IT Security Analyst & Engineer (Project, Remote) Australia-Europe at a manufacturing company with 10,001+ employees
Advanced protection has secured our websites and reduces DDoS and zero‑day attack incidents
Pros and Cons
- "Imperva Application Security Platform has positively impacted my organization by making the website more secure."
- "I would suggest that Imperva Application Security Platform should include new features combined with AI."
What is our primary use case?
My main use case for Imperva Application Security Platform is using it for web application firewall as the main objective for managing a web application that is handled by WAF in the company that my company is working for. Protecting all threats or attacks from the web application is the main objective of the WAF.
What is most valuable?
The best features Imperva Application Security Platform offers are for speed and protection. There is runtime and zero protection, and we have the sub and sub plus protection.
The speed and protection features of Imperva Application Security Platform help my team day-to-day by providing safe and clear access to the website. For example, my company is a multinational company that experiences many attacks, such as DDoS attacks, hitting the general website of the company before. The protection protects all of the websites in Imperva, so accessing the website is safer right now, not disrupted by DDoS attacks.
Imperva Application Security Platform has positively impacted my organization by making the website more secure. It reduces the DDoS attacks and reduces the attacks from threat actors, including SQL Injection and zero-day attacks, by using dynamic application profiling from Imperva. This is very helpful for my company as it reduces the incidents from the website.
What needs improvement?
I would suggest that Imperva Application Security Platform should include new features combined with AI. When I was using Imperva, it was not yet combined with AI. I believe that AI can now be used to make things easier, to track the attacks or IPs, or perhaps to determine the best configuration for each company that is using Imperva.
For how long have I used the solution?
I have been using Imperva Application Security Platform for three years.
Buyer's Guide
Imperva Application Security Platform
May 2026
Learn what your peers think about Imperva Application Security Platform. Get advice and tips from experienced pros sharing their opinions. Updated: May 2026.
893,221 professionals have used our research since 2012.
What other advice do I have?
I would add that I have a unique observation about the features of Imperva Application Security Platform. For protection to protect more safely and restrictively, I have another use case with an internal website. This website is internal, and those people who want to access it can use the VPN or the internal network. I have encountered cases where a person from the internal company wants to access the website without using the API and got blocked by Imperva because there is a feature or configuration that allows specific IPs. I had to log all of the ways to access the web and allow only a few IPs from the internal IPs. I think Imperva is very secure, very restricted, and good for protecting websites, especially for internal websites and production servers.
Regarding improvements to Imperva Application Security Platform, I think all aspects of Imperva Web Application Firewall, including the UI/UX, are good, and I can operate it smoothly with the application. I give this product a rating of 8.5 out of 10.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Apr 19, 2026
Flag as inappropriateIngeniero Preventa at Imperia
Strong protection has improved legacy app security and currently reduces risky server connections
Pros and Cons
- "Imperva Application Security Platform positively impacts us because we have a critical website, so by placing a WAF of Imperva's quality, it allows us to have visibility and granular control over the various attacks that can occur on the website."
- "Imperva Application Security Platform could be improved if it allowed integration with Active Directory in the cloud, or if it provided visibility of user roles and permissions."
What is our primary use case?
Imperva Application Security Platform is generally used for legacy-type applications that cannot be migrated to the cloud. A specific example of how I use this tool to protect legacy applications in my organization is that we have an intranet which has not been fully developed or technologically advanced enough to run in the cloud, so by having this, we secure it effectively.
What is most valuable?
Imperva Application Security Platform allows you to enhance your application security posture. Among the best features that Imperva Application Security Platform offers, the policies are very dynamic, and it also has profiling at the application level that allows you to work in this mode.
I would like to highlight especially the ThreatRadar feature, which is an additional subscription, and ThreatRadar helps with threat intelligence by allowing you to block advanced attacks as well as mitigate risks more effectively.
Imperva Application Security Platform positively impacts us because we have a critical website, so by placing a WAF of Imperva's quality, it allows us to have visibility and granular control over the various attacks that can occur on the website.
A concrete improvement I have seen thanks to Imperva Application Security Platform is that it has decreased the level of connections to the final server. The specific improvement is that the connections that reach the server are fewer because Imperva is already filtering them at the WAF stage.
What needs improvement?
Imperva Application Security Platform could be improved if it allowed integration with Active Directory in the cloud, or if it provided visibility of user roles and permissions.
For how long have I used the solution?
I have been using Imperva Application Security Platform for a little more than three years.
What do I think about the stability of the solution?
I consider Imperva Application Security Platform to be a stable solution.
What do I think about the scalability of the solution?
I would rate the scalability of Imperva Application Security Platform as very good since it adapts well and you can grow independently because the interfaces support one and ten gigs.
How are customer service and support?
Imperva Application Security Platform customer support has been very good; the ticketing platform allows us to have visibility of the case, and the staff makes the effort to respond quickly.
Which solution did I use previously and why did I switch?
I did not previously use any other solution before Imperva Application Security Platform.
How was the initial setup?
The advice I would give to others who are considering using Imperva Application Security Platform is to start with learning mode and then move to blocking mode slowly for approximately one week so that Imperva can identify the website and the connections that are made to it.
What was our ROI?
I have seen a return on investment with Imperva Application Security Platform, as it is generally associated with time savings, because the review of alerts and the visibility it gives saves us significant operational time. The clarification on time savings is that it refers to the time spent on alerts.
What's my experience with pricing, setup cost, and licensing?
My experience with the pricing, implementation cost, and licenses of Imperva Application Security Platform is that it is high compared to a traditional WAF solution, but it meets expectations.
Which other solutions did I evaluate?
Before choosing Imperva Application Security Platform, I did not evaluate other options, as we went directly with Imperva due to recommendations.
What other advice do I have?
I would rate Imperva Application Security Platform an eight on a scale from one to ten. Imperva Application Security Platform is a very good platform; even though it is not in Gartner, clients request it and trust the brand. I would rate customer support on a scale from one to ten as an eight. My overall review rating for Imperva Application Security Platform is eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Socio
Last updated: Apr 21, 2026
Flag as inappropriateBuyer's Guide
Imperva Application Security Platform
May 2026
Learn what your peers think about Imperva Application Security Platform. Get advice and tips from experienced pros sharing their opinions. Updated: May 2026.
893,221 professionals have used our research since 2012.
Cybersecurity Specialist at a healthcare company with 1,001-5,000 employees
Stronger application and API protection has reduced attacks and informed better security design
Pros and Cons
- "After moving to Imperva Application Security Platform, these attacks have been prevented significantly, and the attacks on the initial level have been considerably reduced."
What is our primary use case?
My main use case for Imperva Application Security Platform involves using it in more than a couple of organizations where I was employed.
We used Imperva Application Security Platform for web application firewall and API security in one of those organizations.
Since we integrate a number of external vendor products in our environment, most of these integrations occur via API, and hence we use Imperva Application Security Platform for API security.
What is most valuable?
Imperva Application Security Platform offers features such as Attack Analytics.
Attack Analytics has helped us understand what traffic is being received by our applications, and based on that, we have created the policies. The false positives have been reduced, saving a lot of time for us to work on other important tasks rather than wasting time on addressing those false positives.
Imperva Application Security Platform has considerably improved our web application security posture and it has also helped us design our applications with security as the primary concern. Before using Imperva Application Security Platform, we received many attacks, such as command injection attacks, SQL injection attacks, and even though we were using a niche web application firewall, we were not able to tackle those attacks. After moving to Imperva Application Security Platform, these attacks have been prevented significantly, and the attacks on the initial level have been considerably reduced.
What needs improvement?
We have not yet encountered any issues with Imperva Application Security Platform until now; however, improvements are always expected from the vendor. No major improvements are required, but it should still work on reducing the false positives. Although we do not receive that many false positives, some improvement is still required regarding learning the traffic while using Imperva Application Security Platform.
Nothing as of now because we have still not used all the features of Imperva Application Security Platform, but we are exploring it and in the future, maybe we will understand what improvements are required.
For how long have I used the solution?
I have been using Imperva Application Security Platform on-prem as well as in the cloud for almost four years.
What do I think about the stability of the solution?
Imperva Application Security Platform is quite stable.
What do I think about the scalability of the solution?
I do not have much experience with respect to the scalability of Imperva Application Security Platform because a different infrastructure team manages all these aspects; we, as a security team, are just using it for protecting our applications and APIs.
How are customer service and support?
I had an experience reaching out to customer support for an issue with Imperva Application Security Platform, and it was quite good; they addressed the issue effectively.
Which other solutions did I evaluate?
If anyone is concerned about API security, then Imperva Application Security Platform is definitely a good choice.
Imperva is a trusted brand, and I have been using Imperva Web Application Firewall on-prem and also as SaaS, but Imperva Application Security Platform is a next-generation cloud-based service that is quite helpful and powerful. Based on current attacks and the latest AI-based attacks, some improvement is required, but it remains a promising product that I would recommend to others.
What other advice do I have?
I would rate this product an 8 out of 10.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Apr 29, 2026
Flag as inappropriateSenior Technical Consultant at a tech vendor with 11-50 employees
Custom policies and rate limiting have strengthened our application security and compliance
Pros and Cons
- "We have seen a return on investment with Imperva Application Security Platform, as we started with a few devices and gradually increased the number of on-premises devices for Imperva Application Security Platform."
- "Imperva Application Security Platform could be improved by providing a more user-friendly dashboard."
What is our primary use case?
Imperva Application Security Platform is used primarily for web application firewall security. My organization has a significant number of applications running through the platform, and to monitor those applications, we require firewalls. Imperva Application Security Platform's Web Application Firewall performs the deep inspection necessary for this monitoring.
What is most valuable?
Imperva Application Security Platform offers customization of security policies, allowing me to create policies tailored to my environment.
The rate limiting policy in Imperva Application Security Platform works based on usage numbers and has proven valuable for our operations.
Imperva Application Security Platform is user-friendly, and I can maintain a customized dashboard to monitor the utilization of all gateways in day-to-day operations.
Imperva Application Security Platform serves as the base pillar for applications to grant or deny access appropriately.
From a compliance perspective, Imperva Application Security Platform has been an improvement, as it has passed all compliance processes.
What needs improvement?
Imperva Application Security Platform could be improved by providing a more user-friendly dashboard.
I would recommend that support for Imperva Application Security Platform be enhanced to be more effective.
For how long have I used the solution?
I have been using Imperva Application Security Platform for three years.
What do I think about the stability of the solution?
Imperva Application Security Platform is stable.
What do I think about the scalability of the solution?
Scalability in Imperva Application Security Platform depends on the region. Imperva Application Security Platform can handle more applications or increased traffic easily as my organization grows. Currently, we are running approximately 1000 applications, and it can handle more.
How are customer service and support?
Customer support for Imperva Application Security Platform is good, though it could be better. I would rate the customer support of Imperva Application Security Platform an eight on a scale of one to ten.
Which solution did I use previously and why did I switch?
I did not previously use a different solution.
What was our ROI?
We have seen a return on investment with Imperva Application Security Platform, as we started with a few devices and gradually increased the number of on-premises devices for Imperva Application Security Platform.
What's my experience with pricing, setup cost, and licensing?
The pricing, setup cost, and licensing for Imperva Application Security Platform were user-friendly and good.
Which other solutions did I evaluate?
What other advice do I have?
I would recommend Imperva Application Security Platform compared to Akamai WAF. It has been good to use Imperva Application Security Platform, as I have been using it for three years. I would rate this review a nine on a scale of one to ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Apr 19, 2026
Flag as inappropriateSecurity Software Engineer III at a computer software company with 10,001+ employees
Have noticed several areas that need improvement while some features are helpful during deployment
What is our primary use case?
I prefer not to do a review for EDR since it is a new product that I am using. Instead, I would like to review other products I have worked with before, such as Imperva products, Imperva Web Application Firewall, or Imperva DAM.
What is most valuable?
I worked as a consultant for the customer and was part of a design and deployment team for Imperva API Security.
What needs improvement?
Could you please describe the deployment process, initial setup process, and what challenges were faced?
What was my experience with deployment of the solution?
I would need to check with my manager and run this by the legal team in the US before I would be able to share this information.
What do I think about the stability of the solution?
Please repeat the question.
What do I think about the scalability of the solution?
That would be fine.
How are customer service and support?
The technical support team would be rated 5 out of 10, where 10 represents the best support and 1 represents very poor support.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I would prefer to receive the form via email so I can fill it out manually myself. Additionally, I want this review to be anonymous, with neither my name nor my company's name appearing anywhere.
How was the initial setup?
We can schedule a call in two hours to discuss this further.
What about the implementation team?
Please describe the deployment process, initial setup process, and what challenges were faced.
What other advice do I have?
I would need to check with my manager and run this by the legal team in the US before sharing more information. We can schedule a call in two hours to discuss this further.
Disclosure: My company has a business relationship with this vendor other than being a customer. partner
Last updated: Sep 12, 2025
Flag as inappropriatePrincipal Cyber Prevent and Defense Engineer at a comms service provider with 1,001-5,000 employees
Offers bot protection and DDoS Protection and protects public-facing portals
Pros and Cons
- "It works right out of the box once you integrate the application."
- "Support is one thing I wish Imperva could improve."
What is our primary use case?
We are primarily a customer for Firewall. We're also moving into the managed security space, but we are primarily a customer here.
So, it is primarily used for web application firewalls. Protecting web applications against application-layer attacks. There is advanced bot protection and DDoS Protection.
What is most valuable?
It's very simple to implement. It works right out of the box once you integrate the application. It does the learning for you and starts applying relevant signatures.
It's effective in protecting against different kinds of attacks. For example, it can mitigate DDoS attacks and block application layer attacks like SQL injection, HTTP, and cross-site scripting attacks. The latency is pretty low.
What needs improvement?
Support is one thing I wish Imperva could improve. They follow the phone model and keep rotating you from one customer service person to another. The layer one support isn't very clear about the workings of the product.
My feedback is primarily about Imperva Cloud, not on-premise. On-premise is a whole new story.
Support is the issue for Imperva Cloud. It's also a bit pricey. It's a premium service and very expensive. The licensing model is not very straightforward. Every feature is priced separately, and to enjoy maximum protection, you'll have to spend a lot of money. The licensing model is a bit complex, and each feature is very pricey. For example, API security and web application protection are two separate license packages.
For how long have I used the solution?
For WAF, I have been using it for about four years now.
What do I think about the stability of the solution?
The solution is generally stable, but there are sometimes where a link degradation does not involve a failover to another port where you're able to enjoy the service. So your availability is affected because of link degradation. It will not automatically take you to another port. But otherwise, it's generally stable.
What do I think about the scalability of the solution?
The capacity and everything is managed by Imperva. We don't really get to know much about the back end.
It does a good job because we have very busy applications that seem to work well without any issues. The only issue that we experienced recently is that if there's an issue on the uplinks, the traffic does not automatically fail over to another region or another POP. You're still directed to a POP where there's degradation in service. So, if you're affected, you'll have to bear the pain until the issue is resolved before you're able to access the services again. So, there's no automatic failover between POPs from one POP to another in the event of a link degradation along the path.
How are customer service and support?
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
We have tried out Radware as a POC just a couple of months ago. There is also Cloudflare .
I'd prefer Cloudflare because of its presence on the Internet, the number of services it offers, and the level of automation that it gives you.
I'd look up to Cloudflare because it's more stable. Because of its points of presence everywhere in the world, you're in a better place to enjoy better availability than being on Imperva.
And the level of protection from my test, I think it's pretty good. It's next-generation application firewall. So it's something that I look up to.
How was the initial setup?
The deployment was easy. We have quite a number of sites, more than 300. Per site, it can take about ten minutes to integrate, to move your application to the cloud, before you can achieve maximum protection or before you can achieve protection on your site. So, it's a very seamless process.
We had challenges integrating with our on-premise tools, our SIEM tools and SOAR tools. Integration is a bit complex. There's no capability to integrate with our on-premise tools, or if there is, it's very limited.
It's a SaaS service, so everything's maintained by Imperva. It's something that is managed by Imperva.
What was our ROI?
So, there is a return on investment in terms of achieving protection for our public-facing portals. We have seen quite a number of DDoS attacks being mitigated by Imperva. We have also seen a few web application attacks that have been blocked.
In terms of time savings, we don't have to go to the data center to do upgrades and other mundane things, so we can focus on more important things.
What's my experience with pricing, setup cost, and licensing?
The licensing model is a bit complex and very complicated model.
Which other solutions did I evaluate?
We operate a hybrid cloud and on-premise as well, and we're looking for a solution that would suit all of our needs. Right now, for API security, we don't have anything. But for others, for WAF, we do have something. We use Imperva as our WAF, for example.
We carry out research, which is the first step when we're looking to source a product. We do market research, obviously, and an assessment. So it starts with reviewing PeerSpot or what people say about different products, and then we call vendors in. They give us a demo. They give us a POC. Then, we draft the required set of requirements, and then we eventually pick a product based on what we need.
What other advice do I have?
AI functionality in Imperva does do quite a bit of learning, but Imperva can do more. There's little interaction. There's basically just the machine learning bit. So it basically baselines the application and then analyzes traffic towards the application. But in terms of capability to interact with large language models, that is still not at the level where the competitors are.
Overall, I would rate it an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Large account Manager at Softcell Technologies Limited
Enhanced network security with effective threat filtering and good bot managing features
Pros and Cons
- "The bot management features are very effective, as they help filter unwanted traffic using keywords."
- "Pricing can be improved, as it is quite expensive."
What is our primary use case?
We use Imperva DDoS protection to safeguard our network from multiple attacks. It is especially useful to protect websites or applications by redirecting traffic to eliminate threats.
How has it helped my organization?
Imperva DDoS increases our uptime to 99.99% by filtering and managing traffic to ensure only genuine traffic reaches our site. It optimizes and guides data centers to enhance network security.
What is most valuable?
The bot management features are very effective, as they help filter unwanted traffic using keywords. Imperva's ability to filter out non-genuine traffic provides a significant improvement to security and performance.
What needs improvement?
Pricing can be improved, as it is quite expensive. Additionally, support response times for emails can sometimes be delayed, which is an area that could use improvement.
For how long have I used the solution?
We have used Imperva DDoS for a couple of months.
What do I think about the stability of the solution?
On a scale of one to ten, I rate the stability at eight. It is quite stable, but there might be some room for it to be even better.
How are customer service and support?
Technical support is rated at seven out of ten due to sometimes delayed response times.
How would you rate customer service and support?
Neutral
How was the initial setup?
The initial setup is easy and quick to deploy.
What about the implementation team?
We typically handle the deployment ourselves, as we are partners and not the end customers.
What's my experience with pricing, setup cost, and licensing?
The pricing is rated a ten on a scale where ten is very expensive. The solution is only cloud-based and does not provide on-premises services.
What other advice do I have?
Imperva offers multiple services with a very high uptime guarantee of 99.99%. It is a valuable solution for network security.
I'd rate the solution eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Senior DevOps Consultant at a computer software company with 10,001+ employees
Helps to automate production but needs to improve its compliance and customer support
Pros and Cons
- "Imperva DDoS helps us automate production. The client had specific requirements for a cloud project in the financial sector."
- "We faced issues regarding compliance with client procedures. The client had strict compliance rules, and Imperva needed to be on a VM, while the client required containerization, causing a conflict. They went with Imperva for the on-premise version but shelved the cloud project due to too many blockers."
What is our primary use case?
My use case involved handling specific web applications for our operations team.
What is most valuable?
Imperva DDoS helps us automate production. The client had specific requirements for a cloud project in the financial sector.
What needs improvement?
We faced issues regarding compliance with client procedures. The client had strict compliance rules, and Imperva needed to be on a VM, while the client required containerization, causing a conflict. They went with Imperva for the on-premise version but shelved the cloud project due to too many blockers.
For how long have I used the solution?
I have been using Imperva DDos for six months.
How are customer service and support?
We tried to contact Imperva's technical support but encountered much resistance. I went through the front portal team on their website, but they wanted to know my client's name, which I couldn't disclose due to an NDA. They directed me to a sales guy who was only interested in selling and wasn't helpful.
How would you rate customer service and support?
Negative
How was the initial setup?
We faced challenges integrating Imperva DDoS. The biggest issue was the lack of a Terraform provider for the on-premise version, which was only for the cloud version. We used an API porting server as a stopgap, but I advised the client to discuss with Imperva about releasing a proper Terraform provider. We worked with Imperva DDoS for six months, but it was never fully deployed due to the organization's internal politics and compliance requirements.
What was our ROI?
Imperva DDoS is a web application firewall that protects against and mitigates threats. We aimed to shorten deployment times and deploy it in a scalable way using DevOps.
However, we faced challenges because Imperva only had a Terraform provider for the cloud version.
What other advice do I have?
I would rate the tool itself a five out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Integrator
Buyer's Guide
Download our free Imperva Application Security Platform Report and get advice and tips from experienced pros
sharing their opinions.
Updated: May 2026
Product Categories
Distributed Denial-of-Service (DDoS) Protection CDN Web Application Firewall (WAF) Bot Management API SecurityPopular Comparisons
Cloudflare One
Prisma Cloud by Palo Alto Networks
Cloudflare Web Application Firewall
Fortinet FortiWeb
Azure Front Door
Gigamon Deep Observability Pipeline
F5 Advanced WAF
Microsoft Azure Application Gateway
Buyer's Guide
Download our free Imperva Application Security Platform Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- F5 vs. Imperva WAF?
- Imperva WAF vs. Barracuda: Which One is Better?
- Which Web Application Firewall (WAF) would you recommend? R&S or Imperva?
- Can Imperva Bot Management protect against advanced bot threats, such as credential stuffing and content scraping?
- Can Imperva Bot Management protect against API attacks? Are APIs more susceptible to bot attacks?
- What is a zero-trust cybersecurity model and what would some of its key aspects be?
- We are looking at managed DNS providers and want to know what others are using
- Prolexic vs. Arbor Networks: How do they compare?
- How does a WAF help to protect against DDoS attacks?
- Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?













