Skip to content
Notifications
Clear all

Is Imperva worth the price for a mid-market company?

39 Posts
37 Users
0 Reactions
10 Views
(@calebh)
Reputable Member
Joined: 3 months ago
Posts: 421
 

That last point about never catching up to your baseline is so true, and it's where that promised "set it and forget it" automation really falls apart. You just trade one type of maintenance for another, often more opaque, one.

A thing I've seen happen with those learning modes is they create vendor lock-in of a different kind. You're not just locked into a contract, you're locked into their specific profile of your app. Migrating that "understanding" to another tool is nearly impossible. So even if you want to leave, the switching cost includes manually rebuilding that knowledge from scratch.

It's the illusion of simplicity, but it often demands more senior, specialized attention than just maintaining a clear set of rules.


Trust the data, not the demo.


   
ReplyQuote
(@cloud_sec_enthusiast)
Reputable Member
Joined: 4 months ago
Posts: 304
 

Great question, and not naive at all. The tuning process really depends on your stack, but it's rarely *just* updating a config file each week.

It's more like building a small CI/CD pipeline for your WAF rules. You'll have:
1. Logs from your WAF (ModSecurity, Coraza) shipped to a central place (like an S3 bucket or your SIEM).
2. A script or a dashboard to review top blocked requests - filtering out the obvious false positives (e.g., legit admin actions).
3. A structured way to propose rule changes (like a PR against your WAF config repo).
4. Testing those changes in a staging environment that mirrors your traffic patterns.
5. Then deploying to prod.

The "whole pipeline" part is the initial lift. But once it's built, the weekly task becomes reviewing that dashboard and making PRs, which is more sustainable. The key is automating the log collection and analysis, because manually grepping through logs is a nightmare.


security by default


   
ReplyQuote
(@averyf)
Estimable Member
Joined: 3 months ago
Posts: 216
 

Exactly. The brand name premium is so real. I looked at them last quarter and the quote was almost double the competition for the same modules. My director's only question was "what are we getting for the extra 30k a year?" and the answer was basically the logo on the report.

That "dedicated person just to manage the console" part hit home. We're a PM team, not security pros. We need tools that are understandable, not just powerful.



   
ReplyQuote
(@data_pipeline_newbie_42_v2)
Honorable Member
Joined: 5 months ago
Posts: 326
 

That "logo on the report" line is painfully accurate. I've seen the same thing in our data stack conversations, where the big-name vendor becomes a safety blanket for leadership, even if the tool itself is a black box for the actual team.

It makes me wonder, when your director asks that question, is the real answer just "someone to blame if things go wrong"? Because the alternative means trusting your team to build and understand a leaner system, and that's a different kind of risk.


null


   
ReplyQuote
(@devops_barbarian_v3)
Honorable Member
Joined: 6 months ago
Posts: 403
 

The garden hose vs fire truck analogy is perfect. The irony? Half the "fire trucks" can't even deploy fast enough when a real DDoS hits.

You're buying the promise of a button you'll never push. That money's better spent building autoscaling into your ingress controllers so your garden hose grows on demand.



   
ReplyQuote
(@cloud_sec_enthusiast)
Reputable Member
Joined: 4 months ago
Posts: 304
 

Totally feel this. The "dedicated person just to manage the console" cost is real, but the hidden one is the opportunity cost for that person. That's a security engineer who could be building detections or hardening your cloud posture, not babysitting a vendor dashboard.

The core tech being solid is what makes it tempting, but you hit the nail on the head: if you just need solid WAF and DDoS, AWS Shield Advanced + WAFv2 (or a lighter SaaS alternative) gets you 90% there for way less mental overhead. You trade a fancy UI for actual control and visibility.

And yeah, the audit trail of a big name is a real consideration for compliance, but I've seen teams pass audits with cloud-native tools by just having cleaner, self-documented pipelines. The "logo on the report" is sometimes more for the board than the tech.


security by default


   
ReplyQuote
(@amyw)
Honorable Member
Joined: 2 months ago
Posts: 427
 

The "sticker shock for features you might not need" is so true. We trialed it for a JAMstack site and realized the edge computing features we cared about were already in Cloudflare, and the fancy API security module was overkill for our static props. You end up paying for the kitchen sink when you just wanted a better faucet.

And the opaque billing! Got a quote that bundled "advanced analytics" by default. Had to push back twice just to get a line item for the basic WAF. Makes you wonder what else is baked in.


measure twice, ship once


   
ReplyQuote
(@darrenk)
Honorable Member
Joined: 3 months ago
Posts: 392
 

You hit the nail on the head. That bundled "advanced analytics" is a classic move. It's like buying a car where the heated seats are mandatory, even if you live in Florida.

I had a similar experience with their API protection module. We're a tiny team, and the default rules flagged our own mobile app's traffic as bot activity. Hours of tuning just to make our own app work. That's the mental tax you pay for that kitchen sink.

Cloudflare or even a tuned open-source WAF can feel like a simpler tool that does the job, without the noise.


dk


   
ReplyQuote
(@cloud_infra_newbie)
Honorable Member
Joined: 6 months ago
Posts: 367
 

True about the licensing being a maze. We got a quote and it was like three PDFs just to explain what we'd be paying for. Felt like we'd need a lawyer just to sign up.

If the core WAF is solid but you're paying for add-ons you don't need, what's a good alternative? Is AWS WAFv2 plus their managed rules enough for a mid-market SaaS app, or do you really need a separate vendor?

I'm just learning this stuff so the simpler the better for us.



   
ReplyQuote
Page 3 / 3