Try our new research platform with insights from 80,000+ expert users

Pros & Cons summary

Buyer's Guide

Get pricing advice, tips, use cases and valuable features from real users of this product.
Get the report

Prominent pros & cons

PROS

Orca Security provides comprehensive visibility into cloud environments, offering insights that surpass previous security tools.
SideScanning technology allows seamless security management without performance impact, requiring only account permissions.
The platform features automated scanning and vulnerability management without the need for agent installation.
Orca Security offers robust Cloud Security Posture Management from AWS to Azure with powerful API query capabilities.
The PCI DSS compliance report and patented agentless technologies enhance security control implementation.

CONS

Orca Security needs more automatic remediation options, such as scripts for server hardening that are context-aware.
Orca Security should focus more on comprehensive compliance, not just endpoint compliance, and include external environment scanning.
Orca Security's scope could broaden to improved anti-malware detection, alerting, and code-level security checks.
Orca Security can enhance collaboration with third-party vendors, allowing for the provision of sanitized results and better reporting tool integration.
The scanning feature of Orca Security could be improved, as automatic scans run only every 24 hours, leaving remediated alerts visible until the next schedule.
 

Orca Security Pros review quotes

reviewer1694079 - PeerSpot reviewer
CISO at a tech services company with 501-1,000 employees
Oct 15, 2021
The visibility Orca provides into my environment is at the highest level... When I dropped them into the environment, from the very get-go I had more insight into the risks in my environment than I had had during the entire two and a half years I had been here.
reviewer1696863 - PeerSpot reviewer
CISO at a media company with 201-500 employees
Nov 11, 2021
Orca's SideScanning is the biggest feature. It's the 'wow' factor... With Orca's SideScanning, they just need permissions for your account and that makes it so simple.
reviewer1697910 - PeerSpot reviewer
Chief Risk Officer at a financial services firm with 51-200 employees
Oct 21, 2021
Orca provides X-ray vision into everything within the cloud properties, whereas normally, this would require multiple tools.
Learn what your peers think about Orca Security. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,082 professionals have used our research since 2012.
JJ
CISO at Lemonade Inc.
Oct 24, 2021
Orca's dashboard is excellent. My team needs to be able to focus on specific areas for improvement in our cloud environment. And most recently, we've started to get good use out of sonar, the search capabilities, and the alert creation.
TS
Chief Security & Trust Officer at SiSense
Oct 26, 2021
With its Cloud Security Posture Management capability, we have the ability to read across all of our cloud-based environments, which includes AWS and Azure. We have visibility into those environments. Seeing all vulnerabilities and configurations is really powerful for us, but ultimately, the ability to use the API to query across the fleet to understand what is the current state, what is the patch level, which ones are potentially exposed for a new CVE that just came out is even more valuable. It allows us to gather really specific intelligence through simple queries.
reviewer1729920 - PeerSpot reviewer
Co-founder at a tech services company with 1-10 employees
Nov 29, 2021
Orca's platform provides an agentless data collection facility that collects information directly from the cloud using APIs, with zero impact on performance.
reviewer1731741 - PeerSpot reviewer
CISO at a financial services firm with 51-200 employees
Nov 30, 2021
There are so many valuable features that I could list, but one that I appreciate is the PCI DSS compliance report.
MH
Chief Technology Officer & Chief Information Security Officer at BeyondTrust
Dec 8, 2021
The vulnerability management does not require network scanning or agent technology, so I don't need to modify any of my products in order to do vulnerability assessments.
Shahar Geiger Maor - PeerSpot reviewer
CISO at a recruiting/HR firm with 11-50 employees
Jan 25, 2022
Orca gives you great visibility into your assets. It shows you the issues and the things that you need to attend to first, by prioritizing things. You can see a lot of information that is not always visible, even to DevOps, to help you know about the machines and their status. It's very easy to see everything in a single dashboard. That makes it a very useful tool.
Rooshan Naeem - PeerSpot reviewer
Security Engineer at Eon Health
Dec 19, 2022
The most valuable feature of Orca Security is the automated scanning tool, user-friendliness, and ease of use.
 

Orca Security Cons review quotes

reviewer1694079 - PeerSpot reviewer
CISO at a tech services company with 501-1,000 employees
Oct 15, 2021
There were a couple of times when Orca was down when I was trying to access it. I work strange hours because all of my team is in the UK right now. It was 2 a.m. on a Saturday and I was trying to log in but it wasn't working. But relative to my other security tools, Orca is definitely the most stable that I've seen.
reviewer1696863 - PeerSpot reviewer
CISO at a media company with 201-500 employees
Nov 11, 2021
I would be happy if they offered more automatic remediation options. They're working on that, but the more the better. For example, if they want you to harden a server, they would offer a hardening script that would be more aware of what's going on.
reviewer1697910 - PeerSpot reviewer
Chief Risk Officer at a financial services firm with 51-200 employees
Oct 21, 2021
As with all software, the user interface can always be made simpler to use. It would be helpful for people with very little knowledge, like somebody sitting behind the SOC, to allow them to be able to drill down into things a little bit easier than it is currently.
Learn what your peers think about Orca Security. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,082 professionals have used our research since 2012.
JJ
CISO at Lemonade Inc.
Oct 24, 2021
I think Orca could give me more alerts. It could give me a dashboard with all the specific types of alerts I want to see for the day. It should just be one click.
TS
Chief Security & Trust Officer at SiSense
Oct 26, 2021
They can expand a little bit in anti-malware detection. While we have pretty good confidence that it's going to detect some of the static malware, some of the detections are heuristics. There could be a growth in the library from where they're pulling their information, but we don't get a lot of those alerts based on the design of our products. In general, that might be an area that needs to be filled since they offer it as a service within it.
reviewer1729920 - PeerSpot reviewer
Co-founder at a tech services company with 1-10 employees
Nov 29, 2021
I would like to see an option to do security checks on a code level. This is possible because they have access to all of the code running in the cloud provider, and combining their site-scanning solution with that would be a nice add-on.
reviewer1731741 - PeerSpot reviewer
CISO at a financial services firm with 51-200 employees
Nov 30, 2021
We are PCI DSS compliant, so we need to scan our environment externally with tools vetted by the PCI DSS organization. Orca doesn't scan the environment externally. It only scans what's currently in the cloud.
MH
Chief Technology Officer & Chief Information Security Officer at BeyondTrust
Dec 8, 2021
In the future, I'd like to see Orca work better with third-party vendors. Specifically, being able to provide sanitized results from third parties.
Shahar Geiger Maor - PeerSpot reviewer
CISO at a recruiting/HR firm with 11-50 employees
Jan 25, 2022
The main drawback in an agentless approach is that if the solution detects a virus or malware in the environment, we need to manually remove it. But from my experience with other production environments, it's not straightforward to install agents in the hope they will automatically remediate viruses, even from production environments... Ultimately, the ability to auto-remediate is something that I would like to see.
Rooshan Naeem - PeerSpot reviewer
Security Engineer at Eon Health
Dec 19, 2022
The solution could improve by making the dashboards more elaborative and more descriptive.