I face challenges with the exclusion policy - it still scans folders we told it not to, causing issues. When we contact support, they tell us to update the latest agent, but we can't do that immediately due to medical device protocols and validation testing. I wish support would try to understand our issues better instead of giving this standard response. The machine learning feature they use often tells us to upgrade the agent or add things to the exclusion list, which isn't unacceptable. It's a very good and new technology as a tool and antivirus. But sometimes, it doesn't work properly with our medical devices and products, quarantining files it shouldn't even after we add them to exclusions. This is tricky for us.
It would be good to have a unified agent with EDR and CylancePROTECT. Making the dashboards a bit modern to make them easier to search would also be helpful.
Computer Security and Electronic Government Section at a government with 51-200 employees
Real User
Top 20
2024-04-29T20:31:44Z
Apr 29, 2024
Enhancing the product's detection rates and streamlining the user interface for easier management in daily operations would be beneficial improvements.
The solution should implement AI in the product. The main purpose of CylancePROTECT is to prevent infections on our endpoints and increase security. The more intelligence the product gains, the better it is for us. Currently, it is already intelligent. It will require updates to continue improving and detecting the latest threats. Threat intelligence must always be preferred in AI machines; it will always radiate with new threats and learning.
Learn what your peers think about BlackBerry Cylance Cybersecurity. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
Following the acquisition by BlackBerry, there has been a noticeable slowdown in development and the introduction of new features. Additionally, their channel management has been lacking, with a notable disregard for small and medium-sized businesses, focusing primarily on large enterprises and very large MSPs.
Senior Technical Support Analyst at Paul's Transport Inc
Real User
Top 5
2023-07-19T17:15:45Z
Jul 19, 2023
The product must make the interface a little more user-friendly. It has a little bit of a learning curve. The solution must subsidize the learning curve a little bit.
From my experience interacting with the primary or the central administrative console, it's quite complex. You would need a fair bit of technical experience to set it up, implement and maintain it. That would be one area for improvement. It could be possible to make the UI for the admin dashboard more user-friendly or provide more explainer tooltips or more warnings before you change settings. The solution can do whatever you need, but you could annihilate your machine by changing the wrong setting, and you would have to start again. Another quibble is that the endpoint visibility is a bit spartan. Because if a new policy is released from the admin console, you have to tell Cylance to check for a policy update, but when you do that, it does not tell you it has actually done that policy check, and there is no way of really knowing if it has actually updated. It would be nice to have a notification telling you whether or not the actions you have taken have actually been taken.
I cannot control the agent. If the agent is installed on a machine, then it'll report back. If I have 15 machines on an agent, I cannot see that 15 machines unless I install the agent on each. The solution is not stable right now. The performance isn't so good. It's a hard product to maintain. I have found support to be quite bad. We want them to offer better pricing.
IT Infrastructure Manager at a financial services firm with 51-200 employees
Real User
2021-07-15T16:16:48Z
Jul 15, 2021
When it comes to the management of the application of agents, especially for us as an IT team the dashboard is much easier to manage in the McAfee solution. We were looking to have a multi-factor authentication with the administration dashboard to log in, because it's cloud-based. There is no integration with Google Authenticator and other solution providers. We would like to see secure integration and multi-factor authentication to be able to access the administration dashboard.
BlackBerry Cylance SME - Resident Engineer at a tech services company with 201-500 employees
Real User
2021-06-21T05:24:27Z
Jun 21, 2021
I have already suggested features that need to be improved and Blackberry is already working on those improvements. For example, the interface and the Cylance Optics need to be improved a fair bit. It's a good solution but some features just need to be updated.
Senior Network Administrator at a financial services firm with 51-200 employees
Real User
2021-04-23T21:54:16Z
Apr 23, 2021
Not having OPTICS doesn't allow us to do any history. We don't have OPTICS, but FortiEDR comes with things like OPTICS, which is nice because we are not able to see more. OPTICS gives you things that FortiEDR has built in. For Cylance, there is an add-on to do the things that come with that solution. It would be nice if Cylance didn't separate PROTECT and OPTICS and put them together and made them on the same price point as FortiEDR, and some other ones rather than having to pay extra for something that the others already have built-in, and seen to do better. It often lets you waive something for the firm or for the whole company and then comes back and blocks the same thing because you have to do the certificate instead of the hash. You are finding yourself having to approve for the same program, the same application, the same file more than once and it's frustrating. While the deployment of updates is easy, it would be good to have some more information about which version to use, because the versions that are available seem to be outdated. When you go to the admin section, you will see that you will have the latest update from months ago and a month before that, and a month before that. I have a hard time believing that there are no more updates in between when there are things that are out all the time. It just doesn't make you feel like you're getting covered or have the best protection, which you should have.
Having worked with SentinelOne, Cylance is good, however, it probably needs to add a feature similar to SentinelOne's rollback functionality. With this feature, if you get infected, with a click, you can go back to the pre-infection state. If Cylance could add this functionality to their offering as well, that would be ideal.
The product needs to continue to offer better alerts. In particular, around false positives. It needs to reduce them from happening. I can't speak to the solution lacking any features per se.
Senior NOC Security Engineer at a wholesaler/distributor with 51-200 employees
MSP
2021-01-05T19:42:15Z
Jan 5, 2021
I'd like them to do software distribution too, but they said that that's architecturally not at the product line. I'd like to see where they can push to avoid using another product to push the agents.
IT Security manager at a energy/utilities company with 201-500 employees
Real User
2020-12-13T10:02:00Z
Dec 13, 2020
They could improve on the false positives, reporting and whitelisting features. For future releases, it would be helpful to have an easy uninstall button. The reason being, unless you connect the system to the internet, which you may not want to do, Cylance cannot be uninstalled easily. They claim it's practically impossible. If you have access to the online admin panel, it's very easy to uninstall Cylance. There is no easy way to uninstall locally. I have read online there is a convoluted way with a series of reboots and safety reboots that you could possibly do it locally.
It would be very important to have any kind of utility in the computer for Cylance to install monitoring into it in a simpler way. A computer should be able to self-scan on command. It is not easy to do that just yet. The company that sells us the licenses sometimes doesn't know how to do certain things. They should be offered more training or something, or maybe we could cover out channels ourselves and could have the knowledge of how to do everything ourselves without a third party needing to be involved.
OT Cyber Security Principal Consultant at Jacobs Engineering Group Inc.
Real User
2020-12-01T03:07:13Z
Dec 1, 2020
It could have integration with industrial base HMIS or Human Machine Interfaces Solutions. This is the industrial environment where you have a control center for all the automation that's happening, whether it is oil, gas, or chemical manufacturing. They often have to set up a computer at the back and watch the other stuff to get alerts. In these autonomous or on-premises environments, they often don't have access to email readily. Integration with other industrial solutions, such as HMIS, will allow them to communicate and get an alert that something has been found. This way, they can react to it sooner than having somebody watch the screen and keep checking the screen. Rockwell has its own suite. Similarly, Honeywell has its own suite. There's also an independent HMI/historian solution provider out there called VTSCADA. We actually get asked if we can get it to show up on a screen, which is difficult. Getting those alerts to work within an industrial environment would be a huge plus.
VP at a tech services company with 11-50 employees
Reseller
2020-11-02T18:45:06Z
Nov 2, 2020
The process of whitelisting a script that you want to be able to run can be a little bit difficult, or awkward. Some enhancements to this process would be an improvement.
Vice President Operations at a construction company with 11-50 employees
Real User
2020-10-06T06:57:40Z
Oct 6, 2020
I would like to see a little bit of additional reporting or insight as to what it is doing exactly. I do not think I need anything else included in the next release that I know of. Honestly, just improvement in the reporting would be good enough.
Security Domain Architect at a tech services company with 5,001-10,000 employees
MSP
2020-06-15T07:33:55Z
Jun 15, 2020
The user interface could be improved, it's very outdated. The solution could also do with more help actions and explanations such as what has been identified, things like that.
There are a lot of false positives and it takes up a lot of time. This is something that should be improved. I would like to see them fix the alerting system so that the endpoint reporting is a bit more streamlined. The vendor should be more widely advertising this product because not many people know that these types of solutions exist.
Director of IT Operations at a manufacturing company with 1,001-5,000 employees
Real User
2020-01-22T12:44:00Z
Jan 22, 2020
The OPTICS component could be made more user-friendly with respect to giving people more information. There are some issues that we have around our configuration, so I think that more training with respect to setup and configuration would be helpful.
To be honest, I think the product is, overall, quite good. It's working with AI Technology and machine learning that is connected to the Cylance Infinity Cloud. It picked up malicious files that other vendors didn't. It's actually been great on its own. Cylance is also launching mobile protection in 2020. At the moment the Cylance agent supports Windows, Mac OS and Linux devices, but they do not have an app for Android and IOS yet.
Co-Founder, CEO at a tech services company with 11-50 employees
Real User
2019-06-30T10:29:00Z
Jun 30, 2019
The downside is that the information displayed is not enriched enough. There was not much information available, that we could see. It should provide more details about the events that they have detected. There should be more information available post-incident. Basically, the user is informed that they have caught a threat, stopped it, and that's it. Users want to know what the threat was, the type of attack, how it got in, which IP address, did it go into lateral movement, etc. The kind of information that could be analyzed by IT experts to take forward and understand whether the attack is continuing, or not. They have some of this information but compared to other products, it's basic.
Wirtschaftsprüfer, CPA, Steuerberater at a financial services firm with 11-50 employees
Real User
2019-06-30T10:29:00Z
Jun 30, 2019
Improvements could be made on the user interface of the console. Also, right now it's just an antivirus and there's no firewall or anything. So we have to use the Windows firewall. It's a good firewall. But I think other companies have integrated products. The solution needs better dashboards that are easier to use. Also, a better user interface. Maybe even firewall integration of some kind. It would be helpful if you could see which threats have been detected, and have more information about what is going on. What I'm missing is a backup. In Norton, there was a backup included. In Cylance there is no backup, or at least no backup for the relevant system, programs, or software parts.
Security is an issue because they don't get Powershell. They scan the usual software and they don't scan deeper. The security scripting needs improvement. It needs deeper security for scripting. Also, more speed, less RAM, and less CPU.
BlackBerry Cylance provides endpoint security, threat protection, and antivirus capabilities, using AI and machine learning for protection against malware and ransomware on desktops, servers, and virtual machines worldwide. Its AI-driven threat detection operates even with limited internet, facilitating effective threat management.BlackBerry Cylance's centralized dashboard simplifies threat management and vulnerability protection for organizations globally. The platform combines AI and...
I face challenges with the exclusion policy - it still scans folders we told it not to, causing issues. When we contact support, they tell us to update the latest agent, but we can't do that immediately due to medical device protocols and validation testing. I wish support would try to understand our issues better instead of giving this standard response. The machine learning feature they use often tells us to upgrade the agent or add things to the exclusion list, which isn't unacceptable. It's a very good and new technology as a tool and antivirus. But sometimes, it doesn't work properly with our medical devices and products, quarantining files it shouldn't even after we add them to exclusions. This is tricky for us.
It would be good to have a unified agent with EDR and CylancePROTECT. Making the dashboards a bit modern to make them easier to search would also be helpful.
Enhancing the product's detection rates and streamlining the user interface for easier management in daily operations would be beneficial improvements.
The solution should implement AI in the product. The main purpose of CylancePROTECT is to prevent infections on our endpoints and increase security. The more intelligence the product gains, the better it is for us. Currently, it is already intelligent. It will require updates to continue improving and detecting the latest threats. Threat intelligence must always be preferred in AI machines; it will always radiate with new threats and learning.
The high price of the product is an area of concern where improvements are required. The product's price should be more competitive.
The solution’s user interface could be improved.
Following the acquisition by BlackBerry, there has been a noticeable slowdown in development and the introduction of new features. Additionally, their channel management has been lacking, with a notable disregard for small and medium-sized businesses, focusing primarily on large enterprises and very large MSPs.
CylancePROTECT could be improved in its technical support and communication.
The solution’s technical support could be improved.
The product must make the interface a little more user-friendly. It has a little bit of a learning curve. The solution must subsidize the learning curve a little bit.
From my experience interacting with the primary or the central administrative console, it's quite complex. You would need a fair bit of technical experience to set it up, implement and maintain it. That would be one area for improvement. It could be possible to make the UI for the admin dashboard more user-friendly or provide more explainer tooltips or more warnings before you change settings. The solution can do whatever you need, but you could annihilate your machine by changing the wrong setting, and you would have to start again. Another quibble is that the endpoint visibility is a bit spartan. Because if a new policy is released from the admin console, you have to tell Cylance to check for a policy update, but when you do that, it does not tell you it has actually done that policy check, and there is no way of really knowing if it has actually updated. It would be nice to have a notification telling you whether or not the actions you have taken have actually been taken.
An area for improvement in CylancePROTECT is its pricing, as it's a bit costly.
I cannot control the agent. If the agent is installed on a machine, then it'll report back. If I have 15 machines on an agent, I cannot see that 15 machines unless I install the agent on each. The solution is not stable right now. The performance isn't so good. It's a hard product to maintain. I have found support to be quite bad. We want them to offer better pricing.
CylancePROTECT's dashboard could be more user-friendly.
I find the price for Blackberry Protect expensive, so that's an area for improvement.
When it comes to the management of the application of agents, especially for us as an IT team the dashboard is much easier to manage in the McAfee solution. We were looking to have a multi-factor authentication with the administration dashboard to log in, because it's cloud-based. There is no integration with Google Authenticator and other solution providers. We would like to see secure integration and multi-factor authentication to be able to access the administration dashboard.
I have already suggested features that need to be improved and Blackberry is already working on those improvements. For example, the interface and the Cylance Optics need to be improved a fair bit. It's a good solution but some features just need to be updated.
Not having OPTICS doesn't allow us to do any history. We don't have OPTICS, but FortiEDR comes with things like OPTICS, which is nice because we are not able to see more. OPTICS gives you things that FortiEDR has built in. For Cylance, there is an add-on to do the things that come with that solution. It would be nice if Cylance didn't separate PROTECT and OPTICS and put them together and made them on the same price point as FortiEDR, and some other ones rather than having to pay extra for something that the others already have built-in, and seen to do better. It often lets you waive something for the firm or for the whole company and then comes back and blocks the same thing because you have to do the certificate instead of the hash. You are finding yourself having to approve for the same program, the same application, the same file more than once and it's frustrating. While the deployment of updates is easy, it would be good to have some more information about which version to use, because the versions that are available seem to be outdated. When you go to the admin section, you will see that you will have the latest update from months ago and a month before that, and a month before that. I have a hard time believing that there are no more updates in between when there are things that are out all the time. It just doesn't make you feel like you're getting covered or have the best protection, which you should have.
Having worked with SentinelOne, Cylance is good, however, it probably needs to add a feature similar to SentinelOne's rollback functionality. With this feature, if you get infected, with a click, you can go back to the pre-infection state. If Cylance could add this functionality to their offering as well, that would be ideal.
The product needs to continue to offer better alerts. In particular, around false positives. It needs to reduce them from happening. I can't speak to the solution lacking any features per se.
The implementation was complicated requiring some things that felt unsafe. After that, it was easy
I'd like them to do software distribution too, but they said that that's architecturally not at the product line. I'd like to see where they can push to avoid using another product to push the agents.
They could improve on the false positives, reporting and whitelisting features. For future releases, it would be helpful to have an easy uninstall button. The reason being, unless you connect the system to the internet, which you may not want to do, Cylance cannot be uninstalled easily. They claim it's practically impossible. If you have access to the online admin panel, it's very easy to uninstall Cylance. There is no easy way to uninstall locally. I have read online there is a convoluted way with a series of reboots and safety reboots that you could possibly do it locally.
It would be very important to have any kind of utility in the computer for Cylance to install monitoring into it in a simpler way. A computer should be able to self-scan on command. It is not easy to do that just yet. The company that sells us the licenses sometimes doesn't know how to do certain things. They should be offered more training or something, or maybe we could cover out channels ourselves and could have the knowledge of how to do everything ourselves without a third party needing to be involved.
It could have integration with industrial base HMIS or Human Machine Interfaces Solutions. This is the industrial environment where you have a control center for all the automation that's happening, whether it is oil, gas, or chemical manufacturing. They often have to set up a computer at the back and watch the other stuff to get alerts. In these autonomous or on-premises environments, they often don't have access to email readily. Integration with other industrial solutions, such as HMIS, will allow them to communicate and get an alert that something has been found. This way, they can react to it sooner than having somebody watch the screen and keep checking the screen. Rockwell has its own suite. Similarly, Honeywell has its own suite. There's also an independent HMI/historian solution provider out there called VTSCADA. We actually get asked if we can get it to show up on a screen, which is difficult. Getting those alerts to work within an industrial environment would be a huge plus.
The process of whitelisting a script that you want to be able to run can be a little bit difficult, or awkward. Some enhancements to this process would be an improvement.
I would like to see a little bit of additional reporting or insight as to what it is doing exactly. I do not think I need anything else included in the next release that I know of. Honestly, just improvement in the reporting would be good enough.
The user interface could be improved, it's very outdated. The solution could also do with more help actions and explanations such as what has been identified, things like that.
It should have better support for Windows and Mac.
There are a lot of false positives and it takes up a lot of time. This is something that should be improved. I would like to see them fix the alerting system so that the endpoint reporting is a bit more streamlined. The vendor should be more widely advertising this product because not many people know that these types of solutions exist.
The OPTICS component could be made more user-friendly with respect to giving people more information. There are some issues that we have around our configuration, so I think that more training with respect to setup and configuration would be helpful.
To be honest, I think the product is, overall, quite good. It's working with AI Technology and machine learning that is connected to the Cylance Infinity Cloud. It picked up malicious files that other vendors didn't. It's actually been great on its own. Cylance is also launching mobile protection in 2020. At the moment the Cylance agent supports Windows, Mac OS and Linux devices, but they do not have an app for Android and IOS yet.
The downside is that the information displayed is not enriched enough. There was not much information available, that we could see. It should provide more details about the events that they have detected. There should be more information available post-incident. Basically, the user is informed that they have caught a threat, stopped it, and that's it. Users want to know what the threat was, the type of attack, how it got in, which IP address, did it go into lateral movement, etc. The kind of information that could be analyzed by IT experts to take forward and understand whether the attack is continuing, or not. They have some of this information but compared to other products, it's basic.
Improvements could be made on the user interface of the console. Also, right now it's just an antivirus and there's no firewall or anything. So we have to use the Windows firewall. It's a good firewall. But I think other companies have integrated products. The solution needs better dashboards that are easier to use. Also, a better user interface. Maybe even firewall integration of some kind. It would be helpful if you could see which threats have been detected, and have more information about what is going on. What I'm missing is a backup. In Norton, there was a backup included. In Cylance there is no backup, or at least no backup for the relevant system, programs, or software parts.
Security is an issue because they don't get Powershell. They scan the usual software and they don't scan deeper. The security scripting needs improvement. It needs deeper security for scripting. Also, more speed, less RAM, and less CPU.