TrustRadius: an HG Insights company

Skybox Security

Score10 out of 10

5 Reviews and Ratings

What is Skybox Security?

Skybox Security offers vulnerability and threat management solutions.

Top Performing Features

  • Policy planning and rule management

    Monitor the effectiveness of network security infrastructure

    Category average: 8.9

  • Anomalous Event or Behavior Deviation

    Ability to pinpoint unusual events or trends

    Category average: 8.6

  • Firewall Rule Cleanup

    Ability to detect and cleanup rules that are either partially or completely unused, expired or shadowed

    Category average: 8.9

Areas for Improvement

  • Policy Compliance Auditing

    Automatic identification of gaps in compliance, remediation, and generation of compliance reports for auditors

    Category average: 8.2

  • Attack Path Simulation Testing

    Simulation of potential attack paths to expose network exposure

    Category average: 7.9

  • Vulnerability Scans

    Network scans to pinpoint vulnerable locations for remediation

    Category average: 8.4

Skybox - Studies show it is a leader

Pros

  • Skybox manages compliance for firewalls better than we have seen with other tools.
  • Skybox integrates into standard change management tools so change control can flow through Skybox and assist with all decisions to implement a change.
  • The Skybox network map is more detailed than other management tools showing us paths other tools didn't find.

Cons

  • The management console could use work - move away from Java to HTML5 to something more lightweight
  • Dynamic objects are not properly identified in Skybox

Return on Investment

  • Skybox is in pilot
  • Positive ROI is in change management

Alternatives Considered

Tufin, RedSeal and AlgoSec

Skybox Security for vulnerability management

Pros

  • Vulnerability prioritization
  • Review of firewall rules
  • Review of routing rules

Cons

  • User experience. On the first approach, it's not the simplest tool that I have ever used.
  • Web-based console. In my honest opinion it's very important [to have] this type of functionality to extend the use of Skybox.
  • Too many updates of the product.

Return on Investment

  • Reduces cost in terms of time and money to spend in remediation activity.
  • Improve the network topology and then it's possibile to reduce cost of network/security appliances where they're not necessary.
  • The cost of the solution is not trivial when the number of network appliances is big.

Other Software Used

Splunk Enterprise, Qualys Private Cloud Platform, Bugzilla

Good product with good visualizations, but needs more features.

Pros

  • Firewall change management. It is very important because it helps visualize the effect of a network change or a firewall change before it is applied.
  • It is very user friendly and simple to use with a centralized interface.
  • Has many good modules like the vulnerability control and firewall assurance.
  • Another useful tool is it generates informative reports on all firewalls to help in the risk analysis and assessment of any firewall change on the network. Thus it helps you take any precautions or corrective actions.

Cons

  • It doesn't support and integrate with Microsoft Azure
  • The pricing is quite high compared to others
  • There are a lot of bugs in the solution
  • The implementation is not that easy and takes a long time, it needs to be more automated.

Return on Investment

  • Collects info from all connected firewalls and generates informative reports
  • Long time to implement
  • Easier to scan the whole complex network.
  • Pricing and technical support need to be improved
  • Change management has become easier as it assesses its impact before applying the change.

Usability

Other Software Used

AlgoSec

Excellent product but needs a bit more compatibility with new versions

Pros

  • Change tracking
  • Configuration compliance
  • Network map

Cons

  • Compatibility
  • Support

Return on Investment

  • Good for auditory
  • Compliance of rules

Alternatives Considered

CloudGuard Dome9

Other Software Used

CloudGuard Dome9