

Darktrace and Sublime Security compete in the cybersecurity category. Darktrace appears to have the upper hand due to its advanced AI analytics and comprehensive visibility across various environments, whereas Sublime Security stands out for its specialized phishing and email threat detection capabilities.
Features: Darktrace offers self-learning AI analytics, autonomous response tools, and proficiency in identifying phishing emails and malicious network activities. Sublime Security specializes in advanced phishing and email threat detection, customizable detection logic, and handling business email compromises.
Room for Improvement: Darktrace could improve its false positive reporting, integration, and endpoint security features. Challenges include better visualization, reporting, and support in certain regions. Sublime Security needs to enhance its threat explanation capabilities and reporting for executives, requiring extensive tuning for smaller organizations.
Ease of Deployment and Customer Service: Darktrace offers on-premises and hybrid cloud deployment options, though it faces challenges with complex deployments and technical support responsiveness in certain regions. Sublime Security's cloud-centric deployment model and strong public cloud integrations simplify setup, with highly-rated technical support providing quick and effective solutions.
Pricing and ROI: Darktrace is considered expensive with a pricing model that may be prohibitive for smaller entities, yet it offers significant ROI for larger organizations by enhancing security posture. Sublime Security provides a more competitive and flexible pricing structure appealing to mid-sized companies, delivering good ROI through efficient threat detection and cloud service integration, despite requiring upfront tuning and training investments.
Other NDR solutions provide virtual appliances that can be deployed on virtualization servers to get up and running quickly.
Using this solution provides financial benefits by securing from server attacks, which offers indirect savings.
Importantly, we didn’t need to hire any additional staff; we were able to absorb this responsibility using our existing team.
I estimate that we have improved our efficiency, especially for phishing campaigns where we can handle multiple similar emails together, which has reduced repetitive analyst work and improved our response time.
The technical support from Darktrace is of high quality.
Darktrace provides excellent technical support with a monthly meeting to review platform incidents, ensuring the system functions as expected.
The challenge lies in waiting for a response after logging a ticket.
We were able to get in touch with the person who constructed the LLM and its agentic aspects relatively quickly to address our questions.
I would rate customer support ten out of ten.
Darktrace has high scalability, and I would rate it a nine out of ten.
Since it's cloud-based, it expands easily.
There is still a gap in terms of storage, and we are trying to figure out how to increase that capacity for regulated environments, which require data retention for 5 to 6 years.
Despite nearly doubling the number of mailboxes and adding significantly more detection rules, the service remains just as fast as it was when we first implemented it.
Its scalability is also good, as it can scale with the number of protected mailboxes or users, or as email volume grows, supporting enterprise development across Microsoft 365 or Google Workspace.
The stability of Darktrace is excellent, rated ten out of ten.
The appliance itself has never let me down.
For stability, I would rate Darktrace an eight out of ten.
Sublime Security acted quickly; once Microsoft alerted Outlook about the incoming email, Sublime Security managed to pull it from the stream before it had a chance to appear in the user's inbox.
There is no dedicated salesperson in Egypt, and having one would help to improve focus on this market.
They say they can integrate with most firewalls, but when we did an integration with Meraki MX firewalls, that integration didn't work and still doesn't work to this day.
We need Darktrace on each branch to get the data out, and I suggest having some kind of a centralized product that gets data from multiple sources to aggregate and provide the data.
While they do provide API-level access and web hooks, I believe more out-of-the-box integrations with SOAR platforms and SIEM tools would enhance Sublime's value.
One breach could potentially put a small company out of business, so having a tool such as this might save them from that fate.
Sublime Security could be improved by enabling more integration, better customization of alerts, and more detailed reporting.
The product is considered expensive compared to others.
The pricing is costly in USD, and they charge based on device counts.
The licensing cost is approximately eight dollars a year.
It's competitive with its peers, especially for the number of mailboxes we have.
It is capable of responding to lateral movement and ransomware deployment within environments where there is data exfiltration.
I do not need to manually process incidents as Darktrace provides an incident summary, potential detection paths, and other details, all exportable with just a click.
If I am in a data center where I don't have layer two, it becomes an issue because the autonomous response is reliant on sending spoofed TCP resets to my core switch to block traffic, which is a major issue.
This level of detail is essential for analysts and anyone conducting evaluations, as it helps them understand the specific circumstances of their environment.
It adds a smarter layer that catches anything missed by Microsoft 365 or Google Workspace protection.
The best features of Sublime Security are advanced phishing and BEC detection, campaign grouping, threat hunting, and automated remediation.
| Product | Mindshare (%) |
|---|---|
| Darktrace | 1.8% |
| Sublime Security | 1.2% |
| Other | 97.0% |

| Company Size | Count |
|---|---|
| Small Business | 44 |
| Midsize Enterprise | 20 |
| Large Enterprise | 29 |
| Company Size | Count |
|---|---|
| Small Business | 8 |
| Midsize Enterprise | 5 |
| Large Enterprise | 10 |
Darktrace revolutionizes network security with AI-driven alerts, anomaly detection, and robust visibility across networks. It autonomously detects threats, minimizing the need for human oversight, and offers efficient IP identification with minimal false positives.
Darktrace uses advanced AI analytics to enhance network protection. Its powerful real-time threat response capabilities and self-learning enable thorough monitoring and insightful analysis of network activities. While providing scalable and reliable security, users seek improvements in false positive reduction, user-friendly interfaces, and pricing. Enhanced third-party integration, more effective dashboards, and centralized automation features remain top priorities. Users benefit greatly from its Antigena feature, offering automated responses like blocking suspicious connections for robust network defense.
What Are Darktrace's Key Features?In industries employing Darktrace, it is pivotal in securing LAN networks, analyzing behavioral patterns, and detecting internal and external threats. Adoption alongside platforms like F5 and SAP enhances incident response, traffic analysis, and threat identification, utilizing Antigena for proactive security measures.
Sublime Security provides innovative email security solutions focusing on advanced threat detection and customization, designed to tackle complex security challenges in enterprise environments.
True to its name, Sublime Security delivers a robust platform for email security that empowers professionals with precision tools for threat hunting and detection. It stands out for its focus on customization, allowing users to tailor security protocols to specific threats, enhancing detection accuracy. The platform supports detailed analysis, enabling IT teams to dissect threats and respond swiftly. Despite its strengths, improvement areas include easing integration processes and expanding user documentation.
What features define Sublime Security?
What benefits or returns on investment should users consider?
Within the financial sector, Sublime Security is implemented to protect sensitive client data from phishing and malware attacks. In healthcare, it offers customized solutions for securing patient information against unauthorized access. The adaptability of its detection algorithms makes it valuable in diverse industry applications.
We monitor all Email Security reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.