Skip to content
Notifications
Clear all

Did you see the pricing change for CloudGuard Posture Management?

1 Posts
1 Users
0 Reactions
33 Views
(@cost_cutter_ray)
Honorable Member
Joined: 4 months ago
Posts: 492
Topic starter   [#20333]

I have been conducting a detailed cost-benefit analysis for a client considering the implementation of Check Point CloudGuard Posture Management across their multi-cloud environment (AWS and Azure). During my most recent review of their published pricing documentation, I observed a significant and, in my professional opinion, somewhat opaque shift in their pricing model that I believe warrants community discussion.

Historically, the pricing for CloudGuard Posture Management was relatively straightforward, based on a per-asset, per-hour consumption model, with clear definitions for what constituted an "asset." The new model, as I interpret it, has migrated to a **"Protected Resource"** based structure. While on the surface this may seem like a semantic change, the devil, as always, is in the contractual and technical definitions.

My primary concerns, from a FinOps perspective, are as follows:

* **Definitional Ambiguity:** The term "Protected Resource" appears to be broadly defined and can encompass everything from a single cloud account and a virtual machine to a container cluster or a serverless function. This creates a scenario where cost prediction becomes challenging. A single "resource" in business logic (e.g., an ECS cluster) could be counted as multiple "Protected Resources" by the scanning engine.
* **Cost Scaling Volatility:** In a modern, dynamic environment utilizing auto-scaling groups or Kubernetes, the number of "resources" can fluctuate wildly within a single billing period. Under a per-hour model, this is manageable. Under a per-resumbered model, a short-lived scaling event could lead to a disproportionately large bill, as net-new resources are scanned and counted.
* **Lack of Granular Billing Data:** For effective chargeback and showback, we need line-item clarity. If the billing is based on an aggregated count of "Protected Resources," it becomes exceedingly difficult to attribute costs to specific business units or projects, breaking a core FinOps principle.

I am attempting to model the Total Cost of Ownership (TCO) and need concrete data. Has anyone performed a comparative cost analysis between the old and new models with real-world infrastructure? Specifically:

* What was your experience with the mapping of actual cloud assets (e.g., an AWS account with 100 EC2 instances, 3 RDS databases, and 2 Load Balancers) to the "Protected Resource" count?
* Are there any published, detailed technical guidelines on how the resource counting is performed per cloud service (AWS IAM roles, Azure Key Vaults, GCP Pub/Sub topics)?
* Has Check Point provided any tools or APIs to forecast monthly "Protected Resource" counts based on existing cloud inventory?

The value proposition of a CSPM tool is undeniable for security posture, but its cost must be predictable and justifiable. A move from a transparent consumption model to a bundled resource model often results in higher costs for mature, optimized cloud environments. I am concerned this change may disproportionately impact larger, more dynamic organizations.

- cost_cutter_ray


Every dollar counts.


   
Quote