabilities. Specifically, it could enhance the categorization of what aspects fall under patches resolved by OS or software updates and what pertains to configuration adjustments."
"It is quite expensive. I would prefer a lower price."
"The support we get struggles a bit to provide solutions. They take additional time to respond to support requests."
"The GUI needs to be improved and made more user-friendly. This solution is a little complicated compared with other solutions for database auditing because of the GUI interface."
"The agent does not monitor databases in the containers."
"Most of the feedback I receive relates to clients wanting to see an improvement in the reporting. They like the ability and functionality of the solution but they feel the reporting is lacking."
"Imperva needs to improve their cloud capabilities."
"There is room for improvement in the firewall capabilities when it comes to additional features such as Traffic Shaping, Connection Pooling and Load Balancing."
"The development mode on the platform needs improvement."
"In my opinion, what should be improved about Proofpoint Data Security Posture Management is that it is quite advanced."
 

Pricing and Cost Advice

"Qualys TotalCloud is expensive, but it offers a premier solution with no headaches."
"As a middle management member, I do not have direct pricing knowledge, but based on the knowledge from our meetings, its pricing is competitive."
"Although Qualys TotalCloud is relatively expensive due to its unique automation features, its cost-effectiveness is rated an eight out of ten, with ten being the most costly."
"Qualys TotalCloud is expensive."
"Qualys TotalCloud offers competitive pricing given its comprehensive suite of features, including integration, assessment, remediation, and detection capabilities, all within a single platform."
"While Qualys TotalCloud's pricing is currently acceptable, it is becoming increasingly expensive and may soon be considered overpriced."
"I am not sure about the pricing. From what I understand, it is a bit on the higher side, but I do not have the exact numbers."
"Qualys TotalCloud is cost-efficient and was selected for its value compared to other products."
"The cost of support for this solution is very expensive."
"Imperva is too expensive for small and medium-sized enterprises. They're missing out on technology that helps them manage their data security better. Data security is essential because even the strongest network may be attacked from the inside without it."
"The pricing over-all depends on the entry level. For example, if support and maintenance are about $20,000 - $25,000, the initial cost can be five times more. It is less expensive for the company to maintain the client than to make the deployment."
"We have all the licenses, which we pay for annually. The price is a little high, but the product is good."
"The pricing is reasonable and competitive."
"It is very expensive."
"Imperva SecureSphere Database Security was quite expensive several years ago, but now they provide a subscription plan for licensing. It is available now for smaller and medium-sized companies, not only large enterprises."
"The setup and license are quite expensive."
Information not available
report
Use our free recommendation engine to learn which Data Security Posture Management (DSPM) solutions are best for your needs.
913,683 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Comms Service Provider
16%
Outsourcing Company
12%
Manufacturing Company
11%
Financial Services Firm
10%
Financial Services Firm
19%
Comms Service Provider
7%
Manufacturing Company
7%
Outsourcing Company
7%
Financial Services Firm
13%
Manufacturing Company
9%
Outsourcing Company
9%
Comms Service Provider
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business14
Midsize Enterprise5
Large Enterprise34
By reviewers
Company SizeCount
Small Business28
Midsize Enterprise9
Large Enterprise32
No data available
 

Questions from the Community

What needs improvement with Qualys TotalCloud?
In terms of improvement, remediation still belongs to the cloud team, which is one of the issues we faced with Qualys...
What is your primary use case for Qualys TotalCloud?
My main use case for Qualys TotalCloud is regarding the cloud visibility that we were not having previously. Previous...
How does IBM Guardium Data Protection compare with Imperva SecureSphere Database Security?
IBM Security Guardium Data Protection is a solution for database security from IBM that gives complete visibility, co...
What needs improvement with Imperva SecureSphere Database Security?
There are several aspects of the Imperva SecureSphere Database Security that could be improved or enhanced.There are ...
Ask a question
Earn 20 points
 

Also Known As

Qualys TotalCloud with FlexScan
Imperva SecureSphere Database Security, jSonar, Imperva's Data Security Posture Management
No data available
 

Overview

 

Sample Customers

Information Not Available
BlueCross BlueShield, eHarmony, EMF Broadcasting, GE Healthcare, Metro Bank, The Motley Fool, Siemens
Information Not Available
Find out what your peers are saying about Wiz, Palo Alto Networks, Varonis and others in Data Security Posture Management (DSPM). Updated: September 2026.
913,683 professionals have used our research since 2012.