Skip to content
Notifications
Clear all

Reaction: Their new "client-side protection" - anyone testing it?

1 Posts
1 Users
0 Reactions
2 Views
(@cost_analyst_liam)
Reputable Member
Joined: 3 months ago
Posts: 146
Topic starter   [#10149]

Having observed the recent announcement from Imperva regarding the expansion of their portfolio into client-side security, I felt compelled to initiate a discussion focused specifically on the financial and architectural implications of this new offering. While the marketing materials emphasize the threat protection aspects—which are undoubtedly critical—my primary lens is on the cost structure and operational overhead it introduces, especially for organizations already managing a complex web of cloud and CDN expenses.

My initial analysis, based on the published documentation, suggests this is not a simple feature toggle on existing Application Security plans. It appears to be a layered service, which inherently raises several questions for those of us tasked with cloud cost governance:

* **Pricing Model Nuance:** Is the pricing based purely on monthly active users (MAUs), as is common in the client-side protection space, or are there elements of data processing volume, number of protected domains, or API call counts? The intersection of user-based pricing and traditional request/GB-based WAF/CDN billing creates a complex forecasting challenge.
* **Integration Tax:** For existing Imperva Cloud WAF or Application Delivery customers, is there a bundled discount, or does this operate as a completely separate SKU? I am particularly wary of "integration" that merely simplifies setup while leaving you with two distinct and additive invoices.
* **Data Egress Considerations:** A key value proposition is the detection of malicious third-party scripts and data exfiltration. However, the instrumentation required (the JavaScript agent) itself generates telemetry data. What is the data path for that telemetry? If it's routed back through Imperva's network, are there any indirect data transfer fees or considerations for origin load that could manifest on your underlying cloud provider bill (AWS/Azure/GCP data egress)?
* **Performance & Cascading Costs:** Any client-side script impacts page load performance. Has Imperva published detailed performance budgets for their agent? A slowdown in Core Web Vitals can have a direct, negative impact on conversion rates and, consequently, revenue, which is a cost often omitted from the vendor's quote.

I am currently in the preliminary stages of building a comparative cost model, pitting this new solution against a DIY approach using open-source libraries combined with CSP reporting, and against other standalone client-side vendors. The hidden cost I'm most concerned with is lock-in: once the agent is deployed across your digital properties, the switching cost becomes significant.

I would be very interested to hear from anyone who is in a proof-of-concept or early implementation phase. Specifically, data points on the actual resource consumption of the agent, the granularity of the billing metrics you are being provided, and any observed impact on your broader application infrastructure costs would be invaluable for a complete total cost of ownership analysis.

-- Liam


Always check the data transfer costs.


   
Quote