Our primary use case is for protection.
Technology Specialist at a tech vendor with 11-50 employees
Innovative concept with good detection, scans, and machine learning
Pros and Cons
- "Has good RAM capacity for the power I need"
- "It should have better support for Windows and Mac."
What is our primary use case?
What is most valuable?
The most valuable features of this solution are that it's:
- Easy to use
- Minimalist
- Has good RAM capacity for the power I need.
- Isn't bulky.
What needs improvement?
It should have better support for Windows and Mac.
For how long have I used the solution?
I have been using Cylance for one year.
Buyer's Guide
BlackBerry Cylance Cybersecurity
June 2025

Learn what your peers think about BlackBerry Cylance Cybersecurity. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
856,873 professionals have used our research since 2012.
What do I think about the stability of the solution?
It's stable.
What do I think about the scalability of the solution?
I haven't needed to scale. I use this solution daily.
Which solution did I use previously and why did I switch?
I have used other free products.
You can't directly compare those solutions with Cylance because they're free products and Cylance is paid. It's not good to compare them.
I had a virus attack and malware on my PC even when I used the free solutions. I don't think it works. Those solutions were very bad. They did not have good detection. You can't rely on them because they're not paid for.
How was the initial setup?
The initial setup was easy. It took around an hour and a half. We deployed it ourselves.
What other advice do I have?
My advice to someone considering this solution is that it's a popular product and you should really go for it. Cylance is a new company with a very innovative concept. I really like its detection, its scans, and the machine learning.
I would recommend this solution. I'd rate Cylance a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Owner at Terra Controls
Proactive AI-based security that scales as we need it
Pros and Cons
- "Two or three years ago when the WannaCry virus struck, the people that were on Cylance were the ones that weren't affected."
- "I would like to see them fix the alerting system so that the endpoint reporting is a bit more streamlined."
What is our primary use case?
We are a solution provider and this is one of the security products that we implement for our customers. My biggest customers are two pharmacies and a bank and this makes up part of their security solution.
How has it helped my organization?
We have not had any data breaches. It has found flaws inside of our security procedures that enabled us to close the holes.
What is most valuable?
The most valuable feature is the AI and ML-based virus protection that does not rely on signature-based detection methods. The way this product works is that it does not go to a central server to pick up the latest virus definitions. Instead, it's a processor-powered search that checks to see if anything out of the ordinary is running on your machine. It looks for anomalies and cancels processes that do not look normal. For example, if a program tries to read the registry and then make a change, but it hasn't been authorized, then it is assumed to be a bad actor and the process is canceled or the action is disallowed.
What needs improvement?
There are a lot of false positives and it takes up a lot of time. This is something that should be improved.
I would like to see them fix the alerting system so that the endpoint reporting is a bit more streamlined.
The vendor should be more widely advertising this product because not many people know that these types of solutions exist.
For how long have I used the solution?
I have been using Cylance for about a year.
What do I think about the stability of the solution?
The stability is perfect. It is leaps and bounds beyond our previous solution by McAfee.
What do I think about the scalability of the solution?
It is scalable. From what we were told, we're going to keep on adding more licenses. The only thing that we might have to do is increase the capacity of the VM.
Which solution did I use previously and why did I switch?
We were using McAfee first, and as of last year, we switched to Cylance. McAfee is not a proactive solution. McAfee's support and everything were fine, but the Cylance product is used by the G7 countries the most. The company has a good standing.
Two or three years ago when the WannaCry virus struck, the people that were on Cylance were the ones that weren't affected. That was enough for us to switch.
How was the initial setup?
We engage with Cylance Professional Services, so there was not much need for input from our side. From our point of view, the initial setup is pretty straightforward.
The software is installed on a VM and we have about 70 machines in total. The deployment took about two days.
What about the implementation team?
For my financial client, I was a consultant. They have their own IT team and I acted as the intermediary.
What's my experience with pricing, setup cost, and licensing?
We paid according to the number of endpoints that we have and it was approximately the same that we were paying for McAfee. The monthly fee is $55 USD per user.
What other advice do I have?
I don't think too much about the features when it comes to an antivirus solution, such as this. When you try to combine too much into one product, you end up affecting the product as a whole. If you're a home user then it's great because you only pay once a year and it does everything including the antivirus, firewall, VPN, internet security, and more. However, when you're in an SMB or an SME installation, all of those things are decentralized.
My advice for anybody who is considering this solution is to switch if you have the money put aside. I would suggest using Professional Services to assist with the migration.
I would rate this solution an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
BlackBerry Cylance Cybersecurity
June 2025

Learn what your peers think about BlackBerry Cylance Cybersecurity. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
856,873 professionals have used our research since 2012.
Head of Cloud Services and Projects at Grove
Solution has picked up files that other platforms don't plus it uses machine learning and AI protection
Pros and Cons
- "The solution is extremely scalable. It's got the hybrid functionality, it's got the system functionality and cloud functionality as well."
- "I would say one thing that they might need to bring in is protection for mobile devices."
What is our primary use case?
We did a POC with Cylance, Bitdefender and ESAT. Cylance picked up Zero-Day Malware that the other two solutions did not quarantine.
How has it helped my organization?
With no on-premise hardware required, we easily deployed the Cylance solutions to our end-points. The Cylance Admin console is web-based and it's easy to create custom policies, add zones and manage all our end-points all in the same admin portal.
What is most valuable?
The protection, specifically for endpoint protection, has been the most valuable. With Cylance AI and Machine Learning, it's ensuring that all types of malware, PUP (Potential Unwanted Programs) and Memory Protection your endpoint devices are fully protected, even with day zero threats. Cylance also got the optics add-on for advance scanning and reporting, but most of the clients are more interested in the protection as this is all you need for your endpoint security.
What needs improvement?
To be honest, I think the product is, overall, quite good. It's working with AI Technology and machine learning that is connected to the Cylance Infinity Cloud. It picked up malicious files that other vendors didn't. It's actually been great on its own. Cylance is also launching mobile protection in 2020. At the moment the Cylance agent supports Windows, Mac OS and Linux devices, but they do not have an app for Android and IOS yet.
For how long have I used the solution?
I've been using the solution for 2-3 months.
What do I think about the stability of the solution?
The solution is really stable. We use the solution for small and medium-sized enterprises.
What do I think about the scalability of the solution?
The solution is extremely scalable. It's got the hybrid functionality, it's got the system functionality, and cloud functionality as well.
How are customer service and technical support?
The technical support is really great. We are working hand in hand with them.
How was the initial setup?
The initial setup is easy. You have the option to install the endpoint client on all Windows devices, Mac OS and supported Linux OS. For Windows devices, you can download the exe file, or the MSI file for installation via Group policies to roll out on multiple endpoints at the same time.
What other advice do I have?
You can obviously get in touch with a partner (Grove Group) like us, and we can arrange a POC for your business. While we're dealing with the POC, it will showcase the product and how valuable the product is for your business. Plus, it will actually show what defective files it's picking up in real-time. You can do a side by side comparison while you're running Cylance with your existing endpoint protection to see the difference in protection. You can see exactly what Cylance does pick up on both the endpoint device and the admin console. I also love the fact that the en-point software is not using a lot of resources on the client. I would say you should take the opportunity and run a POC and evaluate the software and you'll notice with the web interface, the admin dashboard on the website, how easy it is to work with Cylance and protect your endpoints. You don't need any on-prem servers to run the endpoints software. Go and experience Cylance and see how AI and Machine Learning is the future to protect your Business.
I would rate the solution as a 10 out of 10.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner.
Co-Founder, CEO at a tech services company with 11-50 employees
Nice management display, easy to install, and works satisfactorily for standard protection
Pros and Cons
- "On the management side, we liked the way it displays things."
- "It should provide more details about the events that they have detected."
What is our primary use case?
We are part of a startup company that is operating in the same domain as this solution, so we tested it as part of the competition.
What is most valuable?
On the management side, we liked the way it displays things.
What needs improvement?
The downside is that the information displayed is not enriched enough. There was not much information available, that we could see. It should provide more details about the events that they have detected. There should be more information available post-incident. Basically, the user is informed that they have caught a threat, stopped it, and that's it.
Users want to know what the threat was, the type of attack, how it got in, which IP address, did it go into lateral movement, etc. The kind of information that could be analyzed by IT experts to take forward and understand whether the attack is continuing, or not. They have some of this information but compared to other products, it's basic.
For how long have I used the solution?
We tested this solution for about six months.
What do I think about the stability of the solution?
We did not thoroughly test its stability, but I can say that we didn't have any crashes or basic problems with it. In our tests, it did not crash, although we were focused on detecting threats as opposed to assessing stability.
What do I think about the scalability of the solution?
We installed this solution for five users.
How are customer service and technical support?
We did not contact technical support.
How was the initial setup?
The initial setup and installation of this solution are quite straightforward. Just download from the management console and install it. It's easy.
What about the implementation team?
We performed the installation ourselves.
Which other solutions did I evaluate?
We have evaluated many products. In fact, we tested most of them for our purposes of developing our own. Because we did a competitive analysis, we are keeping most of the information private. However, I can say that SentinelOne, CrowdStrike, and Carbon Black give you a lot more information than Cylance.
The majority of the leading solutions are quite good, and it's a tough market. For normal people, it is difficult to see the differences between them.
What other advice do I have?
The lack of details for the user is partly because of the way they detect. it is done passively, rather than dynamically, so they don't have a lot of information about the things that they already caught.
The suitability of this solution for any particular person will depend on their expectations. I would not rate this solution in the top five for things like presenting information, or ease of use. For standard protection they are ok, but if you have advanced demands, or a SOC, then I don't think that Cylance can compete with Carbon Black, CrowdStrike, or SentinelOne.
I would rate this solution an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Wirtschaftsprüfer, CPA, Steuerberater at a financial services firm with 11-50 employees
Doesn't consume too many system resources
Pros and Cons
- "The solution is stable."
- "The solution needs better dashboards that are easier to use."
What is our primary use case?
We use this product as our antivirus solution.
What is most valuable?
The most valuable feature is that it's quite small, and does not consume too many system resources.
What needs improvement?
Improvements could be made on the user interface of the console. Also, right now it's just an antivirus and there's no firewall or anything. So we have to use the Windows firewall. It's a good firewall. But I think other companies have integrated products.
The solution needs better dashboards that are easier to use. Also, a better user interface. Maybe even firewall integration of some kind. It would be helpful if you could see which threats have been detected, and have more information about what is going on.
What I'm missing is a backup. In Norton, there was a backup included. In Cylance there is no backup, or at least no backup for the relevant system, programs, or software parts.
For how long have I used the solution?
I've been using the solution for two months.
What do I think about the stability of the solution?
The solution is stable. It was no problem. All went quite well. There are no bugs or freezes.
What do I think about the scalability of the solution?
Adding other computers wasn't a problem. Just send them the link and it works. We have about ten users.
Which solution did I use previously and why did I switch?
Previously, we used Norton. We switched because Norton was very, very, heavy on consuming system resources. The computer itself was very, very slow and buggy. It took a lot of time for backup and things like that.
What's my experience with pricing, setup cost, and licensing?
We would just add more if there are new users, but right now you just need one license for per user.
What other advice do I have?
You just have to download it from the Cylance website, so it's pretty easy. You have to be careful because if you have more firewalls you have to buy a separate product and the question is: How does it work with the firewall from a different vendor?
There should also be backup capability included.
I do, however, recommend the solution. I would rate this solution eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner.

Andrew S. Baker (ASB)Cybersecurity & IT Operations Professional (VirtualCxO) at BrainWave Consulting Company, LLC
Consultant
I prefer my host based Anti-Malware solution with no firewall. Most of the problems I have seen from other AV and similar products have involved the firewall. Different focus and expertise.
I do agree with the need for additional reporting, though.
IT Manager at TIGRA gmbh
A quick installation process but security scripting needs improvement
Pros and Cons
- "The solution is pretty easy to scale."
- "The security scripting needs improvement. It needs deeper security for scripting."
What is most valuable?
The quick installation would be the most valuable aspect of this solution. The interface is also not too bad.
What needs improvement?
Security is an issue because they don't get Powershell. They scan the usual software and they don't scan deeper. The security scripting needs improvement. It needs deeper security for scripting.
Also, more speed, less RAM, and less CPU.
For how long have I used the solution?
I've been using the solution for 6 weeks.
What do I think about the stability of the solution?
The solution was stable. We have just ten test users from different departments.
What do I think about the scalability of the solution?
The solution is pretty easy to scale.
How are customer service and technical support?
I'd rate technical support as medium, because they couldn't answer everything we asked.
What other advice do I have?
We decided to switch to a different platform because we got the EDR and the scripting solution tool in one box. It was an end-point solution, so a scripting solution, plus cybersecurity.
For basic security, I would recommend Cylance. For advanced security, I wouldn't.
I would give the solution a rating of 6 out of 10.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Software Engineer at a tech services company with 1-10 employees
Streamlines vulnerability data and makes it a lot easier to access and sift through it
Pros and Cons
- "It handles situations that the other threat management tools wouldn't find. It has worked well covering the weaker sides of the other products that we're integrating."
- "I would like to see a better UI in terms of sifting through more specific data and providing analytics. A little bit more would be nice."
What is our primary use case?
Our primary use case is threat analytics and log management.
How has it helped my organization?
It streamlines the data and makes it a lot easier to access and sift through. The solution has also helped us a lot in terms of making threats a lot more obvious with our correlation manager. I estimate it has saved us 20 percent of what was our mean time to detect and respond to threats. It has also helped increase staff productivity.
We do vulnerability detection for our product's security and Cylance allows us to make our assessments a lot more accurate.
What is most valuable?
The vulnerability management is the most valuable feature of this solution.
What needs improvement?
I would like to see a better UI in terms of sifting through more specific data and providing analytics. A little bit more would be nice.
What do I think about the stability of the solution?
It works really well.
What do I think about the scalability of the solution?
We use it for really small cases. In terms of scalability, I have no opinion on it. It works on a small scale for us.
How are customer service and technical support?
We've had pretty positive responses from technical support when we have reached out to them for assistance.
Which solution did I use previously and why did I switch?
We went with this product because we were integrating a bunch of other vulnerability threat management solutions. It handles situations that the other threat management tools wouldn't find. It has worked well covering the weaker sides of the other products that we're integrating.
How was the initial setup?
The initial setup was pretty straightforward.
What about the implementation team?
We used an integrator for the deployment. Our experience with them was fine, smooth. It worked, integrating it with our VMs.
What's my experience with pricing, setup cost, and licensing?
Our licensing cost for the solution is around $4,000 for six months. There are no costs in addition to the standard licensing fees.
Which other solutions did I evaluate?
My co-worker planned out what threat tools we needed, and Cylance was one of them.
What other advice do I have?
It works well and covers a good number of the bases you need covered for general cybersecurity and vulnerability management.
I would rate it a nine out of ten for great usage and really good customer service if anything goes wrong.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network & Security Engineer at a healthcare company with 51-200 employees
Endpoints are protected in real-time without the need of a centralized server
Pros and Cons
- "Centralized dashboard online which can be used for managing a huge product."
- "Even if an endpoint loses connection to the Internet, I know that endpoint is protected against 99.99% of the threats in the wild today."
- "Specifically for a Windows domain environment, the product can be customized and pushed via GPO or SCCM without issue."
- "Endpoints are protected in real-time without the need of a centralized server."
- "Work on the math model. We are catching a lot of false positives, which gets to be a pain at the start of a deployment."
How has it helped my organization?
Rather than having to log onto a central server to manage the endpoint protection, I can log onto the dashboard to manage everything. No on-premise server required, chewing up resources needed for other tasks and projects. Endpoints are protected in real-time without the need of a centralized server, whitelist, or the ability to connect to a central host in the cloud. Even if an endpoint loses connection to the Internet, I know that endpoint is protected against 99.99% of the threats in the wild today.
What is most valuable?
Centralized dashboard online which can be used for managing a huge product. Anything I need done can be done from a single website.
What needs improvement?
Work on the math model. We are catching a lot of false positives, which gets to be a pain at the start of a deployment. It is not hard to decipher and add a global safe list, so you do not have to touch or adjust Clients on all endpoints. After you get passed the initial scan, it is clear sailing and very easy to manage and maintain.
For how long have I used the solution?
One to three years.
What do I think about the stability of the solution?
No issues. I had heard of others having some issues early on with performance, but I never experienced any issues. When there is a problem, as administrators, we are notified promptly by Cylance of what the issue is, then they resolve it very quickly.
What do I think about the scalability of the solution?
Never an issue. I have deployed this solution immediately to endpoints of all flavors without issue: PCs, MACs, and servers. Specifically for a Windows domain environment, the product can be customized and pushed via GPO or SCCM without issue.
How are customer service and technical support?
I would rate technical support as a 10 out of 10. I have never had a bad experience and very rarely have had to call them for any type of support for the product.
Which solution did I use previously and why did I switch?
I had just renewed a three year subscription to a very popular endpoint protection suite when I went to a Cylance roadshow and discovered how poorly protected my organization really was. Out of 10 real world live bugs, my endpoint protection, fully-patched, deployed in a best practice environment only stopped seven of them. Cylance stopped all 10, and every show I have ever been to, Cylance has won hands down without question. Many other products require your endpoints to connect to a central hub on-prem or are cloud-based, then soon as they lose that ability, those solutions fail.
How was the initial setup?
Very easy to deploy. It can be done one by one or deployed by customizing an MSI file for GPO push.
What's my experience with pricing, setup cost, and licensing?
Shop around for sure and be assured the price you pay will be close to other solutions available, but even at a slight mark-up from the other solutions, you are getting real endpoint protection versus nothing more than a cheap security blanket that might keep you warm at night. However, it is not actually protecting you from anything.
Which other solutions did I evaluate?
Reviewed these: SEP, Cisco, McAfee, and discussed Palo Alto options as well.
What other advice do I have?
Do your homework. Demo products to see how they will work within your environment and involve your end users. End users are key to testing these deployments and what their experiences will be with it.
Above all, do not get hung up on price. You pay for what you get and expensive will hurt one time, where cheap will hurt forever, especially if you fall victim to a ransom attack, etc.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Andrew S. Baker (ASB)Cybersecurity & IT Operations Professional (VirtualCxO) at BrainWave Consulting Company, LLC
Consultant
My experience was similar to yours. Saw them in a bake off, and it was no question that traditional AV was dead.

Buyer's Guide
Download our free BlackBerry Cylance Cybersecurity Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2025
Product Categories
Endpoint Protection Platform (EPP)Popular Comparisons
CrowdStrike Falcon
Microsoft Defender for Endpoint
SentinelOne Singularity Complete
Cortex XDR by Palo Alto Networks
Fortinet FortiClient
HP Wolf Security
Symantec Endpoint Security
Trellix Endpoint Security Platform
Trend Vision One Endpoint Security
Kaspersky Endpoint Security for Business
ESET Endpoint Protection Platform
Intercept X Endpoint
Cisco Secure Endpoint
Check Point Harmony Endpoint
Buyer's Guide
Download our free BlackBerry Cylance Cybersecurity Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- I'm building a next-gen AI powered threat intelligence platform. What's missing from existing solutions?
- What is the biggest difference between CrowdStrike and Cylance?
- How would you compare BlackBerry Protect vs Cortex XDR by Palo Alto Networks?
- What is the biggest difference between EPP and EDR products?
- Can Cylance be used with Symantec or Kaspersky endpoint solutions without conflict?
- When evaluating Endpoint Security, what aspect do you think is the most important to look for?
- What's the best way to trial endpoint protection solutions?
- What are the threats associated with using ‘bogus’ cybersecurity tools?
- Which Endpoint Protection Solution offers Zero Trust (ZTN) as a feature?
- What to choose: an endpoint antivirus, an EDR solution or both?
You make some good points, and I hope that we'll see Blackberry add to this area moving forward.
That said, there's quite a bit of info via CylanceOptics, and overall the system utilization is very low.