NetWitness NDR and Cisco Secure Endpoint are two leading cybersecurity solutions. Despite higher ratings for pricing and support for NetWitness NDR, Cisco Secure Endpoint stands out due to its comprehensive features, making it perceived as worth the price.
Features: NetWitness NDR offers advanced data collection, deep visibility into networks, and robust analysis capabilities. Cisco Secure Endpoint provides robust malware protection, wide-ranging security functions, and comprehensive threat detection. The main difference is the extensive security features of Cisco Secure Endpoint.
Room for Improvement: NetWitness NDR could improve in automation, simplifying workflows, and enhancing user interfaces. Cisco Secure Endpoint needs improvements in threat intelligence integration, lowering false-positive rates, and enhancing reporting capabilities. The distinct difference is the focus on workflow automation for NetWitness NDR compared to integration improvements for Cisco Secure Endpoint.
Ease of Deployment and Customer Service: NetWitness NDR deployment is complex, requiring significant time and technical expertise, while customer service is reliable. Cisco Secure Endpoint offers a smoother deployment process with faster setup and highly responsive customer service. The primary difference is the ease and speed of deployment favoring Cisco Secure Endpoint.
Pricing and ROI: NetWitness NDR setup costs are high, possibly affecting perceived ROI negatively. Cisco Secure Endpoint offers a better balance between cost and performance, yielding higher perceived ROI from users. The notable difference is that Cisco Secure Endpoint is seen as delivering greater value for its cost.
Cisco has good technical support, especially considering these are newer solutions compared to traditional routing and switching products.
Cisco Secure Endpoint is definitely scalable.
We have not encountered any problems.
The forensic capabilities need enhancement, especially for deep forensic data collection.
Cisco is aggressive in pricing, making it competitive and sometimes even cheaper than other good products like CrowdStrike, Microsoft Defender, or SentinelOne.
Cisco Secure Endpoint is very good in machine learning, which allows it to secure offline contents even if not connected to the internet.
Cisco Secure Endpoint is a comprehensive endpoint security solution that natively includes open and extensible extended detection and response (XDR) and advanced endpoint detection and response (EDR) capabilities. Secure Endpoint offers relentless breach protection that enables you to be confident, be bold, and be fearless with one of the industry’s most trusted endpoint security solutions. It protects your hybrid workforce, helps you stay resilient, and secures what’s next with simple, comprehensive endpoint security powered by unique insights from 300,000 security customers and deep visibility from the networking leader.
Cisco Secure Endpoint was formerly known as Cisco AMP for Endpoints.
Reviews from Real Users
Cisco Secure Endpoint stands out among its competitors for a number of reasons. Two major ones are its ability to enable developers to easily secure their endpoints with one single operation using its management console and its advanced alerting techniques.
Tim C., an IT manager at Van Der Meer Consulting, writes, "The solution makes it possible to see a threat once and block it everywhere across all endpoints and the entire security platform. It has the ability to block right down to the file and application level across all devices based on policies, such as, blacklisting and whitelisting of software and applications. This is good. Its strength is the ability to identify threats very quickly, then lock them and the network down and block the threats across the organization and all devices, which is what you want. You don't want to be spending time working out how to block something. You want to block something very quickly, letting that flow through to all the devices and avoiding the same scenario on different operating systems."
Wouter H., a technical team lead network & security at Missing Piece BV, notes, "Any alert that we get is an actionable alert. Immediately, there is information that we can just click through, see the point in time, what happened, what caused it, and what automatic actions were taken. We can then choose to take any manual actions, if we want, or start our investigation. We're no longer looking at digging into information or wading through hundreds of incidents. There's a list which says where the status is assigned, e.g., under investigation or investigation finished. That is all in the console. It has taken away a lot of the administration, which we would normally be doing, and integrated it into the console for us."
Using a centralized combination of network and endpoint analysis, behavioral analysis, data science techniques and threat intelligence, NetWitness NDR helps analysts detect and resolve known and unknown attacks while automating and orchestrating the incident response lifecycle. With these capabilities on one platform, security teams can collapse disparate tools and data into a powerful, blazingly fast user interface.
We monitor all Endpoint Protection Platform (EPP) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.