No more typing reviews! Try our Samantha, our new voice AI agent.
Rodrigo Americo - PeerSpot reviewer
Security Enginner at a financial services firm with 1,001-5,000 employees
Real User
Top 5
Mar 21, 2026
Centralized visibility has improved cloud risk prioritization and ongoing compliance reporting
Pros and Cons
  • "Using Orca Security, I have visibility in our environment without depending on another team."
  • "Orca Security can improve the way that a customer can create auto-remediation without depending on support to do that."

What is our primary use case?

I use Orca Security to analyze misconfiguration and to alert our SOC team when a misconfiguration occurs in our environment so that we can open an incident and solve it.

For example, we have one alert that triggers when a security group is created and a resource is created and exposed to the internet without an ACL attached on the resource and with the security group allowing any IP from the internet to access the resource.

We have created some custom alerts, and we are trying to create some automatic remediation using Orca Security. However, we need to open a ticket to support Orca Security to inform them that we need it, and it will go to the development team, which is not ideal for us as a customer.

I use the risk score related to our vulnerability management program in Orca Security to analyze and prioritize how to fix issues and what we need to fix first. Any resources that have a risk score more than seven are critical for us, and we prioritize the fix accordingly.

I use Orca Security in our public cloud environment.

Using Orca Security, I have visibility in our environment without depending on another team. I can connect our AWS accounts and our cloud accounts directly on the platform, allowing me to see and analyze our environment automatically.

We use AWS, Azure, and GCP.

I find that using the AI search feature is particularly valuable, as you do not need extensive knowledge of the platform to identify resources and define what you need to find.

What is most valuable?

The vision related to security frameworks is very valuable for us, and we use that to be compliant with standards such as PCI DSS. The way to create dashboards is very useful for us as well.

It is easy for us to have one place to check things, and when we need to create some report for our teams or for another team, we use these compliance visuals to see what is compliant and what is not compliant.

What needs improvement?

Orca Security can improve the way that a customer can create auto-remediation without depending on support to do that. Perhaps creating one space to implement a script or to create the auto-remediation inside the platform without support would be beneficial.

For how long have I used the solution?

I have been using the solution for the last two years.

Buyer's Guide
Orca Security
July 2026
Learn what your peers think about Orca Security. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
908,800 professionals have used our research since 2012.

What do I think about the stability of the solution?

Orca Security is stable.

Which solution did I use previously and why did I switch?

We used the Prisma solution from Palo Alto in the past, and I believe we changed to Orca Security because of the price that Orca Security offered. However, that is not something that relates directly to me, so I am not certain about that.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Mar 21, 2026
Flag as inappropriate
PeerSpot user
CHINTAN MEHTA - PeerSpot reviewer
Cloud Security Automation Engineer at a financial services firm with 10,001+ employees
Real User
Top 5
Nov 22, 2024
Consolidating security tools with comprehensive cloud visibility
Pros and Cons
  • "The best features of Orca Security include its ability to perform a lot of security controls without requiring any installation of agents, making it very easy to set up."
  • "The documentation for Orca Security could be improved."

What is our primary use case?

We used Orca Security for Cloud Security Posture Management (CSPM), vulnerability assessment, and several other security controls, including Shimless Security. It helped us consolidate our security tools and provided a central view for organization-wide visibility.

What is most valuable?

The best features of Orca Security include its ability to perform a lot of security controls without requiring any installation of agents, making it very easy to set up. This feature allowed us to replace a lot of tools with one comprehensive platform, enhancing our ability to consolidate the security footprint on a large scale. 

It provided us with visibility from a central point, increasing our view from the previous thirty percent to a full one hundred percent of our cloud environment. This comprehensive view facilitated improvements in our security posture.

What needs improvement?

The documentation for Orca Security could be improved. The compliance framework also needs enhancements, especially concerning integrations with other tools like ServiceNow's vulnerability modules, which are not as mature as expected. 

It should also increase its capability to ingest data from other security tools like CloudSight for endpoint detection and provide real-time monitoring.

For how long have I used the solution?

I was an administrator of Orca Security in my previous organization for almost two years.

What do I think about the stability of the solution?

There were some stability issues in the initial months of using Orca Security, but overall, it has room for improvement and is rated seven out of ten.

What do I think about the scalability of the solution?

Orca Security's scalability is rated nine out of ten due to its challenge in scaling Kubernetes workloads, which require additional steps on top of connecting cloud accounts.

How are customer service and support?

The technical support has room for improvement. The expertise levels could be improved, and on a scale from one to ten, I rate the support as six or seven out of ten.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

We used several other tools before Orca, such as Microsoft Defender, Twistlock (Prisma Cloud), Rapid7, and AlgoSec. Orca Security replaced these by consolidating their functionalities into a single platform, which helped us save significant costs.

How was the initial setup?

The initial setup of Orca Security was easy. We started with the cloud accounts we already had visibility and control over, then presented its value to the organization.

What was our ROI?

Orca Security significantly improved our visibility from 30% to 100%, enabling better security posture improvements rather than just general cost savings.

What's my experience with pricing, setup cost, and licensing?

The cost of Orca Security is competitive compared to other market solutions.

What other advice do I have?

I would recommend Orca Security to other users and rate it eight out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Orca Security
July 2026
Learn what your peers think about Orca Security. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
908,800 professionals have used our research since 2012.
reviewer2593152 - PeerSpot reviewer
Senior Information Security Engineer at a computer software company with 10,001+ employees
Real User
Top 10
Nov 18, 2024
Detect vulnerabilities and compliance issues quickly with flexible filtering and visualization
Pros and Cons
  • "One of the valuable features of Orca Security is its design and options that allow flexible filtering and user-friendly visualization."
  • "I would rate the quality of support as nine stars out of ten due to their quick and helpful responses."
  • "Orca needs improvement in snoozing or dismissing specific alarms. Currently, snoozing dismisses all future vulnerabilities related to a CVE."

What is our primary use case?

We are using it for cloud security posture management to detect vulnerabilities, misconfigurations, threats, and malware in our cloud environment.

How has it helped my organization?

Orca has helped us reduce the time it takes to address cloud security alerts because of its risk-based calculation and immediate notifications for critical assets and popular vulnerabilities.

What is most valuable?

One of the valuable features of Orca Security is its design and options that allow flexible filtering and user-friendly visualization. 

Additionally, it covers a large scope of vulnerabilities, CVEs, malware, and misconfiguration. It also helps identify compliance issues in our cloud environments like AWS or GCP.

What needs improvement?

Orca needs improvement in snoozing or dismissing specific alarms. Currently, snoozing dismisses all future vulnerabilities related to a CVE. Another improvement is in handling alerts for multiple files with the same CVE; it should provide an option to manage each file separately without affecting others.

For how long have I used the solution?

I have been using Orca Security for around one year.

What do I think about the stability of the solution?

We have experienced some problems with the frontend, which occurred around three times a year, usually when updates introduced new lines of code that disrupted functionality.

What do I think about the scalability of the solution?

Scalability is automatically managed. When you onboard an organization, Orca will find new projects, folders, and resources without any additional effort required.

How are customer service and support?

I contacted support quite often, and they felt like family due to the frequency. I would rate the quality of support as nine stars out of ten due to their quick and helpful responses.

Which solution did I use previously and why did I switch?

I have used CrowdStrike before but was not happy with its features in the CSPM realm. Many of my friends in cybersecurity use Wiz and are pleased with it.

How was the initial setup?

Seventy percent of the deployment was completed successfully with documentation. However, we needed support from Orca for AWS onboarding. GCP was the easiest to onboard, followed by Azure, with AWS being the most challenging.

What's my experience with pricing, setup cost, and licensing?

Pricing is flexible, depending on the number of licenses, contract duration, and future plans. The initial price seemed high, however, after negotiation, the final price was ideal.

Which other solutions did I evaluate?

I evaluated CrowdStrike and have heard positive feedback about Wiz from peers.

What other advice do I have?

New users should have admin rights and follow Orca's clear documentation and web interface instructions for onboarding. 

It's rated eight out of ten for its overall performance.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer2618748 - PeerSpot reviewer
Vulnerability Assessment Analyst at a computer software company with 501-1,000 employees
Real User
Top 10
Dec 12, 2024
Seamless integration and side scanning optimize cloud security management
Pros and Cons
  • "Once our organization is configured, any cloud account under that organization is automatically detected in Orca Security, along with all the assets associated with it."
  • "I recommend Orca Security to others looking for a cloud security solution due to its seamless integration and side-scanning technology that does not hamper cloud asset performance."
  • "Orca Security could improve its ticket creation process."
  • "Orca Security could improve its ticket creation process. Currently, it allows for creating tickets in only one bucket, which requires monitoring to redirect tickets to the appropriate team."

What is our primary use case?

I am primarily using Orca Security for cloud security. Being part of the vulnerability management team, I utilize Orca Security for generating vulnerability alerts on cloud assets.

What is most valuable?

One aspect that stands out is the seamless integration. Once our organization is configured, any cloud account under that organization is automatically detected in Orca Security, along with all the assets associated with it. 

Another valuable feature is the side scanning technology using a snapshot mechanism. This technology allows for coverage of almost all cloud assets without interrupting their operations.

What needs improvement?

Orca Security could improve its ticket creation process. Currently, it allows for creating tickets in only one bucket, which requires monitoring to redirect tickets to the appropriate team. It would be beneficial to have segregation for different projects. 

Additionally, Orca Security could improve in reporting OS package vulnerabilities, such as missing MS patches or Linux patches.

For how long have I used the solution?

I have been using Orca Security for one year.

What do I think about the stability of the solution?

I would rate the stability as nine out of ten. I personally have not encountered any bugs or issues with the console. It runs almost 24/7.

What do I think about the scalability of the solution?

I would rate the scalability as nine out of ten. The seamless integration allows us to automatically reflect any connected project from our cloud into the console.

How are customer service and support?

I would rate customer service between eight and nine out of ten. The support team assists with issues and provides information on new updates, helping us understand the product better.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Previously, we used Rapid7 for vulnerability management. We switched because we moved from on-premises to the cloud, which required a cloud security solution.

What's my experience with pricing, setup cost, and licensing?

I am not sure about the pricing, as all decisions related to pricing and configuration were made by a different department.

What other advice do I have?

I recommend Orca Security to others looking for a cloud security solution due to its seamless integration and side-scanning technology that does not hamper cloud asset performance. It also offers automation for ticket creation directly from alerts.

I'd rate the solution eight out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Krishnakumar M - PeerSpot reviewer
enterprise architect at a tech services company with 1-10 employees
Real User
Top 5
Apr 10, 2025
Good threat intelligence and straightforward deployment
Pros and Cons
  • "The GUI features are very good. Threat intelligence is also very good."
  • "Orca Security has helped reduce the time it takes to address cloud security alerts."
  • "Orca Security can be improved as there should be some kind of central pane of glass. Similar to how cloud management works, Orca Security should have something comparable."

What is our primary use case?

Our clients use Orca Security for various reasons. We implement it for the clients.

How has it helped my organization?

Orca Security has helped reduce the time it takes to address cloud security alerts. It has reduced alerts by almost 30% to 40%. It was initially 300 alerts, and recently with one customer, it reduced to 30% to 40%, which is a good value add for this.

It takes approximately three to six months to see time to value.

What is most valuable?

The GUI features are very good. Threat intelligence is also very good. 

What needs improvement?

Orca Security can be improved as there should be some kind of central pane of glass. Similar to how cloud management works, Orca Security should have something comparable. They have something right now, but it is not fully developed. For example, if they have something similar to Palo Alto Panorama, it would be a great tool for their existing customers.

For how long have I used the solution?

I have approximately two years of experience working with this tool.

What do I think about the stability of the solution?

Orca Security is a very good solution. I consider it stable.

What do I think about the scalability of the solution?

Scalability doesn't really apply here because this is a posture management tool. At the end of the day, whether we have 10 servers, 50 servers, or even 500 servers in the form, we provide just one entry for Orca Security.

How are customer service and support?

I would rate technical support from Orca Security as very good. Orca Security is very good in this regard.

How would you rate customer service and support?

Positive

How was the initial setup?

Deployment is pretty easy. If you take professional services from them, you have to pay the money. If you do not need any professional services, or if there is any vendor for your organization, you can give it to that vendor. The vendor will deploy the tools for you. It is an easy tool.

Our clients are using a hybrid deployment model for Orca Security. Many customers are predominantly using the cloud. If the cloud is not there, a hybrid deployment is used.

What about the implementation team?

The customer asks us to implement Orca Security, and we deploy it based on their best practices.

What's my experience with pricing, setup cost, and licensing?

Its license is a bit expensive.

Which other solutions did I evaluate?

The decision is taken by the customer. Some customers go for it because it is in Gartner's Top 5 and has good reviews. They request us to deploy it. 

What other advice do I have?

We do not use Orca Security for cost optimization. We have different tools for that. 

I tried integrating it with ServiceNow, but I have not integrated it with any other solutions such as Cisco or Palo Alto. We are using it as a standalone service for every customer.

I would rate Orca Security a nine out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Works at Ultraviolet Cyber
Vendor
Top 20
Dec 18, 2024
Maximize cloud security management with effective CIEM and CDR features
Pros and Cons
  • "I find Orca Security's CIEM feature invaluable, as it focuses on entitlement and posture management, identifying assets with older OS versions, and asset misconfiguration."
  • "A notable limitation with Orca Security is its scanning feature. The automatic scan only runs every 24 hours, and if an alert is remediated within an hour, it still remains until the next scheduled scan."

What is our primary use case?

I use Orca Security as a CSPM tool primarily for cloud security and posture management. I utilize its CIEM and CDR features extensively. CIEM focuses on cloud infrastructure and entitlement management, and CDR deals with cloud detection and response.

What is most valuable?

I find Orca Security's CIEM feature invaluable, as it focuses on entitlement and posture management, identifying assets with older OS versions, and asset misconfiguration. 

The CDR feature is also critical, focusing on detection and response, triggering alerts like brute force attacks and malware. It provides alert and asset details, which include multiple remediation actions. It combines functionalities of multiple security tools and collects alerts and logs from them.

What needs improvement?

A notable limitation with Orca Security is its scanning feature. The automatic scan only runs every 24 hours, and if an alert is remediated within an hour, it still remains until the next scheduled scan. A more frequent or on-demand scanning option might mitigate this issue.

For how long have I used the solution?

I've been using Orca Security for one and a half years.

What do I think about the stability of the solution?

The stability of Orca Security is satisfactory, and I would rate it nine out of ten. I have experienced very little downtime.

What do I think about the scalability of the solution?

Orca Security is highly scalable, and I would rate its scalability as eight to nine. I have observed minimal downtime.

How are customer service and support?

I have had experiences where I needed to contact Orca support to address issues with alerts that remained active even after remediation. Based on my interactions, I would rate the support team a six out of ten.

How would you rate customer service and support?

Neutral

What's my experience with pricing, setup cost, and licensing?

Orca Security's pricing is known to be a bit high, however, I'm not directly involved in that aspect.

Which other solutions did I evaluate?

I have not used any alternatives to Orca Security.

What other advice do I have?

I would rate Orca Security overall as eight out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Cédric Thian-Meng - PeerSpot reviewer
Presales Security Engineer / CSM at Cybersel Group
Real User
May 12, 2024
It contacts your account provider and fetches metadata, eliminating the need for snapshots or reserved space to copy client infrastructure
Pros and Cons
  • "Orca Security has patented technologies. It's an agentless solution, so you don't need to install an agent. Instead, it contacts your account provider and fetches metadata, eliminating the need for snapshots or reserved space to copy client infrastructure."

    What is our primary use case?

    We use the solution to show misconfiguration. Often, users lack knowledge about their assets' fingerprints and their cloud provider's configurations.

    What is most valuable?

    Orca Security has patented technologies. It's an agentless solution, so you don't need to install an agent. Instead, it contacts your account provider and fetches metadata, eliminating the need for snapshots or reserved space to copy client infrastructure.

    The multi-cloud capability displays essential information and potential vulnerabilities with granular detail. For instance, it identifies paths that attackers might exploit to gain root or admin access to machines.

    It is comprehensive, covering a wide range of software needs. They also integrate with CI/CD pipelines, enabling developers to ensure security from the early stages of code deployment. This integration provides a 100% guarantee on security, safeguarding images, configurations, and other crucial information throughout the development process.

    What needs improvement?

    The company is managed by industry veterans. It's a cloud-based product. They handle misconfigurations and analyse your runtime to detect malware. They're at the forefront regarding developer security. The platform is vast, inundated with information. One can easily feel overwhelmed by the sheer volume of data.

    The solution is very detail-oriented, which can be overwhelming for nontechnical people.  On the other hand, understanding the security posture is very valuable for a technical person. 

    For how long have I used the solution?

    I have been using Orca Security for a year.

    What do I think about the scalability of the solution?

    If you choose the traditional or legacy option, you'll have to install an agent. Agents don't scale well. You can't effectively scale with agents because it requires manual intervention on each machine, consulting the agent, and it's not scalable because you'll need to reproduce that process. With Orca, we employ scanning technology, avoiding all the workload of installing agents. And then you can scale very quickly, in just a couple of moments. You can basically scale quickly without the need for those interventions.

    How are customer service and support?

    Support is fairly prominent. They have knowledgeable people.

    How was the initial setup?

    The initial setup is straightforward and takes five minutes to complete.

    What's my experience with pricing, setup cost, and licensing?

    The ticket is quite expensive; it depends on which way you want to go. If you want to buy the licence on your own, you can opt for MSP licences where people are going to run a managed service. If you're going in, "I've got no time and no resources to do that," you can use managed service. We manage, we run the scan, and we work on the information on the findings. It's very different from other cloud solutions. Company A is in front of a company in Portugal, and they are linked together. It's a subsidiary. Orca will allow you to get your asset inventory very quickly which is quite expensive.

    What other advice do I have?

    Orca is a SaaS solution. It is deployed on cloud but you can have it on prem as well. It works with all cloud providers.

    All vendors are offering a primary solution for free. You might need to consider Orca for a certain number of workloads like VM, a server, or even a phone.

    Orca is very intuitive and offers a lot of features. You can click on it, and you can see it all. The proper way is to go through an integrator or reseller; that's called the retail side. Before you take any action, call the retailer and ask them for a demo, in order for you to understand. If you start tomorrow and buy Orca, if you never call those guys, it's going to be a little bit difficult for you. You need someone who's trained to explain and show you around the platform.

    Overall, I rate the solution a nine out of ten.

    Which deployment model are you using for this solution?

    Public Cloud
    Disclosure: My company has a business relationship with this vendor other than being a customer. Partner/Reseller
    PeerSpot user
    Cloud Security Contractor at TripAdvisor
    Real User
    Jan 15, 2024
    Quick and easy setup and helps comply with various security frameworks and strengthens overall security posture
    Pros and Cons
    • "The reporting and automated remediation capabilities are valuable to me. They're real game-changers."
    • "I would like to see better customization options for security frameworks and better integration with reporting tools like Power BI or Grafana dashboards."

    What is our primary use case?

    I mainly use it as a posture management tool to comply with security frameworks like CIS and NIST, strengthening my overall security posture.

    What is most valuable?

    The reporting and automated remediation capabilities are valuable to me. They're real game-changers.

    What needs improvement?

    Maybe better customization options for security frameworks and better integration with reporting tools like Power BI or Grafana dashboards. Modularizing reports and dashboards would be fantastic. Simplifying the way users build custom frameworks would be good.

    For how long have I used the solution?

    I have been using this solution for one year.

    What do I think about the stability of the solution?

    No issues at all! It's been quite stable and reliable.

    What do I think about the scalability of the solution?

    It is a very scalable solution. It supports all three major cloud providers and is designed for easy deployment. So, from my perspective, it's highly scalable.

    How are customer service and support?

    The customer support was not good. It really depended on who you got assigned to. Overall, I'd say it was decent, not perfect, but definitely helpful.

    How would you rate customer service and support?

    Neutral

    Which solution did I use previously and why did I switch?

    We also looked at Lacework and CrowdStrike. The main problem with Lacework was the pricing model. It was based on capacity, and with our ever-growing environment, the costs became unsustainable.

    The features, ease of integration, and compatibility with all our security frameworks swayed us towards Orca.

    We migrated everything to Orca and haven't looked back.

    How was the initial setup?

    The initial setup is very easy. I would rate my experience with the initial setup a ten out of ten, where ten is easy to set up.

    What about the implementation team?

    I managed it all by myself. We had some support from Orca at the time, but the process itself was very easy. The whole setup, from initial discussions with Orca and setting up our own environments, was only about two to three days.

    What was our ROI?

    It is worth the money we are paying for it.

    What's my experience with pricing, setup cost, and licensing?

    It's not as expensive as some competitors like Prisma Cloud, but it's not the cheapest either. A subscription model based on AWS usage would be an interesting option to explore.

    What other advice do I have?

    Users can meet all the needs around security, automation, customization, and reporting. Orca is a feature-rich tool, easy to use, and seamlessly integrates with major cloud providers.

    It offers comprehensive visibility not just from a security standpoint but also for management and high availability. That's my key advice.

    Overall, I would rate the solution a ten out of ten.

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    reviewer2201862 - PeerSpot reviewer
    Information Security Engineer at a university with 1,001-5,000 employees
    Real User
    Top 5
    Jun 13, 2023
    User-friendly and efficiently identifies and addresses internal vulnerabilities
    Pros and Cons
    • "Orca Security has updated its interface, making it more user-friendly. I find it particularly useful as it allows me to easily navigate the dashboard and prioritize actions based on severity and criticality."
    • "The interface can be a bit cranky and sometimes takes a lot of time to load."

    What is our primary use case?

    I've been working on this cloud security platform for the past one and a half years. Essentially, we focus on checking different components of AWS and Azure

    We check over containers, instances, and various other elements running in the cloud. Our work is specifically designed for the cloud environment. We identify and address internal vulnerabilities across applications and operating systems which we are using in the cloud. 

    If there are any patch management requirements, we ensure they are done across different applications and even API interfaces. 

    In summary, our goal is to maintain security settings across the cloud infrastructure, such as AWS and Azure, used by our company. We connect with the DevSecOps team to actively work on securing the cloud environment and remediate vulnerabilities. We make sure incidents are properly handled, and necessary updates are implemented without causing disruptions. To facilitate communication, we use SMS for incident closure. This has been our focus for the past year.

    How has it helped my organization?

    Previously, we had a hybrid model where we used both physical devices and VMs across the cloud to manage enterprise security solutions. With Orca Security, we have a specific solution that allows us to monitor internal vulnerabilities and the most exploitable ones across the cloud. This platform is dependable and includes a powerful AI engine that we are currently using. 

    It helps us identify and address vulnerabilities early on, including CPU weaknesses and other variations. Additionally, it provides remediation guidance and facilitates patching and updates. Furthermore, it gathers threat intelligence, which is beneficial during incidents.

    What is most valuable?

    Recently, Orca Security has updated its interface, making it more user-friendly. I find it particularly useful as it allows me to easily navigate the dashboard and prioritize actions based on severity and criticality. 

    This feature makes it easy for me to look at prototypes and determine the necessary steps to take, focusing on critical issues first. I love the interface dashboard.

    What needs improvement?

    I would say that there are some loading issues. Since this is a cloud-native platform, there may be a problem with connecting to the dashboard as soon as it's open. The interface can be a bit cranky and sometimes takes a lot of time to load. So, the way APIs are deployed for our dashboards or monitoring systems needs to be corrected and optimized.

    In future releases, Orca Secure needs to have new integrations with different security solutions apart from the cloud. We have EDRs, XDRs, and MDRs. Orca Security should automate the process of connecting and integrating with these solutions. It can be an essential way of protecting the infrastructure in an effective manner.

    For how long have I used the solution?

    I have been using Orca Security for the last two years. 

    What do I think about the stability of the solution?

    I would rate the stability of Orca Secure a nine out of ten. 

    What do I think about the scalability of the solution?

    I would rate the scalability of Orca Secure a nine out of ten. 

    What about the implementation team?

    We directly bought this product from Orca Security itself, so we did not use any third party to install or deploy it.

    What was our ROI?


    What's my experience with pricing, setup cost, and licensing?

    The price is a bit expensive for smaller organizations. It can be expensive for smaller organizations, but if you are managing your infrastructure in the cloud, it's definitely worth trying.

    We have certain subscriptions and licenses for around a thousand instances deployed across the cloud. We purchased the subscriptions for the necessary devices we are running. It has cost us a lot.

    What other advice do I have?

    I would definitely recommend using Orca Secure. It's a very good cloud security platform. Apart from what I've seen, it has a really extensive dashboard and analysis capabilities. It picturizes actual vulnerabilities and provides guidance for remediation. It's a valuable cloud security evaluation tool, and I would suggest it as the first thing to learn.

    Overall, I would rate the solution a solid nine out of ten. 

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Rooshan Naeem - PeerSpot reviewer
    Security Engineer at Eon Health
    Real User
    Dec 20, 2022
    Effective automated scanning capabilities, low maintenance, and scales well
    Pros and Cons
    • "The most valuable feature of Orca Security is the automated scanning tool, user-friendliness, and ease of use."
    • "The solution could improve by making the dashboards more elaborative and more descriptive."

    What is our primary use case?

    We are using primarily Orca Security for our vulnerability assessment management. We are using it for our container it does free image scanning to find security loopholes that might be present in our overall infrastructure. Additionally, it provides the remediation steps and an overall overview of the security of our infrastructure.

    How has it helped my organization?

    This solution has helped out organizations by recognizing security threats and vulnerabilities in the early stages of software development. That is one of the benefits that we are receiving from the tool. We are dealing with security loopholes and deficiencies in the earlier stages of our development.

    We have the time to review the whole process and Orca Security provides security solutions to our clients. The solution has been beneficial for us to detect security loopholes in our early stages.

    What is most valuable?

    The most valuable feature of Orca Security is the automated scanning tool, user-friendliness, and ease of use.

    What needs improvement?

    The solution could improve by making the dashboards more elaborative and more descriptive.

    For how long have I used the solution?

    I have been using Orca Security for approximately two years.

    What do I think about the stability of the solution?

    The stability of Orca Security is good.

    What do I think about the scalability of the solution?

    Orca Security is scalable. We have 25 users using the solution in my organization.

    How are customer service and support?

    I have used the support a couple of times when we escalated some queries regarding the report formatting and the false positive.

    Most of the time whenever we open a support ticket to their technical department the response time is quite high because we are dealing with frequent deployments. We expect them to respond within one or two days but they take quite a long time to respond back.

    I rate the support from Orca Security a six out of seven.

    How would you rate customer service and support?

    Neutral

    Which solution did I use previously and why did I switch?

    We used to use an open-source vulnerability management tool from OWASP regarding the guidelines that they had listed on their own site using management systems, such as REM, CS, and CVSs, which is a risk management framework. We were using those frameworks for our vulnerability assessment and management.

    Orca Security is an enterprise solution, it scales well with your own infrastructure. We thought that the use cases covers and were aligned with our use cases, and this is why we switched.

    How was the initial setup?

    The initial setup of Orca Security is straightforward. I do not know how long the deployment took, but it is quite intensive, responsive, and has low latency.

    I rate the initial setup of Orca Security an eight out of ten.

    What about the implementation team?

    The implementation of the solution was done in-house.

    What's my experience with pricing, setup cost, and licensing?

    We have a total of 25 licenses for this solution. The solution is on a pay-and-you-use model.

    What other advice do I have?

    The vendor handles the maintenance of the solution, such as patches, and different enhancements.

    Every organization has its own needs and requirements, and configuring a tool with customization depends on the use case of the current organization. It is not a solution for all organizations. If you are dealing with small projects you don't need to switch to this enterprise solution. The usage of this solution depends on the organization's needs and requirements, another solution might be better.

    I rate Orca Security an eight out of ten.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Buyer's Guide
    Download our free Orca Security Report and get advice and tips from experienced pros sharing their opinions.
    Updated: July 2026
    Buyer's Guide
    Download our free Orca Security Report and get advice and tips from experienced pros sharing their opinions.