The best use case is that it actually lifts off a lot of burden on customers, especially when they are deploying Cylance compared to other solutions.
Solution Architect at a computer software company with 1,001-5,000 employees
Good technology that's simple to deploy and easy to expand
Pros and Cons
- "One of the best features of the solution is that it's easy to deploy."
- "If they can add more features on top of their Persona feature that would be ideal."
What is our primary use case?
What is most valuable?
One of the best features of the solution is that it's easy to deploy. Second is the management part and the protection. It's way ahead of the other solutions compared to the signature-based one.
The base platform, the CylancePROTECT is a very good technology. If you upgraded that into a CylanceOPTICS, that will also help, however, CylancePROTECT itself can do a lot of protection.
There's a feature that they added called PERSONA. This is AI-based user behavior monitoring which is very useful.
It's straightforward to deploy.
What needs improvement?
If they can add more features on top of their Persona feature that would be ideal. It could also improve the UEBA feature of Cylance.
For how long have I used the solution?
I've been working with the solution for around five years. I started using it around 2016.
Buyer's Guide
BlackBerry Cylance Cybersecurity
February 2026
Learn what your peers think about BlackBerry Cylance Cybersecurity. Get advice and tips from experienced pros sharing their opinions. Updated: February 2026.
881,757 professionals have used our research since 2012.
What do I think about the stability of the solution?
As a cloud-based management platform, it's very stable. The version of the agent is very minimal in terms of updates. In terms of support, they have very broad support on several operating systems. The stability is quite high for this kind of solution.
What do I think about the scalability of the solution?
It's a cloud-based management platform. It's very scalable. It's easy to ramp up the number of devices that you want to be managed by this kind of solution. It's highly scalable.
Our clients have actually upgraded and ramped up the number of licenses from the first time I deployed and introduced them to the solution. Most of our customers have expanded usage via the number of licenses they have.
How are customer service and support?
I've used technical support in the past. The technical support, the SLA, if they can improve that aspect of the product it'll be much appreciated.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
I've also worked with CylancePERSONA over the past year or so.
How was the initial setup?
The initial setup is very straightforward. It's not overly complex.
The management and maintenance is also very easy.
What's my experience with pricing, setup cost, and licensing?
What I've heard from my customers is that Cylance, in terms of pricing, is a bit higher compared to other prominent solutions like Kaspersky and Symantec, however, that's about it in terms of what I know about the product pricing.
What other advice do I have?
I'm working in a distributor company and we are actually selling CylancePROTECT.
The primary platform is a cloud-based solution. It is managed in the cloud. The one on-premise is called the hybrid platform where you can also do management locally on your site.
The best way to see the solution is to try it out. Try it first before worrying about pricing and see if it will meet your needs and how it works for your business.
I'd rate the solution eight out of ten. They simply need to improve the SLA, the response, and the Persona feature. If they do, I would rate it higher.
Disclosure: My company has a business relationship with this vendor other than being a customer.
IT Manager
Stable and reasonably-priced solution
Pros and Cons
- "CylancePROTECT is very stable - we've had no issues with performance and no errors or bugs."
- "CylancePROTECT's dashboard could be more user-friendly."
What needs improvement?
CylancePROTECT's dashboard could be more user-friendly.
For how long have I used the solution?
I've been using CylancePROTECT for three years.
What do I think about the stability of the solution?
CylancePROTECT is very stable - we've had no issues with performance and no errors or bugs.
What do I think about the scalability of the solution?
CylancePROTECT is scalable.
How are customer service and support?
CylancePROTECT's technical support is non-existent.
How was the initial setup?
The initial setup was easy.
What's my experience with pricing, setup cost, and licensing?
CylancePROTECT's pricing is reasonable, at about €18 per user, per year.
What other advice do I have?
I would rate CylancePROTECT as nine out of ten.
Which deployment model are you using for this solution?
Private Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
BlackBerry Cylance Cybersecurity
February 2026
Learn what your peers think about BlackBerry Cylance Cybersecurity. Get advice and tips from experienced pros sharing their opinions. Updated: February 2026.
881,757 professionals have used our research since 2012.
Senior Network Administrator at a financial services firm with 51-200 employees
Inconsistent stability with a difficult uninstall, although deployment of updates is easy
Pros and Cons
- "The deployment of updates is easy."
- "While you are working, you are finding these things that were supposed to be waived have come back to being blocked. That's frustrating."
What is our primary use case?
We use this solution for endpoint protection for our external devices and laptops.
What is most valuable?
The deployment of updates is easy.
What needs improvement?
Not having OPTICS doesn't allow us to do any history. We don't have OPTICS, but FortiEDR comes with things like OPTICS, which is nice because we are not able to see more.
OPTICS gives you things that FortiEDR has built in. For Cylance, there is an add-on to do the things that come with that solution.
It would be nice if Cylance didn't separate PROTECT and OPTICS and put them together and made them on the same price point as FortiEDR, and some other ones rather than having to pay extra for something that the others already have built-in, and seen to do better.
It often lets you waive something for the firm or for the whole company and then comes back and blocks the same thing because you have to do the certificate instead of the hash. You are finding yourself having to approve for the same program, the same application, the same file more than once and it's frustrating.
While the deployment of updates is easy, it would be good to have some more information about which version to use, because the versions that are available seem to be outdated.
When you go to the admin section, you will see that you will have the latest update from months ago and a month before that, and a month before that.
I have a hard time believing that there are no more updates in between when there are things that are out all the time. It just doesn't make you feel like you're getting covered or have the best protection, which you should have.
For how long have I used the solution?
I have been using this solution for two years.
We are using one of the newer versions. I don't always install the updates.
What do I think about the stability of the solution?
The stability varies. It's not consistent and it's frustrating.
Things that are blocked, you waive and it comes back. It's very frustrating. It doesn't keep up with the machines.
You have a lot of machines and if you reimage a lot you will see many duplicates that you have to export and remove from figuring out which one's the MAC address. It should have an easy way to know that a machine is re-imaged, and not adding to your list of devices.
You end up having all these devices that are no longer being scanned that you have to figure out what they are. It is frustrating.
What do I think about the scalability of the solution?
We have approximately 200 users in our organization. It's for everyone in our accounting firm, who are accountants, auditors, IT, and HR accounting.
We don't have plans to continue using this solution, we are considering other options.
How are customer service and technical support?
We don't go through technical support directly. We go through a reseller and they take care of it. We have never directly talked to BlackBerry or Cylance about any issues that we have had.
Which solution did I use previously and why did I switch?
Previously, we had McAfee ePO. We changed to CylaneProtect, a solution that we felt would be a better fit, and that was not managed in-house, on a local server that we used for that. It was time to move on from that.
How was the initial setup?
The initial setup was fine. It's doesn't take a long time to deploy.
Uninstalling is difficult. Sometimes it doesn't remove easily, and that is frustrating.
It would be nice if it had an uninstalled feature within the dashboard, in the SAS part of the application online, because it would do everything itself. Unless it is something that I have missed or that I didn't see.
With FortiEDR you can go in, and you can uninstall from the dash, find the endpoint you right-click, or you click a button, then you choose to uninstall and it pulls it from the machine. You don't have to put in any keys, or anything. It does it from there. I don't believe that Cylance does that, but it would be nice if it did.
We have a team of two, myself and my colleague maintain this solution.
What about the implementation team?
The deployment and implementation were completed in-house.
What other advice do I have?
I would advise that they keep in mind what it doesn't do and be open to looking at things that include more and cost less.
I would rate CylanceProtect a four out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Vice President Product and Strategy at a tech company with 201-500 employees
Scalable, with a straightforward setup and good virus protection
Pros and Cons
- "A user can continue to add endpoints and the solution will continue to perform well."
- "Having worked with SentinelOne, Cylance is good, however, it probably needs to add a feature similar to SentinelOne's rollback functionality. With this feature, if you get infected, with a click, you can go back to the pre-infection state. If Cylance could add this functionality to their offering as well, that would be ideal."
What is our primary use case?
I primarily use the solution for security purposes. I use it for endpoint protection and response. That's the only real use case for us.
What is most valuable?
The product works pretty well. It does a good job catching good viruses. While we haven't had a chance to test against any kind of ransomware attack, I know it works great and I'm not worried about its capabilities in that respect.
The initial setup was straightforward.
The solution has proven itself to be very stable and unobtrusive.
A user can continue to add endpoints and the solution will continue to perform well.
Technical support is helpful and responsive.
What needs improvement?
Having worked with SentinelOne, Cylance is good, however, it probably needs to add a feature similar to SentinelOne's rollback functionality. With this feature, if you get infected, with a click, you can go back to the pre-infection state. If Cylance could add this functionality to their offering as well, that would be ideal.
For how long have I used the solution?
I've used the solution for only a few months at this point. It hasn't been too long. It's still rather new to me.
What do I think about the stability of the solution?
The solution's stability is good. Most importantly, it is unintrusive. Even when it really goes through a lot of resources, it remains pretty stable. There are no bugs or glitches. It doesn't crash or freeze. it's reliable.
What do I think about the scalability of the solution?
The scalability is very good. I can add additional endpoints and the solution continues to perform well. If a company needs to expand, it should be able to do so with no problem.
We have thousands of departments. We are quite a sizeable business.
How are customer service and technical support?
My understanding is that technical support is quite good. I don't deal with them directly, however, I have heard that they are helpful and responsive. I would say that we are satisfied with the level of support we receive.
Which solution did I use previously and why did I switch?
I've used both Cylance and SentinelOne. I have more experience with SentinelOne.
However, they are very similar in terms of their offering. both offer good performance and are AI-driven with good machine learning capabilities. Neither has an impact on an endpoint's performance levels. They offer good protection as well. The biggest difference is that SentinelOne has a rollback feature, which is something Cylance should consider adding.
How was the initial setup?
The initial setup is not complex. It's very straightforward and very easy to deploy. A company would not have any issues with the process.
What's my experience with pricing, setup cost, and licensing?
I don't have any information in relation to the pricing or the licensing. it's not an aspect of the solution I deal with.
However, I can say that it's my understanding that it is 20% less expensive than SentinelOne.
What other advice do I have?
We are Cylance partners.
I'm not sure which version of the solution we're using. It's likely the most up-to-date version. They update them quite often.
I'd advise companies considering the solution to take some time to do a proof of concept to see how it would react in their environment and then decide if it is the right solution for them.
I would rate the solution at an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
IT Security manager at a energy/utilities company with 201-500 employees
Scalable product, needs work on false positives detection and application integration
Pros and Cons
- "The most functional item that we use is the process to turn off the false flags that it causes."
- "They could improve on the false positives, reporting and whitelisting features."
What is our primary use case?
We put the product on all of our desktops and servers.
How has it helped my organization?
The solution has broken down the organization by taking down the network about six times in two years.
What is most valuable?
The most functional item that we use is the process to turn off the false flags that it causes.
What needs improvement?
They could improve on the false positives, reporting and whitelisting features.
For future releases, it would be helpful to have an easy uninstall button. The reason being, unless you connect the system to the internet, which you may not want to do, Cylance cannot be uninstalled easily. They claim it's practically impossible. If you have access to the online admin panel, it's very easy to uninstall Cylance. There is no easy way to uninstall locally. I have read online there is a convoluted way with a series of reboots and safety reboots that you could possibly do it locally.
For how long have I used the solution?
I have been using it for about two years.
What do I think about the stability of the solution?
It is not stable. The solution has caused six crashes over two years, with one of them requiring us to rebuild all of our Windows 10 devices.
What do I think about the scalability of the solution?
Scalability is pretty good. We have around 100 users using the solution. However, when we rebuild new desktops, we're not installing it on them.
Which solution did I use previously and why did I switch?
We have used Symantec before and a MSSP came in with a package to help us get more secure, but it really was a failure.
What was our ROI?
The biggest issue we have with the product is it gives false positives.
What other advice do I have?
Beware and work out a process to restore items that were deleted by false flags.
Work out a process to investigate any odd behaviour or troubleshooting tickets with open source software being even a small sub-component.
For the majority of installs, the Cylance is going to break because of the small sub-component that's open-source that is out of date. Always no matter what problem is happening, double-check to see if there were any flags in Cylance because it's probably going to be Cylance blocking something along the line. It will drive you nuts to work with your third-party technical support to track down an issue to then find out it was Cylance blocking one small facet of it.
Work out all those details with your Cylance team first, this way, whenever you have an issue, you can identify that Cylance is involved because it's involved in everything.
An example of an issue we were having was while we were trying to install a check scanner the install did not work. Cylance was blocking an old open source piece of software that comes from Kodak that you can't update because Kodak says it is the latest version of our installer for the check scanner. The installer for the check scanner includes the open-source piece of software from Kodak that's out of date. This causes the entire check scanner not to work, Cylance blocks the main installation because of the sub-installation of the open-source software.
Make sure your ducks are in a row so that you can detect when Cylance is causing an issue, report it and get it whitelisted. If you do not, you're going to spend an inordinate amount of time figuring out whether or not Cylance did something to block you, whitelisting and then more time justifying why you need it whitelisted.
I'm sure we were much more protected with it on, but the problem is if you're protecting me from my network being taken down, by taking my network down, you are not protecting it. For this reason, I rate CylancePROTECT a five out of ten.
Which deployment model are you using for this solution?
Private Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
OT Cyber Security Principal Consultant at a construction company with 10,001+ employees
An outstanding product that is pretty spot on and easy to deploy and use
Pros and Cons
- "The non-daily requirement to update signatures is the most valuable feature. From a functional point of view, it is pretty spot on. For instance, we compared an algorithm from five years ago to today's algorithm, and it was 98% accurate. It has the ability to detect and mitigate. In the industrial environment that we work in, there's what we call OT versus IT. You are IT Central, but this is OT. Generally, we don't have the same level of skillset as IT individuals or IT professionals have. This particular product doesn't require you to be a computer scientist to be able to understand its proprietary algorithm and to be able to deploy, use, and work within it. It integrates well with a robust SIEM or SOAR solution, and it plays nice with others. We use other detection solutions like CyberX or site provision with Cisco, and it plays nice. That's one of the things we really liked about it."
- "It could have integration with industrial base HMIS or Human Machine Interfaces Solutions. This is the industrial environment where you have a control center for all the automation that's happening, whether it is oil, gas, or chemical manufacturing. They often have to set up a computer at the back and watch the other stuff to get alerts. In these autonomous or on-premises environments, they often don't have access to email readily. Integration with other industrial solutions, such as HMIS, will allow them to communicate and get an alert that something has been found. This way, they can react to it sooner than having somebody watch the screen and keep checking the screen. Rockwell has its own suite. Similarly, Honeywell has its own suite. There's also an independent HMI/historian solution provider out there called VTSCADA. We actually get asked if we can get it to show up on a screen, which is difficult. Getting those alerts to work within an industrial environment would be a huge plus."
What is our primary use case?
I direct our design and engineering teams, and we craft solutions for on-premises or autonomous networks in the industrial industry, such as oil and gas, water, and manufacturing.
We use this solution as a layered defense for the defense strategy for our on-premises clients. An attractive thing about this solution is that it uses AI official algorithms to not only discover known stuff but also to discover anomalous behavior and things that are out of the ordinary. It is not just signature-based; it is an algorithm or AI and machine learning.
How has it helped my organization?
From an administrative overhead point of view, there is a 75% reduction in administrating the solution.
What is most valuable?
The non-daily requirement to update signatures is the most valuable feature. From a functional point of view, it is pretty spot on. For instance, we compared an algorithm from five years ago to today's algorithm, and it was 98% accurate. It has the ability to detect and mitigate.
In the industrial environment that we work in, there's what we call OT versus IT. You are IT Central, but this is OT. Generally, we don't have the same level of skillset as IT individuals or IT professionals have. This particular product doesn't require you to be a computer scientist to be able to understand its proprietary algorithm and to be able to deploy, use, and work within it. It integrates well with a robust SIEM or SOAR solution, and it plays nice with others. We use other detection solutions like CyberX or site provision with Cisco, and it plays nice. That's one of the things we really liked about it.
What needs improvement?
It could have integration with industrial base HMIS or Human Machine Interfaces Solutions. This is the industrial environment where you have a control center for all the automation that's happening, whether it is oil, gas, or chemical manufacturing. They often have to set up a computer at the back and watch the other stuff to get alerts. In these autonomous or on-premises environments, they often don't have access to email readily. Integration with other industrial solutions, such as HMIS, will allow them to communicate and get an alert that something has been found. This way, they can react to it sooner than having somebody watch the screen and keep checking the screen. Rockwell has its own suite. Similarly, Honeywell has its own suite. There's also an independent HMI/historian solution provider out there called VTSCADA. We actually get asked if we can get it to show up on a screen, which is difficult. Getting those alerts to work within an industrial environment would be a huge plus.
For how long have I used the solution?
I have been using this solution for about a year and a half.
What do I think about the stability of the solution?
It has been rock solid. We haven't had any hiccups in terms of compatibilities and server uptime. Everything, such as application and reliability, is there. It is very strong.
What do I think about the scalability of the solution?
It scales extremely well. We're on the low end of the quantity, but it scales up into tens of thousands very easily.
How are customer service and technical support?
We have the ability to go right into critical because of our partnership level with them. Their support has been exemplary.
How was the initial setup?
The initial setup is pretty straightforward. Our guys are trained up in it.
What other advice do I have?
They like to see licensing at a higher level. That's not the norm for on-premises economist environments in the industrial industry. If you're an integrator versus an end user, they like to look at the quantity. Even though they like to start at quantities less than a thousand, it is cumulative. I've got a thousand clients at a hundred, so now I've got a 100,000. Therefore, don't let the scalability, where they like to play in tens of thousands, dissuade you from incorporating this product.
It is quite different from the standard signature-based approach to endpoint protection. At first, you're a little worried because you're so used to staying on top of it or having to stay on top of it versus building a level of trust that it is actually working, and I don't need to mother it.
I would rate CylancePROTECT a nine out of ten. I'll never give anybody a ten because that's a perfect world, and we don't live in a perfect world. This rating is based on my experience with Cylance from the onset, learning the product, working with it to roll it out, working independently, and interfacing with the client. It has been very outstanding.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT Infrastructure Manager at a financial services firm with 51-200 employees
Good security, cloud-based administration, lightweight, and stable
Pros and Cons
- "We are quite security-focused. Blackberry Protect as an endpoint solution for our service really delivers what we are expecting."
- "We would like to see secure integration and multi-factor authentication to be able to access the administration dashboard."
What is our primary use case?
We are currently using Blackberry Protect as our main endpoint solution, for threat prevention, script control, and scanning of malware. This is the core functionality of the Protect module.
We have the Blackberry Optics, which is the AI module of Blackberry Protect. It is called Blackberry Protect Plus Optics. The Optics feature logs all of the behavior of the servers. For example, when someone runs a PowerShell script and it blocks, it will learn the behavior and knows what to do the next time another user triggers that specific functionality.
It is currently deployed on-premises but our administration dashboard is in the cloud.
The agents are installed for our servers and reporting is to the Blackberry cloud.
What is most valuable?
This is still new to us. We have explored this solution and it fulfills our requirements, in terms of live malware detection.
We are quite security-focused. Blackberry Protect as an endpoint solution for our service really delivers what we are expecting.
What needs improvement?
When it comes to the management of the application of agents, especially for us as an IT team the dashboard is much easier to manage in the McAfee solution.
We were looking to have a multi-factor authentication with the administration dashboard to log in, because it's cloud-based.
There is no integration with Google Authenticator and other solution providers.
We would like to see secure integration and multi-factor authentication to be able to access the administration dashboard.
For how long have I used the solution?
We have been using Blackberry Protect for just less than a year.
We are two versions behind the latest one.
What do I think about the stability of the solution?
Definitely, Blackberry Protect is a stable product. We have not had any kind of blue screen of death or crosstabs.
It's really lightweight in terms of resource consumption as well and in terms of memory and CPU consumption, it's quite low which is very good for us for other applications.
What do I think about the scalability of the solution?
It's a scalable solution.
We have approximately 150 people in our organization who are using it.
Which solution did I use previously and why did I switch?
We are also using Microsoft Outlook to block any kind of unwanted applications, which our users try to run in the background.
How was the initial setup?
The initial setup is very straightforward. You just click on the MSI and provide the key to register for it to sync to the cloud dashboard.
We have a team of seven IT resources who have an account under Blackberry administration.
What's my experience with pricing, setup cost, and licensing?
We pay our license on a yearly basis and have just renewed for two years.
Which other solutions did I evaluate?
We have not evaluated other options. For the time being, we are very satisfied with what we have.
What other advice do I have?
I would definitely recommend this solution to others who are interested in using it.
There is always room for improvement. I would rate Blackberry Protect an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
BlackBerry Cylance SME - Resident Engineer at a tech services company with 201-500 employees
Good endpoint protection, stable, easy to install, and the support is good
Pros and Cons
- "I like the AI and mathematical components that they use."
- "It's a good solution but some features just need to be updated."
What is our primary use case?
I use this solution as a customer and I provide services for my clients. We are system integrators and we use this solution for endpoint security.
What is most valuable?
I like the AI and mathematical components that they use.
I like the pre-execution method of protection that prevents infection. It is a nice feature.
What needs improvement?
I have already suggested features that need to be improved and Blackberry is already working on those improvements. For example, the interface and the Cylance Optics need to be improved a fair bit.
It's a good solution but some features just need to be updated.
For how long have I used the solution?
I have been using Blackberry Protect for almost four years.
What do I think about the stability of the solution?
Blackberry Protect is stable. I have not experienced any issues with bugs or had any limitations with this Blackberry product. It's a good solution.
How are customer service and technical support?
Technical support is good, but the response time could be improved. They can take two or three days to get back to you with a solution.
How was the initial setup?
The initial setup is straightforward. It is very easy to install.
What's my experience with pricing, setup cost, and licensing?
It's not so heavily priced; rather, it's average and decent.
What other advice do I have?
I would recommend going with Blackberry Cylance, it's good.
It's a very lightweight agent that doesn't put very much pressure on the computers, it's really good in terms of resources.
I would rate Blackberry Protect a nine out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Integrator
Buyer's Guide
Download our free BlackBerry Cylance Cybersecurity Report and get advice and tips from experienced pros
sharing their opinions.
Updated: February 2026
Product Categories
Endpoint Protection Platform (EPP)Popular Comparisons
CrowdStrike Falcon
Microsoft Defender for Endpoint
SentinelOne Singularity Complete
HP Wolf Security
Cortex XDR by Palo Alto Networks
Trellix Endpoint Security Platform
Fortinet FortiClient
Check Point Harmony Endpoint
Symantec Endpoint Security
Kaspersky Endpoint Security for Business
ESET Endpoint Protection Platform
Trend Vision One Endpoint Security
Intercept X Endpoint
Buyer's Guide
Download our free BlackBerry Cylance Cybersecurity Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- I'm building a next-gen AI powered threat intelligence platform. What's missing from existing solutions?
- What is the biggest difference between CrowdStrike and Cylance?
- How would you compare BlackBerry Protect vs Cortex XDR by Palo Alto Networks?
- What is the biggest difference between EPP and EDR products?
- Can Cylance be used with Symantec or Kaspersky endpoint solutions without conflict?
- When evaluating Endpoint Security, what aspect do you think is the most important to look for?
- What's the best way to trial endpoint protection solutions?
- What are the threats associated with using ‘bogus’ cybersecurity tools?
- Which Endpoint Protection Solution offers Zero Trust (ZTN) as a feature?
- What to choose: an endpoint antivirus, an EDR solution or both?

















