Imperva Incapsula Overview

Imperva Incapsula is the #2 ranked solution in our list of top CDN tools. It is most often compared to Cloudflare: Imperva Incapsula vs Cloudflare

What is Imperva Incapsula?

Imperva Incapsula is a cloud-based application delivery service that protects websites and safeguards web applications and their data from attacks, and improves their performance by enhancing user experience. Incapsula includes a security platform with a web application firewall, DDoS mitigation, content delivery network, and global load balancer to maximize performance.

Imperva Incapsula is also known as Incapsula.

Imperva Incapsula Buyer's Guide

Download the Imperva Incapsula Buyer's Guide including reviews and more. Updated: May 2021

Imperva Incapsula Customers

Hitachi, BNZ, Bitstamp, Moz, InnoGames, BTCChina, Wix, LivePerson, Zillow and more.

Imperva Incapsula Video

Filter Archived Reviews (More than two years old)

Filter by:
Filter Reviews
Industry
Loading...
Filter Unavailable
Company Size
Loading...
Filter Unavailable
Job Level
Loading...
Filter Unavailable
Rating
Loading...
Filter Unavailable
Considered
Loading...
Filter Unavailable
Order by:
Loading...
  • Date
  • Highest Rating
  • Lowest Rating
  • Review Length
Search:
Showingreviews based on the current filters. Reset all filters
Information Security Analyst at a tech vendor with 10,001+ employees
Real User
Gives us visibility into DDoS, SQL Injection and other types attacks

What is our primary use case?

The first use case was due to the need to protect DDoS attacks as well as protection for SQL injection. The existing application was no longer supported, and to prevent further attacks from occurring, WAF Imperva was applied. The rollout was very fast due to the need for DNS notes only.

Pros and Cons

  • "Provides Anti-DDoS protection, as well as other protections like SQL injection, Cross-Site Scripting, and antiscanner. These types of protection are valuable to the business due to the daily attacks on our portals, and that often cannot be seen without a tool like this."
  • "Setup was straightforward, very simple. I only entered the domain and Incapsula returned the DNS data that I needed to change for the protection to be configured."
  • "Imperva now offers add-ons to add functionality, but I would like to see these included in the product, even if it would cost more."

What other advice do I have?

Only configure it by enabling all protections. This is very important for preventing attacks.
System Administrator at a tech services company with 51-200 employees
Real User
We have peace of mind that nobody will use malware on us or try to hack our website

What is our primary use case?

We use Incapsula as a firewall on our website which can block any suspicious attempts from the outside of the company. For example, if someone is trying to hack our website or put malware on it, it blocks them.

Pros and Cons

  • "On the site security, I can see which countries have incidents, whether it was a robot attack, a real human user, or non-human user."
  • "On the activity log, I can see the exact details, the visit, and the threat."
  • "The dashboard is good and user-friendly."
  • "On the real time, you can see live traffic, which is flowing into our website."
  • "I am not sure if this application has a policy where you can create your custom policy and run it as our firewall. We should have some ability to also create some custom policy, then run it as a firewall."
Learn what your peers think about Imperva Incapsula. Get advice and tips from experienced pros sharing their opinions. Updated: May 2021.
502,104 professionals have used our research since 2012.
Manager Business Development at Seguridad América
Real User
The complete solution is valuable for everything it delivers and the protection it offers.

Pros and Cons

  • "The complete solution is valuable for everything it delivers and the protection it offers."
  • "An improvement has been to our website: It increases the speed of our response, the capacity of the site, and optimizes the bandwidth.​"
  • "​Technical support provides good, quick responses."

    What other advice do I have?

    It is an excellent product.
    Security Consultant at a security firm with 501-1,000 employees
    Consultant
    Top 20
    Gives us the ability to differentiate between a positive and a false-positive intruder action

    Pros and Cons

    • "Gives us the ability to trace each connection, and to have logs to be able to differentiate between a positive and a false-positive intruder action."
    • "I miss being able to integrate the dashboard with other BI tools we are using. We have to export and import data to be able to present it, and doing so is a lot of work."

    What other advice do I have?

    My best advice could be, if you don't have the staff to carry out security in a proper way, have a tool do it, but use a specialized tool like this one, and don't re-invent the wheel. Also, in our case, we soon realized that we needed an expert to fine tune it and to obtain all the features we wanted.
    MS
    Head Of Information Security at IronFX Global Limited
    Real User
    We are able to bring a new website live within minutes, without false positive alerts

    Pros and Cons

    • "IncapRules is one of the most valuable features, as you can create your own security and access control rules on top of your security policy. Using IncapRules we were able to easily block Layer 7 DDoS attacks several times."
    • "Real-time monitoring is also a great tool, as you may watch several parameters in real time."
    • "Incapsula takes care of the CDN infrastructure and bandwidth volume, providing several enterprise "load balancing" features."
    • "It would be better if we were able to manage and apply changes to multiple websites/web applications, and search WAF logs for multiple websites, via the Incapsula dashboard."

    What other advice do I have?

    Go for it and request a free trial.
    System Administator at a tech services company with 201-500 employees
    Consultant
    With the WAF, our web services can't be exploited remotely.

    What other advice do I have?

    Try it.
    Application Security Architect at a hospitality company with 10,001+ employees
    Vendor
    The WAF can identify, block, whitelist or blacklist as needed.
    Head of Cyber Security at KPMG Pakistan
    Real User
    Top 20
    I like the content monitoring feature which I haven't seen in other WAF solutions.

    What other advice do I have?

    Imperva Incapsula WAF is an awesome solution for implementing a WAF with good support and reliable hardware performance.
    Network and Security Engineer at a consumer goods company with 1,001-5,000 employees
    Vendor
    The dashboard shows us traffic, security, and real-time utilization. The default configuration usually does the trick for us.

    What other advice do I have?

    Do a proof-of-concept. It’s quick and easy to set up, and you’ll have Incapsula support to help you if needed. Embrace the ease-of-use of the administrative interface and marvel “can a WAF really be this easy?!”. Monitor the dashboard and enjoy the results. The ease of testing Incapsula and then implementing it into production is one of the most remarkable product experiences in my IT career. It’s clear that Incapsula engineers are busy behind the scenes, which is in contrast to my appreciation of what I would otherwise be doing tuning other WAF options.
    Service Manager at a tech services company with 51-200 employees
    Consultant
    Provides PCI-level IDS/IPS.

    What is most valuable?

    Easy-to-set-up CDN with PCI-level IDS/IPS

    How has it helped my organization?

    We offer Incapsula for every customer project we host, as a default.

    What needs improvement?

    The default service is great!

    For how long have I used the solution?

    I have used it for two years.

    What was my experience with deployment of the solution?

    Sometimes, the SSL setup can be a bit slow/inconsistent.

    What do I think about the stability of the solution?

    There was only one minor incident with service availability, if I remember correctly.

    What do I think about the scalability of the solution?

    Nope; we have not encountered any scalability issues.

    How are customer service and technical support?

    Customer Service: Some tickets seem to hang for some reason and some…
    Technical Consultant at a tech services company with 10,001+ employees
    Consultant
    Provides valuable cache control features like cache purging and cache rule propagation. The dashboard is not accessible on occasion.

    What other advice do I have?

    Imperva has a very impressive core feature set. Imperva has made security analysts scratch their heads. We allow them in from the inside so they can actually hit something worthwhile. We are very confident in the reports we get from Imperva. Its bot identification has allowed us to plan bandwidth appropriately. Identification for good bots (people who hit our site using automation, but for good business reasons) has allowed us to work with our customers who use our services in new ways.
    Security Architect at a financial services firm with 501-1,000 employees
    Vendor
    The anti-DDoS protection has distributed nodes around the world.

    What other advice do I have?

    Check the SLAs carefully.
    AVP Product Development and Architecture at a media company with 1,001-5,000 employees
    Vendor
    Provides WAF configuration. I would like them to improve the reporting interface and filtering.

    What is most valuable?

    WAF configuration is the most valuable feature.

    How has it helped my organization?

    Reduced spammers during competitions Bot reduction

    What needs improvement?

    Improve reporting interface and filtering.

    For how long have I used the solution?

    I have used it for two years.

    What was my experience with deployment of the solution?

    We have not encountered any deployment issues.

    What do I think about the stability of the solution?

    Mostly, we have not encountered any stability issues, except the occasional leak from the HK pod.

    What do I think about the scalability of the solution?

    We have not encountered any scalability issues.

    How are customer service and technical support?

    Customer Service: Customer service is good. Technical Support:…
    Senior Web Manager at a university with 501-1,000 employees
    Real User
    CloudFlare vs. Incapsula

    What other advice do I have?

    Incapsula: You need to understand how DNS works (e.g., A records vs CNAME, TXTs etc.), how SSL works and how to set it up, and how web servers work with domains and proxy servers. It is not for the layman, as the dashboard assumes some level of understanding in these topics. Some settings can break your site, so do perform some tests on a development site before turning features on/off in the dashboard. The good thing is that most settings are reversible and take effect quite quickly, so if things do go wrong, it will not stay broken for too long. Also, use extra caution when dealing with…
    Client Relations Coordinator at a marketing services firm
    Vendor
    I like the interface, customer service, and info updates.

    What is most valuable?

    I like the interface, customer service, and info updates.

    How has it helped my organization?

    We can now quickly respond to issues, as opposed to trying to find the technical problem on our end. We can now quickly address the problems of our clients in an effective manner.

    What needs improvement?

    I have found some issues with caching; seems to be inconsistent

    For how long have I used the solution?

    I have used it for five months.

    What was my experience with deployment of the solution?

    We have not encountered any deployment issues.

    What do I think about the stability of the solution?

    We have encountered very few stability issues, but those could be more due to the stability of our servers.

    What do I think about the scalability of the solution?

    Client Relations Coordinator at a marketing services firm
    Vendor
    Network Security Consultant at a tech consulting company with 51-200 employees
    Consultant
    IncapRules, Login Protect & CDN are the most valuable features

    What is most valuable?

    IncapRules, Login Protect & CDN are the most valuable features of Incapsula.

    How has it helped my organization?

    Incapsula gave us an incredible visiblity in terms of security.

    What needs improvement?

    HTML minification could be improved. The actual HTML minification does not provide the maximum HTML minification nor provides the best result. 

    For how long have I used the solution?

    We are using this solution on our customer for three months.

    What was my experience with deployment of the solution?

    No issues, setup pretty easy and straightforward.

    What do I think about the stability of the solution?

    No issues.

    What do I think about the scalability of the solution?

    No issues.

    How is customer service and technical support?

    The web support…
    Director at a tech company with 51-200 employees
    Vendor
    Considered CloudFlare as well. Didn't like that they want to take control of DNS.

    What is most valuable?

    CDN and DDoS.

    How has it helped my organization?

    This would speed up the images on the website geographically and protect against DDoS attacks.

    What needs improvement?

    Maybe another pricing tier for home uses with a few more features above the free version. An appliance for large enterprise customers.

    For how long have I used the solution?

    6 months.

    What was my experience with deployment of the solution?

    Very straightforward.

    What do I think about the stability of the solution?

    No issues.

    What do I think about the scalability of the solution?

    None, all automatic.

    How are customer service and technical support?

    Customer Service: Excellent, no issues. Technical Support: Excellent.

    Which solution did I use previously and why did I

    Information Security Consultant at a tech services company with 51-200 employees
    Consultant
    Load balancing and DDoS protection.

    What is most valuable?

    Load balancing and DDoS protection.

    What needs improvement?

    Delivery services and information security.

    For how long have I used the solution?

    One year.

    What was my experience with deployment of the solution?

    None, the deployment was very fast and easy.

    What do I think about the scalability of the solution?

    None.

    How are customer service and technical support?

    Customer Service: Excellent, they answered all our questions. Technical Support: Very good, the information provided by Imperva for the deployment was very clear.

    Which solution did I use previously and why did I switch?

    No.

    How was the initial setup?

    Straightforward.

    What about the implementation team?

    Imperva and in-house team, the support provided from the Imperva team was…
    System Adminisrator at a tech services company with 51-200 employees
    Consultant
    We're using the security rules to block all secured areas by IP.

    What is most valuable?

    Security rules and DDoS protection.

    How has it helped my organization?

    Well, just by using the security rules to block all secured areas by IP minimized the chance of sensitive data leaking outside.

    What needs improvement?

    I'd like it to work with Let's Encrypt.

    For how long have I used the solution?

    1.5 years

    What was my experience with deployment of the solution?

    No issues.

    What do I think about the stability of the solution?

    No issues.

    What do I think about the scalability of the solution?

    No issues.

    How are customer service and technical support?

    Customer Service: Once going enterprise, support is excellent. Technical Support: Once going enterprise, support is excellent.

    Which solution did I use previously and why did I switch?

    IT & DevOps Engineer at a comms service provider with 501-1,000 employees
    Vendor
    It has SSL support and content caching. You can 'play' with the rules as much as you'd like.

    What other advice do I have?

    I highly recommend Incapsula for anyone that is looking to integrate a WAF and DDoS protection into their environment.
    IT Director at a tech services company with 51-200 employees
    Consultant
    It can hide the true origin and provide access control. Their customer service sometimes has different responses for similar requests.

    What other advice do I have?

    If you don’t have a strong IT team for security, Incapsula is a good starting point for outsourcing your internet-facing security issues.
    Digital Solutions Architect | Development Manager | Technical Business Analyst at Corporate SEO
    Vendor
    Installation requires just a CNAME entry, avoiding the risk of email downtime.

    What other advice do I have?

    Don't wait till you've been hacked; get protected now. It'll cost you at least a year of Incapsula fees to recover from website hacking. And if your website is running slow, Google is probably already penalising your site, when the fix is so easy. Incapsula is by far the fastest fix for both website speed and security.
    Systems Administrator at a financial services firm with 501-1,000 employees
    Vendor
    Added security is the biggest bonus, as our websites have highly sensitive data.

    What other advice do I have?

    Keep your sites strongly secured but sleep easier knowing Imperva Incapsula continuously baffles our penetration testers.
    Cyber Response Analyst at a insurance company with 1,001-5,000 employees
    Vendor
    Its DDoS Protection and Load Balancing helped maximize our security by adding an extra layer of protection.
    IT Support Engineer at a tech services company with 51-200 employees
    Consultant
    It helped us investigate and narrow down possible attacks from suspicious IPs.
    Sales office at a real estate/law firm with 51-200 employees
    Vendor
    It's improved the speed of our website and setup is straightforward, although the file-purging function could be improved.
    IT Manager at a tech services company with 1,001-5,000 employees
    Consultant
    We were able to dial in the security and protection that it provided and understand the threat to our company website.
    I was introduced to Incapsula after our company website had started to show signs of a persistent active DDoS attack. I got on the phone with their representative, who later brought in an engineer and within that same day we were able to begin mitigating the problem, all under the free trial. We were able to easily dial in the security and protection that the service provided and began to understand the threat (which was not a DDoS attack) quickly. We were so impressed with the effectiveness of the solution and the assistance that we received from support that we subscribed to their service in an ongoing basis, which has proven to be reliable and simple to use. However, I'd like to be able to drill down more into the analytics that Incapsula collects. For example, I'd like to be able…
    Associate Manager at a tech services company with 10,001+ employees
    Real User
    The Web Application Firewall is helpful in protecting SQL injections.

    What other advice do I have?

    You can safely implement it irrespective of your application usage size.
    Application Development Manager at a financial services firm with 501-1,000 employees
    Vendor
    We're using it to replace Barracuda Web App Firewall which we retired several years ago.

    What other advice do I have?

    I would say compare it to other solutions in the marketplace feature by feature and see how Incapsula reporting and analytics dashboards compare and bot control compares – their solution for bot control is pretty good – and check those features with other enterprise level solutions, you get a lot for your money.
    Sales Engineer/Major Accounts with 51-200 employees
    Vendor
    With increasing traffic to our sites, it has protected them from DDoS attacks against which we did not previously have a solution.

    What other advice do I have?

    Make sure you use a premium DNS provider. We had to move from a basic DNS provider to a more complex one to get it work with Incapsula 100%.
    VP R&D with 51-200 employees
    Vendor
    They don't require us to move our DNS service to them like other services do, allowing us to maintain our network in our current configuration.
    Senior Manager, Software Development at a music company with 1,001-5,000 employees
    Vendor
    We've found the caching, CDN, and Web Application Firewall features valuable, giving us an extra layer of PCI compliance.
    President/General Manager with 51-200 employees
    Vendor
    It solves the issue of not being able to install an on-premise WAF solution or other security device.

    What other advice do I have?

    This is very simple to install. Websites that use SSL should pre-export their certificates and be ready to import them into Incapsula.
    Director at a marketing services firm with 51-200 employees
    Vendor
    It provides intelligence on bad IPS and malicious software, and scales without issue.

    What other advice do I have?

    Go for it if you’re looking into it – they are a good solution and are trustworthy people. Just really works.
    IT Manager with 501-1,000 employees
    Vendor
    Because of the load balance functionality, our site is available despite attacks.

    What is most valuable?

    DDOS defence Load balancing Security role

    How has it helped my organization?

    The availability of our sites, thanks to the load balance functionality, has improved. It enables the site to be available all the time, despite people trying to attack it.

    What needs improvement?

    More features to help fine tune it. In general, more features for the platform would be nice.

    For how long have I used the solution?

    I’ve used it for two to three years.

    What was my experience with deployment of the solution?

    I used the customer service once.

    What do I think about the stability of the solution?

    Once or twice, there has been downtime, but it was only a matter of minutes.

    What do I think about the scalability of the solution?

    No issues encountered. …
    Online Marketing Manager with 1,001-5,000 employees
    Vendor
    The user-generated spam stopped after we started using it to speed up and protect our website.

    What other advice do I have?

    Do it on a Sunday in case there is down time. I would ask for support after implementation, and check that the site speed is as fast as it should be.
    ICT Director with 501-1,000 employees
    Vendor
    We've had no compromises to our website and services from potential threats, hackers, etc. as the Web Application firewall has been effective.

    What other advice do I have?

    I think it’s a leading product, a market leader; that’s how it feels to us. But I don’t think it would be a good product if i'ts mission critical. You'd need to proceed with a certain amount of caution because we haven’t had 100% uptime.
    Founder and Team Head at a tech services company with 51-200 employees
    Consultant
    Overall it worked well without any glitches.
    I’ve been using Incapsula CDN for about a month now, So I’d thought to write down a review about my experience. The loading time of a site is important, quite important. The loading time comes among various factors used for ranking a site, With site speed getting so much buzz around the town, your site/blog needs to be quick to be ranked high. The site loading time should be as minimum as possible, this not only makes your site loved by users and bots but also increases your conversion rates. When decreasing your site load speed time, you have to look along several factors, the list of which includes things as easy as optimizing images to as complicated as combining CSS and JS files, the list includes several other things too. One thing which can make your life easier while…
    Owner at a tech services company with 51-200 employees
    Consultant
    Speed up WordPress – increase security
    In a nutshell this is what Incapsula does: Incapsula offers state-of-the-art security and performance to websites of all sizes. Through a simple DNS change, your website’s traffic is seamlessly routed through Incapsula’s globally-distributed network of high-powered servers. Incoming traffic is intelligently profiled in real-time, blocking even the latest web threats: from sophisticated SQL injection attacks to scrapers, malicious bots, intruding comment spammers and thwarting multi-Gigabit DDoS attacks. Meanwhile, outgoing traffic is accelerated and optimized with Incapsula’s global CDN, for faster load times, keeping welcome visitors speeding through. I’ve always been interested in how to make my website faster but with the news about brute force attacks on…
    Director of eCommerce with 51-200 employees
    Vendor
    Incapsula provides enterprise-grade security and acceleration to our customers at an affordable price
    We currently host over 1,100 websites and our clients include some of Australia's best known online retail success stories and its largest eBay trader. The nature of the e-commerce business poses a wide range of challenges that we need to deal with on a daily basis in order to keep our clients' online stores up and running. For our clients, time is (literally) money and it’s our responsibility to make sure that all potential problems are handled quickly, before they affect any business transactions. Security is obviously an issue we couldn’t afford to ignore. We spent several months searching for a solution that could meet our clients' demanding security and performance requirements. As it happened, Incapsula had just opened a new data center in Australia, so we decided to give them a try…
    Engineer with 51-200 employees
    Vendor
    Using Incapsula’s DDoS Protection and Load Balancing we maximized our Website Security and Availability
    To support the growing traffic to our website from online traders, we realized that strong protection from DDoS and other types of attacks was only part of the equation. To ensure high availability (99.999% uptime) and consistent performance for our users, we also needed the ability to efficiently distribute website traffic across multiple servers. As our online business grew, it became clear to us that we needed an enterprise-grade service that was able to combine powerful DDoS mitigation together with advanced load-balancing capabilities that would enable us to cost-effectively scale beyond the capacity of a single web server, as well as supporting automatic failover to prevent downtime. Our previous cloud-based DDoS mitigation service supported load balancing via DNS, which by…
    CEO with 51-200 employees
    Real User
    Incapsula helped us stay up during some of the biggest DDoS attacks on record
    To ensure the success of our online trading operations, we place a major emphasis on state-of-the-art security, high availability (99.9% uptime) and user convenience. Daily high-volume network DDoS attacks against our website were wreaking havoc with business operations, resulting in downtime for our online trading platform. The anti-DDoS solutions we had in place was not equipped to mitigate these attacks, which came precisely at the time when we were experiencing record trading volumes. Since our company deals with a highly competitive and time-sensitive trading market, high availability and stability are paramount to building our users' confidence in our platform. It was obvious to us that in order to maintain and grow our business, we needed the best DDoS protection solution. We…
    Infrastructure Expert at a tech services company with 1,001-5,000 employees
    Consultant
    Great service, great value

    Valuable Features:

    Their solutions are always on, in depth and protect against most all web threats imaginable.

    Improvements to My Organization:

    Essentially, it has added an extra layer of protection to my clients through their DNS routing service. Less downtime, and happier clients.
    Security Expert with 51-200 employees
    Vendor
    CloudFlare vs Incapsula: Web Application Firewall
    CloudFlare vs Incapsula: Round 2 Web Application Firewall Comparative Penetration Testing Analysis Report v1.0 Summary This document contains the results of a second comparative penetration test conducted by a team of security specialists at Zero Science Lab against two cloud-based Web Application Firewall (WAF) solutions: Incapsula and Cloudflare. This test was designed to bypass security controls in place, in any possible way, circumventing whatever filters they have. Given the rise in application-level attacks, the goal of the test was to provide IT managers of online businesses with a comparison of these WAFs against real-world threats in simulated real-world conditions. Zero Science Lab is a Macedonian Information Security Research and Development Laboratory that…
    CEO at a tech services company with 51-200 employees
    Consultant
    ​We use Incapsula for some of our sites and the experience has been excellent
    We use Incapsula for some of our sites and the experience has been excellent. You would not even know it was there – unlike those caching plugins (admittedly they are for speed not for security) – which remind you constantly that they are there so much so that you have to turn them off. Whoops.
    Developer with 51-200 employees
    Vendor
    We Use Incapsula's DDoS Protection Service to Maximize Availability and Performance
    In September 2013, our online store was the victim of a prolonged three-week application-level DDoS attack. Mitigating this type of Layer 7 DDoS attack is a major challenge for security solutions, since malicious bot traffic often appears to be requests from legitimate users. During this attack, our existing anti-DDoS solution was not able to effectively filter out the malicious traffic, which meant that innocent e-commerce customers were blocked from accessing the sites or were forced to unnecessarily fill out CAPTCHA challenges. As an e-commerce company, website security is central to our core business. We needed a DDoS protection solution that would enable us to maintain "business as usual" even under attack, with minimum disruption to the user experience. Minimizing false positives was…
    CEO with 51-200 employees
    Vendor
    We have gone through paid evaluations of several DDoS mitigation services, but all of them failed to block DDOS attacks
    Our company has recently reached 3.5 million registered users and 200,000 hosted websites. Daily DDoS attacks on our platform resulted in unnecessary and prolonged downtime for the thousands of sites on our network. These attacks included network level (layer 3 & 4) attacks ranging from 2Gbps to 10Gbps with various attack vectors such as UDP attacks but most commonly SYN floods which exploit the TCP three-way handshake to consume the server’s connection resources. The more challenging attacks were the diverse application level (Layer 7) attacks. These attacks seem as if they are originating from legitimate sources, try to mimic human behavior and consume the backend computing resources of the website. We were seeing daily DDOS attacks, sometimes multiple DDOS attacks in parallel on various…
    Buyer's Guide
    Download our free Imperva Incapsula Report and get advice and tips from experienced pros sharing their opinions.