Try our new research platform with insights from 80,000+ expert users

Cisco XDR vs FortiXDR comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Ranking in Extended Detection and Response (XDR)
6th
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
108
Ranking in other categories
Endpoint Protection Platform (EPP) (5th), Endpoint Detection and Response (EDR) (7th), Ransomware Protection (2nd), AI-Powered Cybersecurity Platforms (2nd)
Cisco XDR
Ranking in Extended Detection and Response (XDR)
14th
Average Rating
8.6
Reviews Sentiment
6.7
Number of Reviews
13
Ranking in other categories
No ranking in other categories
FortiXDR
Ranking in Extended Detection and Response (XDR)
28th
Average Rating
8.0
Reviews Sentiment
6.6
Number of Reviews
4
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of March 2026, in the Extended Detection and Response (XDR) category, the mindshare of Cortex XDR by Palo Alto Networks is 4.9%, down from 5.6% compared to the previous year. The mindshare of Cisco XDR is 1.8%, up from 1.2% compared to the previous year. The mindshare of FortiXDR is 1.5%, up from 0.5% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Extended Detection and Response (XDR) Mindshare Distribution
ProductMindshare (%)
Cortex XDR by Palo Alto Networks4.9%
Cisco XDR1.8%
FortiXDR1.5%
Other91.8%
Extended Detection and Response (XDR)
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
Pranav Salian - PeerSpot reviewer
Head of Business Operations at SISA
Unified threat detection has strengthened visibility and reduced response time across all environments
Cisco XDR offers a wide range of integrations and connectors where we can integrate a whole range of devices available in our on-premises environment as well as cloud sources which we have primarily on AWS and Azure. Those environment log sources are integrated with Cisco XDR and it helps provide a single pane of glass view in terms of our security posture, giving us visibility within a single platform rather than focusing on individual security devices such as firewalls or EDRs which would typically be working in silos. These integrations are straightforward. Cloud workloads are easier to integrate compared to on-premises devices, primarily because the cloud workloads have readymade connectors and integration standard operating procedures for us to integrate with Cisco XDR. We have typically not faced challenges with integrations with Cisco XDR. There may be certain OEMs which are not well known and cannot be directly integrated without the help of vendor support or OEM support, which we were able to connect with and ensure they are integrated with Cisco XDR. From the reporting perspective, the dashboards offer quite a lot of predefined and useful options which help with live threat monitoring and provide a high-level view of the current threats, incident reporting metrics, mean time to detect, and mean time to respond. These sorts of dashboards are available on the platform and help provide a good view even for someone at the leadership level. Cisco XDR has definitely improved our security posture and our visualization, ensuring that we are protected and providing greater visibility for our SOC team. Cisco XDR has definitely reduced our mean time to respond. Previously it used to be more than 24 hours, but we have been able to reduce it to less than 16 hours due to all the various integrations and automation capabilities. Cisco XDR has been useful for us to gain visibility into gaps in our security posture and how those can be improved by conducting analysis on the platform itself. We have utilized the platform to improve our security posture and reduce blind spots.
HenrikPedersen - PeerSpot reviewer
Infrastructure Manager at Scandinavian Highlands Holding A/S
Comprehensive endpoint protection ensures robust defense against threats with seamless integration
I use FortiXDR as an all-in-one solution for endpoint protection, incorporating features like VPN, malware protection, and antivirus capabilities The most valuable feature of FortiXDR is its ability to block clients, providing comprehensive endpoint protection. This all-in-one tool seamlessly…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Cortex XDR lets us manage several clients from the same console, and its endpoint defense is more advanced than traditional antivirus."
"It has pretty much everything we need and works well within the Palo Alto ecosystem."
"If any application performs suspicious activities, such as changing registries or modifying other applications, Cortex XDR detects and blocks the entire application."
"I generally believe that Cortex XDR by Palo Alto Networks is probably the best in the market right now."
"The behavior-based detection feature is valuable."
"Its interface and pricing are most valuable. It is better than other vendors in terms of security."
"The initial setup isn't too bad."
"On a scale from one to ten, I would rate Cortex XDR by Palo Alto Networks a nine."
"I appreciate the granularity of what I get from Cisco XDR the most."
"Cisco XDR is appreciated as a SaaS-based platform for its user-friendliness with simple management tools that are easy for configuration."
"One of my favorite features of Cisco XDR is the automation tool, which saves a lot of time because we can craft these automations and workflows."
"My advice for other organizations considering Cisco XDR is that it offers proactive security measures that are really very helpful."
"The feature I appreciate the most about Cisco XDR is the reliability."
"In just four months, I have seen a good return on investment with Cisco XDR, as I have reduced incidents and saved time because previously, if I encountered any incident, I would have spent considerably more time and effort reaching out to every security control on my network and checking logs across multiple systems."
"Cisco XDR offers threat intelligence and links with the Firewall."
"One of my favorite features of Cisco XDR is the automation tool, which saves a lot of time because we can craft these automations and workflows."
"The most valuable feature of FortiXDR is it integrates well with other Fortinet solutions, such as Fortinet firewall, FortiMail, FortiSandbox, Forti Fabric, switches, and access points. Whatever the flow of the traffic comes in or goes out, the entire traffic can be managed and monitored properly."
"The most valuable feature of FortiXDR is its ability to block clients, providing comprehensive endpoint protection."
"The product is stable enough."
"The most valuable feature of FortiXDR is its ability to block clients, providing comprehensive endpoint protection."
"Our customers are satisfied with FortiXDR."
"FortiXDR is valuable for its integration capabilities with one hundred percent compatibility with other vendors in cloud environments like Google, Oracle, and Microsoft."
"FortiXDR is valuable for its integration capabilities with one hundred percent compatibility with other vendors in cloud environments like Google, Oracle, and Microsoft."
 

Cons

"The connection to the internet has not performed as expected."
"The playbooks could be improved to include more functionalities or actions."
"Impact on system performance is horrible, adding a lot of delays for users."
"Cortex XDR could improve its sales support team, including better commission structures and referral programs."
"Cortex does not offer an on-premises solution. However, some customers would prefer not to be on the cloud. It would be ideal if it could offer something on-prem as well."
"To jump from the partner to Palo Alto directly was challenging."
"It is not easy to sell Cortex XDR, not because it isn't a good tool. Its marketing needs to be improved."
"The solution should force customers to integrate with network traffic to see the full benefits of XDR."
"The licensing of Cisco XDR is a bit complicated. The cost can depend on what it is, and the process can be a little complicated."
"One area that needs improvement is the limited visibility due to the licensing structure. For more visibility, customers need the advantage or premier licensing, which involves additional costs."
"Improvements in Cisco XDR revolve around performance."
"When we first started with Cisco XDR in August, everybody was having issues. There were three people in our organization, including me, who couldn't even log in to Cisco XDR."
"The interface of Cisco XDR can be improved."
"My only complaint about Cisco XDR is related to licensing, which is complicated."
"They need to provide better pricing and bundle XDR licenses with products like Meraki solutions or Firepower Threat Defense."
"Cisco XDR can be improved by addressing the upfront cost."
"They could change their licensing costs to make it more affordable for smaller businesses."
"They could change their licensing costs to make it more affordable for smaller businesses."
"The pricing of FortiXDR should be improved."
"Improvement is needed in the intuitiveness and integration measures of FortiXDR, especially in terms of compatibility."
"The pricing of FortiXDR should be improved. It's a point of concern for us."
"Improvement is needed in the intuitiveness and integration measures of FortiXDR, especially in terms of compatibility."
"Many of the solutions, such as CrowdStrike have an MDR solution where remediation can be provided by the vendor. For example, if there is any zero data threat found, a new threat that the customer is not able to recognize, fix, or understand what needs to be done this feature has to be added in FortiXDR so that the customer feels comfortable."
 

Pricing and Cost Advice

"It's way too expensive, but security is expensive. You pay for your licensing, and then you pay for someone to monitor the stuff."
"The cost of Cortex XDR by Palo Alto Networks is $55 to $90 USD per endpoint per month."
"It's about $55 per license on a yearly basis."
"The solution is expensive. It's pricing is on a yearly-basis."
"If one wishes to work with another team or large number of users at a future point, he must purchase a license for them."
"It is cost-effective compared to similar solutions. It fits for the small businesses through to the big businesses."
"The tool's price is moderate."
"It is present, but when compared to other competitive products, I would say it is not less expensive; however, when all of the other added values are considered, the price is reasonable."
"The licensing of Cisco XDR is a bit complicated. The cost can depend on what it is, and the process can be a little complicated."
"This is an expensive solution compared to other vendors, such as Check Point."
report
Use our free recommendation engine to learn which Extended Detection and Response (XDR) solutions are best for your needs.
884,933 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
9%
Manufacturing Company
9%
Financial Services Firm
9%
Comms Service Provider
7%
Computer Software Company
12%
Government
11%
Manufacturing Company
9%
Comms Service Provider
6%
Comms Service Provider
12%
Government
10%
Financial Services Firm
7%
Wholesaler/Distributor
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business44
Midsize Enterprise20
Large Enterprise47
By reviewers
Company SizeCount
Small Business6
Midsize Enterprise6
Large Enterprise3
No data available
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
What is your experience regarding pricing and costs for Cisco XDR?
In terms of licensing and support cost, it is quite seamless. Based on the number of users we require, we have purcha...
What needs improvement with Cisco XDR?
Cisco XDR can be improved in terms of out-of-the-box integrations and standard operating procedures available on the ...
What is your primary use case for Cisco XDR?
Cisco XDR serves as the main platform for threat detection and threat response in my organization. We have integrated...
What is your experience regarding pricing and costs for FortiXDR?
Comparing to the enterprise level, the pricing is reasonable. However, for some companies, it might be a little high.
What needs improvement with FortiXDR?
They could change their licensing costs to make it more affordable for smaller businesses.
What is your primary use case for FortiXDR?
We are a system integrator and cloud service provider. Although I am in sales and not technical, I am involved with t...
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
No data available
No data available
 

Interactive Demo

Demo not available
Demo not available
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
Information Not Available
Information Not Available
Find out what your peers are saying about Cisco XDR vs. FortiXDR and other solutions. Updated: February 2026.
884,933 professionals have used our research since 2012.