Sign in
Categories
Your Saved List Become a Channel Partner Sell in AWS Marketplace Amazon Web Services Home Help

Trend Vision One

Trend Micro

Reviews from AWS customer

2 AWS reviews
  • 5 star
    0
  • 2
  • 3 star
    0
  • 2 star
    0
  • 1 star
    0

External reviews

260 reviews
from and

External reviews are not included in the AWS star rating for the product.


    KISHOREKUMAR G.

One stop for monitoring cross functional log sources and correlation of logs

  • November 21, 2023
  • Review provided by G2

What do you like best about the product?
1. Helps in correlating the incidents of various log sources.
2.The providing a benchmark for the events and rating the events from low to critical
3. Providing different modules for endpoint, cloud, network,mail and mobile in a single dashboard
4. A typical tool which acts as MDR with threat detection, forensics and threat intelligence
What do you dislike about the product?
Credit Usage is causing some limitation in logs which we integrate in the Vision One XDR
What problems is the product solving and how is that benefiting you?
A single platform for monitoring Endpoints Severs, Cloud environments and other channels like network and mail, which is the major problem for any organisation. Trend Micro Vision One has soultuion for this


    David G.

The visibility, integration and orchestation is the turnkey on Trend Micro Vision One

  • November 20, 2023
  • Review provided by G2

What do you like best about the product?
Personally i consider that Trend Micro Vision One have a lot of functionalities that we can access easily, let us to have a lot of posibilities to view and monitoring the ciber risk and the surface attack.
Another thing that i like very much about Vision One is that is always refreshing and updating funcitonalities accopling technologies to the enterprise enviroment. Ive seen the importante of use in the enterprise, because the administrator permant access to the platform to monitoring and see the risk information.
What do you dislike about the product?
It would be interresting that Trend Micro Vision One, have te ability to see other endpoint, mail sensors besides its own sensors.
What problems is the product solving and how is that benefiting you?
The main problem that is solving is about the visibility and the automation of cibersecurity incidents. In ocassions is important to give this control to the cibesecurity tools. A really big benefit about Vision One is the capacity to correlate the information about some feeds, this let us to have one point and unique control and risk insights.


    Matthew Guzzi

Provides great visibility, saves us time, and integrates well

  • November 17, 2023
  • Review provided by PeerSpot

What is our primary use case?

We utilize Trend Vision One to identify and neutralize malicious activities on our network. This comprehensive security solution extends beyond traditional antivirus software, which relies on pattern matching, by actively monitoring endpoint behavior for anomalies and deviations from established norms.

In 2020, we transitioned to remote work like many other companies. During this transition, we conducted an internal Trend Micro office scan, which revealed that many of our users' devices were out of date due to their inability to connect to the VPN for extended periods. This prompted us to switch to Apex One later that year. As part of the Apex One implementation, we were given a complimentary trial of Vision One. During this trial, we received an alert that demonstrated the product's effectiveness, leading us to purchase a subscription. Vision One has been an excellent addition to our security arsenal. Trend Micro continuously adds new features and updates, making it an ever-evolving and valuable tool. The product's capabilities, functionality, and incident response capabilities have improved significantly over the past several years. We can set up playbooks to automate our response to specific incidents, which is a tremendous asset. Vision One is an outstanding security solution.

How has it helped my organization?

We are a state government agency that is subject to oversight by the state. Vision One has detected attempted attacks that the state SOC has missed, enabling us to swiftly halt these attacks and address the vulnerabilities before they escalate into more widespread problems.

The integrations have been great. There have been a couple of issues, but overall they've been very helpful. Vision One recently added the ability to connect to our on-premises AD. This was a sticking point for us for a year or so because we didn't have Azure. So we were stuck in a situation where we couldn't tie Vision One to our AD. But since they added the on-premises integration, it's been easy to set up.

Trend Vision One has saved us ten percent of our time. It has eliminated the need for us to rebuild machines. It has helped us even more than that because the few times we have had a threat, it has stopped it in its tracks. This has prevented the threat from spreading and compromising multiple machines. Without Trend Vision One, we would have had to investigate the threat, which would have taken time and resources. Additionally, we would have had to rebuild the compromised machines, which would have taken them offline and impacted our users. In some cases, a widespread outbreak could have occurred, causing even more disruption.

What is most valuable?

The dashboard provides great visibility into our risk profile. We receive a daily email report that outlines our risk score and identifies the machines with the highest risk. This information is based on usage patterns, vulnerabilities, and non-compliance issues. This helps us prioritize which machines require patching or further investigation.

Drilling down further, we can analyze how our users are utilizing their workstations, including the websites they visit. While we don't track specific website URLs, we can categorize website types and identify any potentially risky or inappropriate usage patterns. This allows us to proactively address any potential security concerns.

For instance, we identified a user who was using ChatGPT for work-related tasks. This flagged our system, and we were able to discuss the user's usage of ChatGPT to gain a better understanding of how our users are working and identify any areas that require additional attention.

What needs improvement?

Trend Vision One offers training sessions every few weeks or every month to showcase new features. However, the product's rapid development and the introduction of numerous new features make it challenging to keep track of the evolving interface and maintain a consistent understanding of its usability. While the continuous addition of features is commendable, the sheer volume of changes makes it difficult to stay abreast of the latest developments.

For how long have I used the solution?

I have been using Trend Vision One for two years.

What do I think about the stability of the solution?

Trend Vision One has proven to be extremely stable in our environment. We have deployed the Trend Micro client across all workstations. Additionally, we utilize a tool for vulnerability scanning, one for application whitelisting, and FireEye, as mandated by state regulations. These security solutions coexist harmoniously, causing no compatibility issues. We have also implemented laptop encryption and other security measures to further enhance protection. Throughout our experience, Trend Micro has not caused any conflicts with Microsoft or our other security tools.

What do I think about the scalability of the solution?

Trend Vision One is scalable. We can add another 150 machines with no problems.

How are customer service and support?

The technical support is excellent. We experienced what we initially thought was a technical issue, but it turned out to be a state update that triggered alerts across all of our machines. I contacted the support team and our sales representative. Within an hour, the incident response team was on the phone with me, examining the file hashes of the updated DLL to determine the cause of the issue. They quickly identified that the update was not malicious. Their promptness and thoroughness were outstanding. The incident was resolved within three hours of receiving the alerts.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We lacked an XDR tool. Instead, we relied on FireEye, which offers similar capabilities, but it doesn't provide us with the same level of visibility as Vision One. Vision One has consistently detected threats that FireEye missed. While we were mandated to use FireEye by state regulations, we sought a more robust solution that could effectively identify anomalies and patterns. Vision One's utilization of the MITRE ATT&CK framework has been particularly advantageous. We've found great value in Vision One's comprehensive feature set, particularly its well-designed playbooks.

How was the initial setup?

The initial deployment was straightforward. I was able to deploy Trend Vision One with the vendor's assistance within one week.

What about the implementation team?

The vendor guided us through the implementation process and continues to conduct periodic check-ins to verify that everything continues to function effectively in accordance with industry best practices.

What was our ROI?

Our return on investment does not stem from direct cost savings but from the fact that Vision One has mitigated issues before they escalated into larger problems. This has saved us time, which is a valuable asset.

What's my experience with pricing, setup cost, and licensing?

The pricing for Trend Vision One is reasonable. I am not sure of the exact amount we pay, but it is not excessively expensive.

What other advice do I have?

I would give Trend Vision One a perfect score of ten out of ten. It is undoubtedly the best product in the market today. While I appreciate CrowdStrike and its offerings, I believe Trend Vision One stands out as the leader. In my opinion, these two products are the clear frontrunners in the XDR space at this moment.

Trend Vision One is deployed at a single location. We have approximately 50 endpoints. Most of our devices are laptops because we have a large number of employees who travel frequently.

Trend Vision One is maintenance-free, which is convenient because patching is handled seamlessly from the backend in the cloud. Trend Micro proactively notifies users about upcoming patching schedules and provides detailed information about the patches, new features, and updates. The patching process is managed entirely by Trend Micro, eliminating the need for user intervention. A client installed on the machines receives updates from the cloud server, ensuring that all devices remain protected and up-to-date without any manual effort.

I highly recommend Trend Vision One. Contact Trend Micro and they'll be happy to schedule a demo. I suggest installing the demo, testing it out, and seeing if it's a good fit for the organization's needs before purchasing. Trend Vision One is worthwhile.

Which deployment model are you using for this solution?

Public Cloud


    Julio César Quezada

A cloud solution for providing all information in one dashboard

  • November 07, 2023
  • Review provided by PeerSpot

What is our primary use case?

We use the solution for event correlation.

How has it helped my organization?

We are deploying a server inside our network to use it as a data collector.

What is most valuable?

The solution provides all the information in only one dashboard. We have integrated with Lumen, NETSCOUT, and other MDM products such as Microsoft Intune and ManageEngine MDM. We have also integrated Chrome with VisionOne.

What needs improvement?

The login system could be improved. We must pass two different dashboards to log in to the solution. We have a second-factor authentication. We need to check the platform, which delays three or four minutes because of logging, checking email, and returning to the platform. If you multiply the entire team, we lose a lot of time daily.

For how long have I used the solution?

I have been using Trend Vision One for two years.

What do I think about the stability of the solution?

I rate the solution’s stability an eight out of ten.

What do I think about the scalability of the solution?

I rate the solution’s scalability a nine out of ten.

Which solution did I use previously and why did I switch?

We have used Symantec before. We switched to Trend Vision because Symantec cut off support for Windows XP. We still have Windows XP in our environment.

How was the initial setup?

The initial setup is easy because our assets are in interactive directory.

What was our ROI?

We’ve seen ROI because we controlled a malware attack in our network with Trend Micro two weeks ago.

Which other solutions did I evaluate?

We have tried other malware solutions. We chose Trend Vision because it supports Windows XP.

What other advice do I have?

Overall, I rate the solution a nine out of ten.

Which deployment model are you using for this solution?

Public Cloud


    Bruno De Amorim Campos

Centralized visibility, helpful support, and great for vulnerability detection

  • October 31, 2023
  • Review provided by PeerSpot

What is our primary use case?

I work with it as a third party in other companies. I installed XDR in other companies. And then, I help them understand the tool, help them with developing the necessary use cases, and understand, for example, how to do a threat intel, how to do a threat investigation, and stuff like that. Sometimes, I work with it as well by implementing it and actively using it in the customer's environment.

What is most valuable?

The workbench feature is excellent. It helps a lot with understanding how the environment is working and how the threats are working in their own environment. It helps a lot to understand where the threat is coming from, where it is going, how is it being dealt with, et cetera. 

We do not use XDR to protect a multi-cloud or hybrid cloud environment. I have other solutions on the cloud, like Apex One, the endpoint protection feature in the cloud. I have Cloud One Workload Security, which is protection for workloads and servers where the main console is in the cloud. I'm mainly using this to protect an on-premises environment. 

I've been using it for emails, for networks, endpoints, workload servers, et cetera. It has the ability to cover all of those. The coverage is really important. The integration between all those different tools and those different assets makes a big difference in understanding the analytics.

It provides centralized visibility and management across our protection layers. That helps in a lot of ways. For example, the fact that it has some centralized visibility means we can do searches between email addresses and an endpoint. We can take a workspace, for example, and do IPS detection in a workspace and understand from which endpoint something is coming. 

We use the executive dashboards that they have almost every day. Once we see an anomaly or something that feels weird in the environment, we can go straight to work, straight to the detections, and we can take a look at it to see what's going on. 

We use the Risk Index mainly to help us understand a customer's environment. We use it to get a brief overview of how the environment is, how high their risk is, and then, given the score that we've received, to understand what is causing this risk and then give them suggestions on how to take the score down.

We use the Managed XDR feature. It just basically collects the telemetry and sends it to the console so we can use it in other parts. It has helped a lot with the team's workload. The detection has been really, really useful. It helps a lot to rank where we should put our efforts. Sometimes we'll have to take a deep investigation into some of the stuff we see. Sometimes other issues emerge as we dig. It's helped in detection.

We use the risk management attack surface capability to understand the vulnerabilities and how high a risk something is in the environment. It can help with detection. It's helped us effectively identify blind spots. 

The product has helped us decrease time to detect. We've had some issues with a couple of our customers in which the XDR helped us easily detect an issue, and it was fast enough for us to be able to react and respond quickly in order to mitigate damages.

What needs improvement?

The web viewer could be improved. I've had some issues with it in the past. 

The zero trust is a bit complicated compared to other parts of the solution. 

Mostly, I don't have any issues with XDR.

For how long have I used the solution?

I've used the solution for about three years.

What do I think about the stability of the solution?

I haven't had any issues with stability. There has been no crashing to lagging. We occasionally get informed about maintenance that may cause downtime. 

What do I think about the scalability of the solution?

We've had no issues with scalability. 

How are customer service and support?

I've contacted support in the past. They are pretty good. They have a high understanding of the platform and the solutions. If they need to escalate, it's easy to do so. 

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We did not use a different solution previously.

How was the initial setup?

I was involved in the installation. We have an agent installed in the endpoints or a sensor connected to the mail sensors. 

The initial setup is straightforward. You just click through with a simple connection. 

It doesn't require any maintenance on my end. 

We had about four people handling the implementation. We just had to have some credential access, and once the connections were made, we had to distribute the sensors throughout the environment. 

You need the whole platform to use XDR. However, there are some activities you don't need XDR to use. 

What's my experience with pricing, setup cost, and licensing?

I'm not familiar with their pricing and licensing. 

What other advice do I have?

We are an official Trend Micro partner.

We do not yet use the automation capabilities found in XDR.

I'd rate the solution nine out of ten. 

After implementing XDR, have a good understanding of how the workbenches work to create a decent playbook. Use the service gateway to your benefit. Connect your active directories, make connections, and use integrations with your firewalls. These third-party integrations are really good, and they help you a lot with your environment. 

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other


    reviewer2005038

Reduces the time to detect, investigate, and respond

  • October 30, 2023
  • Review provided by PeerSpot

What is our primary use case?

We have deployed Trend Micro XDR on all our endpoints. It is deployed as an agent because we are using Trend Micro Apex, the antivirus agent, and the SaaS agent. This means that we receive notifications from XDR for any suspicious activity related to endpoints. For example, if a user connects to a suspicious website, XDR should alert us based on our rules. It can also generate alerts for malicious Windows activities.

In addition to deploying XDR on our endpoints, we have connected Vision One XDR to our Office 365 email platform. This allows XDR to read incoming emails. We can then configure rules to remove emails from mailboxes if they have certain properties or are particularly suspicious.

We have also connected XDR to our Azure platform, which is our user authentication platform. XDR can monitor for risky user sign-ins, such as sign-ins from unusual locations. If it detects any risk, it will notify us.

Finally, we have integrated XDR with a third-party tool to receive indicators of compromise. When we receive an IOC, Vision One will automatically run a check in our environment to see if any endpoints have been compromised. It will also check to see if any emails have been sent from any of the senders in the IOC listing. If it finds any matches, it will notify us.

We can also configure playbooks to automatically take action when XDR detects a threat. For example, we could configure a playbook to force a user to reset their password or isolate an endpoint from the network.

We are using the Trend Micro Vision One XDR agent. This agent component is installed on all of our endpoints, including servers, workstations, desktops, and any other computer elements. Vision One also has an API-based element, which we have connected to our email system, such as Azure.

How has it helped my organization?

Before Vision One, we had limited visibility into our security posture. Things were happening all around us, but we couldn't see them. With Vision One, we have centralized visibility and management across all of our protection layers, so we can see and respond to threats quickly and effectively.

I cannot imagine my day-to-day operations without the visibility that Vision One provides. It makes all the difference. No other platform compares to Vision One in terms of simplicity, ease of use, and importance.

Vision One has improved our efficiency with centralized visibility. Before Vision One, we had to go to different platforms and tools in our environment. Sometimes the information was missing and sometimes we were searching with the wrong terms. But because I can now see everything at once, it has helped. The decision we are making now is simply to go there, and whatever we have been faced with, the console is enough to make a decision.

We just signed a contract for Managed XDR services. We were managing our security before, but we'll start using their managed services next year. We've received a few escalations from them already, but that's because they're proactively searching for threats, which is a good thing. For example, I got an escalation from them last week for something that we wouldn't have discovered on our own. It wasn't something that the tool would have generated an alert for either, because it was very similar to what a user would normally do. But they were able to find it because they're looking into all of the addresses that they have. This led to us being able to control incidents that would have happened otherwise.

The XDR service has saved us time, enabling us to work on other tasks. The environment is quite complex, so before we had XDR, we didn't have any tool that considered all possibilities or provided any visibility into our environment. When we first started using the tool, it was new to us, but after a couple of years of using it, we've found that it is a legitimate tool that provides valuable information. Instead of seeing it as adding more work to our workload, we see it as helping us to be more proactive and prevent future incidents. For me, it has been a great help and has added real value to our work.

XDR helped us reduce our time to detect and respond to threats. With a single click, I can isolate a computer from the rest of the compliant environment. I had to do this last week when I had to support two escalated computers. Without XDR, there would be hundreds of things that we would not have seen or known about. But with XDR, we can see everything. And that even includes coverage of devices or computers that are not owned by us, such as those used by vendors. If a vendor brings a malicious device onto the property and downloads something malicious, we can detect it as early as possible.

Trend Micro XDR has helped us reduce the time we spend investigating false positive alerts. I am 100 percent confident that everything that comes out of the platform is legitimate. We had a few false positives when we first started using the solution, but because Trend Micro allows us to whitelist specific items, we were able to build our policy accordingly. Sometimes, there are malicious items that we need to allow because of our environment, such as certain security tools. Trend Micro allows us to build a policy that excludes these items from alerts, so we no longer receive alerts for them.

We use the XDR automation capabilities extensively, including playbook automation for tasks like isolating computers, and API-based automation for most other tasks. For example, we are a member of the retail ISAC information-sharing platform, and we have automated scripts from that platform that pull in all malicious senders, IPs, and domains, and pool them into XDR. XDR then automatically scans all computers to see if any of these malicious entities exist. If they do, XDR generates an alert and allows us to take action, such as removing the file. We generally set XDR to allow only, so that we have visibility into all malicious activity, even if we don't take action on it.

What needs improvement?

I would like to have the capability to export the information we receive from the XDR into Microsoft Excel.

For how long have I used the solution?

I have been using Trend Micro XDR for almost four years.

What do I think about the stability of the solution?

Trend Micro XDR is stable. We have not experienced any stability issues when using the console. 

What do I think about the scalability of the solution?

I do not have access to the backend, so I am not aware of the specific technical details. However, from an end-user perspective, the scalability of the system appears to be excellent.

How are customer service and support?

I reach out to technical support almost every week to address any questions I have. I also have a bi-weekly meeting with their technical team. They guide open tickets and address any concerns we may have. Additionally, we have a monthly meeting with Vision One developers where they discuss upcoming features and seek input. I know exactly who to contact for any assistance I may need. Sometimes, I can simply email them directly instead of opening a ticket. The process is always straightforward and efficient. At times, the prompt responses make me wonder if they are using AI assistance, but I hope that's acceptable. I usually receive a response within a minute or two, which suggests AI involvement. However, the signature at the end of the IT person's email confirms that an actual person is handling my request.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We had Carbon Black, but we're using it only for application control. With Trend Micro XDR we can detect and respond.

How was the initial setup?

The initial deployment was straightforward. I have extensive experience in deployments across various companies and platforms. However, Trend Micro XDR surpassed all my expectations. We had previously deployed on-premises, and all we had to do was access the designated console and click a button to migrate all on-premises agents to cloud agents. It was incredibly easy. My team of two and I handled the entire process without any involvement from the teams and properties. I right-clicked and moved everything over. A few agents remained unmovable due to their outdated versions, but we successfully migrated close to 99 percent of all agents.

What about the implementation team?

The implementation was completed in-house. Trend Micro provided a document link to help with the deployment.

What's my experience with pricing, setup cost, and licensing?

Trend Micro XDR is reasonably priced for its value, comparable to other products like VMware Carbon Black.

Which other solutions did I evaluate?

We evaluated an additional option with Carbon Black because we already had that agent in our environment. We also considered Cisco, which has its own XDR platform.

What other advice do I have?

I would rate Trend Micro XDR ten out of ten.

We tried to use the risk index feature, but I didn't have the resources to focus on it at the time. I was more focused on the actual findings that were happening. I have since hired someone who will focus on the risk index, as the primary reason I hired them is to focus on the risk element coming from Vision One, as well as from other third-party intelligence platforms that we work with or have contracts with. Now that I have someone here, we will be focusing on the risk index.

No maintenance is required.

Which deployment model are you using for this solution?

Public Cloud


    nishant k.

A unified XDR Solution trend micro vision one

  • October 30, 2023
  • Review provided by G2

What do you like best about the product?
So far trend micro vision One's implementation was the smooth and hassle free. Trend micro's customer's support was communicative and responsive anytime i faced any issues pre and post deployment. i have been frequently using this product like wise i am supposed to provide demo to the customers along side showing them all the features it provids. It integration with different SIEM and SOAR solution including all the major OEM's
What do you dislike about the product?
As per my usage it becomes a mess while understanding due to various tabs and same information on 2 or more tabs. it confuses a user to look out for important information.
What problems is the product solving and how is that benefiting you?
Trend micro Vision one solution provided me visiblity and IOC/IOA acorss my network and endpoints which helped me and my security team to act upon the responses in timly and effective manner.


    Dariusz Podleśny

Enabled me to completely change user behavior and manage all our endpoints almost single handedly

  • October 24, 2023
  • Review provided by PeerSpot

What is our primary use case?

It's a perfect tool for monitoring infrastructure, including endpoints, servers, and potential attacks via networks. That's especially true for internet-visible hosts, which we can monitor directly from the tool.

We had problems with users not using legitimate tools, such as pendrives. We needed to protect hosts from external threats and third-party actors. That included monitoring behavior, scanning our infrastructure, and exploitation of vulnerabilities.

How has it helped my organization?

The solution has enabled us to completely reorganize our work. I was the first person using this tool in our company, and I completely changed user behavior to become more restricted. In Poland, but also in the United States, we are very strict about abnormal usage of our tools or attempts to download tools that shouldn't be on desktops, laptops, or servers. From my point of view, we are now a completely different organization than when I joined it. Trend Micro is one of the most important security tools we have implemented.

We don't need to use an external vulnerability scanner because Trend Micro XDR has a module for that, and we can save that money.

Trend Micro's Managed XDR is quite nice because I can manage more than 2,000 endpoints. I use the playbooks with particular scenarios for incident management. It's a very nice tool. It competes with anyone on the market. Sometimes, when we detect some kind of threat and we have no idea how we should investigate, troubleshoot, or mitigate the risk, we use the managed service team with Trend Micro engineers. I'm very happy with this team. They are very good professionals.

We respond much faster thanks to the intelligence used by Trend Micro. They have very good knowledge because they have many threat sources. That is why we are reacting much faster than we would if we had to dig deeper without that knowledge and this tool. It would be absolutely impossible to manage this infrastructure by a single admin or even two security admins. We are able to detect and respond about 80 percent faster. It's not only the monitoring and alerting for classic signature threats; there is also a tool for monitoring user behavior. It would be utterly impossible to find abnormal user behavior without this type of tool.

And we have mitigated most of the false positives—more than 90 percent. About one out of 10 alerts may be a false positive. In the beginning, we had to learn about Trend Micro, what was a legitimate action and what was a suspicious or malicious action. We had to learn what the right approach was.

What is most valuable?

This product is simple to use. Sometimes, especially when new features come out, I need to spend a little bit of time discovering how they work. But overall, it's simple. The interface is quite nice.

The integration is also nice because there are many external tools that we can connect to the platform, such as configuration management tools. Because the platform is integrated, I can manage almost the whole company across our global organization. I can almost manage the infrastructure alone. We have minimized the need to expand our team.

It also handles vulnerability management.

We use Trend Micro to cover endpoint protection and server protection. That's one of the key points for our company. And Trend Micro Vision One absolutely gives us centralized visibility and management. Especially when we integrate it with Active Directory, we get full visibility of our endpoint and server infrastructure. That is very important; a 10 on a scale of one to 10.

We also use the solution's Executive Dashboards. We present the findings in steering committees periodically. Sometimes, there is a repetitive alert or event. Directly from this dashboard, I can see the groups of this type of event. For me, it's quite a nice tool for presenting the results to the C level and the whole company for those who are not technically experienced.

And especially because of the new European regulation called NIST 2, we are using the solution's Risk Index feature. We calculate our risk score and we can see how it is changing in the timeline. Is it growing? Is there a new vulnerability detected? We can also compare our risk score with organizations of the same size or in the same industry and see if we are better or worse.

What needs improvement?

The area for improvement is mobile security. We have just finished a proof of concept for Zero Trust Secure Access. We withdrew from this PoC because it does not have that many points for proxy across Europe. Our organization is across Europe, and it will be nice when it is possible to have Trend Micro proxies across many more countries. At this time, they are only located in Germany and the UK. For us, it's not enough. We are waiting for them to increase the points of contact, and after that, we will return to this project. 

From my experience, it was quite a nice tool, and I could manage almost all of the actions that I could not manage in a traditional way. Traditionally, I could allow or block usage of an application. But using the Zero Trust Secure Access tool, I could manage the schema of the usage. I will wait for this tool to change in the next few months.

For how long have I used the solution?

I have been using Trend Micro XDR for almost 20 months.

What do I think about the stability of the solution?

It's a stable product. We haven't detected any issues other than the false positives, but that's normal.

What do I think about the scalability of the solution?

We use it in multiple locations because our company is spread across Europe and Asia, as well as the United States and Canada. We have more than 2,000 users, and the solution covers 400 or 500 assets.

If our company were to increase over two to three months to 10,000 users, it would not be a problem. We have the ability to extend as we scale our users. It's very simple and absolutely flexible.

How are customer service and support?

Their technical support is nice. On a scale of one to 10, it's a 10. They respond fast using email, phone, and the customer service portal.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I used competitors' tools, Secureworks, as well as Carbon Black. These are nice tools, but they are very heavy to implement and heavy on daily operations. Trend Micro is much better, much more flexible, and I have much more visibility. It is a cost- and time-saving tool.

How was the initial setup?

Our deployment is a hybrid. We have advanced our implementation a lot. The first implementation was only one of the features called OfficeScan. That was a few years ago, and the implementation was in the United States. After that, we moved forward with the implementation across servers and endpoints, including Mac and Microsoft endpoints.

The whole project took about three months, with the custom discovery and the fine tuning. We had two people involved, one in Europe and one in the US.

Sometimes, maintenance is required if there is a new feature. It needs to be restarted. But this function is done by Trend Micro engineers because we are using the XDR in the cloud. We don't touch it. There is maintenance on our side for Deep Discovery because that part is an on-prem solution. But it's simple to manage.

What other advice do I have?

They are implementing new tools, like Trend Micro Apex One and DDI. They are ready for implementation on the console, and we are waiting to transition to these tools.

For the new features, I prefer doing a proof of concept, like we did for the Zero Trust Secue Access platform. That was a good move because we saved time when it came to resolving issues on the user side. We had a few users in every department, and we tried to discover what would happen if we implemented this tool. That is my approach to being safe with such products. We can do things without any technical training and can disconnect users around the world using one switch. For new features, I'm a big fan of using a proof of concept.


    Judiciary

Great experience to High administration

  • October 19, 2023
  • Review provided by G2

What do you like best about the product?
great information for vulnerable process and how to solve it.
ease of use.
ease of implememtation.
number of feature.
ease of integration.
What do you dislike about the product?
few graphics and search not working.
customer support.
frequency of use.
What problems is the product solving and how is that benefiting you?
vulnerable IPs and domains


    Israel A.

Visibility

  • October 19, 2023
  • Review provided by G2

What do you like best about the product?
Vision One provides us with complete visibility of our organization, helps us understand our level of risk and what factors we can improve. The possibility of integrating with other solutions helps us to have a more accurate and real risk index.
Another important factor is the correlation of events when investigating a security incident, which gives us valuable information.
What do you dislike about the product?
I think the reporting could be more specific, for example we cannot have a report with all the vulnerabilities of our assets, it can only be obtained in a csv and that makes it difficult for us to deliver the results.
What problems is the product solving and how is that benefiting you?
Visibility, the ability to manage everything from a single console is an important factor in decision making.