What is our primary use case?
I have been working with
Trellix Helix Connect for a long period of time, almost nine years. I have worked on different products including
Application Control, encryption, email security, EDR,
XDR, and all the newly added products in Trellix.
The orchestrated workflows in Trellix Helix Connect have helped enhance my threat response. In the orchestration, we are getting the reporting site and an investigation report. If you are using DLP or XDR, we get the DLP report on the orchestrated platform. For SaaS-based EPO that is already in the cloud, customers have no hassle because all upgradations and products are upgraded automatically on the cloud side. However, for on-premises platforms, customers want different types of reporting. For example, if any incident happens, it instantly shows in the dashboard, and from this, we can get detailed reporting on that attack surface and incident report. I think if these types of things are added to the platform, it would be helpful for customers and for us.
What is most valuable?
The features that I find most valuable in Trellix Helix Connect are the incident response capabilities, which include EDR and XDR, along with the SoC capabilities added in the new advanced Trellix AI intelligence. These things are very important to all organizations.
Additionally, DLP is also very essential for our organization, as they are already using it. We are trying to introduce the Trellix layer security, but we still need some time to introduce all aspects to our own customers. We are working at our level best to achieve that.
The customizable alerts and reports in Trellix Helix Connect assist my team in adapting security strategies. When using cloud sites with products such as EDR and XDR, you are not left with vulnerabilities, but when you are using third-party tools, you can analyze that your site is totally secured. This is something customers sometimes require. For example, with this type of report submitted to CrowdStrike, that product shows their reporting and sends the email to that customer particularly, and they are very happy about that. In Trellix, we need these types of reports where you are giving information for analyzing or reporting, and scanning shows that your site is very secure and you are using a high-level, advanced-level threat protection detection product. This type of report could sometimes be sent to the customer, stating that you are using it and you are totally secure. This would be helpful for us.
What needs improvement?
I would assess the effectiveness of Trellix Helix Connect's threat detection capabilities as improved nowadays. Some aspects of Trellix are improved using the AI technological sector, particularly EDR, which is Extended Detection and Response, capable of visualizing the incidents and the response. However, from my perspective, compared to other products, we need to improve the integration of detection and response in the product. For example, if I consider CrowdStrike, they provide their EDR capabilities, the scanning report, and vulnerability in the product, and they have provided third parties to analyze the report. Trellix has not provided their actual report on whether there is any vulnerability on the cloud side or not. This is the type of thing that customers sometimes recommend, in that they need a report showing clear visualization and that AI has detected something on the cloud service which needs to be reported. These types of things are required for customers nowadays.
Trellix Helix Connect can be improved in various ways. There are some issues such as high CPU utilization that we have experienced in the past whenever we were using Trellix Endpoint Security in the cloud system, which prevented anyone from working properly. I think they are reducing this with the upgradation of the Endpoint Security product and other products, but the main concern is sometimes the client cannot work properly when using Endpoint Security because it takes high CPU utilization. We also sometimes face issues with encryption. We are worried about this because sometimes some systems are taking the encryption as inactive. The encryption is happening, but it is not active and is showing as inactive. However, for reporting purposes in the EPO, it is showing that it is active when it is not actually active. These types of mismatches between the customer and Trellix platform side need to be improved.
For how long have I used the solution?
I have been working almost nine years.
How are customer service and support?
I would rate technical support for Trellix Helix Connect as eight out of ten based on my calculations and perspective.
What other advice do I have?
I do use the integration feature in Trellix Helix Connect. Trellix is now not only on-premises but also working on the SaaS base. In the SaaS-based EPO, we are integrated with the on-premise or SaaS base, and we are transferring the system to the SaaS base. Some clients are trying to transfer their system to the cloud and some are using that cloud DLP. The problem is with the DLP integration. Another product is Solidcore, which is related to
Application Control,
Change Control, and Execution Monitoring, and it is not properly integrated with the SaaS-based EPO. It is a main concern that we need proper integrations to the cloud services for Application Control,
Change Control, and integrity monitoring for Solidcore devices.
I can share that the efficiency improvement Trellix Helix Connect brought to my customer's security operations varies because for different customers, their expectations, design, and requirements are different. For example, banks have different requirements than customers on the medical side, such as pharmaceuticals. In some banking sectors, they want proper visualization, reporting, and a customized dashboard that can help them submit their report to higher authorities. On the other hand, if you consider the pharmaceutical sector, they want total security where nobody can access and nobody can get any internal report or internal information. They want to secure their site. This is the difference between companies using it, as their requirements are totally different. Some use Application Control for ATM security for banks, but on the other hand, if you consider pharmaceuticals, they do not need any ATM security level of protection. They need high-level data protection as that is a high concern for them. Overall, the different products and their working capabilities are different, and customers want to get their organization secure in that way. I think penetration testing and other things could be added which would be helpful for customers for future reporting purposes, protection purposes, or detection purposes. My overall rating for Trellix Helix Connect is eight out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other