Which should I choose, Cloudflare or Imperva Incapsula?


One of the most popular comparisons on IT Central Station is Cloudflare vs Imperva Incapsula.

One user says about Cloudflare, "They were able to truly disrupt the market because prior to them, only enterprises had access to such features. They offer free CDN to all websites."

Another user says about Imperva Incapsula, "By using this application, the firewall is blocking every suspicious activity and event. Now, we are safe. We have peace of mind that nobody will use malware on us or try to hack our website"

In your experience, which is better and why?

ITCS user
99 Answers

author avatar
Top 20Reseller

Imperva Incapsula. Has the biggest POP capacity.

author avatar

Hello, As Carlos and Barry mentioned all of them are good. One has to choose CDN based on their priorities like if their main priority is saving website from DDoS or Performance or Quick Site failover mechanism and of course keeping it under cost. If you go with Cloudflare they have more PoP then Incapsula. When it comes to origin shield, you need to buy it separately in CloudFlare but in Incapsula its included. There are lot of factors on which you can differentiate between them but i would personally suggest instead of comparing two products, firstly write down your needs and prioritize them. It will help you to choose right product under your project budget.


author avatar

Neither is better or worse. Full disclosure, I’m build new security tools @ Akamai. Some would say Akamai is better than both. But... in truth it all depends on:

1. What service you are defending.
2. What is your tolerance of “DOS downtime” to your business.

Each company is going to be different for different reasons. There is no “this one is better than that one.” It is ALL SITUATIONAL ON THE ORGANIZATION”S REQUIREMENTS!.

For example, if I have an API I need to protect from DOS attack because there are IoT applications which depend on it, I would look for a API scaling solution (like Akamai) or a IoT scaling solutions (Akamai’s IoT Edge Connect).

Contrast that with me and my personal website. It is simple and straight forward Wordpress. Easy for Cloudflare (which I use).

It does not mean one is better than the other. It just means one fits the requirements/cost.

author avatar
Real User

Hello, happy to be able to help, although cloudfare has the largest CDN network and currently distributed, what we should look at when choosing a DDoS solution is in the technology of scrubbing center, this technology is what allows filtering and stop attacks of this type more easily, although the incapsula CDN network has 40 PoP in the world all of them are scrubing centers, versus the rest that if I remember correctly only have some with this technology, I hope I have helped you I insist that both solutions are good.


author avatar

One important point to keep in mind is how to achieve comprehensive protection of *all* your assets, not only the ones hosted on the CDN. What about corporate internet access? your own origin servers? services other than web?
Visibility is also very important. what is happening during a ddos attack? what attack vectors are being used? why traffic is dropped or passed? what ability you have to surgically apply filters and countermeasures?
Does the service provide 24/7 access to expert SOC operators?

author avatar

Choose Imperva. We used this WAF in conjunction with ImmuniWeb (they have partnership) https://www.htbridge.com/immuniweb/partners/TAP/. No complaints. Zero false positives and no cost for integration. Plus.

author avatar
Real User

I recommend the solutions from Radware - https://www.radware.com/products/cloud-ddos-services/

author avatar


author avatar

Neither. Radware has the best technology in the DDoS space to stop a Distributed Denial of Service attack.

Find out what your peers are saying about Cloudflare vs. Imperva Incapsula and other solutions. Updated: September 2021.
536,244 professionals have used our research since 2012.