Sign in
Categories
Your Saved List Become a Channel Partner Sell in AWS Marketplace Amazon Web Services Home Help

Trend Vision One

Trend Micro

Reviews from AWS customer

2 AWS reviews
  • 5 star
    0
  • 2
  • 3 star
    0
  • 2 star
    0
  • 1 star
    0

External reviews

260 reviews
from and

External reviews are not included in the AWS star rating for the product.


    Hospital & Health Care

Review of Trend

  • January 09, 2024
  • Review provided by G2

What do you like best about the product?
Very Good at response when there is a breach. They worked with us to prevent further infection and kept your systems safe
It detects well and once you get the hang of the components it's good to configure
What do you dislike about the product?
The dashboard is too much eye candy. I prefer the old format - easier to read and layout is more logical, Layout is not descriptive and icons don't make sense.
What problems is the product solving and how is that benefiting you?
We've been able to see what is happening on our network in regards to security. It is good because we can drill down the each incident and get plenty of information about each action/even. Also, the desktop agent works well, very few false positives. Also the reports are helpful for a quick view of what's going on


    Dairy

Trend M-XDR Senior IT CS Engineer review

  • January 03, 2024
  • Review provided by G2

What do you like best about the product?
Single pane-of-glass VisionOne portal is brilliant
What do you dislike about the product?
certain functionality is buried so deep it is impossible to find
What problems is the product solving and how is that benefiting you?
Enhance our cyber incident response and consolidate cyber threat detection and response using one tool


    reviewer1656681

Provides centralized visibility, eliminates blind spots, and saves us a significant amount of time

  • January 03, 2024
  • Review provided by PeerSpot

What is our primary use case?

We use Trend Vision One for our endpoint detection and antivirus solution.

The endpoint agents are deployed locally on our computers and the centralized controller is in the cloud.

How has it helped my organization?

Trend Vision One's centralized view boosts our visibility into harmful malware, viruses, and ransomware. Before Trend Vision One it was impossible to protect against attacks but the centralized management now makes it easy for us to focus on one platform.

The centralized visibility and management across protection layers have improved our efficiency. Now we have multiple tools to monitor our computers across our enterprise.

The executive dashboard is important because it allows us to dive into advanced functions.

I use the risk index feature daily and report the information weekly. This helps us address the risk factors.

Ransomware and intrusion attacks are common these days and Trend Vision One has helped us protect our devices and prevent these types of attacks.

The attack surface risk management eliminates blind spots.

Trend Micro XDR helps decrease our time to detect and respond because everything is available in one dashboard eliminating the need to use multiple dashboards and look at multiple locations.

Trend Vision One has saved us 80 percent of our time by constantly monitoring our environment and reducing our investigation time.

What is most valuable?

The automatic EDR system that notifies us when something is wrong is valuable.

What needs improvement?

The information captured by Trend Vision One needs to be more detailed.

For how long have I used the solution?

I have been using Trend Vision One for two years.

What do I think about the stability of the solution?

Trend Vision One is stable and I would rate it ten out of ten.

What do I think about the scalability of the solution?

Trend Vision One is scalable.

How are customer service and support?

The technical support is good but 20 percent of the time the response is slow or they assume our issue is solved so they stop communicating with me.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial deployment is straightforward. We run the program and it deploys automatically.

What about the implementation team?

We used a reseller for the implementation.

What was our ROI?

We have seen a return on investment.

What's my experience with pricing, setup cost, and licensing?

The price for Trend Vision One is reasonable compared to Microsoft and Symantec.

What other advice do I have?

I would rate Trend Vision One a nine out of ten.

We have Trend Vision One deployed across 250 endpoints.

Minimal maintenance is required.

I recommend Trend Vision One because it is easy to deploy and includes rich content. 

Which deployment model are you using for this solution?

Hybrid Cloud


    Hassam-Uddin

Provides a centralized dashboard, protects older servers, and reduces our time to detect

  • January 02, 2024
  • Review provided by PeerSpot

What is our primary use case?

We use FireEye, Microsoft Defender, and Trend Micro for our endpoint solutions. Trend Micro.

We implemented Trend Vision One because we have many production servers and wanted to secure all endpoints.

We are planning to move our XDR to the cloud, but all of our production servers are currently on-premises. 

How has it helped my organization?

Trend Vision One's ability to cover all our servers is important because we can detect and quarantine any vulnerabilities as well as block and isolate third-party applications from being installed on our servers.

The centralized visibility empowers us to monitor and manage all our servers from a single console. This includes generating reports, deploying security updates, and identifying offline or outdated servers.

The centralized visibility and management across protection layers have helped increase our efficiency. We receive alerts and make changes all from one place.

Trend Vision One helps us protect our servers, specifically our older servers that are not supported by Microsoft.

It has reduced our time to detect by 50 percent.

Trend Micro XDR has reduced the time spent on false positive alerts by up to 40 percent.

What is most valuable?

The zero-day vulnerability is valuable. As end users, we may not be aware of exploitations and Trend Micro makes suggestions to update to protect our endpoints from attack.

What needs improvement?

The automation capabilities on-premises could be improved, as we currently have to manually activate servers and push policies.

I would like the uninstall process of agents to require two-step verification.

For how long have I used the solution?

I have been using Trend Vision One for ten months.

What do I think about the stability of the solution?

Trend Vision One is stable.

What do I think about the scalability of the solution?

Trend Vision One is scalable.

How are customer service and support?

The technical support is good but we sometimes face delays because they will only respond to our partner who then relays the information to us.

How would you rate customer service and support?

Positive

How was the initial setup?

The migration from on-premises to the cloud allows us to access the cloud and on-premise servers from the cloud. The migration is not complicated but some rule-based ports require a lot of approvals and assistance from our network team.

The migration can be done in a few hours if all the ports are available.

Two people are required for the migration.

What about the implementation team?

We used a third-party service from JVS for the migration.

What other advice do I have?

I would rate Trend Vision One a nine out of ten.

For the on-premises deployment, maintenance is required because we have to manually check the connectivity of the agents. One person is required for the maintenance.

I recommend Trend Vision One, especially for older servers that are not supported by some other endpoint solutions.

Which deployment model are you using for this solution?

On-premises


    Azizullah M.

TrendMicro Vision One XDR with intelligence

  • December 19, 2023
  • Review provided by G2

What do you like best about the product?
TrendMicro Vision One XDR uses holistic approach to detect and respond. it collects and correlates deep activities across the layers like – email, endpoint, server, cloud workloads, and network. The platform automates the analysis and detects threats faster. As a result, security analysts enjoy data at tips and able to conduct through investigations.
What do you dislike about the product?
In my experience, teams need to be careful while implementing as this needs to be customized little bit.
What problems is the product solving and how is that benefiting you?
We are keenly aware of the growing risk of threats from both inside and outside the organization. The ramifications of any network security breach to an organization are far-reaching, and post-breach cleanup costs are significant. We need to be prudent and implement proper security controls that will put ahead of criminals and provide the ability to detect and prevent complex, integrated attacks on the networks. We implemented TrendMicro Vision One with virtual patching to examine network traffic traffic to devices. TrendMicro's R&D team is quick and fast on releasing the remediation code that can prevent the specific exploits.


    AndrewAdams

The observed attack techniques feature lets you see what an attacker is doing or how malicious code is operating

  • December 18, 2023
  • Review provided by PeerSpot

What is our primary use case?

We use Vision One for antivirus, endpoint protection, and identifying misconfigurations in our cloud platform. It secures our servers and endpoints and detects any sort of malicious software or inappropriate user behavior. It's a cloud solution with agents on the machines for endpoint protection. 

How has it helped my organization?

Vision One gives us more insight. When we implemented the solution, we didn't have a mature security platform, so we couldn't see what was happening on our servers or what our users were doing. It has decreased our time to detect and respond. Initially, we didn't have as much insight into any attacks that came through. It gives us more data points to work with and guidance about the remediation efforts. We aren't dealing with eight or nine different systems to identify one issue. It's all centrally located in one place.

Their Managed XDR service acts as our security operations center. It helps us sleep a little better at night. We know that they can call us on the phone when a significant alert comes in after hours. It makes things more efficient because we know there's someone on the other side who can look at alerts for us and at least do the preliminary analysis if anything comes in. Multiple teams are notified when an alert comes in. We can allocate security resources more efficiently and plug more data sources into the Vision One platform. We don't need to dedicate personnel to continuously monitor the dashboard because we know someone is looking at it with us.

The platform has allowed us to identify blind spots and see where there are holes in our network. It suggests remediation steps in many cases.  There is typically a link in the documentation. That has been a significant benefit because it tells you what to do. For example, it might suggest running a command in the terminal to identify the issues or take x output and put it into y input. 

The solution reduces the time spent investigating false positives by around 65 to 75 percent. For example, when we are pushing out custom code, the workbench tells us the risk level. If it's 70 or higher, we check it out. At 69 or lower, it could be a false positive, so it might require some poking around. It gives us enough data in the alerts that anyone who knows the system could say, "Oh, that was me. I was running patches," instead of checking nine different systems to identify what triggered the alert. It's all there in the alert, including the hashes, commands, impacted web files, etc. We can instantly dismiss it as a false positive and flag it as resolved.

Vision One's playbooks help us save time but I can't say how much because we're still maturing those. For instance, we know what those patching commands look like, so we're working on a playbook to automatically ignore or close those false positive alerts as they come in. We're still trying to fine-tune those playbooks. 

What is most valuable?

I like Vision One's observed attack techniques feature. It lets you see what an attacker is doing, how they have tried to exploit a machine, or how malicious code is operating. It helps us discover indicators of compromise so we can write better rules for detection.

Migrating to the Vision One platform helped us because we no longer need to look at eight different screens to find data. It's all just consolidated into one location. Having everything in one place is critical. I've been in the industry for almost a decade now, and it's a struggle to find that single pane of glass for all my alerts, logs, and anomalies like random users clicking on a link or downloading a file. It's nice to have it all in one location. Having centralized visibility saves the time we would spend checking various systems to look for things. I can also correlate data points more effectively and make data-driven decisions about the remediation and mitigation of any internal or external threats discovered.

The executive dashboard is nice. It's consolidating all of the tools into the Vision One platform, giving you a high-level overview. Executives love dashboards and pretty colors. The ability to drill down into XDR detection from the executive dashboard his handy. I don't have to go fishing. We get an alert that says a machine did X, and I can fire it up. It's on the dashboard, so I can click on that machine, and it lets me drill down into the logs. It cuts down on the time required to do any kind of forensic analysis on anomalous alerts or behavior. 

The Risk Index gives you an overview of the risk and how it compares with others in your industry. It's nice to be able to quantify the risk, and it enables you to justify the spending on these tools to your executives by showing that it pays off. Also, if we start plugging in more data points and the risk score goes up, we can conclude that there are some issues with the new data source that we just hooked up to our platform. The goal is to have a risk level of zero, but that will be hard to achieve. 

What needs improvement?

We've received some mild complaints that the documentation is sometimes not up to date. 

For how long have I used the solution?

I used Vision One at my last job, and I brought them on board when I joined this company, so I have been using the platform for about two years. 

What do I think about the stability of the solution?

I haven't had any issues with stability. 

What do I think about the scalability of the solution?

We run several different AWS accounts, and Vision One keeps up pretty well. I haven't noticed any downtime, lagging, or crashes.

Which solution did I use previously and why did I switch?

They were using something else, but my team wasn't in charge of it. Vision One offers a more mature platform. I had used it at my previous job. My boss brought it in because we had both worked with Trend Micro in the past. We know the platform and the engineers. 

How was the initial setup?

Deploying Vision One was relatively straightforward. We were on the legacy platform. They had written a script, so all you had to do was hit the play button. We recently moved to their all-in-one VisionOne platform, which was super simple. The deployment team included two on our side and two on the Trend Micro side. Their engineers hopped on a call and walked us through the process. The setup process primarily entails deploying the agents globally. 

What's my experience with pricing, setup cost, and licensing?

Trend Micro's licensing is fair. 

What other advice do I have?

I rate Trend Micro nine out of 10. This is a SaaS product, so you can do a trial period. If you like it, contact their sales people and try to develop a good relationship with the company. 

Which deployment model are you using for this solution?

Public Cloud


    Retail

Almost perfect

  • December 12, 2023
  • Review provided by G2

What do you like best about the product?
The unified and centralised view of all assets to take control of their security risk and vulnerabilities. Ease of Use,Ease of Implementation, Good Customer Support, Ease of Integration
What do you dislike about the product?
When we activate the centralised view, we lose the ability to delete/remove agents. We wait for an update to resolve it
What problems is the product solving and how is that benefiting you?
The visibility of security risks and vulnerabilities. The telemetry for the forensics


    Reviewer302881

Provides centralized visibility, alerts us of potential risks, and enhances security posture

  • December 12, 2023
  • Review provided by PeerSpot

What is our primary use case?

We have deployed the Trend Micro product suite across all our servers and workstations, including their XDR component, Vision One.

Our decision to switch from Kaspersky to Trend Micro stemmed from the concerns surrounding Kaspersky and the Russian government. Following those developments, we were advised to discontinue using Kaspersky and began the process of evaluating alternative security solutions. Trend Micro ultimately emerged as our preferred choice due to their exceptional support during the proof-of-concept stage. Unlike other vendors, Trend Micro proactively dispatched an engineer to our corporate headquarters at their own expense to assist with setting up and running the POC, demonstrating their commitment to our success. Vision One was released a year into our contract and we were able to work with the Trend Micro account team to deploy it in our organization.

Previously, our security setup with Trend Micro was entirely on-premises. This meant we were managing our backend servers and manually reviewing security updates. It was a time-consuming process, especially when vulnerabilities arose in their on-prem products. Reviewing briefing files and ensuring everything was patched was a constant burden. Moving to the cloud was a game-changer. The maintenance of backend servers is now handled by Trend Micro, freeing up our resources. We receive monthly emails notifying us of upcoming maintenance, and they take care of everything behind the scenes. It's a breeze. Vision One has always been cloud-based, but our previous on-premises solutions included their endpoint product Apex One, server product Deep Security, and exchange product. When we transitioned to the cloud, Apex One remained our endpoint protection, while Deep Security evolved into Cloud One. Additionally, Cloud App Security was introduced, providing security features for SharePoint and Teams alongside Exchange Cloud. 

How has it helped my organization?

Trend Vision One streamlines our security by centralizing data collection and threat management. It pulls data from Exchange, SharePoint, endpoints, and servers to the cloud, providing a unified view of our IT environment. This centralized data feeds into advanced playbooks that automatically block URLs and files based on predefined conditions, reducing our reliance on manual intervention. For potential threats requiring further analysis, Vision One flags them for human review, allowing security personnel to quickly approve or deny access to specific URLs or files. These decisions then inform the suspicious object lists used across all deployed Trend Micro products, maximizing our overall security posture. In short, Vision One effectively automates routine tasks while empowering security teams to focus on critical decisions, making it a valuable asset for our organization.

Vision One grants us centralized visibility and management across our protection layers. With its ongoing development, Trend Micro has steadily consolidated this visibility into a single pane of glass.

Centralized visibility significantly improves our efficiency. Instead of scouring endpoints or hopping between the mail server and data lake, we can consolidate our search for malicious activity into one central location. Vision One empowers us to leverage comprehensive search parameters and scan all data within the data lake, not just data limited to specific products.

For me, the executive dashboard is always the first one I check. Then, I turn to the operations dashboard for a more detailed look. These two dashboards provide a comprehensive overview of our security posture, drawing data from internal and external assets, application agents without vulnerability assessments, and detected account compromises. Vision One also excels at alerting us to potential risks, including accounts exposed to data breaches. I've personally experienced this when the executive dashboard's risk score suddenly spiked due to flagged accounts. After investigating and confirming the risk, we dismiss the alert and the score adjusts accordingly.

The attack surface risk management capability has identified several vulnerability issues in external assets, necessitating immediate action. It has also shed light on blind spots within our environment. 

When we identify blind spots, we need to implement measures to address them and mitigate, reduce, or even eliminate the associated risk from our environment. Our team is relatively small, so dedicating someone to focus intensively on a single issue can be challenging. Vision One has alleviated this burden. Vision One's playbook and built-in automation features help us by proactively alerting us to issues requiring immediate attention, enhancing our overall security posture.

Vision One offers a feature where, if it detects a phishing email with high confidence, it automatically locks the email, removes it from the Exchange database, quarantines it, and disables any links within the email or similar emails. For emails requiring human intervention or immediate action, Vision One flags them for review. We can then approve or deny the actions on the URLs and emails within the system. We use Vision One as a secondary measure if something slips through our other security layers. It allows us to see exactly what happens when users click on a malicious link, even if it wasn't flagged beforehand.

To some extent, Vision One helps us reduce the time we spend investigating false positive alerts generated by our firewalls. While firewalls throw out many alerts, I often turn to Vision One for clients flagged as compromised. Jumping over the firewall report, I check Vision One's insights on those specific endpoints and the sites flagged by the firewall. Previously, I'd spend time on the machine itself, sifting through cookies and deleting temporary files to track the source of the suspicious traffic. But with Vision One, I can quickly see if the endpoint is trying to reach those flagged endpoints. In most cases, it turns out to be just Google searches – images or other elements loading as part of a search.

Vision One has become my go-to spot every morning because of the dashboards. They put everything I needed in one place, saving me the hassle of jumping between multiple platforms. It's a half-hour ritual that sets me up for success, allowing me to review everything efficiently and tackle the rest of my day with confidence. Vision One has probably saved me several hours of valuable time per day.

We currently have some playbooks in place, and we're exploring the option of adding more automation features to them. Our limited IT support staff is one factor that makes a managed XDR solution particularly appealing. However, we recognize the need to invest time in learning and understanding the available automation features, of which there are many.

What is most valuable?

I could visit VisionOne daily and check the operations dashboard. It provides a good high-level overview of our risk posture, and I can drill down to see the specific registrations from the endpoint network that VisionOne is highlighting. This helped us understand that our risk index recently increased due to users requiring patches for the latest Google Chrome bug. Beyond that, VisionOne offers a clear window into the security posture of our endpoints. It shows any existing vulnerabilities and, if applicable, highlights any available tools from Trend Micro that can help us reduce the risk and mitigate the issues.

What needs improvement?

The support documentation could be more comprehensive. The last time I needed to find information, it was scattered, and took me a long time to locate what I needed. 

For how long have I used the solution?

I have been using Trend Vision One for almost six years.

What do I think about the stability of the solution?

While all products can encounter occasional stability issues, we've had specific instances where Trend Micro caused problems. We were unable to pinpoint the exact cause ourselves. Therefore, we contacted Trend Micro's technical support and collaborated with them to resolve the issue. In one case, it was a bug or previously unknown problem that was fixed in the next release.

What do I think about the scalability of the solution?

Vision One is fairly scalable, especially the cloud model. Because as long as we have the licenses installed. They can create folders and groups to help keep things organized for us.

How are customer service and support?

The technical support team is always incredibly helpful. Whenever we call them, they typically recommend using their data collection tool to gather some information. However, they're quick to respond, easy to work with, and knowledgeable, making for great customer service.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Previously, we used Kaspersky for several years after Symantec's exorbitant pricing led us to switch. We hadn't considered Trend Micro at the time. When concerns about Kaspersky arose due to the geopolitical situation, our director decided to move away from it. Seeking an alternative that was lightweight and met our needs, we explored various vendors and ultimately settled on Trend Micro.

How was the initial setup?

The initial deployment was straightforward. Trend Micro sent one of their engineers from Toronto to Halifax to help us set up the point-of-sale system for the proof-of-concept trial. The beauty of their approach was that if we decided to move forward with Trend Micro after the POC, we only needed to apply the license to the existing model, and it could be seamlessly transitioned into production. The engineer worked closely with us to develop a script that would uninstall Kaspersky and install the Trend Micro product. They also helped us configure the necessary policies, making the entire process remarkably simple.

Three people were involved in the deployment including the engineer from Trend Micro.

What about the implementation team?

The implementation was completed in-house with the help of a Trend Micro engineer.

What's my experience with pricing, setup cost, and licensing?

Initially, the new pricing structure from Trend Micro seemed reasonable compared to what we'd seen before. They've introduced a credit system, where we purchase credits and then allocate them to the specific services we need active. This concept is intriguing, but it has its pros and cons. In the past, licensing for 700 clients meant purchasing 700 licenses for everything in the package, a straightforward approach. Now, the new system requires a sizing exercise to determine our actual needs. However, the upside is that unused credits don't go to waste. We can divert some to a sandbox environment or other Trend Micro service for a limited time, if needed, to address specific issues.

Each feature costs a certain amount of credits.

What other advice do I have?

I would rate Trend Vision One a nine out of ten.

The on-premises version requires maintenance on the management server and update the software. The cloud model reduces the amount of time spent on maintenance dramatically because the cloud model automatically takes care of the software maintenance side of Trend Micro.

Which deployment model are you using for this solution?

Private Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other


    Mohammed Houssani

Good protection with centralized visibility and nice executive dashboards

  • December 11, 2023
  • Review provided by PeerSpot

What is our primary use case?

It offers very good ransomware protection. You have more visibility on the network.

How has it helped my organization?

It helps with compliance. We are also well-protected from ransomware and network attacks.

It's improved our organization in two ways: we can have more visibility and have more confidence in security. We also have better reporting for regulatory compliance. 

What is most valuable?

The endpoint protection is the most useful. It's powerful. I've faced issues with other products regarding ransomware; however, with Trend Micro, I have no fear of network attacks. I have experience with consistent protection. 

Customers have NDR and XDR protection, and it's very good for protection. There are also regulations within our country that require us to use XDR. 

The centralized visibility is good. It's great for the IT team as they have to export reports to management for compliance. It helps with reporting. It's essential. 

The centralized visibility and management across protection layers helped our efficiency. We have a limited number of security engineers. With Trend Micro and its centralized dashboard, it will show everything we've learned and reflect reporting on the dashboard and this helps when you have a limited amount of users. It simply reduces the number of people that need to be involved in the security effort. 

We use the executive dashboards on both sides. We can drill down on them right into XDR detection. It's essential when we have an incident. If we need to know more about the threat, we need to know where and how they are attacking. We can drill down and get forensic data. 

The solution's risk index feature is very good. It comes out of the box. Our customers can use it. 

The product has helped us decrease our time to detect and respond to threats. 

What needs improvement?

It took some time to realize the benefits, as we had some issues with support. It took us three to four months to realize its benefits. 

The support should be improved. 

We'd like to see deception features in the next release. It would help us to reduce false positive alerts. 

For how long have I used the solution?

I've been using the solution for seven years now.

What do I think about the stability of the solution?

The stability is good overall. 

What do I think about the scalability of the solution?

The solution is scalable. You simply need the resources on the VM, and you can easily change your license. 

How are customer service and support?

We've had issues with support. Their services could be improved. 

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

I have used Fidelis and found you can control the endpoints better. They also have a deception module, which is very powerful. You can manage your endpoints perfectly. It also offers very good network visibility. I use both products. It depends on the customer's needs and approach.

How was the initial setup?

I observed the deployment process. 

We had issues. It should be straightforward; however, with a customer, we faced a problem with technical support. It took us almost eight months to deploy. They had issues with the installation on the endpoints and on the network side. We had a problem with a few things, including use cases. 

The plan was to deploy in two weeks, and yet it took almost eight months.

From the customer side, there were three engineers, and from Trend Micro, there were one or two engineers working on the solution.

Almost every two weeks, there are maintenance calls. The customer has three people handling maintenance duties. 

What about the implementation team?

The solution was deployed by support. 

What's my experience with pricing, setup cost, and licensing?

The pricing is average. The costs are acceptable. It's good for small or medium-sized businesses. 

What other advice do I have?

I'm a partner. 

We're using the latest version of the solution. 

I'd rate the solution eight out of ten. 

For enterprise customers, I wouldn't recommend the solution. However, it's a good solution for small or medium customers. New users need to ensure they have the correct sizing and licensing. 

You need to talk to the right support engineers in order to have a smooth experience. 

Which deployment model are you using for this solution?

On-premises


    Ashish Kumar N.

vision one xdr is powerfull tool for MDR

  • December 04, 2023
  • Review provided by G2

What do you like best about the product?
vision one xdr console is user friendly and integrate with other third party tool.
smooth deploymentation
TAC support is very technical and knowledgable
frequency user friendly vision one dashboard
What do you dislike about the product?
vision one reportig for server and agent upgradtion.
What problems is the product solving and how is that benefiting you?
vision one reporting and workbench alerts are very helpful to mitigate the suspicious activity.