It has improved our monitoring capabilities.
Group CISO/CTO at Gulf Based Private Conglermate
Improved our monitoring capabilities and has a good graphical user interface
Pros and Cons
- "The most valuable feature is the alerts. The alerts are meaningful. The event rolls up into meaningful and actionable alerts rather than just being noise."
- "I would like for the product to work on the endpoints as well. I would like to see enhanced visibility into the endpoints and network but this solution only sits on the network itself."
- "The stability isn't good but I like the product."
How has it helped my organization?
What is most valuable?
The most valuable feature is the alerts. The alerts are meaningful. The event rolls up into meaningful and actionable alerts rather than just being noise.
What needs improvement?
The products is designed to monitor traffic sent and received via the corporate egress /network points.
I would be interested to see further integration or development of a capability to obtain visibility of mobile devices such as Laptops and Mobiles, which operate outside of the network and may communicate specifically when off the corporate network.
For how long have I used the solution?
We have done pilots with this solution and have used it for around three months.
Buyer's Guide
Darktrace
September 2026
Learn what your peers think about Darktrace. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
914,805 professionals have used our research since 2012.
What do I think about the stability of the solution?
The stability isn't good but I like the product. It's a good product but we need to look into other similar products that operate in the same zone: user behavior analysis and user detection. We need it to be good in comparison.
What do I think about the scalability of the solution?
We currently have an inner network. We don't have a full-scale deployment. It is on network segment where there are around 5,000 users. The full company would be around 9,000 users if we deployed it across all the subsidiaries.
How are customer service and support?
Their technical support is good.
Which solution did I use previously and why did I switch?
This is the first solution of this type that we've used. During the initial three month trial, we saw a lot of stuff from the product that we were unable to see through the conventional tooling technologies that we had in place.
How was the initial setup?
The setup was straightforward. It was a matter of hours. It took around two to three hours.
What other advice do I have?
My advice to someone considering this solution is to install it, conduct a pilot, and see. You need to see how easy it is to implement and you need to add it to install. You need to see what kinds of results it provides and compare it to your existing tool kit. The product demonstrates its actual capabilities when it's actually working. It's difficult to comprehend what it can actually do but it does give you an added level of visibility.
It has good capabilities. I would rate it an eight out of ten.
Cross-correlation with the endpoint based activities would be useful, like the ability to look at the deep supervised learning engine of the artificial intelligence unit and being able to take input data from the endpoints in order to apply the rules. It works on supervised learning and rules but I would like to be able to do things on different feeds as well.
It has a very good graphical user interface. The ability to get a console on the mobile phone and being able to respond and do basic incident response capabilities remotely is also a good feature.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
CEO at a tech services company with 11-50 employees
Good security and network visibility but they should develop integration with other SIEM solutions
Pros and Cons
- "DT console and alerting system allow getting detailed information about the behavior of users and malicious external or internal threats."
- "Block attack capabilities or integration with other SIEM solutions such as IBM QRadar."
What is our primary use case?
- Security
- Network visibility
- Breach detection in a VMware environment of about 25 VMs.
How has it helped my organization?
- Developed breach detection and security threats
- GDPR
- Privacy compliance
- ISO 27001 compliance.
What is most valuable?
DT console and alerting system allow getting detailed information about the behavior of users and malicious external or internal threats.
What needs improvement?
Block attack capabilities or integration with other SIEM solutions such as IBM QRadar.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Darktrace
September 2026
Learn what your peers think about Darktrace. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
914,805 professionals have used our research since 2012.
Solution Architect at a tech services company with 51-200 employees
Excellent portfolio, subscription based pricing, with plans to increase usage
Pros and Cons
- "I find the complete portfolio to be excellent."
- "I would like to see some additional enhancements."
What is our primary use case?
Our primary use case is for monitoring traffic for unusual behaviors.
What is most valuable?
I find the complete portfolio to be excellent.
What needs improvement?
I would like to see some additional enhancements and the price adjusted because it is expensive.
For how long have I used the solution?
I have been working with Darktrace for the past six months.
What do I think about the scalability of the solution?
It is scalable and we have ten users currently using the system. We do have plans to increase the usage.
How was the initial setup?
The setup is straightforward and not complex at all.
What about the implementation team?
The deployment took us about a week and a half to implement. We did not use a third party to implement but it is available.
What was our ROI?
The return on investment is evident when it comes to security incidents.
What's my experience with pricing, setup cost, and licensing?
The pricing is subscription-based and it is high.
What other advice do I have?
I would rate Darktrace an eight on a scale of one to ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network Security Engineer at a tech services company with 51-200 employees
The NDR is good in their solution and they have NTG for email
Pros and Cons
- "The NDR is good in their solution and they have NTG for email."
- "I think there is some MSSP missing."
- "They are too expensive compared with other vendors."
What is most valuable?
The NDR is good in their solution and they have NTG for email. They have multiple solutions, but for me, I was focusing on one solution, in the NDR section.
What needs improvement?
I think there is some MSSP missing. The market as a whole needs to enhance this area. Some additional integration would be helpful. They need to focus on having additional tools based on how competitive the market currently is.
For how long have I used the solution?
I have been working with Darktrace for the past six months.
What do I think about the stability of the solution?
I find the solution to be stable. I faced one issue and I think it is good after resolving that issue.
What do I think about the scalability of the solution?
I think it is scalable like Vectra.
How are customer service and support?
I have not used technical support for Darktrace.
What's my experience with pricing, setup cost, and licensing?
They are too expensive compared with other vendors.
What other advice do I have?
When considering Darktrace you need to have a plan and decide if it is something you really need as an organization. I would rate Darktrace an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Principle Cloud Architect at a tech services company with 11-50 employees
Intelligent threat response has improved incident handling and provides clear attack path visibility
Pros and Cons
- "Regarding the autonomous response feature, I appreciate how it functions within the platform."
- "If asked to rate Darktrace support on a scale from zero to ten where ten is the best, I would give them five points."
What is most valuable?
Regarding the autonomous response feature, I appreciate how it functions within the platform.
What needs improvement?
Based on my experience, I believe the solution could be improved in some areas, and there are certain drawbacks that I have encountered.
For how long have I used the solution?
I have been working with Darktrace for approximately one to one and a half years or longer.
What do I think about the stability of the solution?
In general, I would say that the interface of Darktrace is intuitive enough, and it aids in understanding threat landscapes and attack paths.
What do I think about the scalability of the solution?
Regarding scalability, I would rate it eight points.
How are customer service and support?
If asked to rate Darktrace support on a scale from zero to ten where ten is the best, I would give them five points.
How would you rate customer service and support?
Neutral
How was the initial setup?
Regarding the installation and initial setup, I found it to be straightforward rather than complex.
What's my experience with pricing, setup cost, and licensing?
Concerning pricing for the product, I would say it is somewhat expensive.
What other advice do I have?
I have rich experience with many tools including Vectra, Cisco firewall, and Check Point.
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company has a business relationship with this vendor other than being a customer. MSP
Last updated: Jan 5, 2026
Flag as inappropriateBuyer's Guide
Download our free Darktrace Report and get advice and tips from experienced pros
sharing their opinions.
Updated: September 2026
Product Categories
Network Detection and Response (NDR) Email Security Intrusion Detection and Prevention Software (IDPS) Network Traffic Analysis (NTA) Extended Detection and Response (XDR) Cloud Security Posture Management (CSPM) Cloud-Native Application Protection Platforms (CNAPP) Attack Surface Management (ASM) AI-Powered Cybersecurity Platforms AI ObservabilityPopular Comparisons
Fortinet FortiGate
Cortex XDR by Palo Alto Networks
Cloudflare
Cloudflare One
Datadog
Qualys TotalCloud
SentinelOne Singularity Endpoint
Dynatrace
Wazuh
SentinelOne Singularity Cloud Security
Microsoft Defender for Cloud
IBM Security QRadar
Prisma Cloud by Palo Alto Networks
Buyer's Guide
Download our free Darktrace Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- I'm building a next-gen AI powered threat intelligence platform. What's missing from existing solutions?
- Which is better - SentinelOne or Darktrace?
- What are the pros and cons of Darktrace vs CrowdStrike Falcon vs alternative EPP solutions?
- Which alternative solutions (other than Darktrace) do you recommend for an SMB?
- How does Crowdstrike Falcon compare with Darktrace?
- How does Network Detection and Response (NDR) Differ from SIEM?
- What aspects of network security are more concerning to small and medium-sized enterprises?
- What are the best practices for Security Operations Center (SOC)?
- What is the future of the Network Operation Center (NOC)?
- Which alternative solutions (other than Darktrace) do you recommend for an SMB?















