Try our new research platform with insights from 80,000+ expert users
Mohamed Elnobi - PeerSpot reviewer
Cloud Cyber Security Tech Lead at Vodafone
Real User
Enables efficient threat detection and investigation through seamless cross-border capabilities
Pros and Cons
  • "Trend Vision One's greatest assets are its cloud-based platform and credit-based purchasing system, which eliminate the need for traditional licensing and procurement processes, enabling quick product acquisition within one or two days."
  • "One area that requires improvement is the installation process of the agents, as it is not seamless."

What is our primary use case?

Vision One access supports multiple modules, including endpoint protection, the XDR module, and the Cloud One module, which are the ones that particularly caught our interest.

We have been doing a proof of concept for Trend Vision One to assess its capabilities as a cybersecurity solution. Vodafone is partnering with Trend Micro to offer security services and products to our customers to secure their environments, similar to a SaaS solution. We are exploring it as a partnership opportunity to provide enhanced security solutions to our customers.

How has it helped my organization?

We conducted a POC and tested multiple use cases by downloading malicious files and observing their behavior. Trend Vision One successfully detected and blocked all threats, including malicious files, scripts, and even dormant scripts that later became active. All these threats were stopped at the endpoint level, demonstrating that Trend Vision One effectively defends against malware, ransomware, and malicious scripts.

Trend Vision One incorporates a machine learning agent designed to defend against advanced threats, such as zero-day attacks. This agent monitors endpoints for malicious activity and, if detected, automatically quarantines the affected machine to conduct further analysis.

It employs machine learning to quarantine devices during ransomware attacks, however, this functionality has not yet been tested.

Trend Vision One provides a single console with a unified dashboard that consolidates information from our entire environment.

The single console provides end-to-end visibility into our IT security environment. We tested the endpoint security, and the SDR performed exceptionally well, providing a clear topology and metrics of our environment. This allows us to monitor the status of each node within our network.

The Trend Vision One platform was integrated with a Linux-based Service Engine to facilitate integration with third-party IT security solutions.

Learning to use Trend Vision One was straightforward, thanks to the helpful courses available on their portal and the excellent support provided during product introduction.

Administering Vision One endpoint security is easy through the single console.

We successfully tested Trend Vision One in a hybrid environment, with components deployed both on-premises and in the cloud.

Trend Vision One offers virtual patching to protect against vulnerabilities while vendors develop permanent patches. This is crucial because vendor patches can be delayed, leaving systems exposed. Virtual patching provides immediate protection, acting as a temporary shield until the official fix is released.

Since we are still in the testing phase, we have not yet seen a reduction in viruses or malware. However, we anticipate potential improvements in security operations across hybrid environments if implemented fully.

What is most valuable?

Trend Vision One's greatest assets are its cloud-based platform and credit-based purchasing system, which eliminate the need for traditional licensing and procurement processes, enabling quick product acquisition within one or two days. Trend Micro's strong reputation and excellent threat intelligence further enhance the platform's value. The analytics are also good, particularly the XDR and cloud assessment tools, which correlate logs and information to consolidate alerts for the SOC team.

What needs improvement?

One area that requires improvement is the installation process of the agents, as it is not seamless. The installation sometimes requires multiple troubleshooting steps and is not straightforward.

Buyer's Guide
Trend Vision One
October 2024
Learn what your peers think about Trend Vision One. Get advice and tips from experienced pros sharing their opinions. Updated: October 2024.
824,067 professionals have used our research since 2012.

For how long have I used the solution?

We have been conducting the POC of Trend Vision One for approximately three to four months.

What do I think about the stability of the solution?

There were no major issues with stability, no bugs, glitches, or errors, except for the challenges faced with agent installation. I rate the stability of Trend Vision One eight out of ten.

What do I think about the scalability of the solution?

I rate the scalability of Trend Vision One ten out of ten.

How are customer service and support?

We did not engage with customer support during the POC phase, so we cannot provide feedback on that aspect at this time.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

For endpoint protection, we have used Microsoft Defender and Cortex XDR. We encountered issues with those solutions, but Trend Vision One seemed to address these concerns effectively.

How was the initial setup?

The initial setup was not complex. The prerequisites were set first, allowing integration to be completed in about a week.

What's my experience with pricing, setup cost, and licensing?

The pricing is mid-range, neither cheap nor overly expensive. The cost is considered fairly priced.

What other advice do I have?

I would rate Trend Vision One nine out of ten.

Our team from our organization includes three members involved in the POC testing.

I recommend Trend Vision One to other users based on our experience during the POC phase.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Microsoft Azure
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
PeerSpot user
reviewer2286210 - PeerSpot reviewer
Chief Technology Officer at a hospitality company with 5,001-10,000 employees
Real User
Top 10
Has built-in AI, a single pane of glass, and centralized visibility
Pros and Cons
  • "We are very impressed with the single pane of glass visibility that Trend Micro XDR provides."
  • "I think that continued optimization of the environment towards automation and orchestration, a kind of layer that sits underneath all of the technologies, would be extremely important."

What is our primary use case?

We use Trend Micro XDR for rapid response to end-user computing and security concerns.

As a health system, one of our core challenges is ensuring full visibility into our attack surface. We have many thousands of endpoints and end users that must be properly secured and protected. Our primary use case was to improve visibility, and response time, and reduce complexity. That is why we chose Trend Micro XDR.

Trend Micro XDR is deployed on Trend Micro's private cloud.

How has it helped my organization?

We are using Trend Micro XDR on our endpoint and server infrastructure. The coverage is extremely important to our organization.

Trend Micro XDR provides us with centralized visibility and management across protection layers.

The centralized visibility and management across protection layers have helped our efficiency. The most significant advantage is that we used to manage these platforms with three or even five engineers, and now we're managing them with one.

It is extremely important to us that we can drill down from the executive dashboards into XDR detections. This provides us with the single pane of glass view that I mentioned previously. Being able to see at a high level that there may be systems that are behind on patch levels or need additional service or support, and then being able to drill down specifically to an individual machine, which may be unique in our environment, is very helpful.

We use the risk index to evaluate ourselves holistically, including our performance against best practices and security, as well as our performance against other healthcare systems around the world. This allows us to identify areas where we may have vulnerabilities or where we are particularly strong so that we can focus on improving in the areas where we need to.

Trend Micro XDR has helped us improve our resource utilization through automation, reducing manual effort and enabling faster response times. In under a week, we had tuned our environment to perform optimally.

Trend Micro's Managed XDR service has significantly reduced our team's workload by nearly 50 percent, providing a big improvement in our overall threat intelligence and endpoint security.

The Managed XDR service has enabled our team to work on other tasks. This additional availability for our staff has allowed us to reduce our need for contractors. If we are overburdened, we will hire contractors to assist in other areas of the business. However, because we have become more efficient, I have been able to hire some of those contractors and reduce the burden of contract labor.

Attack surface work management capabilities have been extremely valuable. The user and identity services provided by ASRM help us to focus on and improve visibility into end-user behavior, including that of endpoints such as laptops and desktops, the network, cloud infrastructure, and applications.

The ability to detect our blind spots has significantly improved our security posture. Seeing everything clearly in a single, easy-to-understand dashboard allows us to allocate our resources directly to where they are needed most, enabling us to respond faster.

The biggest advantage of Trend Micro XDR is that it has helped decrease our time to detect and respond to threats by around 50 percent.

Trend Micro XDR has helped reduce the amount of time we spend investigating false positive alerts by 60 percent.

Trend Micro XDRs automation capabilities save us around ten hours per week. 

What is most valuable?

We are very impressed with the single pane of glass visibility that Trend Micro XDR provides. It allows us to work from a single console instead of having to use four or five separate tools to maintain the same level of security. This is extremely helpful.

The manageability and artificial intelligence built into Trend Micro XDR are extremely helpful.

What needs improvement?

I've seen a lot of improvement in just the year that we've been with Trend Micro. However, I think that continued optimization of the environment towards automation and orchestration, a kind of layer that sits underneath all of the technologies, would be extremely important. When we look at the speed and sophistication of attacks today, such as ransomware, malware, and cyber threats, we need tools and technologies that can react faster. So, I think integration with automation, orchestration, and artificial intelligence will help tremendously.

For how long have I used the solution?

I have been using Trend Micro XDR for one year.

What do I think about the stability of the solution?

Trend Micro XDR is remarkably stable.

What do I think about the scalability of the solution?

Considering our growth rate of nearly 30 percent per year, Trend Micro XDR is scalable enough to keep up, so we have no concerns.

How are customer service and support?

Technical support is exceptional. They are extremely engaged and supportive of everything we have needed.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We previously used Sophos but switched to Trend Micro because of its enhanced capabilities.

How was the initial setup?

The initial deployment was straightforward. The deployment took between one and two weeks to complete. 

Moving between security tools requires an analysis of the existing environment to understand the current configuration, rulesets, and architecture. This analysis is quickly followed by implementation to improve the security posture and validation to ensure that the infrastructure is not only properly protected, but better protected than before.

Three people were required for the deployment.

What was our ROI?

We have been able to reduce some labor costs and use our resources more efficiently. These savings of hours per week are definitely a return on investment.

What's my experience with pricing, setup cost, and licensing?

The solution is fairly priced.

What other advice do I have?

I would rate Trend Micro XDR ten out of ten. The solution works extremely well for us. In a healthcare environment, the types of data and the sheer size of the attack surface are somewhat extraordinary. Having the enhanced capabilities of the Trend Micro toolset has been very important to us, and I strongly recommend it.

We have 11,000 users, five acute care hospitals, and around 80 clinics.

Two people are required to maintain Trend Micro XDR for the investigation of threats and incidents. When threat intelligence comes in from Trend Micro or we receive an alert, we validate or respond to it. A lot of this process has been automated, which has helped tremendously.

I strongly recommend Trend Micro XDR and advise doing a proof of concept against any current tool on the market, as it works extremely well and a POC can clearly demonstrate this in a short period of time.

Which deployment model are you using for this solution?

Private Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Buyer's Guide
Trend Vision One
October 2024
Learn what your peers think about Trend Vision One. Get advice and tips from experienced pros sharing their opinions. Updated: October 2024.
824,067 professionals have used our research since 2012.
Jana Odineca - PeerSpot reviewer
Co-founder & CTO, Director (Special Advisory Services) at ORNA Inc.
Real User
Top 20
Consolidated security operations enhance threat management
Pros and Cons
  • "Trend Vision One's most valuable feature is its centralized console, which provides comprehensive security features, including attack surface risk management."
  • "Overall, I rate Trend Vision One a ten out of ten as I am extremely happy with Trend Micro's capabilities and their platform's strength."
  • "Expanding compatibility to include currently unsupported security tools, such as firewalls, would be beneficial."
  • "To improve support, the company should streamline communication and reduce response times."

What is our primary use case?

We primarily use Trend Vision One for its XDR capabilities, email security features, and MDR services offered through ServiceOne. Leveraging these Trend Vision One products allows us to provide robust security solutions to our customers.

My customers range from small non-profits with 40 endpoints to large enterprises with over 2,000 endpoints across diverse sectors, including energy, manufacturing, finance, and software.

How has it helped my organization?

Vision One possesses machine learning predictive capabilities that have already proven effective. In the past week alone, it detected and blocked two scans for unknown threats. This capability is crucial, especially since our predominantly Canadian customer base faces an elevated risk of cyberattacks from China due to the recent government-level ban on TikTok. Consequently, we anticipate an increase in attacks. Trend Vision One boasts the largest zero-day initiative, renowned for its proficiency in detecting such threats.

The single console in Vision One streamlines cross-layer detection, threat hunting, and investigation, incorporating sandbox analysis and log search capabilities. It allows for endpoint isolation, remote shell establishment, and integration with tools like Active Directory and Microsoft Entra ID. Automated playbooks enable actions such as endpoint isolation, custom script execution, forensic investigations, user lockouts, and password resets, all of which are customizable. This automation is crucial for containing threats outside of working hours, as playbooks can be configured to automatically execute actions based on specific criteria, mitigating damage before staff return.

The single console provides comprehensive visibility across the entire IT security environment, including endpoints, cloud activity, workflow protection, email protection, and mobile device management, all within a single, unified platform.

Trend Vision One integrates with a range of security products, including various SIEM solutions, vulnerability management tools, and select firewalls. A comprehensive list of compatible products is available on Trend Micro's website.

Trend Vision One is relatively easy to learn for those with some security background. While first-time users may find it initially confusing, abundant learning resources such as YouTube videos and comprehensive documentation are available to help users quickly familiarize themselves with the platform.

Some of my customers maintain hybrid environments, and Trend Vision One enhances visibility by consolidating all systems into a single platform.

Trend Vision One has malware scanning capabilities, allowing it to detect, quarantine, and block malware effectively.

Trend's Managed Detection and Response service provides continuous 24/7 monitoring, effectively reducing staff workloads by eliminating the need for in-house security monitoring.

Trend Vision One improves my organization's visibility by consolidating security functions into a single console. These capabilities enhance our security operations, making it easier to manage threats.

What is most valuable?

Trend Vision One's most valuable feature is its centralized console, which provides comprehensive security features, including attack surface risk management. This allows for benchmarking our risk score against similar organizations based on size, industry, and location. Additionally, it offers endpoint vulnerability assessment, user behavior analytics, and standard XDR detection capabilities.

What needs improvement?

An area for improvement is integrating more tools with Trend Micro's SIEM. Expanding compatibility to include currently unsupported security tools, such as firewalls, would be beneficial.

For how long have I used the solution?

I have been using Trend Vision One for approximately four months.

What do I think about the scalability of the solution?

Trend Vision One is scalable.

How are customer service and support?

To improve support, the company should streamline communication and reduce response times. Specifically, support tickets often require customers to provide redundant information, creating unnecessary extra steps in the process.

How would you rate customer service and support?

Positive

What other advice do I have?

Overall, I rate Trend Vision One a ten out of ten as I am extremely happy with Trend Micro's capabilities and their platform's strength.

Trend Vision One is easy to maintain.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Flag as inappropriate
PeerSpot user
Osajie Williams Irekponor - PeerSpot reviewer
Associate Manager - Information Security at a tech vendor with 10,001+ employees
Real User
Top 10
Reliable threat intelligence with customizable reporting improvements
Pros and Cons
  • "Its threat intelligence sources enable it to automatically block domains known for command-and-control callbacks, effectively preventing attacks from those sources."
  • "The reports lack detail and customization options, particularly for XDR, which hinders our ability to provide tailored reports to clients."

What is our primary use case?

We use Vision One XDR to provide managed security services to our clients by correlating logs from various Trend Micro products like Apex One, Cloud One, and Deep Security. Vision One acts as a central monitoring platform, providing a single pane of glass view of our clients' security posture. This simplifies monitoring and allows us to easily create playbooks and analyze alerts. While our EDR solutions, Apex One, Cloud One, and Deep Security provide robust security features like anti-malware, web reputation, and intrusion prevention, Vision One enhances this by correlating logs and leveraging threat intelligence to identify incidents missed by these individual products. Essentially, Vision One functions like a level three SOC analyst, providing an additional layer of protection and ensuring comprehensive security coverage.

How has it helped my organization?

Trend Vision One's centralized visibility and management are crucial for our managed security services because they reduce the overhead required for monitoring. As an XDR solution, it performs many of the tasks an analyst would typically handle, streamlining our workflow and allowing us to focus on in-depth analysis when needed. This reduction in workload is a significant benefit, enabling us to efficiently provide comprehensive security services to our clients.

The executive dashboard is a valuable tool for analyzing the threat level of specific assets, particularly for generating end-of-month reports that detail threat and alert volumes, and highlight high-security risks. This comprehensive analysis helps customers understand their security posture and take appropriate action to strengthen their defenses. However, it's important to note that the dashboard's usefulness may vary depending on the individual customer's needs and priorities.

The risk index is a useful tool that provides benefits, but its value depends on the specific needs of the customer. Some customers may utilize the risk index to identify assets with high-security risks, allowing them to address vulnerabilities and implement necessary patching. However, other customers may rely on alternative sources for vulnerability visibility and, therefore, may not prioritize the risk index. While not always a primary focus, the risk index remains a valuable resource.

Trend Vision One provides immediate benefits upon deployment. Its built-in XDR, which includes EDR functionality and integrates with existing security models like Apex One, Cloud One, or Workload Security, allows for seamless provisioning of endpoints and workloads. Rigorous testing confirms that Vision One effectively identifies and correlates alerts, including those missed by other EDR solutions. This enhanced detection capability is evident during post-deployment testing, as Vision One Workbench alerts are generated immediately.

We use Trend Vision One to consolidate security across hybrid environments.

We use attack surface risk management and often customize it in our reports to meet client needs. This service helps identify vulnerabilities and blind spots in their environments. For instance, we assisted a customer experiencing recurring attacks due to unknown vulnerabilities. Our attack surface management analysis provided the data to identify and patch these critical vulnerabilities, ultimately enhancing their security posture.

Vision One XDR significantly reduces threat detection and response time by automating the analysis typically done by a level two or three analyst. It provides a comprehensive view of the environment, incorporating behavioral analysis and intelligence sources to quickly identify unusual activity. This eliminates the need for manual investigation of logs and data, allowing analysts to focus on addressing actual threats. The XDR's automated workbench triggers alerts with a high degree of accuracy, minimizing false positives and further streamlining the security process.

We use security playbooks for certain low-level security alerts because many of these alerts, despite the large volume of data they represent, do not require significant time or attention. Playbooks are particularly useful in these situations as they automate the process of blocking the source or IP address associated with the alert.

What is most valuable?

Vision One offers several features I value. 

The threat intelligence sources enable it to automatically block domains known for command-and-control callbacks, effectively preventing attacks from those sources. 

Additionally, the security playbooks provide templates to block URLs or scripts, enhancing endpoint protection. 

Finally, the console allows for remote connection to endpoints, enabling direct investigation and remediation within the customer's environment. This flexibility and comprehensive functionality make Vision One a valuable tool.

What needs improvement?

Trend Micro is making many improvements, including addressing some of our feature requests. However, their reporting functionality needs improvement. The reports lack detail and customization options, particularly for XDR, which hinders our ability to provide tailored reports to clients. For example, we cannot generate reports on threat intelligence data from XDR, making it difficult to assess the protection received from external sources. This limitation also prevents clients from seeing the total value of XDR, including external factors contributing to their security posture. Threat intelligence is crucial, and clients want to understand its impact. Therefore, enhancing report customization, especially for XDR, would be a significant improvement.

For how long have I used the solution?

I have been using Trend Vision One XDR for one and a half years.

What do I think about the stability of the solution?

Lagging does happen in Trend Vision One but it is infrequent and does not significantly disrupt operations. This is typical for many SaaS platforms and not a major issue.

What do I think about the scalability of the solution?

Trend Vision One is scalable, allowing for flexibility from four licenses to a hundred or more, depending on how much or how fast scaling is needed.

How are customer service and support?

The experience with customer service can vary depending on the case. Simple issues might involve referring to KB articles for resolution, while more complex issues might need backend support, which can take time. Overall, my experience has been positive.

How would you rate customer service and support?

Neutral

How was the initial setup?

Trend Vision One is easy to set up and can potentially be handled by one person. However, teamwork is preferred to ensure accuracy, catch potential errors, and maintain a high standard of service.

What's my experience with pricing, setup cost, and licensing?

Trend Micro's licensing is outsourced to third-party vendors, resulting in price variations depending on the vendor. Since Trend Micro doesn't directly handle pricing, I cannot provide specific cost details.

What other advice do I have?

Trend Vision One XDR is an excellent security product that deserves a ten out of ten rating. It's surprising that more companies haven't adopted XDR, given its advantages over traditional SIEM solutions. XDR automates tasks like configuration, signature creation, and rule implementation, significantly reducing the manual workload required with SIEM. While I expect a shift towards XDR, many companies still rely on SIEM, which seems inefficient in comparison.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: MSP
Flag as inappropriate
PeerSpot user
Cephas Odero - PeerSpot reviewer
Head of ICT at Sumac Microfinance Bank Ltd
Real User
Top 10
A unified platform for simplified operations and automation
Pros and Cons
  • "From an automation point of view, I find the ability to curate and deploy playbooks very helpful. I find that very convenient for us."
  • "There should be a bit more dynamism when it comes to their playbooks in terms of the action triggers. That is the only thing that I would want to see a bit more."

What is our primary use case?

Its main purpose is orchestration where I have full visibility into all the different Trend Micro products I use, and it is all centralized in a single dashboard. There is ease of use with this centralized dashboard. With this centralized management, I can dive into technicalities, and I am able to do all my workbench investigations. It is quite clear, and I do not have to sift through different logs. It makes our work so easy when we need to respond to or remediate a particular issue.

The main problem that we wanted to solve by implementing Trend Vision One was the blindspots. We tend to focus on endpoints, but we forget IoT devices such as printers and CCTV cameras. This is where we had serious blind spots simply because these devices do not have an operating system. For us, it was just about eliminating these blind spots. That was our number one focus.

How has it helped my organization?

It has been exceptional. If you look at the evolution of the Trend Micro products up until Vision One, you can see that they do what they say they do. It has worked for me so well. That is why I have had it all these years.

We have protection against zero-day threats. One of the things that pushed me towards Trend Micro was the fact that they have the R&D for the zero-day initiative. They are a pioneer in terms of classifying CVEs. It gives me comfort. When you go and check the workbench or the report, you can see the type of exploits that it was able to detect, which have even been classified as CVEs.

Apart from the things that I do in IT, my responsibility is to protect my company's assets. I am able to safeguard my data against ransomware. The company does not have to worry that they can be held at ransom. The assurance that they do not have to pay just to get their data back makes it easy to sleep at night.

We have a single console for cross-layer detection, threat hunting, and investigation. We have what we call the executive dashboard. This is what I share with the C-suite. It is quite easy for me to break down cybersecurity in a business way, and then, of course, we have the operational dashboard and the security dashboard where I centralize all the products into one single pane. From an orchestration point of view, I love Trend Vision One. We are able to orchestrate all of our different products from one single dashboard.

Trend Vision One provides visibility into different products. I have a 360-degree view of my entire IT infrastructure, which helps me understand my threat landscape and the way it looks. The beauty of it is that it has metrics. I can see how I am performing as compared to 30 days or 7 days ago in terms of the risk indicator. Is it going up or is it going down? This is important for me because I am able to forecast and anticipate behaviors or patterns from the people perspective and the process perspective. I know what I need to do and train people on, and in terms of processes, I know what I need to do to clean up my policies. In terms of technology, I can assess if there is any other thing of Trend Micro that I need to supplement to make sure I am fully protected.

Our response is instantaneous. I do not have an exact percentile in mind when it comes to the reduction in the response time, but our response is instantaneous.

I have integrated it with my NUC, my firewall, and my database monitoring tool. Trend Micro has a feature for virtual patching through Trend Micro TippingPoint. It instantaneously does the patching and cascades them across. Apart from what we call scheduled patching, on-demand patching is a part of their product features.

Trend Vision One is very easy to learn. This is the second organization where I am using this Trend Micro solution. When I introduced it, my team did not know about Trend Vision One, but within a month, simply with the help of the business portal where we have the e-learning, they were fully skilled and even certified at the entry-level of Trend Micro. Their feedback was that it was quite easy for them to adopt.

Trend Vision One is not at all difficult to administer.

We have seen a reduction in viruses and malware since implementing this solution. They provide you with the metrics for risk posture. You can see the reduction in your threat landscape. It goes granular to the point of telling you which type of malware or threat you are exposed to and the reduction. It is very definitive from a percentile marking. In my previous organization, we saw about a 75% reduction when we rolled it out. We were previously using something else there.

It reduces administrative overhead. I stopped adding additional headcounts from a security analyst and a security officer's point of view. It helps me reduce the overhead. On average, considering the annual wage of a security analyst, there is a reduction of about 7,000 dollars per annum.

I use Trend Micro's managed XDR services in conjunction with Vision One Endpoint Security. It reduces overhead. It is a fully-fledged managed service, so I do not need to have the business invest in an in-house SOC. It is a whole lot cheaper.

What is most valuable?

From an automation point of view, I find the ability to curate and deploy playbooks very helpful. I find that very convenient for us. It gives away the manual process. There is the ease of use.

I love what they have done with their Trend Companion AI, where it becomes so easy to have it do something for you instead of sifting through different tabs. So, the automation element and their new AI feature are top-notch for me.

I find the virtual patching that they offer superb.

What needs improvement?

There should be a bit more dynamism when it comes to their playbooks in terms of the action triggers. That is the only thing that I would want to see a bit more. There should be a bit more dynamism, especially when you are creating your own playbook. This is something I have also discussed with Trend Micro.

For how long have I used the solution?

I have been using Trend Vision One since 2020 when it was rolled out. I have been using Trend Micro products since 2015.

What do I think about the stability of the solution?

It is stable. I would rate it a ten out of ten for stability.

What do I think about the scalability of the solution?

It is scalable. I would rate it a ten out of ten for scalability.

How are customer service and support?

I would rate their support a ten out of ten.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I have used a plethora of other solutions. I moved to Trend Vision One for multiple reasons:

  • The ability to do what the solution says it does
  • The ability to orchestrate all different solutions into one single pane
  • The ability to have automation when it comes to detecting and responding to threats

How was the initial setup?

It is deployed on the cloud. For me, the deployment was easy. For the endpoints, we just did a GPO push through Active Directory. For the cloud, we used just simple tenancy APIs and we were good to go.

It took us a week simply by virtue of how big the organization was.

In the IT team, there are 10 people working with this solution. We also have other departments such as risk and audit that use it. Overall, there are about 20 people directly working with it. The remaining are users for whom it just works silently in the background.

The maintenance is not done in-house. It is handled 100% by the OEM. They do share notifications, but we as users do not feel it, so whatever maintenance is required is handled 100% by the OEM. That is the beauty of a cloud service. You are not overly bothered by it.

What was our ROI?

In my previous company, over the four years, I believe we had seen about 81% ROI.

There are cost reductions because of the simple fact that I have automation. It means that I do not need to spend a whole lot on headcount for security analysts. From a commercial point of view, it has helped me reduce my operational costs, and then there are also security cost reductions because of the fact that it is automated and it responds in real time.

What's my experience with pricing, setup cost, and licensing?

When I compare it to its peers that can do the same, it is cost-effective.

What other advice do I have?

The evolution has been great. When I started using Trend Micro Vision One, the product feature was what they used to call business worry-free. It has evolved from an EDR to a fully-fledged XDR. You can see that the R&D is putting in work, and there is evolution. In terms of product coverage, they do not look at only endpoint protection. Right now, we have bespoke server protection. We have cloud asset protection and email security. You can see the growth of Trend Micro when it comes to its cybersecurity offering.

Based on my experience, I would recommend this solution. The ease of use, elimination of overhead, and return on investment are the reasons why you should have this solution.

I would rate Trend Vision One a ten out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
PeerSpot user
Karsh Trivedi - PeerSpot reviewer
Cyber Security Analyst at a tech services company with 51-200 employees
Real User
Top 20
Centralized management enhances threat response with automation and comprehensive insights
Pros and Cons
  • "The workbench alerts provide valuable insights into attack chains and relevant information, while Observer techniques give a comprehensive overview of ongoing activities."
  • "Trend Vision One requires several enhancements for optimal performance."

What is our primary use case?

As a cybersecurity analyst at a managed security service provider, I use Trend Vision One for two of my clients. My primary use cases involve standard XDR functions, such as anomaly monitoring, alert analysis, and incident response. To streamline these processes, I've configured automated response playbooks within Trend Vision One. The insights provided by the platform, mainly through the Workbench and Observe Auto module, are invaluable for understanding my clients' environments and identifying vulnerabilities that need to be addressed.

I work with clients across various industries, including education and power. My education client utilizes Trend Vision One for specific security needs, while my power industry client, an electricity board, has a comprehensive Trend Micro solution in place, including Vision One, Apex One, and Deep Security Manager. With Vision One, I've successfully detected and addressed numerous web attacks, malware attacks, and unauthorized access attempts on production servers in the education sector. For the power client, the solution has effectively detected and blocked multiple ransomware attacks. These are common occurrences and demonstrate the value of Trend Micro's security solutions.

We use Trend Vision One on all endpoints in two scenarios. For one client with on-premises servers and endpoints, we use Trend Vision One as a comprehensive solution. For another client in the education sector, we use Trend Micro Deep Security Management alongside the Vision One XDR platform on their cloud-based Linux servers.

How has it helped my organization?

Trend Vision One provides centralized visibility and management across all protection layers. This is crucial for efficiently sharing data with management, both internally and client-side. The platform avoids technical jargon, offering executive summary dashboards and summarized incident reports that clearly communicate security status. This allows for concise and effective communication with non-technical stakeholders, assuring them of their security posture. Trend Vision One's automated dashboards streamline reporting, eliminating the need for extensive manual documentation, which is especially valuable for technical users.

I use executive dashboards to build on threat detection, check for vulnerabilities, and create appropriate responses for individuals or groups of endpoints.

We use the risk index to assess and enroll our risk score. We maintain a low-risk index, which helps both management and me understand our score in relation to global risk factors.

Although I inherited Vision One as a service provider from another team, I eventually began utilizing its full potential and reaping its benefits.

Trend Vision One offers a phishing simulation feature in its cyber risk assessment. I frequently use this tool with my clients to evaluate employee email awareness. It generates comprehensive reports and provides functionalities for easy management.

Attack surface risk management helps identify vulnerabilities and high-risk threats in an environment, but it may also generate some false positives.

Trend Vision One significantly reduces MTTD and MTTR by approximately 50 percent. Its automated playbooks enable an immediate response to detected threats, providing near-instantaneous protection. While manual analysis and reporting of critical errors typically take an analyst up to 15 minutes, Trend Vision One's configured playbooks can automatically complete the same task within two minutes.

I have configured some playbooks to take automated actions on Trend Vision One while detecting some specific alerts or while detecting some specific playbook alerts.

What is most valuable?

Trend Vision One offers several features that I appreciate. The workbench alerts provide valuable insights into attack chains and relevant information, while Observer techniques give a comprehensive overview of ongoing activities. The platform's automated playbooks streamline incident response, significantly reducing MTTD and MTTR. Additionally, the ability to integrate with various firewalls and data sources, including Trend Micro's suspicious object management, centralizes threat management and simplifies daily security operations and incident response tasks.

What needs improvement?

Trend Vision One requires several enhancements for optimal performance. The platform should allow users to create custom phishing templates directly within the console and improve logging capabilities to facilitate seamless integration with SIEM solutions. Additionally, it should provide a mechanism for configuring Office 365 Advanced Threat Protection alerts to be displayed within the Workbench for streamlined threat management.

For how long have I used the solution?

I have been using Trend Vision One for about a year and a half.

What do I think about the stability of the solution?

Trend Vision One is a stable platform with no significant issues like lagging or crashing.

What do I think about the scalability of the solution?

Trend Vision One is easy to scale up by adding new agents, although the credit system for feature usage is confusing and could be simplified.

Which solution did I use previously and why did I switch?

I have experience with solutions like Sophos Central XDR and Wazuh, and while they have their strengths, I find Trend Vision One to be a competitive option with a comprehensive range of capabilities.

What other advice do I have?

I would rate Trend Vision One nine out of ten.

The on-premises Trend Micro solutions may require updates.

After deploying Trend Vision One on pilot devices, I recommend exploring the entire portal to familiarize yourself with its features and capabilities.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company has a business relationship with this vendor other than being a customer: MSP
Flag as inappropriate
PeerSpot user
Rob Rice - PeerSpot reviewer
Senior Security Architect at a tech services company with 5,001-10,000 employees
Real User
Top 10
Massive reduction in alerts, great visibility, and excellent support
Pros and Cons
  • "I like the workbench. It is a view of all the alerts or problems in your estate. The visibility that it provides to engineers is very useful. It is one thing having lots of alerts. It is another thing to have something to correlate all your alerts into a workbench for you so that you can see what is going on."
  • "Having more variables within the playbook would be useful. It would allow us to have more refined playbooks for the business. It would allow us to take stronger action through a playbook. It will give us confidence to target a particular area of business where our risk tolerance might be higher or lower. We would like to have more granular playbooks."

How has it helped my organization?

Our biggest security challenge was the number of alerts. It has helped with the reduction in alerts. We had too many alerts in the past that were false positives. The reduction in alerts was definitely a big benefit to us.

With Vision One, we have a platform view and all alerts go to one place. It gives us a much better understanding.

We definitely have better visibility. We can now detect things that we could never detect in the past using traditional AV platforms. That is definitely the biggest benefit. The second one is the risk score where we can see where the risk is in the business, and we can actively call and address it.

We use it on all of our endpoints. We use it on our cloud, on our email, M365, SharePoint, and OneDrive. We have been using it pretty much everywhere.

Vision One provides us with centralized visibility and management across protection layers. It is critical to us. Without it, our staff has to work harder because we are in multiple dashboards, and we do not have a giant picture between the systems and the security layers. Vision One connects it all together for you, and it can show us an attack from start to finish. It allows us to defend that much better.

Vision One has definitely increased our efficiency by reducing the number of alerts and correlating them. It is almost impossible to put a real number on it, but we definitely see things that we could not detect without it. There is probably 50% efficiency.

We use the Executive Dashboards. It is important to us that we can drill down from the Executive Dashboards into XDR detections.

We use the Risk Index feature. We look at the highest risks to the business, and we actively address those risks. There is a little bit of gamification with it. We have engineers looking to reduce the overall score of the business. They are targeting the biggest risks that Vision One has given us and that are most likely to be exploited. By addressing that, we reduced our risk score, and, as a side effect of that, we improved our business' security posture.

We use the Attack Surface Risk Management capabilities. We can see what is being actively exploited in the wild, and if we see some of that in our perimeter, we are going to do that straight away. We have full visibility of what is vulnerable, which allows us to prioritize.

Trend Micro XDR has helped to decrease our time to detect and respond to threats. With the combined visibility of Vision One, we get a lot of better-quality reports. In the past, with products like SIEM, we used to get a lot of noise. We would get thousands of alerts that were never risks to us, whereas XDR is all joined together. It gives you a much more confident data set, and from our data set, we can then start addressing the real risks to the business, which we have never been able to do in the past. It is the primary driver for business change. We get great visibility and high-quality alerts. We never measured the time to detect in the past, but I know that we are now detecting things within an hour or so, whereas in the past, it might be in hours if not days. We would have never detected some of the things in the past because we did not have a tool to do it.

Vision One has helped to reduce the amount of time we spend investigating false positive alerts. It has saved a lot of time. Traditional tools give you completely out-of-context alerts, which take time. We had thousands of alerts to look at, but 99% of them were just false positives. People sat on those alerts all day long that were never going to be an issue for us. When you get an XDR and Vision One in place, you start getting good-quality alerts. It just frees up countless amounts of time, but I cannot give a number.

We use its automation capabilities. Some of the playbooks have saved us days. They have taken action without the security being involved. 

It is definitely the center of our detection and response these days. We are seeing things that we have not seen before or never detected with other tools. It has made us far more aware of what is on our estate. It provides better visibility and allows the threat detection team to stop anything that might even be a suspect well in advance. It has definitely improved our response times.

What is most valuable?

I like the workbench. It is a view of all the alerts or problems in your estate. The visibility that it provides to engineers is very useful. It is one thing having lots of alerts. It is another thing to have something to correlate all your alerts into a workbench for you so that you can see what is going on. 

Integration is very good. There are lots of integrations. There are third-party products that we use, so the integrations are beneficial.

Within five minutes, even a new engineer can understand how to use it. It is very intuitive. You can easily learn how to use the platform and get the most from it. 

It is very good. It is very simplistic to learn. It is very intuitive to learn. We do not spend a lot of time training the staff on how to use it. They can just pick it up and use it themselves quite well.

On the reporting side, we use quite a lot of reports and dashboards. This visibility is very beneficial.

What needs improvement?

Playbooks are very good, but on the automation side, they could always improve. Having more variables within the playbook would be useful. It would allow us to have more refined playbooks for the business. It would allow us to take stronger action through a playbook. It will give us confidence to target a particular area of business where our risk tolerance might be higher or lower. We would like to have more granular playbooks.

Further integrations with other products are always beneficial.

For how long have I used the solution?

I have been using it for four years.

What do I think about the stability of the solution?

It has never been down for us, so it is very stable. I would rate it a ten out of ten in terms of stability.

What do I think about the scalability of the solution?

We have never had any scale issues. It has been absolutely fine. I would rate it a ten out of ten for scalability. 

How are customer service and support?

Their support is great. Whenever I have called them, the support teams have always been fast to respond. They are always helpful and willing to talk by email, phone, or WebEx. The escalations are always good as well. If we need further support, they are always there to promote that.

I would rate their support a ten out of ten. I do not think it can be improved. It is excellent.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We had a SIEM from LogRhythm. We almost replaced that entirely. We went for Trend Micro for a lot of reasons. The product was definitely the number one reason. It went through some rigorous testing with us, and we proved it to be very good and helpful to the business. Trend Micro's support model from their sales and delivery and their pricing model just worked for us. They were a good fit with our business.

How was the initial setup?

Deployment on the cloud is always easy. Deploying the agents to the endpoints can take time due to the size of your estate, but it is not a Trend Micro issue. It is purely down to the size of your environment. If you have 1,000 endpoints, it is not going to take as long if you have 100,000 endpoints. It is just a bit of a scale thing. You have got to deploy it out. It is not the worst deployment we have ever seen.

It is fairly straightforward. Cloud-to-cloud gets done in minutes. With all such tools, it is always about how long it is going to take the IT team to deploy the agents to all of their endpoints. It was not a massive issue for us.

We spent a few months getting it working.

What about the implementation team?

We had about four people for implementation and maintenance. We had about 11,000 endpoints. We have offices around the world. We have the UK, India, Canada, Australia, and many others. We have a full global team there. 

In terms of maintenance, the cloud does not require maintenance. The rest of it is about looking at the agents in terms of how the agents work, how they are deployed, and whether they are doing what we are expecting.

What was our ROI?

We do not calculate return on investment as such, but we have detected things that we may never have detected in the past. Those things could have turned into an actual real attack. We have probably saved far more than the cost of the system by not having an attack. The cost of being attacked, being exploited, having downtime, and reputation damage would be huge. It easily pays for the product.

What's my experience with pricing, setup cost, and licensing?

It is definitely not cheap. I do believe you get what you pay for to some degree. It is cost-effective. The money we spend on it is justifiable. It is not the most expensive product in the market. It is definitely not the cheapest product in the market. You have got to weigh that off as part of your business risk and understand what the risk to the business is if you do not spend and invest in modern tools like Vision One.

What other advice do I have?

I would definitely recommend this product. We would not be without it. I would definitely recommend doing a proof of concept in your environment. Once you have done that, you will realize the value of it, and once you realize the value of the tool, there is no going back. You would have to purchase it.

I would rate Trend Vision One an eight out of ten. They have room for improvement, but that is not at all unusual. It is still very good, and we would not want to get rid of it any time soon.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Information Technology Security Manager at Mewah International Inc
Real User
Top 20
What would previously take us two to three hours to fix, we can do in one hour or even half an hour
Pros and Cons
  • "The user interface is very good."
  • "We'd like to see more use of AI around analytics and controls."

What is our primary use case?

I primarily use the solution to prevent attacks. 

How has it helped my organization?

It's good for detecting malware and anomalies. We use it on our endpoints. 

What is most valuable?

The user interface is very good. Everything is all on one single platform.

With this product, we get centralized visibility and management across all of our protection layers. With a central platform, we don't have to look around across different websites or platforms. We can go right on the portal and manage things. It also helps us reduce the learning curve. We can manage and monitor products from the same place instead of learning different platforms. It's also helped us increase efficiency.

We have made use of the executive dashboard. It greatly increased visibility. We get a risk management view and metrics that help us narrow down and find issues. It helps us reduce risks. The risk index feature gives us a score to help us in our security goals. With it, we know what's the baseline or standard, so now we know what we need to do in order to meet the standards out there in the industry. We can see everything we need to in one glance. 

It's kept up to date and is consistently improving. This helps us protect our environment. 

The patch management has been very useful. They help recommend what needs to be installed.

We leverage the attack surface risk management capabilities. It shows the entire incident, including how it happened. We can use the information when we're doing forensics.

We've been able to reduce our mean time to detect and mean time to respond. What would previously take us two to three hours to fix, we can do in one hour or even half an hour. We've also been able to reduce the amount of time we spend investigating false positives. 

What needs improvement?

We'd like to see more use of AI around analytics and controls. 

For how long have I used the solution?

I've been using the solution for five years. 

What do I think about the stability of the solution?

The stability is good; I'd rate it eight out of ten.

What do I think about the scalability of the solution?

We're a small-to-medium-sized company. We have it deployed to less than 5,000 users. 

I'm not sure of the scalability. It works for us and our company size.

How are customer service and support?

Support is okay. They could be more responsive and could provide more communication channels. 

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We did not previously use a different solution. 

How was the initial setup?

I'm more of an end-user. I do not handle the installation aspect. The deployment was done a long time ago. 

The tool does not require much maintenance. 

What's my experience with pricing, setup cost, and licensing?

I'm not familiar with the exact pricing of the solution. My understanding is the licensing is reasonable. 

What other advice do I have?

I'm an end-user and customer. 

I'd rate the solution eight out of ten. It has very good management and monitoring benefits. 

Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
PeerSpot user
Buyer's Guide
Download our free Trend Vision One Report and get advice and tips from experienced pros sharing their opinions.
Updated: October 2024
Buyer's Guide
Download our free Trend Vision One Report and get advice and tips from experienced pros sharing their opinions.