RA
Raza A.
Analyst
Small-Business (50 or fewer emp.)
"Lacework enforces policies and monitors containers at runtime to prevent vulnerabilities"
5/5
What do you like best about FortiCNAPP?

I love its capabilities like centralized administration, control groups, role-based access, and auditing. Additionally, the graphical user interface is easy to understand and clearly breaks down which resources are failing or passing which policies. Review collected by and hosted on G2.com.

What do you dislike about FortiCNAPP?

I thought the initial setup process was a bit long, but we managed to do it with the help of the Lacework team. And I think some areas of the user interface require improvement. Review collected by and hosted on G2.com.

Aleksandr K.
AK
Aleksandr K.
Mid-Market (51-1000 emp.)
"Good tool for the job it does"
4/5
What do you like best about FortiCNAPP?

It provides excellent documentation to integrate the tool within the workspace easily. I believe this is great when it comes down to containers specifically, as it looks in the skeleton of the image and a runtime scan. Review collected by and hosted on G2.com.

What do you dislike about FortiCNAPP?

I believe the downside of the Lacework comes from its offering of infrastructure as code scanning. It is not context aware thus when you use your IaC code with imported modules, it won't understand what you are importing from those modules thus won't give you a concrete dataflow. Review collected by and hosted on G2.com.

Response from Emily Chin of FortiCNAPP

Thank you for the detailed update of your review, Aleskandr. We're thrilled to hear that Lacework has enhanced your observability and incident response capabilities. It's fantastic to know that our solution is simplifying forensic investigations and improving your container traffic flows. We appreciate you sharing about the IaC challenges you’re experiencing; our team suggests scanning the code in your CI/CD pipeline (instead of in the code repos) with a "terraform plan" file. This file resolves the nested set of files (these are places where one IaC file calls another) and generates a single file to analyze. I hope this suggestion is helpful, or if I can connect you directly with the team to chat more, please send me a note at emily.chin@lacework.net and I would be happy to facilitate.

NA
Noufissa A.
Cloud security engineer
Education Management
Small-Business (50 or fewer emp.)
"We enhanced security and compliance"
4/5
What do you like best about FortiCNAPP?

I like Lacework because its interface is very intuitive and can plug directly into the tools we are already using, such as AWS and Azure. Many features that have proven to be a great benefit to our company include the real time threat detection, which gives alert and comprehensive report. Another thing that needs a mention is the customer support, the service is always willing to help with various problems. Lacework has more than likely helped save time in our security aspects. Review collected by and hosted on G2.com.

What do you dislike about FortiCNAPP?

A disadvantage of Lacework is that it can be somewhat complicated to set up at the beginning. This consumed more time and resources that could have been used in our work thus affecting it. Also the number of features available can be quite confusing and may take time to get used to, thus reducing the initial productivity rates. However, after some time, it was possible to notice the features that made the software useful. Review collected by and hosted on G2.com.

Verified User in Information Technology and Services
AI
Verified User in Information Technology and Services
Enterprise (> 1000 emp.)
"Good product but dont like the UI experience much"
3/5
What do you like best about FortiCNAPP?

Mainly like the different set of standards it provides like SOC2, PCIDSS, HIPAA etc. where we can generate reports directly against each compliance framework which is very helpful during an audit.

I really like the findings it provides using agents with our kubernetes platform where lacework can give us more granular findings on the container behavior in the platform where we struggled to find what was happening within the kubernetes infrastructure. Review collected by and hosted on G2.com.

What do you dislike about FortiCNAPP?

The dashboard is difficult to navigate, making it challenging to quickly find specific information or insights.

Also creating custom dashboards for our requirement is not straightforward.

Automation with the AWS control tower is not working time to time where they have not considered large scale setups where the architecture does not scale for hundreds of accounts migration. Review collected by and hosted on G2.com.

Md F.
MF
Md F.
Salesforce Developer
Enterprise (> 1000 emp.)
"Platform is good"
4/5
What do you like best about FortiCNAPP?

Security container and Integration with 3rd party applications Review collected by and hosted on G2.com.

What do you dislike about FortiCNAPP?

Integration documentation not available widely Review collected by and hosted on G2.com.

FD
Francesca D.
Cloud security analyst
Small-Business (50 or fewer emp.)
"Our cloud data is strongly protected by this modern software"
4/5
What do you like best about FortiCNAPP?

The main feature of Lacework is its strong cloud security compared with others. The way it perfectly harmonizes with our cloud headings has made a tremendous impact in our cyber security. It enables us to uncover any activities instantly and conduct in-depth threat analysis, making us to be always in front of the possible threats. The AI-driven analytics are the source of good insights allowing early identification of the risk issues. Also the simplicity of its interface makes security management quick thus it boosts our team effectiveness. Review collected by and hosted on G2.com.

What do you dislike about FortiCNAPP?

Of course Lacework, without a doubt, also has some aspects where it could improve. Although it provides a great range of features, it is not as capable as certain other similar softwares. Although it is perfect on its main functions related to reporting, notifying anomalies, and impact scanning, sometimes we need such extra features that Lacework doesn't deliver. This restriction makes it necessary to find the circular solutions or integrate our system with other tools to meet all our needs, which increases the complexity of our process. Review collected by and hosted on G2.com.

Response from Emily Chin of FortiCNAPP

We love the detailed feedback and are thrilled to hear that our features have positively impacted your cybersecurity efforts. Please reach out to me directly at emily.chin@lacework.net with any additional questions or details to share back with the team. Thank you so much.

VP
Veeresh P.
Cloud Security Consultant
Enterprise (> 1000 emp.)
"The best Cloud Security Assessment Tool"
4/5
What do you like best about FortiCNAPP?

We are the security consultants and we provide Lacework Tool as the Cloud Security Assessment Tool as a Service to the Customers.

Lacework has helped to find all the cloud misconfigurations as well as vulnerabilities in the azure,aws and gcp clouds. This tool also helps a lot as the security administrators as the tool is very easy to use and also generates very high level reports according the the CISO requirements.

The security administrators can easily find the vulnerabilities, and threats very easily by the lacework's best feature i.e Polygraph feature(also known as graphical/ flowchart view of the threats) which also helps in preventing the issue before happening.

We have already helped the customers in providing Lacework cloud Security Assessment service and they are pretty much satisfied.

The Customer Support is also very decent.

The one thing which I personally like is that Lacework always tries to expand new features in their tool. Review collected by and hosted on G2.com.

What do you dislike about FortiCNAPP?

1] The implementation as well as the Cloud Onboarding into Lacework Platform is very complex and it requires very high level of effort.

2] the Integration of the other security products such as SIEM, Tcketing Tools are also very complex process.

3] to generate cloud security alerts lacework requires some of the prerequisites of the cloud services.

example :- the get AWS Cloud Security Alerts in Lacework, the AWS Config Service must be enabled in the AWS Cloud. Review collected by and hosted on G2.com.

Response from Emily Chin of FortiCNAPP

We appreciate your detailed feedback on how Lacework has helped you.We’re pleased to hear that Lacework has effectively helped you manage cloud misconfigurations, vulnerabilities, compliance, and integrations with containers and Kubernetes environments.. We appreciate your insights on your implementation and integration, and would be happy to connect you directly with the team if we can further streamline your experience, please reach out any time! emily.chin@lacework.net

Verified User in Legal Services
AL
Verified User in Legal Services
Enterprise (> 1000 emp.)
"Good product with high fidelity alerting"
4.5/5
What do you like best about FortiCNAPP?

Good UX and provides great visibility into cloud environments with intuitive and actionable insights. Also provides good contextual benefits for detections (events) that might amount to incidents, which is helpful if you need to triage and respond quickly. I also find the ability to easily deploy and integrate with various cloud services incredibly helpful for me and my team, especially when we're under tight time constraints to provide assurance back to the business on levels of visibility. Review collected by and hosted on G2.com.

What do you dislike about FortiCNAPP?

I think the ability to build out automation workflows for more granular types of alerting could be helpful for organisations that have Lacework but don't yet have a SIEM and/or SOAR platform. Review collected by and hosted on G2.com.

Verified User in Financial Services
IF
Verified User in Financial Services
Mid-Market (51-1000 emp.)
"It used to best but not anymore!"
4/5
What do you like best about FortiCNAPP?

easy to implement.

Good with alert handling.

Vulnerability & compliance scanning Review collected by and hosted on G2.com.

What do you dislike about FortiCNAPP?

UI can be more user-friendly.

No free trails to educate new customers.

Can improve alert handling. Review collected by and hosted on G2.com.

Sergey M.
SM
Sergey M.
Security Engineering (Tools & Automations; Threat and Vulnerability Management)
Enterprise (> 1000 emp.)
"Lacework CNAPP tool"
4/5
What do you like best about FortiCNAPP?

Easy to deploy and navigate. Clear CIS and SOC2 reoports. Deployment ahents to EC2 is simple with agent intregration into goldem AMI. Customer support ppl are always on time and helpfull. We are using Lacewirk daily on real time bu multile teams, starting with IR, CSPM, Vulnerabilities ... Review collected by and hosted on G2.com.

What do you dislike about FortiCNAPP?

We need to use third party tool to push auto remediation Review collected by and hosted on G2.com.