No more typing reviews! Try our Samantha, our new voice AI agent.

BlackBerry Cylance Cybersecurity vs Symantec Endpoint Security comparison

Why PeerSpot?
Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Feb 8, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Ranking in Endpoint Protection Platform (EPP)
4th
Average Rating
8.4
Reviews Sentiment
6.7
Number of Reviews
118
Ranking in other categories
Endpoint Detection and Response (EDR) (5th), Extended Detection and Response (XDR) (4th), Ransomware Protection (2nd), AI-Powered Cybersecurity Platforms (1st)
BlackBerry Cylance Cybersec...
Ranking in Endpoint Protection Platform (EPP)
30th
Average Rating
8.0
Reviews Sentiment
4.6
Number of Reviews
44
Ranking in other categories
No ranking in other categories
Symantec Endpoint Security
Ranking in Endpoint Protection Platform (EPP)
8th
Average Rating
7.6
Reviews Sentiment
6.8
Number of Reviews
146
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of September 2026, in the Endpoint Protection Platform (EPP) category, the mindshare of Cortex XDR by Palo Alto Networks is 3.8%, up from 3.8% compared to the previous year. The mindshare of BlackBerry Cylance Cybersecurity is 1.6%, up from 1.1% compared to the previous year. The mindshare of Symantec Endpoint Security is 3.7%, up from 3.7% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Endpoint Protection Platform (EPP) Mindshare Distribution
ProductMindshare (%)
Cortex XDR by Palo Alto Networks3.8%
Symantec Endpoint Security3.7%
BlackBerry Cylance Cybersecurity1.6%
Other90.9%
Endpoint Protection Platform (EPP)
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
Sooraj Makkancherrry - PeerSpot reviewer
Security Operations Manager at Philips
Doesn't have daily updates, which is important for healthcare IT
I face challenges with the exclusion policy - it still scans folders we told it not to, causing issues. When we contact support, they tell us to update the latest agent, but we can't do that immediately due to medical device protocols and validation testing. I wish support would try to understand our issues better instead of giving this standard response. The machine learning feature they use often tells us to upgrade the agent or add things to the exclusion list, which isn't unacceptable. It's a very good and new technology as a tool and antivirus. But sometimes, it doesn't work properly with our medical devices and products, quarantining files it shouldn't even after we add them to exclusions. This is tricky for us.
Abhimanyu Das - PeerSpot reviewer
Senior Cybersecurity Engineer at Kyndryl
Behavioral protection has blocked ransomware and now saves extensive recovery and audit time
The best feature of Symantec Endpoint Security is its effectiveness in malware protection. Its malware protection capabilities stand out due to their ease of management. Although multiple tools assist in this process, managing them all can sometimes be challenging. In terms of malware protection, Symantec Endpoint Security performs well, and its mechanisms, tactics, and techniques are effective. Symantec Endpoint Security offers robust features such as advanced reporting capabilities with a customizable dashboard that integrates EDR timelines, threat maps, and compliance metrics into a single view. Additionally, reports can be exported to PDF or CSV formats, making reporting one of its strong points. It also provides comprehensive device control features, which block unauthorized USB devices and support whitelisting. This helps prevent data exfiltration and phishing scenarios without disrupting user workflows.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Stability-wise, it is good; I did not hear about any issues in terms of stability, and Cortex XDR by Palo Alto Networks can be trusted completely."
"It'll not slow down your system when compared to others."
"Based on my experience with Cortex XDR by Palo Alto Networks, I highly recommend it due to its quick response to zero-day attacks and low utilization from end-user devices."
"We switched because there were a lot of added features with Palo Alto that Check Point didn't have, and it was an upgrade for us."
"Its interface and pricing are most valuable, and it is better than other vendors in terms of security."
"Cortex is the best solution for avoiding security breaches, malware attacks, and other kinds of security issues."
"The most valuable feature of Cortex XDR by Palo Alto Networks is its machine-learning capabilities. Additionally, there is full integration with other solutions."
"The one feature of Palo Alto Networks Traps that our organization finds most valuable is the App ID service."
"The solution is stable."
"​Very easy to deploy. It can be done one by one or deployed by customizing an MSI file for GPO push.​"
"The solution runs in the background, and I do not need to care about it."
"It is extremely simple to manage and deploy."
"The solution is extremely scalable. It's got the hybrid functionality, it's got the system functionality and cloud functionality as well."
"Even if an endpoint loses connection to the Internet, I know that endpoint is protected against 99.99% of the threats in the wild today."
"On the management side, we liked the way it displays things."
"The Application Guard and ByteGuard are useful features."
"Helps to protect our organization from known attacks and blocks malicious files, which are not generally repelled well."
"The most valuable feature of this solution is the antivirus and the protection against Ransomware/Malware/Zero day attacks and device control."
"The solution is easy to use"
"All the features are valuable."
"This is a very complete solution."
"Basic features, as in every AV solutions, the virus and spyware protection are very good compare to other AV solutions in market."
"If there is exposure, we need to investigate the source of the attack, e.g., whether it came from the network or externally. We view the firewall logs, and if there has been exposure, then we use the Application Isolation feature. When there is an attack with on-prem, that system will go into isolation mode, removing connectivity to other internal systems. We also restrict the WLAN part to avoid that system broadcasting to other networks."
"SEP was very useful for protecting devices that belonged to students, faculty, and staff."
 

Cons

"I think sometimes Cortex XDR agent automatically stops event capturing from the device, and then even the dashboard does not get any notifications from the agent."
"While using Cortex, I noticed some aspects that could be improved, such as increasing the synchronization speed between XDR and Xnor."
"For working with the solution, you only really need a web browser, however, we've found that working on Chrome, for example, is horrible."
"Limited remote connection."
"The negative aspect I see is the economic model used by Palo Alto."
"A potential area of improvement for Cortex XDR by Palo Alto Networks is the cost."
"In an upcoming release, the solution could improve by proving hard disk encryption. If it could support this it would be a complete solution."
"The configuration could be simplified. I would like to see better protection, specifically to protect email applications."
"I'd like them to do software distribution too, but they said that that's architecturally not at the product line."
"I face challenges with the exclusion policy - it still scans folders we told it not to, causing issues. When we contact support, they tell us to update the latest agent, but we can't do that immediately due to medical device protocols and validation testing. I wish support would try to understand our issues better instead of giving this standard response. The machine learning feature they use often tells us to upgrade the agent or add things to the exclusion list, which isn't unacceptable."
"The security scripting needs improvement. It needs deeper security for scripting."
"Having worked with SentinelOne, Cylance is good, however, it probably needs to add a feature similar to SentinelOne's rollback functionality. With this feature, if you get infected, with a click, you can go back to the pre-infection state. If Cylance could add this functionality to their offering as well, that would be ideal."
"An area for improvement in CylancePROTECT is its pricing, as it's a bit costly."
"While you are working, you are finding these things that were supposed to be waived have come back to being blocked. That's frustrating."
"I would say one thing that they might need to bring in is protection for mobile devices."
"The company that sells us the licenses sometimes doesn't know how to do certain things."
"I would less likely recommend this product to users who only have average RAM and CPU power."
"The biggest thing I would like to see is malware remediation, if there is some kind of outbreak. We'd like to see better remediation and better detection and response. It's pretty good at capturing things, but it doesn't stop everything, so better machine learning would be helpful."
"Nowadays, threats are changing, and they are moving more towards script control and zero-day attacks. So, we would like to have more control similar to an EDR solution. Symantec Endpoint Protection has certainly come a long way as a traditional antivirus, but because the threats are changing, we would like to have more EDR features so that we have a detailed view of the source from where the infection entered the environment and whether it has tried to connect any other endpoint. It should provide such a detailed view for investigation. It should protect against zero-day threats, etc. These are the key enhancements that can make it a complete solution for any enterprise. Currently, we have seen organizations going for two solutions: antivirus and EDR. With both these capabilities, it would be a complete package."
"There are limitations because everyone these days has hybrid working; however, the endpoint does not work for us unless we are connected to a VPN, which is a major limitation."
"We are essentially left with a vulnerability."
"Some vendors are starting to give Symantec Endpoint Security a run for their money."
"Maybe Symantec Endpoint Security could amend their pricing structure, but they always offer a good product."
"The on-prem console doesn't do the product justice — it's a bit cumbersome."
 

Pricing and Cost Advice

"It is "expensive" and flexible."
"The pricing seems fair, and I do like the licensing model. You use wherever they are, and it is elastic."
"I am using the Community edition."
"Every customer has to pay for a license because it doesn't work with what you get from a managed services provider."
"The pricing is a little bit on the expensive side."
"The price was fine."
"It has a yearly renewal."
"Cortex XDR’s pricing is very reasonable."
"This cost of the license is approximately $5 USD monthly per user."
"We went through a third party initially to do the renewal, but we won't be renewing, we will move on to something else."
"The license price for this solution could be better. It's on the expensive side."
"Our licensing cost for the solution is around $4,000 for six months. There are no costs in addition to the standard licensing fees."
"CylancePROTECT's pricing is reasonable, at about €18 per user, per year."
"I think that the price we are paying is good for what it is."
"The licensing part of the product is too expensive compared to other solutions in the market."
"On a scale from one to ten, where one is cheap and ten is expensive, I rate the solution's pricing a seven out of ten."
"The licensing terms can range from subscription-based to perpetual, to annual, to tri-annual."
"This is not the cheapest product and I know others that are most cost-effective, although it is difficult to compare because it depends on the features."
"The licensing costs are huge compared to what is normally included in the licensing with other products such as the Microsoft products that we're using. We're paying between $300 and $400 per seat."
"They're on the reasonable side. They are at mid-level. They're not too expensive as compared to their competitors. They're also not too cheap. In terms of price structure, hopefully, they could do a subscription."
"It is the better product, even if it is a little on the higher side."
"The licensing is okay. Symantec has a very granular licensing model, so you only buy what you need."
"Its price is fair."
"Its price should be reasonable."
report
Use our free recommendation engine to learn which Endpoint Protection Platform (EPP) solutions are best for your needs.
913,806 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Outsourcing Company
12%
Comms Service Provider
12%
Construction Company
11%
Financial Services Firm
9%
Construction Company
12%
Outsourcing Company
11%
Comms Service Provider
7%
Financial Services Firm
7%
Outsourcing Company
13%
Comms Service Provider
13%
Financial Services Firm
9%
Construction Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business47
Midsize Enterprise21
Large Enterprise55
By reviewers
Company SizeCount
Small Business33
Midsize Enterprise5
Large Enterprise14
By reviewers
Company SizeCount
Small Business69
Midsize Enterprise32
Large Enterprise63
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
What is your experience regarding pricing and costs for Blackberry Protect?
The price is reasonable for us at the moment. I rate the overall solution an eight out of ten.
What needs improvement with Blackberry Protect?
I face challenges with the exclusion policy - it still scans folders we told it not to, causing issues. When we conta...
What is your primary use case for Blackberry Protect?
I am using CylancePROTECT as an active learning algorithm. We installed it on almost 20,000 servers and virtual machi...
Which is better - Cortex XDR or Symantec End-User Endpoint Security?
Aqua Security is easy to use and very manageable. Its main focus is on Kubernetes and Docker. Security is a very valu...
Which offers better endpoint security - Symantec or Microsoft Defender?
We use Symantec because we do not use MS Enterprise products, but in my opinion, Microsoft Defender is a superior sol...
What is your experience regarding pricing and costs for Symantec End-User Endpoint Security?
Symantec Endpoint Security's pricing is better than most offerings based on my research. It seems to be half the cost...
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
Blackberry Protect
Symantec EPP, Symantec Endpoint Protection (SEP)
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
Panasonic, Noble Energy, Apria Healthcare Group Inc., Charles River Laboratories, Rovi Corporation, Toyota, Kiewit
Audio Visual Dynamics, Red Deer Advocate, Asia Pacific Telecom Co. Ltd., Kibbutz Ein Gedi, and AMETEK, Inc.
Find out what your peers are saying about BlackBerry Cylance Cybersecurity vs. Symantec Endpoint Security and other solutions. Updated: September 2026.
913,806 professionals have used our research since 2012.