No more typing reviews! Try our Samantha, our new voice AI agent.

BlackBerry Cylance Cybersecurity vs Symantec Endpoint Security comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Feb 8, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Ranking in Endpoint Protection Platform (EPP)
4th
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
115
Ranking in other categories
Endpoint Detection and Response (EDR) (5th), Extended Detection and Response (XDR) (4th), Ransomware Protection (2nd), AI-Powered Cybersecurity Platforms (1st)
BlackBerry Cylance Cybersec...
Ranking in Endpoint Protection Platform (EPP)
32nd
Average Rating
8.0
Reviews Sentiment
4.6
Number of Reviews
44
Ranking in other categories
No ranking in other categories
Symantec Endpoint Security
Ranking in Endpoint Protection Platform (EPP)
9th
Average Rating
7.6
Reviews Sentiment
6.8
Number of Reviews
146
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of August 2026, in the Endpoint Protection Platform (EPP) category, the mindshare of Cortex XDR by Palo Alto Networks is 3.9%, up from 3.7% compared to the previous year. The mindshare of BlackBerry Cylance Cybersecurity is 1.6%, up from 1.0% compared to the previous year. The mindshare of Symantec Endpoint Security is 3.7%, down from 3.8% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Endpoint Protection Platform (EPP) Mindshare Distribution
ProductMindshare (%)
Cortex XDR by Palo Alto Networks3.9%
Symantec Endpoint Security3.7%
BlackBerry Cylance Cybersecurity1.6%
Other90.8%
Endpoint Protection Platform (EPP)
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
Sooraj Makkancherrry - PeerSpot reviewer
Security Operations Manager at Philips
Doesn't have daily updates, which is important for healthcare IT
I face challenges with the exclusion policy - it still scans folders we told it not to, causing issues. When we contact support, they tell us to update the latest agent, but we can't do that immediately due to medical device protocols and validation testing. I wish support would try to understand our issues better instead of giving this standard response. The machine learning feature they use often tells us to upgrade the agent or add things to the exclusion list, which isn't unacceptable. It's a very good and new technology as a tool and antivirus. But sometimes, it doesn't work properly with our medical devices and products, quarantining files it shouldn't even after we add them to exclusions. This is tricky for us.
Kumbesh Rajagopal - PeerSpot reviewer
Senior Security Delivery Analyst at Accenture
Management becomes easier with minimal complications, but improvement in support tools needed
Regarding areas of improvement for Symantec Endpoint Security, there are many changes, and the support portal tool is complicated compared to other tools. When trying to get service from Symantec, the process is complex. I'm not sure whether it's because of my project or something else. Though it is easy to manage, easy to get, easy to install, and works efficiently for managing policies, we faced a significant disadvantage. We wanted to add multiple hashes because of numerous new alerts coming, but we could only add them one by one, which is a considerable disadvantage in Symantec.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"They did what they said, and this solution could apply to any scenario."
"The integrations are out-of-the-box, as are the playbooks."
"The good thing about the product is that it's always scanning."
"Palo Alto Networks Traps improves our security posture and lowers risk by providing next-gen methods to combat against modern threats on all the major platforms."
"We have found in our test Cortex XDR by Palo Alto Networks to be a very good tool."
"From the Palo Alto side, whatever they buy, they integrate that really well into their integration suite, and that makes a massive difference."
"It is a simple platform to use."
"WildFire AI is the best option for this product."
"The most valuable feature of CylancePROTECT is the support."
"It handles situations that the other threat management tools wouldn't find. It has worked well covering the weaker sides of the other products that we're integrating."
"CylancePROTECT works on AI technology, is always up to date, and uses very few resources on your devices."
"I find the actual overall endpoint malware protection the most valuable feature of CylancePROTECT."
"In most cases, the solution's ability to detect in the MITRE framework, and its ability to be able to detect attacks in any one of seven or eight different areas of the life cycle of an attack is very useful."
"CylancePROTECT is going to tell you if there are any issues and you are going to be able to see everything from one single dashboard."
"From an administrative overhead point of view, there is a 75% reduction in administrating the solution."
"The solution is pretty easy to scale."
"Previously scans were taking a long time, hours or even a day, but nowadays, when the product scans, the time taken is only 15 to 20 minutes for a full scan, which no longer affects the day-to-day work of users."
"Basic features, as in every AV solutions, the virus and spyware protection are very good compare to other AV solutions in market."
"The scheduled scans and the active protection were the most valuable because it allowed me to have the systems protected in real-time and also be able to schedule scans so that as new definitions would update, machines could be scanned to make sure that everything was in tip-top shape and there was nothing lurking in the background."
"It is a scalable product and is average stability-wise."
"It's customizable, we're able to tune it to work with our products."
"The product provides great security and is very user friendly."
"Symantec Endpoint Security's pricing is better than most offerings based on my research."
"The mobile application is valuable. You are able to see the reports of intrusions and the like on mobile devices. That is one of the coolest aspects."
 

Cons

"There is a severe gap in functionality between Windows, Linux, and Mac versions. For example all folder restriction settings are Windows only. Traps 5.0+ does not have SAML / LDAP integration."
"Cortex XDR could be improved with more GUI features."
"When it comes to core analysis, and security analysis, Cortex needs to provide more information."
"In terms of areas of improvement, we have not completed our review of the product. We're also looking at other products. So, it's a little bit hard to tell what could be different because we have not completed the review of this product, but based on our experience so far, its implementation is quite complex."
"A potential area of improvement for Cortex XDR by Palo Alto Networks is the cost."
"It's more focused on network communication. If a customer wants to increase the level of protection and start working with documents, it's impossible to integrate these features into the system. It's more of a communication-oriented system than a content security-oriented system."
"I would like to see them include NDR (Network Detection Response). Then it would work well with SIEM Response."
"Cortex XDR by Palo Alto Networks could improve by adding a sandbox feature to better compete with their competitors which have it."
"The process of whitelisting a script that you want to be able to run can be a little bit difficult, or awkward."
"It was not effective. There were a lot of false positives, even when we use Adobe, and everybody uses Adobe, which is not a threat."
"An area for improvement in CylancePROTECT is its pricing, as it's a bit costly."
"The product must make the interface a little more user-friendly."
"I would like to see a better UI in terms of sifting through more specific data and providing analytics. A little bit more would be nice."
"While you are working, you are finding these things that were supposed to be waived have come back to being blocked. That's frustrating."
"The product does not do a lot of reporting on what it is taking care of. Enhanced reporting would be a welcome improvement."
"We would like to see secure integration and multi-factor authentication to be able to access the administration dashboard."
"It would be nice to be able to manage the endpoints a bit further. A valuable attribute would be the management of software inventory, software deployment, and third-party software deployment. I would like to see the ability to deploy and delete unlicensed software. Many users try to install what they shouldn't, so that would be really useful."
"I know they were just bought out by Broadcom and there have been some difficulties with Broadcom as far as getting license renewals, etc. Mostly, due to the fact that it's confusing, even for the vendor, people are turned off by it. The vendors are telling us that it can take weeks for them to get a renewal quote, nevermind the actual renewal."
"There could be definition updates installed and running for the product, similar to new EDR solutions that receive updates from the internet."
"I'd like to see a full anti-ransomware solution because there are some anti-ransomware functionalities that would assist us if they were included in the solution."
"Sometimes the interface can be a bit cumbersome, and maybe the help features."
"It would be great if the solution could match up with the competition's offerings - for example, making sure they are keeping up with, for example, CrowdStrike and other offerings."
"In a few cases, when we enable the IPS/IDS feature, there are performance-related issues on the end devices. If we run quite a few features of Symantec, especially the IPS/IDF, it consumes a lot of processing and memory capacity."
"We are switching because we don't feel that Symantec as a company is keeping up with next-generation trends. They just seem to be resting on their accomplishments too much and don't seem like they are progressive."
 

Pricing and Cost Advice

"The price is on the higher side, but it's okay."
"Cortex XDR's pricing is ok."
"I feel it is fairly priced."
"The solution has one subscription for endpoint protection and one subscription for detection and response. The two licenses combined give you the BRO version."
"I don't recall what the cost was, but it wasn't really that expensive."
"Cortex XDR’s pricing is very reasonable."
"Traps pays for itself within the first 16 months of a three-year subscription. This is attributed to OPEX savings, as security teams spent less time trying to identify and isolate malware for analysis as a result of a reduction in malware incidents, false positives, and breach avoidance."
"Cortex XDR by Palo Alto Networks is quite an expensive solution."
"Currently, we have competitive pricing for Cylance, which is affordable enough to consider."
"I think that the price we are paying is good for what it is."
"The license price for this solution could be better. It's on the expensive side."
"Our licensing cost for the solution is around $4,000 for six months. There are no costs in addition to the standard licensing fees."
"The initial end-point cost may seem a little high (~$55/device/year) but when you look at the total peace of mind that the solution provides, with no reboots for updates, and negligible performance impact, it is well worth it."
"The product cost is about $5, per user, per month."
"Do not get hung up on price. You pay for what you get and expensive will hurt one time, where cheap will hurt forever, especially if you fall victim to a ransom attack, etc.​"
"The solution's pricing is around the same as most EDRs but slightly behind some of the major ones."
"We receive a discounted price for this solution because we are a non-profit organization."
"Symantec is expensive."
"The licensing terms can range from subscription-based to perpetual, to annual, to tri-annual."
"The EDR options are costlier than other products."
"Pricing and licensing are important to us when choosing a product."
"Each annual client license is around 1200 or 1600 INR."
"The pricing is good, very moderate, and the licensing is also good. It gives you more room to install a lot of endpoints and it even gives you the opportunity to install it on your mobile phone without any extra cost."
"Licensing fees are paid on a yearly basis."
report
Use our free recommendation engine to learn which Endpoint Protection Platform (EPP) solutions are best for your needs.
908,834 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Construction Company
13%
Financial Services Firm
10%
Comms Service Provider
10%
Manufacturing Company
10%
Construction Company
12%
Comms Service Provider
7%
Manufacturing Company
7%
Outsourcing Company
7%
Comms Service Provider
12%
Financial Services Firm
10%
Construction Company
9%
Manufacturing Company
9%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business46
Midsize Enterprise21
Large Enterprise54
By reviewers
Company SizeCount
Small Business33
Midsize Enterprise5
Large Enterprise14
By reviewers
Company SizeCount
Small Business69
Midsize Enterprise32
Large Enterprise63
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
What is your experience regarding pricing and costs for Blackberry Protect?
The price is reasonable for us at the moment. I rate the overall solution an eight out of ten.
What needs improvement with Blackberry Protect?
I face challenges with the exclusion policy - it still scans folders we told it not to, causing issues. When we conta...
What is your primary use case for Blackberry Protect?
I am using CylancePROTECT as an active learning algorithm. We installed it on almost 20,000 servers and virtual machi...
Which is better - Cortex XDR or Symantec End-User Endpoint Security?
Aqua Security is easy to use and very manageable. Its main focus is on Kubernetes and Docker. Security is a very valu...
Which offers better endpoint security - Symantec or Microsoft Defender?
We use Symantec because we do not use MS Enterprise products, but in my opinion, Microsoft Defender is a superior sol...
What is your experience regarding pricing and costs for Symantec End-User Endpoint Security?
Symantec Endpoint Security's pricing is better than most offerings based on my research. It seems to be half the cost...
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
Blackberry Protect
Symantec EPP, Symantec Endpoint Protection (SEP)
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
Panasonic, Noble Energy, Apria Healthcare Group Inc., Charles River Laboratories, Rovi Corporation, Toyota, Kiewit
Audio Visual Dynamics, Red Deer Advocate, Asia Pacific Telecom Co. Ltd., Kibbutz Ein Gedi, and AMETEK, Inc.
Find out what your peers are saying about BlackBerry Cylance Cybersecurity vs. Symantec Endpoint Security and other solutions. Updated: June 2026.
908,834 professionals have used our research since 2012.