I use the solution primarily for EDR. The top challenges in our industry are the accuracy of the detections and the visibility of alerts and events.
We are accessing it via the cloud, and we are monitoring the endpoints and cloud servers.
I use the solution primarily for EDR. The top challenges in our industry are the accuracy of the detections and the visibility of alerts and events.
We are accessing it via the cloud, and we are monitoring the endpoints and cloud servers.
Vision One provides centralized visibility and management across protection layers, which is critical for tracking threats, viewing vulnerable assets, and understanding the overall security posture of the organization.
Vision One helps me a lot when it comes to reporting. The reports are very detailed and informative. There are recommendations and analyses of how to mitigate threats. We have comprehensive visibility.
The executive dashboards are very helpful for us in assessing our security posture. We can see what needs to be prioritized and mitigated first.
The risk index feature helps us make security improvements and implement security policies. It helps to have robust security.
Vision One helps to harden security controls and policy implementations.
Vision One improves our organization's security posture by allowing us to apply more robust security controls, implement security policies, and improve the security culture. The centralized visibility enables more efficient security operations.
Vision One makes it convenient to assess and mitigate or block threats across the organization. The XDR is collecting data from more than one client or company and correlating it. The XDR detects the loopholes or vulnerabilities of the system. It uses MITRE ATT&CK techniques to identify and respond to cyber threats or vulnerabilities.
Vision One improves our security posture because we can patch any vulnerable machines that are prone to risks and attacks.
Vision One has decreased our time to detect and respond to threats by 50%.
We use automation capabilities, especially when there is a breach or a risk activity with the user or the endpoint. It helps us by isolating devices automatically. This automation saves us about 20% of the time.
I love everything about the solution, especially the XDR features, the attack surface management, and the workbench alerts. It oversees vulnerabilities among the system and devices, prioritizing areas that need patching.
When I started working with it, I knew nothing about this solution. I found it very user-friendly and easy to understand.
There are limitations in terms of threat response actions.
I have been using Vision One since December 2022. It has been about two years.
There are some errors with the solution. I would rate the stability a seven out of ten.
It is scalable. I would rate the scalability of the solution as eight out of ten.
We have clients of various sizes. Our clients are small, medium, and large organizations.
The customer service or technology is responsive, but they take a minimum of one day, and up to three days, which is too long.
Positive
I previously used Azure Sentinel. Vision One is an advanced solution compared to Azure Sentinel. I prefer Vision One because of the convenience and easy correlation.
The initial setup is complex due to the various cloud resources that we have. We have workstations, servers, etc. Its implementation can be simplified.
It did not take us very long. We migrated from Apex One to Vision One. It did not take long.
It provides returns on investment by saving about 50% of time, money, and resources.
I find it to be a cost-efficient platform.
I would recommend this solution. It helps a lot when it comes to security. It covers endpoint security, email security, web security, and data leak prevention. It has everything.
I would rate Vision One a nine out of ten.
I was team lead with incident responses and incident management. We used the solution for that.
We were already using Trend Micro endpoint, NGAV by Trend Micro, and we got that upgraded to the XDR version. There was not much of a change after that. The only good thing about upgrading to XDR from NGAV was, having those real-time logs and network activities in front of us.
My reviews with Trend Micro are somewhere average. I won't rate it as an excellent tool or utter nonsense. I won't rate the two extremes, however, I would say it's in between them. It was mostly fine.
XDR provided a much more deep view into what is actually happening.
The rest of the features were pretty simple. There's nothing glamorous about them, however, it works. Nothing much really stood out amongst what the others were giving and what Trend Micro was giving. They are all pretty typical.
The dashboard was pretty easy to navigate. It was pretty convenient and user-friendly.
Results were delayed. We had all the logs in our hands. We were pretty quick in giving out the results and coming up with a conclusion. Trend Micro was pretty delayed on that front, however.
Their turnaround time or the response to their MDR services was slow. While doing POC, we did MDR as well. They could improve the response time on that. That was my view back then, as it used to take a lot of time to get that case generated, get that case analyzed. In the end, we were more interested in the responses from the actual human analysts. Instead of having a machine-generated thing, we were banking on understanding how an incident is treated and how a response is being given. For us, for example, we were able to do our analysis and come to the same conclusion maybe four or five hours before we received Trend Micro's report. Almost all the results were identical.
There was one feature called Sandbox that I wanted to try on, however, at that time, they had not released it yet.
Since last August, I have been working with another organization, so I am not sure how Trend Micro has developed within the last ten months.
I was never able to test the live response feature, wherein I could take access, remote access of the infected system, and send some commands to kill the processes, or maybe to grab the artifacts, to triage the artifact. By the time it came online, I was moving to another organization.
We'd like a bit of freedom or flexibility on the portal. If I'm the end-user, and I see something bad which might not be bad from Trend Micro's perspective, however, for my organization, was an abnormal activity.
Executing things via PsExec might be something that is normal for some organizations, however, for my organization, it is a highly suspicious thing. If I want to investigate that, having the flexibility for me to investigate it in a deeper sense would be ideal.
That was something that was not possible at that time. I don't know if they have given more freedom to Trend Micro admins.
We'd love more flexibility in terms of implementing some of the configurations, estate-wise. That is something that I would have loved to see in Trend Micro.
I used the solution for a month and a half, maybe. Or six weeks.
The response time, the analysis, or the human part was something which was requiring improvement. From the tool perspective, there were a lot of things that were to be released at the time I was using it.
We used to see those on the dashboard. For example, the sandbox. They had a sandbox, just like what CrowdStrike does where you can have a license for the sandbox. You can run those EXEs or whatever files, or malicious artifacts through those sandboxes and get a result.
That was something that was under development, though it was being displayed on the dashboard as "coming soon". There were a lot of features that were to be implemented. It was notified to the end-user as "Okay, that these features are coming in, and we are not sure how long it will take."
The trend lines were pretty extensive - like a year or maybe seven months, eight months. Those were the timelines for the actual deployment of those features into the dashboard. Therefore, it's hard to speak to the stability of the product.
The scalability is good. It was just a matter of installing the agent, which was pretty easy to deploy via a group update. Scalability was not an issue. The more licenses we purchased, the more systems we could get coverage upon.
There were endpoints plus servers covered.
We were heavily dependent on them. The reason was, that we had Trend Micro NGAV and we upgraded to Trend Micro XDR.
Their technical support isn't that great.
I used to speak with their CSMs quite frequently. They used to take a lot of feedback from us, asking about how things were, as their detection improvement was something which, also we were part of, not directly, however, we had one more team who used to do VAPT.
We used to post those results and say, "Okay, this is what we did. We did not get any alerts from you. We did not get any communications from you. What if this was an active hands-on keyboard activity and we were under attack?" They used to take that feedback. They used to get it implemented. Detection was then pushed in. They were in that development phase. I am not sure how well they are doing right now.
Negative
I've worked with CrowdStrike and Sophos and they provide a much better way to handle things than Trend Micro.
We never had any other tools or other antiviruses, other EDR solutions, that were playing any roles in the infrastructure. We only had ESET, and we were phasing those ESET servers out to Trend Micro. The only tool that we worked on, or XDR that we worked on, was Trend Micro.
The initial setup was pretty straightforward. They had given us one file which we could push through group policy updates. It was implemented throughout the organization. Implementing was pretty easy and it was pretty lightweight.
I was happy about that as it was not a resource-hungry agent which was running in the background, and we could not kill it, we could not limit it. Typically, XDR agents can be a bit resource-hungry, however, this one from Trend Micro was very light.
I'm not sure how long the deployment itself took.
Our IT team was pretty huge. It was around 30 odd people who used to work on it, however, I'm not sure how many of them were dedicated to working on Trend Micro for maintenance.
We had our internal IT team who we used to do the installation.
The company I worked for did not lose its money as Trend Micro was a low-cost tool. The features which we were getting were justified by the cost. It was not too costly to have those features.
I'm not sure of the exact price, although it is moderate. I'd rate it 3.5 out of five in terms of affordability.
You could get new features with an added cost per license, or it used to be bulk. Having that modularity helped in choosing and protecting our systems, and keeping the cost down. That modularity helped us in the beginning.
We also evaluated CrowdStrike with Trend Micro. CrowdStrike was phenomenal. I have all the good answers for them. If I have to rate them, I will rate each feature four out of five and above since they were that good.
CrowdStrike was too costly for our organization to have, as we had started building the Infosec inside, having Infosec in-house. Previously, it was outsourced. I was the first person who was enrolled for Infosec.
I was an end-user.
I'm not sure which version we were using it.
The solution was on the cloud. We were discussing having it on-prem, however, the cloud made much more sense for such a small organization rather than utilizing the resources on-site.
I'd rate the solution six out of ten.
We use Trend Vision One for our endpoint detection and antivirus solution.
The endpoint agents are deployed locally on our computers and the centralized controller is in the cloud.
Trend Vision One's centralized view boosts our visibility into harmful malware, viruses, and ransomware. Before Trend Vision One it was impossible to protect against attacks but the centralized management now makes it easy for us to focus on one platform.
The centralized visibility and management across protection layers have improved our efficiency. Now we have multiple tools to monitor our computers across our enterprise.
The executive dashboard is important because it allows us to dive into advanced functions.
I use the risk index feature daily and report the information weekly. This helps us address the risk factors.
Ransomware and intrusion attacks are common these days and Trend Vision One has helped us protect our devices and prevent these types of attacks.
The attack surface risk management eliminates blind spots.
Trend Micro XDR helps decrease our time to detect and respond because everything is available in one dashboard eliminating the need to use multiple dashboards and look at multiple locations.
Trend Vision One has saved us 80 percent of our time by constantly monitoring our environment and reducing our investigation time.
The automatic EDR system that notifies us when something is wrong is valuable.
The information captured by Trend Vision One needs to be more detailed.
I have been using Trend Vision One for two years.
Trend Vision One is stable and I would rate it ten out of ten.
Trend Vision One is scalable.
The technical support is good but 20 percent of the time the response is slow or they assume our issue is solved so they stop communicating with me.
Positive
The initial deployment is straightforward. We run the program and it deploys automatically.
We used a reseller for the implementation.
We have seen a return on investment.
The price for Trend Vision One is reasonable compared to Microsoft and Symantec.
I would rate Trend Vision One a nine out of ten.
We have Trend Vision One deployed across 250 endpoints.
Minimal maintenance is required.
I recommend Trend Vision One because it is easy to deploy and includes rich content.
Currently, our company uses the solution solely to monitor our servers for intrusions and other security-related issues.
I will have to have a look at my end to be able to explain the features that I find most valuable about the solution.
A room for improvement is Trend Micro XDR's website. It's a very complicated website since finding the right point one wants to see is difficult.
I have been using Trend Micro XDR for a year now. Also, I am a customer using the solution.
It is a stable product. It works very well.
Presently, we have 150 users in our company using the solution. Even if the number of users were to increase in my company, it would still work the same.
Initially, while using the solution in a company, we faced some issues. Our company did help us to resolve these issues.
Since another company carried out the initial setup process, my company did not find it complicated.
The solution is currently deployed on-premises, but we are planning a move to the cloud. We have a plan to conduct a POC for Trend Micro XDR on the cloud shortly.
The pricing of the solution is okay. There is a need for me to look into the new pricing plan introduced by the solution recently.
I would tell those planning to use the solution that they need to consider using it. I rate the overall product an eight out of ten.
The primary use of Trend Vision One is for its Endpoint Detection and Response and Extended Detection and Response solutions.
To address challenges with our attack surface management, we implemented Trend Vision One.
Trend Vision One's most valuable feature is its endpoint firewall rules.
The centralized visibility and management have been very important to us, as it allows for an effective EDR or XDR solution with central management. Without such solutions, I cannot imagine dealing with problems efficiently. The executive dashboards are used for main reporting and central management, improving readability.
Trend Vision One's attack surface management capabilities are a critical feature that we utilize.
Integration with other tools and deploying in hybrid environments need improvement. The deployment can be complex, and we'd like an easier process, especially when integrating with on-prem and cloud environments.
The high number of false positives in Trend Vision One presents a challenge. Reducing these requires extensive exclusion and allow lists, which are difficult to manage effectively.
I have been using Trend Micro Vision One for one year.
Trend Vision One is scalable.
The technical support is not good. We have to purchase support separately and the engineers are not readily available.
Neutral
We previously used Sophos and Microsoft Defender. For hybrid, we switched to Microsoft Defender due to easier integration with on-prem and cloud. I would recommend Trend Micro for Linux and mixed environments.
The standard deployment of Trend Vision One was straightforward and took approximately 24 hours to complete with two people involved.
Trend Vision One offers a competitive price-to-value ratio.
We evaluated Microsoft Defender and Sophos before switching. Microsoft offers more options for attack surface reduction rules compared to Trend Vision One.
I would rate Trend Vision One eight out of ten.
We have 400 users of Trend Vision One in our organization.
Two administrators are required to manage Vision One.
We use Trend Micro XDR to enhance our security framework.
One of our partners was the victim of a major attack, and we realized that our environment was susceptible to the same thing because we were only using an antivirus solution.
Trend Micro XDR is deployed on-premises, and we use it on our core business servers, clients, and the management portal to protect all of our network nodes from attacks.
Trend Micro Vision One provides centralized visibility and management across protection layers, which is important. It is part of our monitoring tool. The visibility gives us a centralized view of our network nodes, activities, and possible attacks.
The risk index feature plays an important role in our KPIs, which we report to the management team. Our business is dependent on our systems running 24/7.
Trend Micro XDR has helped decrease our time to detect and respond to threats.
Trend Micro XDR has reduced the time we spend investigating false positive alerts by 50 percent.
The most valuable feature is the network protection shield on every server, which isolates attacks and prevents our clients from being affected.
The deployment process could be more streamlined over the existing infrastructure, as it was not as easy as we thought. We are working with an expert from Trend Micro to improve the rollout process, but it has taken some time and we do not yet have a concrete understanding of the issue. There are some features that we have to install repeatedly before they start running.
I have been using Trend Micro XDR for one year.
Trend Micro XDR is stable.
Trend Micro XDR is scalable.
The technical support is good.
Positive
The deployment took six to eight weeks to complete. We had around five part-time people involved in the deployment.
Trend Micro XDR is expensive but we got a good deal from Trend Micro. We pay for an annual license.
Currently, we are researching the question of whether to use Trend Micro XDR when we switch from our classic NPLS internal corporate lines to an SD-WAN solution. Or if we should use an integrated solution from the SD-WAN and firewall provider, such as Palo Alto or Fortinet.
I would rate Trend Micro XDR eight out of ten.
We have 300 people in our organization that use the solution.
Maintenance is easy and done by two people, who update, patch, and install new servers; client-side, they also update user stations and analyze logs.
I recommend Trend Micro XDR. It is user-friendly.
Our primary use case is protecting our environment from malicious threats with antivirus protection. Additionally, we utilize Trend Vision One for its integrated solution, providing comprehensive visibility across the entire environment.
The organization implemented Trend Vision One to support best practices.
Trend Vision One is essential to our organization because it provides comprehensive security coverage across our entire environment, including email, network, and endpoints.
Trend Vision One offers centralized visibility and management across all protection layers, which is crucial for comprehensive environmental protection. This holistic approach empowers the SOC team to perform their duties effectively.
The executive dashboard is handy.
The risk index feature helps us identify issues and where to improve our environment.
The solution has improved our quality by enhancing the visibility into our estate and our ability to manage risk.
The consolidated security features of Trend Vision One improved the efficiency of our SecOps team by simplifying their workflows.
Improved asset visibility and enhanced risk management capabilities have raised our overall quality.
Trend Vision One offers centralized visibility and management across all protection layers, providing a holistic view of our environment and enhancing visibility across the entire infrastructure.
Trend Vision One would be enhanced by incorporating an SIEM solution as a built-in feature. This integration would streamline functionality and eliminate the need for us to acquire and manage separate SIEM solutions.
I have used Trend Vision One for over ten years.
Trend Vision One's stability is rated a six out of ten due to compatibility issues with other solutions and endpoint security interference.
The solution is scalable and there have been no issues with scalability.
I would rate Trend Micro's customer service an eight out of ten. While I experienced some minor issues, these are common with any technical solution.
Positive
We have not really seen a return on investment from this solution.
While the pricing and licensing for Trend Vision One are generally acceptable, the need to purchase additional features separately adds complexity. A single, comprehensive price for the entire solution is not available.
I would rate Trend Vision One seven out of ten.
Trend Vision One is deployed across multiple departments in our organization.
Trend Vision One requires maintenance.
Trend Vision One is a comprehensive endpoint security platform that combines NDR, XDR, and MDR capabilities in a single dashboard. We deploy it in offline environments, such as power plants, using relay management to ensure system connectivity without internet access. This approach allows for implementing robust security workflows even in isolated networks.
Trend Vision One effectively protects endpoints from malware, ransomware, and malicious scripts by allowing for the configuration of policies and sensors that detect and prevent unauthorized file modification.
Trend Vision One offers advanced threat protection that adapts to new and unknown threats. Upon detecting a threat, it deploys a virtual patch to mitigate the issue.
Trend Vision One helps detect ransomware with runtime and machine learning capabilities and will alert us of the detection.
Trend Vision One provides us with a single console for cross-layer detection, threat hunting, and investigation and is easy to learn.
It enhances risk management by providing comprehensive visibility into our environment. This ensures all systems are up-to-date and vulnerabilities are minimized.
Virtual patching is extremely helpful because it provides proactive protection against vulnerabilities even before a fix is available for the underlying issue.
Trend Vision One has helped reduce the number of viruses and malware we received. It has also helped manage risk effectively across various products like workload security, email security, and others through a single dashboard, thus making it easier for the organization to manage risk.
The most valuable features of Trend Vision One are its capabilities for XDR, EDR, MDR, and NDR, allowing for network detection and response. It is a comprehensive solution, and even Gartner recognizes TrendMicro as a leader. Additionally, it offers excellent endpoint security and protection that can be easily managed with sensors and agents.
I would like Trend Vision One to incorporate more AI.
I have been using Trend Vision One for approximately two and a half years.
I rate Trend Vision One's stability ten out of ten. I have only faced downtime once and am confident in its stability.
Trend Vision One is scalable, and I have not encountered any issues scaling the solution to meet different client requirements.
I rate the scalability of Trend Vision One ten out of ten.
Customer service and support are excellent. The support team is very timely and helpful, offering solutions and assistance as needed.
Positive
The initial deployment can be done quickly and easily, especially for smaller deployments within one day. For larger deployments, like those with hundreds of endpoints, it might take a few weeks.
I am not directly involved with pricing, but I emphasize the need for competitive pricing to facilitate easier sales.
I would rate Trend Vision One ten out of ten.
Our clients range from small up to enterprise level.
I recommend Trend Vision One to others.