No more typing reviews! Try our Samantha, our new voice AI agent.

Cisco XDR vs Secureworks Taegis XDR comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Ranking in Extended Detection and Response (XDR)
4th
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
114
Ranking in other categories
Endpoint Protection Platform (EPP) (4th), Endpoint Detection and Response (EDR) (6th), Ransomware Protection (2nd), AI-Powered Cybersecurity Platforms (1st)
Cisco XDR
Ranking in Extended Detection and Response (XDR)
9th
Average Rating
8.4
Reviews Sentiment
6.9
Number of Reviews
21
Ranking in other categories
No ranking in other categories
Secureworks Taegis XDR
Ranking in Extended Detection and Response (XDR)
18th
Average Rating
8.6
Reviews Sentiment
6.0
Number of Reviews
9
Ranking in other categories
Network Detection and Response (NDR) (14th)
 

Mindshare comparison

As of July 2026, in the Extended Detection and Response (XDR) category, the mindshare of Cortex XDR by Palo Alto Networks is 4.6%, down from 5.1% compared to the previous year. The mindshare of Cisco XDR is 1.6%, down from 1.7% compared to the previous year. The mindshare of Secureworks Taegis XDR is 1.3%, up from 1.2% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Extended Detection and Response (XDR) Mindshare Distribution
ProductMindshare (%)
Cortex XDR by Palo Alto Networks4.6%
Cisco XDR1.6%
Secureworks Taegis XDR1.3%
Other92.5%
Extended Detection and Response (XDR)
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
Fred Parks - PeerSpot reviewer
Senior Systems Consultant at W.C. Bradley Co.
Centralized visibility has transformed incident investigations and now cuts response time dramatically
Workflows could definitely be easier to work with. Workflows are automated tasks that can be kicked off inside of a playbook. When someone is responding to something, they can click a button and it will perform automated tasks for them inside of these other products. The product can actually control the behavior of a firewall and you can write a rule in a firewall from Cisco XDR without having to go into the firewall software. However, if it is not a native workflow automation, it is very difficult to create your own. It is not intuitive and you almost have to be a developer and get really good with the API. This could definitely be improved on, particularly the custom workflow automation. Another thing that could be improved is Cisco documenting how it makes decisions, because there are certain factors or criteria that it uses from the source products. Cisco XDR gets all of its data from the integrations, so if you do not integrate anything, it is not going to do anything. Sometimes in these integration products, such as Secure Network Analytics or Cisco Security Exposure, they could be generating some type of alert and you do not necessarily see that in Cisco XDR. This is because it knows, maybe because of these other products, it is not really a big deal and is not big enough to raise an incident. However, I do not think Cisco does a great job in explaining what those rules are, such as why this happens and how this happens. This can cause some questions and some concern. I think it is doing the right thing, but I think it would be better if they had a rule set to say, based on this data, this is how the product actually works.
Mohammad Talha Talkin Alam - PeerSpot reviewer
Assistant Manager IT at PDS Multinational
Improved network protection has secured our servers and monitors web and application traffic
Till now, I have not seen any weak point that needs to be improved in Secureworks Taegis XDR. I think that since the technology is becoming upgraded, it will be good for Sophos to include more features in future updates of this solution. Secureworks Taegis XDR is a good product, but it should include AI technology.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Cortex XDR is a very capable solution for protecting large networks and a lot of endpoints. It's very useful because the automation is very high, and if you combine it with the features on Palo Alto firewalls, it provides very strong protection."
"The most valuable features are the fact that it was running in the background and it would intercept any weird stuff, and the fact that it would send things directly to the cloud for sandboxing. It's quite practical."
"One of the main benefits of the solution is its intelligence to correlate the events into an incident."
"The solution's most valuable feature is the user interface."
"It is easy to use."
"We have found in our test Cortex XDR by Palo Alto Networks to be a very good tool."
"It can automatically correlate events and logs, which is very helpful for an IT administrator. It can correlate different kinds of malware activities over a network, agent, or host system. You do not need to do it manually. It is a good feature. It is also a user-friendly solution. We have deployed it on the cloud because our space does not provide any flexibility for on-premises deployment, but Palo Alto has added some flexibility to install it on-premises. It must be like the same Cortex XDR agent for all the VPN services, web filtering services, and everything else."
"Cortex XDR features advanced threat detection capabilities."
"In just four months, I have seen a good return on investment with Cisco XDR, as I have reduced incidents and saved time because previously, if I encountered any incident, I would have spent considerably more time and effort reaching out to every security control on my network and checking logs across multiple systems."
"Cisco XDR helps to detect the threats in my organization, prioritizes the most critical incidents, and responds to them faster as well."
"My advice for other organizations considering Cisco XDR is that it offers proactive security measures that are really very helpful."
"The feature I appreciate the most about Cisco XDR is the reliability."
"The biggest ROI from Cisco XDR was time savings in the SOC, as we saw triage and investigation time drop by roughly 40 to 50 percent for common incidents because analysts were not manually coordinating alerts across multiple tools anymore."
"The features of Cisco XDR benefit my company since time is money. When outages happen and when a customer can't reach the internet, they get agitated. Therefore, the quicker we can mitigate an issue, our customers get happier in a quicker fashion."
"The merging of all of that data into one display is probably the best benefit of Cisco XDR."
"Cisco XDR has positively impacted my organization because instead of ten people working on one event, Cisco XDR can do many things an analyst can do, reducing the human effort required and coordinating everything."
"Using Secureworks Taegis XDR has positively impacted our organization overall."
"The price for Secureworks Taegis XDR is very competitive."
"The features I find most valuable are the fact that Secureworks Taegis XDR runs itself without any form of intervention."
"It's a complete solution package."
"The initial setup was straightforward."
"The auto-triage feature of Secureworks Taegis XDR makes my workflow easier and efficient, helping me shorten the time of responding to every alert, make my activities productive, and manage everything that I need to check every alert and detection."
"Secureworks Taegis XDR has positively impacted our organization by improving detection rates and reducing our time; as I mentioned, it saves us from manually going through all the logs, which is not practical."
"Sophos is a good XDR, and I recommend it for large companies since they have approximately 2,000 or 3,000 devices and can implement it as it is the best XDR."
 

Cons

"It would be better if they could educate the customers more. Some sort of seminars and roadshows will help educate the customers and show what the product can do. The price could be better. It would also help if they had a team for deployment and support."
"Based on our experience so far, its implementation is quite complex."
"It's not an ideal choice for smaller businesses, as you need a minimum of 200 endpoints to even use the solution at all."
"Whenever the tool releases a new version when deploying the product across the organization, I feel like there are some disturbances in the CPU usage after upgrading the tool to the latest version."
"I have faced some issues with Cortex XDR by Palo Alto Networks; there is room for improvement in the sense that certain options prevent us from seeing and segregating data."
"Currently, we are monitoring all USB drives and ports but we would like to improve our device control capabilities."
"Cortex XDR by Palo Alto Networks is a very good product, but financially, it is very expensive, so the company should look into that area."
"We would also like to have advanced tech protection and email scanning."
"Customer support for Cisco XDR is a bit slow in the initial stages, but I believe it has improved nowadays."
"Workflows could definitely be easier to work with."
"Improvements in Cisco XDR revolve around performance."
"One area where Cisco XDR could improve is the learning curve for new users, especially during initial setup and workflow customization."
"I believe the false positive reports can be reduced through AI automation, as well as the duration while loading the software."
"The licensing of Cisco XDR is a bit complicated. The cost can depend on what it is, and the process can be a little complicated."
"Cisco XDR can be improved in terms of out-of-the-box integrations and standard operating procedures available on the platform where we would not have to refer to documents outside of the platform to integrate."
"Cisco XDR could be improved in areas concerning dashboard customization and reporting flexibility."
"Hardware compatibility could be an area for improvement."
"Customer support for Secureworks Taegis XDR is not that bad; they are reachable but not super efficient."
"The efficiency or the smooth navigation of the website or the application can be improved in Secureworks Taegis XDR."
"Secureworks Taegis XDR is a good product, but it should include AI technology."
"We found limitations in the XDR's detections, lacking the ability to create customized detection and log parsing rules."
"I do not see any other problems with Secureworks Taegis XDR besides pricing."
"The pricing could be improved."
"To improve Secureworks Taegis XDR, we need to enhance the support part."
 

Pricing and Cost Advice

"It's way too expensive, but security is expensive. You pay for your licensing, and then you pay for someone to monitor the stuff."
"The pricing is a little high. It is per user per year."
"The pricing is okay, although direct support can be expensive."
"I am using the Community edition."
"Very costly product."
"Its pricing is kind of in line with its competitors and everybody else out there."
"It has a higher cost than other solutions, like CrowdStrike or Microsoft’s EDR tools, but it reduces the cost of our operations because it’s a new generation antivirus tool."
"The cost depends on your chosen license type, like Pro or other licenses."
"The licensing of Cisco XDR is a bit complicated. The cost can depend on what it is, and the process can be a little complicated."
"The pricing is six out of ten."
report
Use our free recommendation engine to learn which Extended Detection and Response (XDR) solutions are best for your needs.
905,526 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Construction Company
12%
Financial Services Firm
11%
Manufacturing Company
10%
Comms Service Provider
9%
Outsourcing Company
20%
Computer Software Company
9%
Government
8%
Manufacturing Company
8%
Financial Services Firm
15%
Manufacturing Company
13%
Computer Software Company
9%
Educational Organization
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business46
Midsize Enterprise21
Large Enterprise53
By reviewers
Company SizeCount
Small Business17
Midsize Enterprise9
Large Enterprise4
By reviewers
Company SizeCount
Small Business2
Midsize Enterprise1
Large Enterprise7
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
What is your experience regarding pricing and costs for Cisco XDR?
The centralized visibility, automation, and reduction in investigation time have provided good operational value for ...
What needs improvement with Cisco XDR?
Cisco XDR could improve the UI customization experience. Some workflows still feel more complex than they need to be,...
What is your primary use case for Cisco XDR?
We mainly use Cisco XDR for centralized threat detection and incident investigation, especially for correlating endpo...
What needs improvement with Secureworks Taegis XDR?
To answer how Intercept X with XDR can be improved as an end customer, I would need to sit down with the solution. In...
What is your primary use case for Secureworks Taegis XDR?
I am working with Trend Micro Vision One, mostly MCC Vision One, for smaller customers. I see a lot of customers opti...
What advice do you have for others considering Secureworks Taegis XDR?
I do have feedback about the customizable workflows. I have a customer who has pretty much loaded the XDR agents on h...
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
No data available
Secureworks Taegis NDR
 

Interactive Demo

Demo not available
Demo not available
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
Information Not Available
Information Not Available
Find out what your peers are saying about Cisco XDR vs. Secureworks Taegis XDR and other solutions. Updated: June 2026.
905,526 professionals have used our research since 2012.