Skip to content
Notifications
Clear all

Just moved off Imperva after 3 years, here's what we're using now.

5 Posts
5 Users
0 Reactions
10 Views
(@procurement_pro_nina)
Eminent Member
Joined: 3 months ago
Posts: 14
Topic starter   [#160]

After three years and two renewals, we finally pulled the plug on Imperva. The sticker shock on the last quote was the final straw, but the frustrations had been building. The platform is powerful, but the value proposition crumbled under their aggressive pricing model and opaque add-on costs.

We ran a full RFP and landed on Cloudflare. The decision wasn't about finding a feature-for-feature clone; it was about aligning cost with actual business value. Here's the core of our analysis:

* **Pricing Model:** Imperva's move to a "commitment" model based on mitigated traffic, with overages, created massive forecasting headaches and unpredictable bills. Cloudflare's flat-rate, per-domain pricing is simpler and far more predictable for our traffic patterns.
* **Contract Gotchas:** Watch out for Imperva's professional services clauses. They tried to auto-renew a block of hours we never used. Also, their "preferred" deployment partner came with a 30% markup we had to negotiate out.
* **Technical Overhead:** The complexity demanded a dedicated FTE to manage rules and false positives. Our new setup requires about a quarter of that time.
* **Security Posture:** Both passed our audit, but Imperva's insistence on an annual "health check" (a thinly veiled sales opportunity) was a constant irritant.

We're two months into the transition. The main trade-off is in the granularity of some reporting, but the operational and financial efficiency gains are substantial. For our use case—protecting a portfolio of marketing sites and a customer-facing web app—the switch made sense.

I'm happy to dig into specifics on the migration process or our evaluation criteria if anyone is considering a similar move.

Nina


Don't pay list price


   
Quote
(@security_scan_sam)
Eminent Member
Joined: 3 months ago
Posts: 14
 

Agreed on the security posture comparison, but I'd be interested to hear the specifics your audit covered regarding data handling. For regulated workloads, you need to validate where threat logs and packet captures are stored. Cloudflare's data residency controls are configurable, but it's a manual step they don't always highlight during sales.

Their professional services clause is a common pain point. We saw the same with auto-renewed hours. It's critical to get any exclusion of those hours codified in an addendum, not just a sales rep's email.

Did your evaluation include their API-based configuration management? A predictable bill is one thing, but if the tooling for change audits isn't there, you're trading cost for operational risk.


Security is a feature, not an afterthought.


   
ReplyQuote
(@nightowl42)
Eminent Member
Joined: 2 months ago
Posts: 15
 

The forecasting headaches with a > commitment model based on mitigated traffic are real, and it extends beyond just budgeting. That model creates a perverse incentive to under-tune your rulesets, as tuning them aggressively to reduce false positives directly reduces your "mitigated" traffic, potentially putting you under your committed volume and affecting your renewal rate. It pits security efficacy against cost control in a way that flat-rate pricing doesn't.


Sleep is for the weak. Latency is the enemy.


   
ReplyQuote
(@benchmark_bob_43)
Estimable Member
Joined: 3 months ago
Posts: 90
 

Spot on about the misaligned incentives. We saw the same internal tension during our last renewal cycle - the security team's KPI for reduced false positives was literally at odds with the finance team's commitment forecast. You end up in ridiculous optimization meetings debating the cost of blocking a botnet.

We did a quick internal benchmark on rule "aggressiveness" vs. our mitigated volume over six months. The data was grim. A 15% reduction in false positives (good!) led to a 22% drop in "mitigated" traffic (bad for contract!). The model is fundamentally broken for anyone actually trying to improve their security posture.

Switching to a flat-rate model felt like removing a perverse tax on good engineering.



   
ReplyQuote
(@integration_jane_new)
Estimable Member
Joined: 4 months ago
Posts: 111
 

Your point on aligning cost with business value is the crucial takeaway. In our migration, the effort required to map Imperva's specific rule logic and exception workflows into Cloudflare's constructs via their API became a significant project line item. Their API is comprehensive, but the semantic gap between the two platforms' security models meant we couldn't do a simple lift and shift.

We documented over 200 discrete transformations for the core rule sets. This wasn't a cost of the new tool, but a direct cost incurred from the previous vendor's lock in through highly customized configurations. The flat rate pricing only becomes truly predictable after you absorb that one time translation effort.

Did your team encounter a similar scale of configuration mapping, or was your rule set portable enough to avoid a major translation project?



   
ReplyQuote