My company uses CylancePROTECT as an antivirus solution, installed on each PC.
Senior Consultant at IIJ Singapore
Stable, accurate, and doesn't give many false positives
Pros and Cons
- "What I like best about CylancePROTECT is its accuracy, as it doesn't give many false positives."
- "An area for improvement in CylancePROTECT is its pricing, as it's a bit costly."
What is our primary use case?
What is most valuable?
What I like best about CylancePROTECT is its accuracy, as it doesn't give many false positives.
What needs improvement?
An area for improvement in CylancePROTECT is its pricing, as it's a bit costly.
For how long have I used the solution?
I've been using CylancePROTECT for three years.
Buyer's Guide
BlackBerry Cylance Cybersecurity
February 2025

Learn what your peers think about BlackBerry Cylance Cybersecurity. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
838,713 professionals have used our research since 2012.
What do I think about the stability of the solution?
So far, CylancePROTECT is stable. I've never had any problems with it in terms of stability.
What do I think about the scalability of the solution?
CylancePROTECT was deployed for my company with two hundred users, but I'm unsure if it can be deployed for more than that number and if it would still be scalable.
How are customer service and support?
I only had to contact the technical support for CylancePROTECT once, and I don't have any complaints support-wise, so I'd give the support team a ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
My company used Symantec before using CylancePROTECT, and it switched to CylancePROTECT because the update for Symantec was troublesome, plus it had some false positives. Symantec also couldn't detect some viruses, so the company decided to switch to a next-gen antivirus, such as CylancePROTECT.
How was the initial setup?
The setup for CylancePROTECT was easy. You just had to do some clicking.
It took less than a month to deploy the solution, mainly three weeks, including installing tools on the endpoints.
What about the implementation team?
An in-house team deployed CylancePROTECT for my company. I work for an IT company, so my company can do the deployment without help from an integrator or third party.
What was our ROI?
We've never calculated CylancePROTECT ROI.
What's my experience with pricing, setup cost, and licensing?
My company is on a yearly CylancePROTECT subscription. Price-wise, the solution is slightly expensive, so I'd rate it as eight out of ten.
What other advice do I have?
My company currently has two hundred CylancePROTECT users. That number could increase, but not significantly.
Two to three people took care of the deployment of CylancePROTECT.
I'd recommend CylancePROTECT to others looking into using it.
My rating for CylancePROTECT is eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Senior Network Administrator at a financial services firm with 51-200 employees
Inconsistent stability with a difficult uninstall, although deployment of updates is easy
Pros and Cons
- "The deployment of updates is easy."
- "While you are working, you are finding these things that were supposed to be waived have come back to being blocked. That's frustrating."
What is our primary use case?
We use this solution for endpoint protection for our external devices and laptops.
What is most valuable?
The deployment of updates is easy.
What needs improvement?
Not having OPTICS doesn't allow us to do any history. We don't have OPTICS, but FortiEDR comes with things like OPTICS, which is nice because we are not able to see more.
OPTICS gives you things that FortiEDR has built in. For Cylance, there is an add-on to do the things that come with that solution.
It would be nice if Cylance didn't separate PROTECT and OPTICS and put them together and made them on the same price point as FortiEDR, and some other ones rather than having to pay extra for something that the others already have built-in, and seen to do better.
It often lets you waive something for the firm or for the whole company and then comes back and blocks the same thing because you have to do the certificate instead of the hash. You are finding yourself having to approve for the same program, the same application, the same file more than once and it's frustrating.
While the deployment of updates is easy, it would be good to have some more information about which version to use, because the versions that are available seem to be outdated.
When you go to the admin section, you will see that you will have the latest update from months ago and a month before that, and a month before that.
I have a hard time believing that there are no more updates in between when there are things that are out all the time. It just doesn't make you feel like you're getting covered or have the best protection, which you should have.
For how long have I used the solution?
I have been using this solution for two years.
We are using one of the newer versions. I don't always install the updates.
What do I think about the stability of the solution?
The stability varies. It's not consistent and it's frustrating.
Things that are blocked, you waive and it comes back. It's very frustrating. It doesn't keep up with the machines.
You have a lot of machines and if you reimage a lot you will see many duplicates that you have to export and remove from figuring out which one's the MAC address. It should have an easy way to know that a machine is re-imaged, and not adding to your list of devices.
You end up having all these devices that are no longer being scanned that you have to figure out what they are. It is frustrating.
What do I think about the scalability of the solution?
We have approximately 200 users in our organization. It's for everyone in our accounting firm, who are accountants, auditors, IT, and HR accounting.
We don't have plans to continue using this solution, we are considering other options.
How are customer service and technical support?
We don't go through technical support directly. We go through a reseller and they take care of it. We have never directly talked to BlackBerry or Cylance about any issues that we have had.
Which solution did I use previously and why did I switch?
Previously, we had McAfee ePO. We changed to CylaneProtect, a solution that we felt would be a better fit, and that was not managed in-house, on a local server that we used for that. It was time to move on from that.
How was the initial setup?
The initial setup was fine. It's doesn't take a long time to deploy.
Uninstalling is difficult. Sometimes it doesn't remove easily, and that is frustrating.
It would be nice if it had an uninstalled feature within the dashboard, in the SAS part of the application online, because it would do everything itself. Unless it is something that I have missed or that I didn't see.
With FortiEDR you can go in, and you can uninstall from the dash, find the endpoint you right-click, or you click a button, then you choose to uninstall and it pulls it from the machine. You don't have to put in any keys, or anything. It does it from there. I don't believe that Cylance does that, but it would be nice if it did.
We have a team of two, myself and my colleague maintain this solution.
What about the implementation team?
The deployment and implementation were completed in-house.
What other advice do I have?
I would advise that they keep in mind what it doesn't do and be open to looking at things that include more and cost less.
I would rate CylanceProtect a four out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
BlackBerry Cylance Cybersecurity
February 2025

Learn what your peers think about BlackBerry Cylance Cybersecurity. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
838,713 professionals have used our research since 2012.
Lead Systems Administrator at a energy/utilities company with 1,001-5,000 employees
Does malware analysis. Blocks WannaCry and other attacks that have come out.
Pros and Cons
- "Does malware analysis. Blocks WannaCry and other attacks that have come out."
- "It needs real analysis of quarantined files. The EDR product isn't showing much right now."
What is most valuable?
Does malware analysis. Blocks WannaCry and other attacks that have come out.
How has it helped my organization?
It lifted the burden on the helpdesk from having to keep computers updated with definitions and thus reduced the labor hours spent monitoring AV on endpoints.
What needs improvement?
It needs real analysis of quarantined files. The EDR product isn't showing much right now.
For how long have I used the solution?
We have been using this solution for one year.
What was my experience with deployment of the solution?
Some DLLs and in-house apps were quarantined. Alerting mode is the way to deploy this software for at least three weeks.
What do I think about the stability of the solution?
I did not encounter any issues with stability.
What do I think about the scalability of the solution?
I did not encounter any issues with scalability.
How are customer service and technical support?
Customer Service:
I would rate customer service as excellent.
Technical Support:I would rate technical support as excellent.
Which solution did I use previously and why did I switch?
The previous solution had too many things to monitor and required dedication to fix corrupt definitions. These required manual transfers and sometimes helpdesk time on the endpoint to fix the incumbent product.
What about the implementation team?
We implemented it in-house with the help of the sales engineer.
What was our ROI?
The ROI is immense, particularly in less dedicated labor hours. The ROI was much more in terms of security, particularly when new security flaws have recently appeared. By virtue of having this software product, the C-level suite feels more secure, because IT does not have to start taking downtime to patch servers in a hurry.
What's my experience with pricing, setup cost, and licensing?
Review closely how many endpoints you actually need before buying into a pricing level. Deal and deal with the VAR of your choice.
Which other solutions did I evaluate?
We evaluated Palo Alto Traps and Carbon Black.
What other advice do I have?
Review the performance of Cylance over the next year and ask for a 60 day trial, not just a 30 day trial. Monitoring the growth of this company is very important to determine if the product remains at the level that is in today.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Computer Security and Electronic Government Section at a government with 51-200 employees
Simplifies management tasks and has valuable malware detection capabilities
Pros and Cons
- "The platform's most valuable features are the malware detection capabilities."
- "Enhancing the product's detection rates and streamlining the user interface for easier management in daily operations would be beneficial improvements."
What is our primary use case?
We utilize the solution to safeguard approximately 500 users against malware threats. It notifies us via email about any suspicious files or activities.
How has it helped my organization?
Compared to our previous antivirus solution, Kaspersky, CylancePROTECT has significantly simplified our management tasks.
What is most valuable?
The platform's most valuable features are the malware detection capabilities.
What needs improvement?
Enhancing the product's detection rates and streamlining the user interface for easier management in daily operations would be beneficial improvements.
For how long have I used the solution?
I've been using CylancePROTECT for about two years.
What do I think about the stability of the solution?
I would rate the stability about a seven. While generally stable, there is room for improvement.
What do I think about the scalability of the solution?
I would rate the product scalability around a three. It can be slow when making system-wide changes that affect all 500 computers.
How are customer service and support?
The technical support services need improvement in terms of their knowledge and responsiveness.
How would you rate customer service and support?
Neutral
How was the initial setup?
Deployment took approximately a month due to the complexity of managing multiple remote offices. We initially attempted deployment via group policies but encountered challenges. Eventually, we opted for an external application like PDQ Deploy to facilitate the process. I would rate the initial setup process around a six. While manageable, it required some assistance from the provider.
What other advice do I have?
Overall, I am quite satisfied with CylancePROTECT. Its effectiveness in malware detection is a significant advantage.
I would rate it around an eight or nine.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Last updated: Jul 4, 2024
Flag as inappropriateSolution Architect at Westcon-Comstor
Good technology that's simple to deploy and easy to expand
Pros and Cons
- "One of the best features of the solution is that it's easy to deploy."
- "If they can add more features on top of their Persona feature that would be ideal."
What is our primary use case?
The best use case is that it actually lifts off a lot of burden on customers, especially when they are deploying Cylance compared to other solutions.
What is most valuable?
One of the best features of the solution is that it's easy to deploy. Second is the management part and the protection. It's way ahead of the other solutions compared to the signature-based one.
The base platform, the CylancePROTECT is a very good technology. If you upgraded that into a CylanceOPTICS, that will also help, however, CylancePROTECT itself can do a lot of protection.
There's a feature that they added called PERSONA. This is AI-based user behavior monitoring which is very useful.
It's straightforward to deploy.
What needs improvement?
If they can add more features on top of their Persona feature that would be ideal. It could also improve the UEBA feature of Cylance.
For how long have I used the solution?
I've been working with the solution for around five years. I started using it around 2016.
What do I think about the stability of the solution?
As a cloud-based management platform, it's very stable. The version of the agent is very minimal in terms of updates. In terms of support, they have very broad support on several operating systems. The stability is quite high for this kind of solution.
What do I think about the scalability of the solution?
It's a cloud-based management platform. It's very scalable. It's easy to ramp up the number of devices that you want to be managed by this kind of solution. It's highly scalable.
Our clients have actually upgraded and ramped up the number of licenses from the first time I deployed and introduced them to the solution. Most of our customers have expanded usage via the number of licenses they have.
How are customer service and support?
I've used technical support in the past. The technical support, the SLA, if they can improve that aspect of the product it'll be much appreciated.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
I've also worked with CylancePERSONA over the past year or so.
How was the initial setup?
The initial setup is very straightforward. It's not overly complex.
The management and maintenance is also very easy.
What's my experience with pricing, setup cost, and licensing?
What I've heard from my customers is that Cylance, in terms of pricing, is a bit higher compared to other prominent solutions like Kaspersky and Symantec, however, that's about it in terms of what I know about the product pricing.
What other advice do I have?
I'm working in a distributor company and we are actually selling CylancePROTECT.
The primary platform is a cloud-based solution. It is managed in the cloud. The one on-premise is called the hybrid platform where you can also do management locally on your site.
The best way to see the solution is to try it out. Try it first before worrying about pricing and see if it will meet your needs and how it works for your business.
I'd rate the solution eight out of ten. They simply need to improve the SLA, the response, and the Persona feature. If they do, I would rate it higher.
Disclosure: My company has a business relationship with this vendor other than being a customer:
Co-Founder, CEO at a tech services company with 11-50 employees
Nice management display, easy to install, and works satisfactorily for standard protection
Pros and Cons
- "On the management side, we liked the way it displays things."
- "It should provide more details about the events that they have detected."
What is our primary use case?
We are part of a startup company that is operating in the same domain as this solution, so we tested it as part of the competition.
What is most valuable?
On the management side, we liked the way it displays things.
What needs improvement?
The downside is that the information displayed is not enriched enough. There was not much information available, that we could see. It should provide more details about the events that they have detected. There should be more information available post-incident. Basically, the user is informed that they have caught a threat, stopped it, and that's it.
Users want to know what the threat was, the type of attack, how it got in, which IP address, did it go into lateral movement, etc. The kind of information that could be analyzed by IT experts to take forward and understand whether the attack is continuing, or not. They have some of this information but compared to other products, it's basic.
For how long have I used the solution?
We tested this solution for about six months.
What do I think about the stability of the solution?
We did not thoroughly test its stability, but I can say that we didn't have any crashes or basic problems with it. In our tests, it did not crash, although we were focused on detecting threats as opposed to assessing stability.
What do I think about the scalability of the solution?
We installed this solution for five users.
How are customer service and technical support?
We did not contact technical support.
How was the initial setup?
The initial setup and installation of this solution are quite straightforward. Just download from the management console and install it. It's easy.
What about the implementation team?
We performed the installation ourselves.
Which other solutions did I evaluate?
We have evaluated many products. In fact, we tested most of them for our purposes of developing our own. Because we did a competitive analysis, we are keeping most of the information private. However, I can say that SentinelOne, CrowdStrike, and Carbon Black give you a lot more information than Cylance.
The majority of the leading solutions are quite good, and it's a tough market. For normal people, it is difficult to see the differences between them.
What other advice do I have?
The lack of details for the user is partly because of the way they detect. it is done passively, rather than dynamically, so they don't have a lot of information about the things that they already caught.
The suitability of this solution for any particular person will depend on their expectations. I would not rate this solution in the top five for things like presenting information, or ease of use. For standard protection they are ok, but if you have advanced demands, or a SOC, then I don't think that Cylance can compete with Carbon Black, CrowdStrike, or SentinelOne.
I would rate this solution an eight out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Founder at XPose
It has an easy-to-use dashboard and monitoring system and comes with an optics feature
Pros and Cons
- "What's most valuable in CylancePROTECT is the optics feature. I also like its easy-to-use and user-friendly dashboard and monitoring system."
- "The AI of CylancePROTECT has room for improvement. I'm on a trial license of SentinelOne, and its AI is much better than what's on CylancePROTECT."
What is our primary use case?
I use CylancePROTECT for intrusion detection, so it's more of an antivirus. I also use its optics feature for live monitoring of every computer.
What is most valuable?
What's most valuable in CylancePROTECT is the optics feature. I also like its easy-to-use and user-friendly dashboard and monitoring system.
What needs improvement?
The AI of CylancePROTECT has room for improvement. I'm on a trial license of SentinelOne, and its AI is much better than what's on CylancePROTECT.
I want CylancePROTECT to have an automatic overruling feature in the future for specific situations. In my previous example, a colleague couldn't install Oracle VM VirtualBox because I didn't specify files and programs that CylancePROTECT should block. Sometimes, I want the solution to be less strict so that when a file or application comes from a well-known developer, CylancePROTECT should let it pass, regardless of what file it contains.
For how long have I used the solution?
I've been using CylancePROTECT for five years.
What do I think about the stability of the solution?
CylancePROTECT is a very stable product, but in terms of updates and features, it's a letdown.
What do I think about the scalability of the solution?
Scalability-wise, CylancePROTECT has room for improvement. SentinelOne is more scalable, though that could also be because it's bigger. For small businesses, CylancePROTECT is scalable.
Regarding scalability, I'm rating CylancePROTECT as five out of ten.
How are customer service and support?
My colleagues said that support-wise, CylancePROTECT is slow to respond, and it's challenging to communicate with support or get a person on the phone. You can only contact support via email or chat when sometimes, you prefer calling support or speaking to someone via phone.
Email support is fine, but the level of support needs to be more in-depth, so I'm giving the CylancePROTECT support team a six.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
My company went with CylancePROTECT because my company has smaller companies or customers than enterprise customers. It's easier to deploy CylancePROTECT for smaller businesses, and it works better than SentinelOne, which is more for multinationals or enterprise businesses.
How was the initial setup?
The setup process for CylancePROTECT was pretty straightforward. Setup-wise, it's an eight out of ten.
How long deployment takes depends on the client. For a bigger client, it might take around two weeks for every device to be deployed, but for a small business with a few employees, deploying CylancePROTECT might take a few days.
What's my experience with pricing, setup cost, and licensing?
CylancePROTECT is worth the money, but I'm not sure of its exact price. I can't remember off the top of my head.
Which other solutions did I evaluate?
We evaluated SentinelOne.
What other advice do I have?
At the moment, my company uses CylancePROTECT, but it's considering using SentinelOne in the future for enterprise clients.
Between five thousand to ten thousand people use CylancePROTECT. That's the total for my company and its customers. Specifically, sixty to seventy people in my company use the solution, with forty engineers and developers, myself included. In contrast, twenty to twenty-five people belong to sales, marketing, and management teams.
CylancePROTECT requires maintenance, but not much because my company has strict policies. For example, a colleague came to me a few days ago because he wanted to install Oracle VM VirtualBox but couldn't because CylancePROTECT wasn't allowing him to install it. In that case, I either have to acknowledge it or make some policy changes because CylancePROTECT is too strict.
To anyone looking into implementing CylancePROTECT, my first question would be, "Are you working in a small or big company?" My advice to you would be based on your answer. My next question would be how strict you want your antivirus to be because if you want it to be less rigid and with less maintenance, then I'd tell you to use CylancePROTECT. If you're looking for a stricter solution with more maintenance, go with SentinelOne.
My rating for CylancePROTECT is eight out of ten because its technical support could be better, plus it needs to update its software regularly. The solution also has several areas for improvement, but the team still needs to work on it. In general, as an antivirus with an optics feature, CylancePROTECT is very good but still has room for improvement.
My company is a CylancePROTECT partner.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
IT Cyber Security Engineer at a legal firm with 201-500 employees
Could improve the number of false positives, and ineffective, but is simple to install
Pros and Cons
- "Its setup is simple if you have a Windows device; it is executable."
- "It was not effective. There were a lot of false positives, even when we use Adobe, and everybody uses Adobe, which is not a threat."
What is our primary use case?
We use CylancePROTECT for import protection, which is why we got it.
We switched from one product to another, believing this would be a better fit based on what we were informed, but it just didn't work as it should.
What needs improvement?
We have been dissatisfied with CylanceProtect and CylanceOPTICS and want to leave within the next several months. It just hasn't been an effective tool.
It was not effective. There were a lot of false positives, even when we use Adobe, and everybody uses Adobe, which is not a threat.
We are in the process of moving on to another solution.
For how long have I used the solution?
I have been working with CylancePROTECT for just over two years.
What do I think about the scalability of the solution?
We are an enterprise company.
Which solution did I use previously and why did I switch?
I have experience with Blackberry Cylance.
I have some experience with CylanceOPTICS which is part of CylanceGateway.
How was the initial setup?
Its setup is simple if you have a Windows device; it is executable.
You start the program, make a few clicks, and then enter an extension code into it. Then it begins to mute services before installing. It's fairly simple, maybe five or six minutes.
We never implemented a single solution. We completed what is known as the university installation, and it does the bundle installation. The single-bite variant was never used. We used the bundle to make it easier.
What's my experience with pricing, setup cost, and licensing?
We went through a third party initially to do the renewal, but we won't be renewing, we will move on to something else.
We received both. We prepared a quotation for a year. It is based on a calendar year. We spent a year on both Protect and Optics.
I would rate the pricing a three out of five.
What other advice do I have?
I would rate CylancePROTECT a three out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Buyer's Guide
Download our free BlackBerry Cylance Cybersecurity Report and get advice and tips from experienced pros
sharing their opinions.
Updated: February 2025
Product Categories
Endpoint Protection Platform (EPP)Popular Comparisons
CrowdStrike Falcon
Microsoft Defender for Endpoint
SentinelOne Singularity Complete
Cisco Secure Endpoint
Fortinet FortiClient
Cortex XDR by Palo Alto Networks
Symantec Endpoint Security
Intercept X Endpoint
Trend Vision One Endpoint Security
Trellix Endpoint Security
Kaspersky Endpoint Security for Business
ESET Endpoint Protection Platform
HP Wolf Security
Buyer's Guide
Download our free BlackBerry Cylance Cybersecurity Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- I'm building a next-gen AI powered threat intelligence platform. What's missing from existing solutions?
- What is the biggest difference between CrowdStrike and Cylance?
- How would you compare BlackBerry Protect vs Cortex XDR by Palo Alto Networks?
- What is the biggest difference between EPP and EDR products?
- Can Cylance be used with Symantec or Kaspersky endpoint solutions without conflict?
- When evaluating Endpoint Security, what aspect do you think is the most important to look for?
- What's the best way to trial endpoint protection solutions?
- What are the threats associated with using ‘bogus’ cybersecurity tools?
- Which Endpoint Protection Solution offers Zero Trust (ZTN) as a feature?
- What to choose: an endpoint antivirus, an EDR solution or both?
You make some good points, and I hope that we'll see Blackberry add to this area moving forward.
That said, there's quite a bit of info via CylanceOptics, and overall the system utilization is very low.