No more typing reviews! Try our Samantha, our new voice AI agent.

BlackBerry Cylance Cybersecurity vs Microsoft Defender for Business comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Feb 8, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Ranking in Endpoint Protection Platform (EPP)
4th
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
115
Ranking in other categories
Endpoint Detection and Response (EDR) (5th), Extended Detection and Response (XDR) (4th), Ransomware Protection (2nd), AI-Powered Cybersecurity Platforms (1st)
BlackBerry Cylance Cybersec...
Ranking in Endpoint Protection Platform (EPP)
32nd
Average Rating
8.0
Reviews Sentiment
4.6
Number of Reviews
44
Ranking in other categories
No ranking in other categories
Microsoft Defender for Busi...
Ranking in Endpoint Protection Platform (EPP)
12th
Average Rating
7.6
Reviews Sentiment
6.6
Number of Reviews
20
Ranking in other categories
Microsoft Security Suite (15th)
 

Mindshare comparison

As of August 2026, in the Endpoint Protection Platform (EPP) category, the mindshare of Cortex XDR by Palo Alto Networks is 3.9%, up from 3.7% compared to the previous year. The mindshare of BlackBerry Cylance Cybersecurity is 1.6%, up from 1.0% compared to the previous year. The mindshare of Microsoft Defender for Business is 1.4%, down from 2.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Endpoint Protection Platform (EPP) Mindshare Distribution
ProductMindshare (%)
Cortex XDR by Palo Alto Networks3.9%
Microsoft Defender for Business1.4%
BlackBerry Cylance Cybersecurity1.6%
Other93.1%
Endpoint Protection Platform (EPP)
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
Sooraj Makkancherrry - PeerSpot reviewer
Security Operations Manager at Philips
Doesn't have daily updates, which is important for healthcare IT
I face challenges with the exclusion policy - it still scans folders we told it not to, causing issues. When we contact support, they tell us to update the latest agent, but we can't do that immediately due to medical device protocols and validation testing. I wish support would try to understand our issues better instead of giving this standard response. The machine learning feature they use often tells us to upgrade the agent or add things to the exclusion list, which isn't unacceptable. It's a very good and new technology as a tool and antivirus. But sometimes, it doesn't work properly with our medical devices and products, quarantining files it shouldn't even after we add them to exclusions. This is tricky for us.
Paritosh Jani - PeerSpot reviewer
Associate VP (Managed Information Technology Services) at Dev Information Tech Pvt Ltd
Has delivered automated threat response and streamlined integration with advanced tools
The best features of Microsoft Defender for Business include it coming as an XDR solution which provides automated investigations, remediations, and endpoint detection and response. Moreover, it can be tightly integrated with vulnerability management or detecting vulnerabilities and pushing them to the SIEM solution. I utilize the advanced threat hunting feature of Microsoft Defender for Business and find it helpful; it's good and improving with every update. Microsoft Defender for Business integrates effectively with the Microsoft ecosystem as with Azure Sentinel, and it has a two-way natural integration. Apart from that, it also integrates with industry SIEM solutions such as Splunk.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The tool's use cases are relevant to security."
"The initial setup is easy."
"What I like about Cortex XDR by Palo Alto Networks is that it is a comprehensive solution that contains everything the organization may need when using endpoints."
"Based on my experience with Cortex XDR by Palo Alto Networks, I highly recommend it due to its quick response to zero-day attacks and low utilization from end-user devices."
"Stability-wise, it is good; I did not hear about any issues in terms of stability, and Cortex XDR by Palo Alto Networks can be trusted completely."
"Cortex XDR is a very capable solution for protecting large networks and a lot of endpoints. It's very useful because the automation is very high, and if you combine it with the features on Palo Alto firewalls, it provides very strong protection."
"The most valuable features of this product are the management capabilities, which allow an IT organization to get quite a good picture of attempted cyber attacks, and its out-of-the-box investigation capabilities."
"Its ability to react to cyber data attacks is awesome."
"The most valuable features of CylancePROTECT are its powerful machine-learning capabilities and predictive intelligence."
"It actively monitors the behavior and activity of processes and will, without hesitation, terminate at root anything it determines to be suspect."
"Blackberry Protect offers endpoint protection, it's easy to deploy, and it's scalable and stable."
"The most valuable feature of CylancePROTECT is the support."
"Even if an endpoint loses connection to the Internet, I know that endpoint is protected against 99.99% of the threats in the wild today."
"The solution is pretty easy to scale."
"A user can continue to add endpoints and the solution will continue to perform well."
"It works well and covers a good number of the bases you need covered for general cybersecurity and vulnerability management."
"The solution includes attack-savvy service and risk protection, part of data center management, and offers an effective single-dashboard view with Microsoft 365."
"Because Microsoft Defender for Business is a native solution to Microsoft 365, it has contributed to my organization's proactive defense strategies by saving time on integration."
"A few things are valuable. One is the alerting we see when any kind of intrusion is happening, any kind of malware is being deployed across the endpoints, or any kind of suspicious activity is going on. We have a footprint across all of North America, Canada, and Mexico, so we want to make sure that all our endpoints are protected and we are able to look for any anomalous activity."
"The most effective features of Microsoft Defender for Business include its threat detection and response capabilities in managing vulnerabilities and ransomware attacks."
"The security features in Microsoft Defender for Business that have been most effective for our company include the way it's built-in and intertwined into all the operating systems, giving us a good opportunity to holistically block things for the organization using that tenant."
"Microsoft Defender for Business offers the best pricing option in the market and is very cost-effective."
"Defender's main strength is its integration with Microsoft Sentinel, offering valuable insights."
"The most valuable feature of the solution is its central console."
 

Cons

"The deployment is pretty hard."
"Technology evolves every day, so it would be nice if it gets more secure. It can also have more integration with other platforms."
"It's more focused on network communication. If a customer wants to increase the level of protection and start working with documents, it's impossible to integrate these features into the system. It's more of a communication-oriented system than a content security-oriented system."
"Managing the product should be easier."
"The server sometimes stops continuously to check things so it would be helpful to receive access updates or technical reasons."
"The onboarding process could be better."
"It's very time-consuming to log support issues and the people that answer the tickets aren't very knowledgeable."
"The solution should enhance the ADR and reporting."
"The solution needs better dashboards that are easier to use."
"The solution’s technical support could be improved."
"Technical support is bad. I am not happy with the level of support they offer."
"While you are working, you are finding these things that were supposed to be waived have come back to being blocked. That's frustrating."
"The OPTICS component could be made more user-friendly with respect to giving people more information."
"The company that sells us the licenses sometimes doesn't know how to do certain things."
"CylancePROTECT's dashboard could be more user-friendly."
"An area for improvement in CylancePROTECT is its pricing, as it's a bit costly."
"I have an open case for close to two months with no responses or updates, except for an email response, and I've made four or five phone calls regarding the Microsoft Interconnect for AD and cloud tenant."
"The tool's support is an area of concern where improvements are needed."
"The user interface has a lot of features which can make it complex and hard to adapt to for some users."
"Defender's reporting is rather scattered, and its URL filtering mechanism doesn't really work."
"The areas where Microsoft Defender for Business could improve include the support, installation process, and wiki. I should be able to find solutions to issues quickly without having to delve too deep."
"Threat protection could be improved even though it is already a built-in feature."
"If I need logs and don't have local storage bundled with Defender, I need to add workspace and log analytics, which is costly for storing logs of 2 GB, 5 GB, 10 GB."
"Pricing could be lowered as it is expensive and not suitable for low-budget organizations."
 

Pricing and Cost Advice

"Traps pays for itself within the first 16 months of a three-year subscription. This is attributed to OPEX savings, as security teams spent less time trying to identify and isolate malware for analysis as a result of a reduction in malware incidents, false positives, and breach avoidance."
"The price was fine."
"Compared to CrowdStrike, Cortex XDR is an expensive solution."
"Cortex XDR’s pricing is very reasonable."
"The cost of Cortex XDR by Palo Alto Networks is $55 to $90 USD per endpoint per month."
"In terms of the cost Cortex XDR by Palo Alto Networks is very expensive because we are a Mexican company and when you translate dollars to pesos the cost is very high. The solution is very expensive for Mexican companies. I understand that they have international prices, but I do not think it offsets the price enough for many companies in countries, such as Mexico. The amount it is reduced is not a massive percentage."
"Cortex XDR by Palo Alto Networks is an expensive solution."
"I don't recall what the cost was, but it wasn't really that expensive."
"Our licensing cost for the solution is around $4,000 for six months. There are no costs in addition to the standard licensing fees."
"The license price for this solution could be better. It's on the expensive side."
"CylancePROTECT's pricing is reasonable, at about €18 per user, per year."
"The product cost is about $5, per user, per month."
"CylancePROTECT is an affordable solution."
"It is expensive, but not unreasonable."
"On a scale from one to ten, where one is cheap and ten is expensive, I rate the solution's pricing a seven out of ten."
"The licensing part of the product is too expensive compared to other solutions in the market."
"It has to get more competitive because we are starting to see some of the competitors providing better pricing, and some of it, of course, is to gain market share. The Defender product pricing is probably a little higher than the competitors."
"Since we're a nonprofit, we get pretty good discounts on the tool."
"Defender for Business is included by default with an Office 365 premium subscription."
"The tool is cheap, while some other solutions are more expensive. I remember the tool cost about five euros for a workstation or for a user on a monthly basis."
"The tool's cost has been a little high, but I do not think it was terrible."
report
Use our free recommendation engine to learn which Endpoint Protection Platform (EPP) solutions are best for your needs.
908,858 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Construction Company
13%
Financial Services Firm
10%
Comms Service Provider
10%
Manufacturing Company
10%
Construction Company
12%
Comms Service Provider
7%
Manufacturing Company
7%
Outsourcing Company
7%
Computer Software Company
14%
Comms Service Provider
10%
Financial Services Firm
8%
Outsourcing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business46
Midsize Enterprise21
Large Enterprise54
By reviewers
Company SizeCount
Small Business33
Midsize Enterprise5
Large Enterprise14
By reviewers
Company SizeCount
Small Business15
Midsize Enterprise2
Large Enterprise4
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
What is your experience regarding pricing and costs for Blackberry Protect?
The price is reasonable for us at the moment. I rate the overall solution an eight out of ten.
What needs improvement with Blackberry Protect?
I face challenges with the exclusion policy - it still scans folders we told it not to, causing issues. When we conta...
What is your primary use case for Blackberry Protect?
I am using CylancePROTECT as an active learning algorithm. We installed it on almost 20,000 servers and virtual machi...
What is your experience regarding pricing and costs for Microsoft Defender for Business?
Our thoughts on the pricing for Microsoft Defender for Business are that we wish it could be better. If the pricing w...
What needs improvement with Microsoft Defender for Business?
I see room for improvement in Microsoft Defender for Business, particularly regarding the consolidation of all securi...
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
Blackberry Protect
No data available
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
Panasonic, Noble Energy, Apria Healthcare Group Inc., Charles River Laboratories, Rovi Corporation, Toyota, Kiewit
Information Not Available
Find out what your peers are saying about BlackBerry Cylance Cybersecurity vs. Microsoft Defender for Business and other solutions. Updated: August 2026.
908,858 professionals have used our research since 2012.