What is our primary use case?
They provide end-to-end data security, so everything to do with applications, APIs, et cetera.
We've got a Telco client, and they'll be partnering with us to use the DDoS solution with their clients.
It's primarily for DDoS attacks. It's looking at anything that's trying to remove the ability of the company to operate, usually volumetric, however, since it's got a three-second SLA, it's better than the competition.
What is most valuable?
We can look after an entire what used to be a Class C network/24. Now, they could do single IP addresses, so they can protect a single IP address, and they have a three-second SLA to stop an attack. They back that up with a very large amount of money as well, so you've got a guarantee on it.
What needs improvement?
It’s hard to think of an improvement. The three-second service level agreement is already better than the competition.
You would ordinarily say something like API protection. However, they've got that with another product. It's not that DDoS protection does everything. It's that within their family of products, they've got a solution for everything. That's what I like about it, the whole integrated service. There’s nothing that’s missing in terms of features.
For how long have I used the solution?
We've been working with Imperva for about a year, and we've been working on a particularly big client at the moment as well.
What do I think about the stability of the solution?
The product is stable. It's resilient architecture. If one site is down for maintenance, then another site will take over the load.
What do I think about the scalability of the solution?
It's very, very scalable. They've just added a lot more capacity to it. It's something like six or nine terabytes per second of protection capacity, which is more than the biggest attack there's ever been by quite a margin.
How are customer service and support?
Technical support is very, very responsive. They're very good and they've got strength in depth. Across the world, they've got people. We deal with the local guys in the Netherlands, and they're pretty good.
How would you rate customer service and support?
How was the initial setup?
The setup itself is straightforward.
It's quite quick. It can be done as a reactive solution. Therefore, if somebody rings up and says I'm being attacked, we can get them onboard very quickly.
You only need one person to handle the deployment. It's all done virtually. We're working with the Telco and the Telco sends out the BGP VPNs and we just reroute traffic. It’s all very easy.
There's no maintenance as such apart from reports on traffic utilization. If you are using it as a continuous service, if you're running it continuously rather than just invoking it when there is a DDoS attack, then you get reports basically on your utilization of traffic and the types of traffic that you're transporting, et cetera. It helps you improve your security.
What about the implementation team?
We're doing the deployment for the client.
What was our ROI?
The ROI depends if you're being attacked or not. If you're the sort of organization that gets regularly attacked, then the ROI is extremely high as you could be down for quite some time with a DDoS attack. What usually happens these days is they don't have long attacks. They have very short attacks. However, the idea is to take down parts of the infrastructure to attack other parts. Therefore, it’s a diversion attack in many cases. Due to that, it's one of those products. It's very difficult to say what the ROI might be since it depends on what people are trying to do. However, it's the precursor to a lot of attacks.
What's my experience with pricing, setup cost, and licensing?
The solution is very affordable. It's based on the traffic utilization, the average traffic utilization, not the DDoS traffic. Therefore, if you're being DDoSed, you don't pay extra for the absorption of the DDoS traffic. It's purely based on your average traffic.
What other advice do I have?
We're an end-to-end Imperva partner. We're an Imperva reseller.
We're building an MSP at the moment, and it starts with a number of solutions. We then add on for those that have cloud exposure. We’ve added CloudWave DDoS and the API Protection and Bot Protection, and then for companies that have GDPR requirements, we've got the database side.
We use a cloud deployment with a variety of cloud providers. The telco, for example, is on the Equinix cloud. They're on a variety of data center sites. A lot of it is Equinix. I can't remember the name of the other providers, however, that's not relevant to us particularly since we are bringing in another Telco partner.
I’d rate the solution eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.