No more typing reviews! Try our Samantha, our new voice AI agent.
IT/Marketing at Mason Law and Planning Group, LLC
Real User
Jul 7, 2022
Offers excellent reporting, advanced ML, and comprehensive training in a highly scalable and stable solution
Pros and Cons
  • "The report function through Gmail is probably the most valuable feature. The next most valuable features are simulation and training."
  • "IRONSCALES offers a sense of security and confidence from being well protected."
  • "I would love to see the indication of compromise and how the solution utilizes open source resources. It would be good to see that included in the paid versions. It would be a small addition but add a lot of value for clients."

What is our primary use case?

We mainly use the solution for email security and threat mitigation through that vector, which could be phishing, malware, and malicious attacks. It allows us to inspect emails and enables end-users to report and quarantine potential threats in a sandbox, which is very valuable. The response time is imperative for us, a notification gets to me as the tech very quickly, and I can mitigate any issues we may have.

We have IRONSCALES deployed over two companies. The leading company owns the account, and we have two companies under that: Mason Law and Planning Company and Warrior Insurance. They're in the same building on different floors, but both companies are situated with IRONSCALES at all endpoints for all users. We don't have any off site users, with the occasional exception. The vast majority of our staff work on-site. We don't have anyone working from outside the office. 

How has it helped my organization?

We spend significantly less time dealing with email issues. For example, the routine process of determining if an email is a threat or not is now taken care of in a minute or less, instead of up to five or ten minutes. This adds up and results in a lot of time saved. This product also makes our end-users feel comfortable. Our employees are more confident in their email abilities because of the training and their months of experience using this program. 

What is most valuable?

The report function through Gmail is probably the most valuable feature. The next most valuable features are simulation and training.

I would say IRONSCALES is probably one of the best products of its class that I've seen. I've seen some other companies that offer similar technology and a similar product, where the training is an afterthought or add-on. IRONSCALES do offer premium training, but the regular training is very well-rounded. The integration of excellent reporting, single sign-on, and freedom from logins and passwords for end-users makes this a fantastic product. 

The AI and machine learning capabilities of the solution are significant. I have a small background in AI and machine learning, and we discussed how those functions would operate in our system with IRONSCALES. I've never seen a machine learning program work as effectively and often as this one. There aren't as many hitches as I would expect to find in a solution of this kind.

If I had to put a number on it, I would say 95% of the time, it works flawlessly. The remaining 5% of the time, a tech like myself would have to intervene, but in my opinion, that's an excellent standard to have. 

The automated detection and response capabilities have reduced the time we have spent manually reviewing emails and events a hundredfold.

I think the ability to customize offered by the solution works well. 

The solution has allowed me to spend more time on other activities. It's sped up our business process, and our response time has gone from five to ten minutes to less than a minute. Sometimes even more time is saved, especially in the last couple of months. The first week we implemented the solution, the saved time wasn't as noticeable. Three or four months down the road, I can see we have saved many hours, if not more. 

What needs improvement?

I would love to see the indication of compromise and how the solution utilizes open source resources. It would be good to see that included in the paid versions. It would be a small addition but add a lot of value for clients. 

Buyer's Guide
IRONSCALES
July 2026
Learn what your peers think about IRONSCALES. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
908,402 professionals have used our research since 2012.

For how long have I used the solution?

We have been using the solution for nine days.

What do I think about the stability of the solution?

I'd say 98 to 99% time, the product is up and running. It has minimal downtime, if at all.

What do I think about the scalability of the solution?

The solution is entirely scalable. We have up to 50 licenses at the moment. It wouldn't be difficult if we needed more than that. I would say it's perfect as far as scalability. 

How are customer service and support?

I would give the technical support a nine out of ten only because when we did contact support for the unprotected mailboxes, my contact was out on vacation. That happens, but the backup solution was another customer service rep who said we should re-do the whole integration process. I wasn't satisfied with that, as I didn't want to restart the program, break it, and make more work for myself. That was my one issue with the customer service. 

Which solution did I use previously and why did I switch?

We tried other solutions. We've had a secure gateway, and tested traditional VPNs and a few other options. The good customer service is the main reason we moved to IRONSCALES. They are excellent at ensuring everything is up to date and working, and the follow-ups are phenomenal. Next, I would say the technology integrates well with our office setup. Because it's a SaaS product and lives in the cloud, it doesn't affect other things like a gateway. Gateways can influence IP addresses, and printers don't like change. We previously had a lot of compatibility issues with other products because they would affect the network, whereas IRONSCALES sits on top of it, in a sense, which fits in well with our use case.

How was the initial setup?

It was more straightforward than the other Google Workspace app installations I've carried out. I also received advice from our other company. I would say that IRONSCALES goes above and beyond to make sure everything is connected correctly. When we first implemented the solution, it showed our emails as unprotected for a while, but the program was functioning correctly and checking emails. That was resolved within a couple of weeks and probably would've been much faster, but my customer support contact was out on vacation for about seven days, which is fine. Everything got taken care of, which was to my liking. 

I wouldn't necessarily say the system requires maintenance. I check that everything is working correctly on a daily basis, and that improves with time. As the ML algorithm understands the company functions better, the automation improves significantly. Initially, more manual labor was involved, but still less than if you didn't have IRONSCALES. After a month or so, the automation was functioning well and required less involvement from me. Now it requires at most a few minutes of my time every day.  

What about the implementation team?

I implemented the solution with the help of an IRONSCALES rep. 

What was our ROI?

When it comes to cybersecurity it's hard to pinpoint an ROI, but I would say that, based on what this product has done for our company, there's no way it hasn't saved us money.

What's my experience with pricing, setup cost, and licensing?

We pay $3000 plus a little more a year for the number of employees we have, and we're not even that big. The solution is at the higher end in terms of cost. It's not the most expensive product, but I would say it's worth the price if you have a high volume of email traffic. In our case, the solution has inspected over 162,000 emails between three and four months. It saved us a lot of time and money. It's a worthwhile investment because a bad actor only has to succeed once; we must defend against everything in our business. IRONSCALES offers a sense of security and confidence from being well protected. 

Which other solutions did I evaluate?

We looked at other gateways like Perimeter 81, and other antivirus software, but IRONSCALES is more of a dedicated email security tool we use in conjunction with our antivirus. 

The AI/ML program that IRONSCALES has is much more efficient and effective than any other ML program I've seen or experienced. The UI is very user-friendly and looks good, which aids in quicker information access. I would say a lot of the alternatives are very clunky; I wouldn't quite say MS-DOS, but Windows 98 style, old and blocky.

What other advice do I have?

I would rate this solution a ten out of ten. I feel like nobody ever gets perfect scores, but the downsides are minimal and quickly resolved, so the product is quite remarkable.

The solution is only situated for employees with specific email addresses. Apart from that, it's a private cloud deployment. 

The biggest lesson I've learned is that even with my level of expertise, there are still emails that I probably wouldn't have noticed checking them manually.

Which deployment model are you using for this solution?

Private Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Google
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
IT Manager at LAVI Light Rail Operation & Maintenance
Real User
Jun 27, 2022
It has an easy installation that can be done in a matter of minutes
Pros and Cons
  • "There is buzz around phishing awareness training. When I make a campaign, all of a sudden people in our organization are talking, thinking, and wondering about it. Therefore, it keeps people on their toes. That is perfect because it does exactly what we want it to do."
  • "IRONSCALES has enabled us to spend more time on other activities because it is just install and forget."
  • "I would like it if IRONSCALES had some sort of reminder mechanism, meaning IRONSCALES knows if a user completed the training or not. As long as it hasn't been completed, it keeps reminding every so often, alerts the manager, etc. Right now, it is all in the hands of the employee, and not all of them continue the process, which is a shame."
  • "As far as training awareness, I would give it 6.5 to 7 out of 10."

What is our primary use case?

We needed it for mail relay and phishing awareness training.

We use the IRONSCALE solution on all our email platforms, including mobile apps, web access, and Outlook on computers.

Our deployment model is hybrid. Our private environment is in Microsoft 365 and we also have SaaS through BDO.

Since we are using Microsoft 365 and everybody is basically connected to that infrastructure for their emails, all we had to do was implement IRONSCALES into 365 and that covered my whole organization. There are about 175 email boxes. We expect that to at least double that amount in the next couple of years

How has it helped my organization?

There is buzz around phishing awareness training. When I make a campaign, all of a sudden people in our organization are talking, thinking, and wondering about it. Therefore, it keeps people on their toes. That is perfect because it does exactly what we want it to do. 

Everything seems fine with the mail relay. I can't complain.

What is most valuable?

Monthly, we have been using the campaigns. Besides that, the actual work that it does as a mail relay, protecting our email infrastructure, is valuable. Also, the ease of integration into Microsoft 365.

The artificial intelligence and machine learning capabilities of the solution are very important because we don't know what we don't know. The fact that I can use the community for artificial intelligence based on other case studies is perfect. Why not learn from other people's experience?

We use the AI to determine if an email is phishing or dangerous.

For email security effectiveness, I would give it 8 out of 10. As far as the mail relay is concerned, we haven't had major attacks, concerns, or phishing emails. So, we can't complain. Thank God everything has been working fine, but we never really tested IRONSCALES to its fullest. We have been using its automatic features where it gives me advice that some email might be phishing and so on. As for that, it does work really well. However, I can't tell you that it is battle-tested. That is why I am not giving it more than 8.

What needs improvement?

As far as training awareness, I would give it 6.5 to 7 out of 10. In regards to phishing awareness training, I have been having some issues with the Hebrew aspects of IRONSCALES since most of our company's employees need the Hebrew language, and the phishing awareness in Hebrew is so-so. In addition, the biggest problem that I have is with people who fail since most of them just don't do the training, and IRONSCALES doesn't have some sort of reminder feature.

When someone fails, if they open up the email and push on the link, then they get to a dedicated website which is supposed to give them basic information, e.g., what they could have noticed, then some sort of link to an instructional video, and in the end, training. I just noticed that 95% of the people who click on the email are flunking. For the awareness training, they don't continue to watch the video or do the training. Instead, they just exit the screen and move on.

I would like it if IRONSCALES had some sort of reminder mechanism, meaning IRONSCALES knows if a user completed the training or not. As long as it hasn't been completed, it keeps reminding every so often, alerts the manager, etc. Right now, it is all in the hands of the employee, and not all of them continue the process, which is a shame.

I would like to have more of an ability to intervene in the landing page for phishing awareness, e.g., more design options, change logos, color, and fonts. Right now, it is a template.

For how long have I used the solution?

We have been using IRONSCALES since February 2022.

What do I think about the stability of the solution?

I would rate the stability as 10 out of 10. It is always up and running. I have never seen downtime.

It requires someone from my help desk team to keep watch on the logs and see if there are any alerts or events. Besides that, there isn't much maintenance.

What do I think about the scalability of the solution?

It seems to me that it is really easy to scale up or down, meaning I just need to add licenses. 365 is already implemented. So, as long as I just add email boxes, they are automatically within the system. Therefore, I just need to be up to par as far as licenses are concerned. It scales within seconds.

How are customer service and support?

Since I have it as a SaaS, I never really need to talk to IRONSCALES. I just talk to BDO who just does whatever needs to be done. I would rate the support from BDO as nine out of 10.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

My organization didn't use another solution before IRONSCALES.

How was the initial setup?

The initial setup was straightforward. It took 10 minutes and then the product was up and running.

It provides an easy installation. It is a matter of minutes, which makes a big difference. Imagine the difference if you had to install a server or physical product. This solution is all software.

We started as a PoC. We implemented IRONSCALES as a trial version into our 365. From that point, we purchased it, then it became a non-evaluation version.

What about the implementation team?

The deployment took one person and someone from IRONSCALES.

What was our ROI?

We realized the solution's benefits within the PoC.

IRONSCALES has enabled us to spend more time on other activities because it is just install and forget. Our main goal was not to deal with it, meaning I can implement it and it does what it's supposed to do without a lot of intervention on our side unless some sort of case or event happens. That is exactly what it did. I have a fully functioning mail relay that basically takes care of itself. Obviously, we have to view all the logs and everything, and that is something our SOC also does. It just takes a burden off my shoulders. I can let it run.

If we can prevent a phishing attack or ransomware attack, then the ROI will be immense. At this point in the game, when everything is okay, I can't really see an ROI. However, when time comes, it will be there.

What's my experience with pricing, setup cost, and licensing?

They are pretty much the same as all the other competitors in the market.

There is an installation cost. Since we have this as a managed service, we pay for licensing and the managed service itself. Other than that, there are no additional costs.

Which other solutions did I evaluate?

We were looking for some sort of platform that we could use to do phishing awareness training. We were looking into Cisco and different solutions. Eventually, we came upon IRONSCALES because we also needed a mail relay. This actually gave us both solutions in the same spot.

We evaluated Cisco's trainee portal and Fortinet FortiMail. In the end, we went with IRONSCALES because it was both products in one solution. Another reason being that we wanted a managed solution. Our provider in Israel, BDO, is an official retailer of IRONSCALES. They work with IRONSCALES and offer this service as a service. Therefore, we got a managed IRONSCALES solution.

Microsoft 365 offers standard anti-phishing functionality, but nothing beyond that.

What other advice do I have?

Try it. It takes seconds.

I would rate the product as nine out of 10.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Buyer's Guide
IRONSCALES
July 2026
Learn what your peers think about IRONSCALES. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
908,402 professionals have used our research since 2012.
Tamunoibiton Adoki - PeerSpot reviewer
Information Security Officer at a financial services firm with 201-500 employees
Real User
Jul 26, 2022
Saves a lot of hours, has good detection and remediation capabilities, and is worth the investment
Pros and Cons
  • "AI-driven phishing detection and incident remediation are valuable. It saves time from having to do manual analysis and investigation, and we also get alerts for phishing emails."
  • "It is an important part of our security infrastructure and gives us confidence that we are protected from email threats."
  • "Even though they have been continuously improving it, it is not 100% there. We have had a few incidents where legitimate emails were getting blocked, and we had to manually remove those emails from quarantine. It is 90% effective or accurate because, on rare occasions, some emails from customers were not getting delivered. In one or two instances, their emails got blocked by IRONSCALES, and we had to manually remove the emails from quarantine. I would like them to improve their algorithm to avoid flagging genuine emails as malicious. I would also like to be able to whitelist certain email addresses. I'd love to be able to whitelist a particular customer."

What is our primary use case?

The main challenge that we wanted to solve with this solution was the email-based attacks. They are a major threat for our staff and customers. So, we are using this solution for protection from threats and remediation of phishing emails. We also use it for simulation to train our staff to recognize a phishing email. For those users who click on the phishing email, we provide the training content to improve their awareness.

How has it helped my organization?

Its artificial intelligence and machine learning capabilities are really important and helpful in saving time. It saves a lot of hours, and we don't have to do a manual review of each incident or email. Without IRONSCALES, we will have to rely on our staff to report emails that might be malicious, but you can't always depend on the staff to do that.

It is an important part of our security infrastructure. It gives us confidence that we are protected from email threats.

It allows us to report an email as spam. If our staff suspects an email to be malicious, they can report it as spam.

It is helpful in assessing the awareness level of our staff. We compare the metrics of every new phishing campaign with the metrics of previous campaigns. We also determine if the awareness training we are conducting for our staff is effective. We can see all the data. If a lot of people have clicked on the phishing email, we get to know that we need to step up our efforts on phishing awareness.

Its automated detection and response capabilities save a lot of time. We are a financial institution, and we get quite a lot of emails. If someone has to manually review and investigate each alert or email event, it would be a full-time job. On a daily basis, it would take more than three hours of analysis work. A financial institution like ours receives quite a lot of emails from customers and internal staff, and IRONSCALES saves a lot of our time. We don't have to dedicate someone to manually review alerts or emails.

The time that we have saved by not having to manually review each incident can now be used to focus on other tasks. 

It has also helped reduce the number of people or analysts needed to deal with and respond to email incidents.

It allows us to customize the automated detection and response capabilities. Each email that IRONSCALES detects has a confidence level rating. For example, it has 90% or 70% confidence in a phishing email. We have the ability to configure the threshold for automatic remediation. For example, we can say that for emails with a 70% or higher confidence level, it can automatically remediate, but for emails with a 69% confidence level, it should raise an alert, and we'll manually investigate. It gives us the ability to raise or reduce the threshold.

What is most valuable?

AI-driven phishing detection and incident remediation are valuable. It saves time from having to do manual analysis and investigation, and we also get alerts for phishing emails.

What needs improvement?

Even though they have been continuously improving it, it is not 100% there. We have had a few incidents where legitimate emails were getting blocked, and we had to manually remove those emails from quarantine. It is 90% effective or accurate because, on rare occasions, some emails from customers were not getting delivered. In one or two instances, their emails got blocked by IRONSCALES, and we had to manually remove the emails from quarantine. I would like them to improve their algorithm to avoid flagging genuine emails as malicious. I would also like to be able to whitelist certain email addresses. I'd love to be able to whitelist a particular customer.

It is good for user awareness, but I would love to have more content for our staff that is related to not only phishing but also general awareness. I don't know whether it is a functionality that is already available and we have not subscribed to it, but I would love to be able to send awareness emails to staff on different topics related to email security. They should provide us with more security awareness content. Based on the current trends in the security landscape, they can give us security content in emails that I can easily share with my staff to keep them aware.

I use IRONSCALES' mobile app. The mobile app doesn't notify me about the incidents, but I get email alerts instantly, which are helpful when I'm on the move. I get them a lot on my mobile. I get notifications in the email that an incident has been automatically remediated. If an email doesn't have the specified threshold level, I can quickly log in to the IRONSCALES app and do a manual authentication. It helps a lot when I'm on the go, or I don't have my PC with me. Email alerts are fine with me, but it probably would be good to have push notifications from the mobile app. If someone doesn't have an email client on their mobile, they can get notifications through the app.

For how long have I used the solution?

I have been using this solution for just under a year. I joined the department in September, and I started using the product in September last year.

What do I think about the scalability of the solution?

It is a cloud-based solution. So, I expect it to scale well regardless of the number of users we have. We don't expect to experience a drop in performance. Cloud-based solutions generally scale well.

We use it for every email account we have. We currently have between 700 to 800 users, and it is being used for all our departments, users, and group mailboxes.

We definitely have plans to increase its usage. We are currently growing, and we are expecting a significant addition to the number of users in Q3 and Q4.

How are customer service and support?

We haven't had an issue so far. So, we haven't contacted their support. During implementation, we got full support from them, and we loved the support we got. We have no issues with their support. I would rate them a nine out of ten.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I am not aware of any other solution being used previously. IRONSCALES was already in the company when I joined.

How was the initial setup?

It was already in place when I joined. In terms of maintenance, it doesn't require any maintenance from our end. All we have to do is integrate our Outlook email server with IRONSCALES, and that's it. 

What was our ROI?

We have definitely seen an ROI. The amount that we pay for licenses is definitely way less than what we would pay if we are hit by a ransomware attack. So, it definitely provides a return on investment.

We were able to realize its benefits immediately after the deployment. We started analyzing emails and getting alerts right from the time it was activated. You have to do a bit of tuning for the threshold, but the effect was immediate. We didn't have to wait even a bit for it to be effective.

What's my experience with pricing, setup cost, and licensing?

Considering the value it provides, it is definitely worth the cost. We don't have to do manual analysis and remediation of phishing emails, which saves us a lot of hours.

Its licensing is based on the number of users being supported and the number of email addresses being protected. I'm not aware of any additional costs.

What other advice do I have?

I would definitely recommend the product. It is definitely worth the investment.

I would rate it an eight out of ten because I would like to have some of the features. We don't have them currently, and I'm not sure whether these features are available with an additional license.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Vice President of Information Technology at MENIN HOTELS LLC
Real User
Jul 14, 2022
Allows other users to flag an email as spam, has excellent detection capabilities, and is easy to deploy and manage
Pros and Cons
  • "The fact that it is set-and-forget is valuable. Once you turn it on, you very rarely have to micromanage it, whereas, with a lot of spam filters, you have to go in very often."
  • "It is just good to know that it is watching when we don't have to watch; I can go to sleep, and it is still working."
  • "Its UI could be improved. My pet peeve with a lot of these cloud-based systems is that a lot of times, the interface for the management is a little clunky. If you live and breathe IRONSCALES all day long, you'll obviously know where everything is just from muscle memory, but the system is not designed for people to be in it all day long. You're only supposed to occasionally look at it. When things get moved around, it is not necessarily that intuitive. I'm an IT guy, and I can pretty much take the worst UI and figure it out, but the menus and the options in the interface could be a little cleaner graphically. If you have a quick problem that you want to resolve, it takes a little bit of digging in the admin console, whereas it should take a few clicks up front."
  • "Its UI could be improved. My pet peeve with a lot of these cloud-based systems is that a lot of times, the interface for the management is a little clunky."

What is our primary use case?

It is a glorified email spam filter. IRONSCALES catches whatever the built-in Microsoft spam filter doesn't catch. Its intelligence is different. Microsoft spam filters are only strong to a certain extent, and IRONSCALES catches what falls through the cracks, which is super important. It checks the links and other things, and our mailboxes are much cleaner.

How has it helped my organization?

Every company is different. In our company, it is helpful because it lets people know what to look out for. The reason we got IRONSCALES was that you can train all day long, but not everyone is going to get it. That's just the nature of working in the industry. It helps to remind people from time to time, but the scams evolve, and IRONSCALES has also evolved. So, the training is much less important than it used to be in terms of how to determine what's what in the malicious message, whether it is phishing, etc.

Its artificial intelligence and machine learning capabilities are the most important pieces. It is just good to know that it is watching when we don't have to watch. I can go to sleep, and it is still working. The AI knows what to pick up on. It learns from other companies. The key is that it is not just our tenants that it is examining; it is examining all the tenants. So, it can take what it learns from a different company that has nothing to do with us and apply it to our mailbox. So, the whole system gets smarter overall.

It provides the ability to customize the automated detection capabilities. The system is set up for that when you start, and there is not a whole lot of going back in and reteaching it after the fact. Only when we're doing the training, to teach people what to look out for, we intentionally do white list certain messages that are designed to be spammed. This way we can go back, look and find out which employees need a refresher on how to find a malicious email because they opened the wrong email or clicked the wrong link. That's the only time that we would go and update anything. Most of the time you leave it alone.

It enabled us to spend more time on other activities. Previously, when we had very strong spam filters, a lot of things were positive. It took a lot of digging. Every time somebody would send an email saying that they are missing something, we'd have to go back and release it. IRONSCALES doesn't do that. The messages that are legit go through because the false positive rate is very low. It seems to catch real problems, and it lets the clean ones through, which is what it is supposed to do. The only time we have an issue is when people word an email poorly, it might be considered a SPAM message, whereas it is not. It is legit. In such a case, I just have to release it, and it is fine. 

What is most valuable?

The fact that it is set-and-forget is valuable. Once you turn it on, you very rarely have to micromanage it, whereas, with a lot of spam filters, you have to go in very often. 

Its nicest feature is that other users in our company can flag something as spam, and it'll automatically flag it for everybody else in the company. It'll pull that out of your mailbox before it becomes an issue. This way 50 people don't get the same notice. One person clicks it, and it automatically goes away. 

What needs improvement?

Its UI could be improved. My pet peeve with a lot of these cloud-based systems is that a lot of times, the interface for the management is a little clunky. If you live and breathe IRONSCALES all day long, you'll obviously know where everything is just from muscle memory, but the system is not designed for people to be in it all day long. You're only supposed to occasionally look at it. When things get moved around, it is not necessarily that intuitive. I'm an IT guy, and I can pretty much take the worst UI and figure it out, but the menus and the options in the interface could be a little cleaner graphically. If you have a quick problem that you want to resolve, it takes a little bit of digging in the admin console, whereas it should take a few clicks up front. That's about it, and that's a superficial issue. I understand that it is difficult to refine when you have a lot of information to deliver. It is not an easy job. Microsoft gets it wrong too.

For how long have I used the solution?

We went live at the very beginning of this year, but we started using it before that. We had a tenant change in our Microsoft system. So, we waited, and then at the very beginning of this year, we cut over to a new hosted email platform.

What do I think about the stability of the solution?

It just works. We haven't had any outages. 

What do I think about the scalability of the solution?

We have a Microsoft Office 365 tenant. In that tenant, there are multiple domains or multiple companies with multiple employees. We don't discriminate or distinguish between the two. We simply apply IRONSCALES to the tenant, and it grabs all the accounts regardless of the domain they are associated with. We don't have anybody who is not being protected. We did not granularly decide who gets what. It was a very simple, shotgun approach. We have one tenant, and we have one IRONSCALES that fits in the tenant, and that was it. We did not decide to tailor it in any particular way.

It is easy to scale. When we grow, it grows with us, and if we run out of seats, I just call our customer service rep and say that we added 10 more people, and we need 10 licenses. It is that simple.

How are customer service and support?

Their service is great. We have a customer service representative. I know they have a tech team, but we haven't really had any tech questions for them since we did the deployment. 

For any random question that comes up, I'll just fire off an email to our rep who can decide whether to open up a ticket with their tech team or not. Usually, it is very quickly resolvable just with our customer service representative before it requires opening a ticket. I don't have to open tickets or get a call, which is super helpful for me. I can just shoot a quick email, and they take care of it, and it is done. They can almost be my IT department. 

I would rate their service a 10 out of 10. They are friendly and responsive.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We had Cyren previously. Cyren is great. We routed all of our messages through Cyren first, and it would flag everything, and then it would release whatever we wanted into the mailboxes. The problem was that if we found something that was spam, it was too late to release. IRONSCALES sits in the tenant. It'll pull messages out of the inbox. So, even if something made it through the first time, we can recall it. Instead of tightening up the filter and hoping nothing gets through, with this solution, even if something gets through, after we determine that something is bad, we can remove that. If somebody didn't check their messages today, and we had a spam message, by the time they get to the office, it is gone. It is not sitting in their inbox waiting. That was the major reason. It can pull out even old messages that are in their box, which is very good. It is like a housekeeping service.

Our email provider supplies anti-phishing functionality, but we went with IRONSCALES because Microsoft's spam filtering isn't as sophisticated. It is very clunky to use, and it wasn't available at the time when we signed up with IRONSCALES. Because of the AI of IRONSCALES, it is much easier to look through it, whereas Microsoft's anti-spam Defender filter is a work in progress, and they change its branding all the time. It was easier for us to stick to one that we knew would double-check and catch whatever slips through the cracks of Microsoft. Microsoft doesn't have AI, and they're not necessarily using group analysis. It is only based on whatever its filters think is good or bad. So, I just didn't trust it. I trusted IRONSCALES a little more.

How was the initial setup?

It was very simple. There were a few basic steps, and that was it. When you log into the IRONSCALES site, you set up your tenant, and you set up your domain. After that, you just have to authorize the bot in your mail tenant. Once that's done, it automatically scans your tenant for applicable mailboxes, and you tell it what you want it to do. That's it.

There are five steps to the whole process. The trickiest one is making sure that it has grabbed all mailboxes when it did its pass to make sure it has all the right accounts. As we add employee accounts to our system, it automatically grabs them and sets them up dynamically. So, there are no extra steps that we have to do. After a mailbox is removed from our tenant, it'll automatically get purged from IRONSCALES by itself. It doesn't require a lot of hand-holding.

What about the implementation team?

I was the one who did the work with the IRONSCALES team, but technically from an invoicing perspective, IRONSCALES doesn't bill us. IRONSCALES bills our security company, and we pay the security company. I'm assuming there is some kind of revenue share.

Which other solutions did I evaluate?

I don't remember what they were at the time. Another security company that we work with also recommended IRONSCALES. So, with various vettings and the blessing from our third-party security consultant, it was an easy decision.

What other advice do I have?

I would advise taking the time to learn about it during the installation. You shouldn't just rely on the IRONSCALES team to do it because they can do it in their sleep. The best way to learn how it works is to do the work. It is good to figure out what the menus do, what it means, and what the interface does. I know a lot of IT departments like to farm it out, but don't farm it out. Take the time to see how it is working and how you can best integrate with it. Some people just don't pay attention, but it is something to which you should pay attention.

I would rate it a 10 out of 10.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
reviewer1605060 - PeerSpot reviewer
Digital Risk Intelligence Partner at a comms service provider with 1-10 employees
Real User
Aug 16, 2021
Easy to set up with great AI and very good threat-sharing capabilities
Pros and Cons
  • "The stability is good."
  • "I couldn't believe that it could filter out 35% of the email."
  • "The integration with Google Suite needs to be better. it's something they can work on."

What is our primary use case?

We help customers use this to help them to secure against business email compromises, phishing, and impersonation.

What is most valuable?

They're outstanding as a solution. They have a threat-sharing capability so that you get information from all the customers regarding any phishing attack. That's a great feature for us due to the fact that we get information very fast if someone else in the world has seen that email. 

The artificial intelligence is excellent. They are able to use it to recognize phishing emails due to the language used.

The initial setup is very easy.

The solution can scale.

The stability is good.

We've been satisfied with technical support.

What needs improvement?

The integration with Google Suite needs to be better. it's something they can work on.

The pricing is a bit high.

In the future, I'd like to see digital exposure of the users, such as credential exposure, or this kind of feature.

For how long have I used the solution?

We've been working with the solution over the past year.

What do I think about the stability of the solution?

The solution has been very stable. It's reliable. We haven't found bugs or glitches and it doesn't crash or freeze. 

What do I think about the scalability of the solution?

We don't have any issues with scaling - even when dealing with many different customers. 

Our clients range in size. We help companies with anywhere from 50 users to thousands of users. 

How are customer service and technical support?

We have been satisfied with the solution's technical support. They have been helpful and responsive. 

Which solution did I use previously and why did I switch?

We have used Darktrace in the past. The reason we are looking into Darktrace is to have another option. However, for us, Darktrace is not so good as IRONSCALES. IRONSCALES is easier to use, easier to implement, and more accurate when it comes to false positives.

We've also worked with Proofpoint and some Microsoft-owned options, however, we haven't worked with anything else. 

How was the initial setup?

The initial setup is amazing. it's not overly complex or difficult at all. 

It was fast, easy, and straightforward to implement and deploy. On average, with the customers, it takes us around 10 minutes to one hour to set everything up, depending on the size of the customer.

What about the implementation team?

We can assist our clients with the initial setup.

What's my experience with pricing, setup cost, and licensing?

We have a yearly licensing contract. The pricing is a bit expensive, and we'd, of course, like it to be lower, however, we really like the product.

What other advice do I have?

We are a customer as well as an integrator. In some cases we sell the solution, in some cases, we provide the customer with the service. We are a security service provider.

We are working with the latest version. IRONSCALES is a universal service cloud for service. So you always have the latest one.

I would recommend the solution to other users and companies. I couldn't believe that it could filter out 35% of the email. We've very satisfied.

I'd rate the solution at a nine out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. System provider, Partner
PeerSpot user
reviewer2537955 - PeerSpot reviewer
Systems Engineer at a tech services company with 10,001+ employees
Real User
Top 5
Sep 24, 2024
Has an easy to setup phase and can be managed conveniently by the users
Pros and Cons
  • "The most valuable features of the solution are that it is easy to set it up, install, and manage the product."
  • "The tool supports 15 to 16 languages, but the content it uses in the training in Spanish has certain limitations."

What is our primary use case?

I use the solution in my company to stop phishing and spam efficiently and automatically.

What is most valuable?

The most valuable features of the solution are that it is easy to set it up, install, and manage the product.

What needs improvement?

I think maybe on the side of the awareness training, the tool can improve a little more information and have some other languages since even though English is good, Spanish is not so good. The tool can improve the content in Spanish and other languages. The tool supports 15 to 16 languages, but the content it uses in the training in Spanish has certain limitations.

For how long have I used the solution?

I have been using IRONSCALES for a year. My company is an end user of the tool.

What do I think about the stability of the solution?

It is a very stable solution as it is software that runs in the cloud. I didn't have any outages with the tool.

What do I think about the scalability of the solution?

It is a very scalable solution. I know the tool scales up very well. Some of our customers have thousands of use of mailboxes. In my case, only one hundred users use the tool. It requires very little installation, but I know thousands of customers.

How are customer service and support?

The technical support offered is very good. The tool's support team attends very quickly to the support tickets raised. The technical support is very good at resolving issues.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I have used a security gateway from Forcepoint, which was a lot more complicated to maintain and set up. Forcepoint decided to discontinue its solution for email gateway, and then it decided to introduce another solution in the market that includes AI.

How was the initial setup?

The product is easy to set up as it is an API-based solution. With IRONSCALES, you don't have to do anything on the platform. You just need to do the integration and the connection with Office 365 tenants, and that is it.

I rate the product's setup phase as a ten out of ten.

The solution can be deployed by one person from IRONSCALES, who will create the tenant for me. Then, I do the rest of the setup process, which includes three or more steps, but it can be done in minutes.

The solution can be deployed in 15 to 30 minutes.

What's my experience with pricing, setup cost, and licensing?

The product is available as a middle-priced tool. I think it is not the cheapest solution. There are other solutions apart from IRONSCALES that are more expensive, while some are a little bit more cheap, but they are not available with the same capabilities.

What other advice do I have?

The automated response capabilities are very accurate for detecting suspicious activities and suspicious languages used by the attackers.

The only people needed when using the tool are to take care of the console and an analyst. In some cases, some incidents require an analyst to complete the analysis of the email. I don't create incidents that can be automatically resolved by AI. I create incidents that need a review from an analyst. The only people who need to be aware of the incidents and where such details should not be classified is when it comes to analysts. I don't need to do any maintenance process for the tool every day. Everything is available as a service, so I don't need to do anything to maintain the platform apart from dealing with the non-classified incidents.

The tool uses a lot of AI technologies to detect the accuracy of the email, especially to filter out phishing emails. It not only detects phishing emails but also provides a preview of who the attackers are before we receive the real phishing email. It is not just to detect phishing emails but also to detect the intent of the attacker in creating a phishing email.

I rate the tool a nine and a half out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free IRONSCALES Report and get advice and tips from experienced pros sharing their opinions.
Updated: July 2026
Buyer's Guide
Download our free IRONSCALES Report and get advice and tips from experienced pros sharing their opinions.