No more typing reviews! Try our Samantha, our new voice AI agent.

IBM Resilient vs NetWitness NDR comparison

Why PeerSpot?
Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 5, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Torq
Sponsored
Ranking in Security Orchestration Automation and Response (SOAR)
4th
Average Rating
8.6
Reviews Sentiment
6.5
Number of Reviews
18
Ranking in other categories
AI-SOC (1st), AI-Powered Security Automation (1st)
IBM Resilient
Ranking in Security Orchestration Automation and Response (SOAR)
19th
Average Rating
7.4
Reviews Sentiment
6.6
Number of Reviews
18
Ranking in other categories
Security Incident Response (7th)
NetWitness NDR
Ranking in Security Orchestration Automation and Response (SOAR)
23rd
Average Rating
8.0
Reviews Sentiment
6.9
Number of Reviews
15
Ranking in other categories
Endpoint Protection Platform (EPP) (48th), Threat Intelligence Platforms (TIP) (33rd), Endpoint Detection and Response (EDR) (56th), Network Detection and Response (NDR) (19th), Extended Detection and Response (XDR) (38th)
 

Mindshare comparison

As of September 2026, in the Security Orchestration Automation and Response (SOAR) category, the mindshare of Torq is 3.5%, down from 5.7% compared to the previous year. The mindshare of IBM Resilient is 2.3%, up from 1.9% compared to the previous year. The mindshare of NetWitness NDR is 1.8%, up from 0.7% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Orchestration Automation and Response (SOAR) Mindshare Distribution
ProductMindshare (%)
Torq3.5%
IBM Resilient2.3%
NetWitness NDR1.8%
Other92.4%
Security Orchestration Automation and Response (SOAR)
 

Featured Reviews

AD
Solutions Architect at ProArch
Automation has streamlined multi-tenant SOC workflows and improves alert handling efficiency
Although the reporting within Torq is not that great, we did ask for many features regarding reporting in Torq, but due to some platform constraints, they could not make the whole dataset available for us to be used in reporting. Except for that, we used some basic reporting. When I used Torq, it was indeed in the early stages of AI capabilities. Only a few customers were allowed to use it, and we were among them. It functioned well as long as we summarized the data properly. If you input garbage, you would get garbage out. Thus, we had to do significant fine-tuning regarding what data context we provided to the AI orchestrator to get meaningful results. In terms of Torq's unified platform approach to AI SOC automation and case management compared to managing multiple point solutions across my security stack, I find it case-centric. The unified view in case management is good since it provides clarity, although there are limitations regarding how many items in case management can be modified at once. Bulk operations are very limited, potentially due to their back-end database or data retrieval processes that can be improved. Regarding improvements for Torq, when we were onboarded, there were aspects we were uncertain about, such as the number of cases that could be generated, what data we could bring in, how many clients we could onboard, and similar concerns. Initially, we also lacked clarity about the number of playbooks or workflows we could build. Different triggers like system triggers, case-based triggers, and others can be employed without restrictions, but when it comes to on-demand and scheduled jobs, there is a limitation based on the subscription and pricing tier that notably caps the number of workflows we can create. No bulk editing across cases was one issue, along with limited filtering related to single grouping constraints. Additionally, the out-of-the-box case templates provided require substantial modifications before they become usable. There is also a feature in the cases for notes that cannot be searched. They are only visible through the UI, which is another area for improvement. The workflow and execution-based charges seem misleading as this was not discussed initially. I am not sure if new customers are made aware of this. It seems that workflows revolving around cases hinder functionality outside of case management, as we have many use cases needing on-demand triggers and schedules for functions like reporting or polling devices. Creating additional workflows to achieve basic functionalities raises costs significantly, which disadvantages customers. While they facilitate optimization and scaling, the support received tends to be very basic. Improvements can be made in that area as well.
ZaidHaddad - PeerSpot reviewer
Technical Seller at Alawtad group
Suitable for different industries and ensures effective incident response
IBM Resilient is great in many aspects like its wide range of integrations and customizable playbooks. However, one thing to improve is how it handles data formats, which currently might require scripting for conversion to CSV before uploading. Despite this, it stands out for incident response, case management, task organization, and team collaboration, making it a strong choice for organizations compared to competitors like Demisto Palo Alto. When it comes to additional features, I think IBM Resilient is on the right track with its AI capabilities, like linking related incidents and providing recommended actions. It would be nice to see more enhancements in this area, but overall, it looks good.
reviewer1799727 - PeerSpot reviewer
Manager, IT Security Operations at a non-profit with 11-50 employees
Reliable and good support but can be expensive
I have no real complaints about the solution. Threat detection could be better. They need to enhance their threat intelligence feeds. We would like to have more IOCs or more trade intelligence to not only rely on the intelligence of the engineer in charge but to have some threat intelligence and some seeds of IOCs and to have the host have some artificial intelligence to reduce the number of false positives. I don't see this solution being very scalable. The solution is pricey.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Torq has exceeded expectations by delivering workflows in a timely and lower effort manner than XSOAR, and it meets all my needs while saving a ton of time and targeting $600,000 saved this year, which is a substantial amount of money."
"According to positive outcomes, Torq reduced manual work and made incident response more efficient."
"Almost four or five hours of work is now completed in four or five minutes."
"Using that one piece of AI, we auto-closed 511 cases in quarter four alone."
"What I appreciate most about Torq is that it is an essential part of our system."
"What I liked the most about Torq is the actual workflow builder, which is really great because they offer a lot of features and convenience features that are useful for any automation engineer."
"We have seen fewer failures of automations from the time Torq came into the picture, we've had a more streamlined process of handling incidents, and at the same time, we've learned to embed the AI into our incident types, and that is how it has helped us in the automation."
"Since we started working with Torq, I am handling much fewer alerts, it is becoming really easy for me to handle an alert, I have all the information that I need, I do not need to connect to different vendors to receive this information, and the main thing I got from Torq is time, which now helps me to build another automated system and learn."
"The most valuable thing about it is how easy it is to navigate the user interface."
"It's really simple and has a flexible interface."
"It is a stable solution...It is a scalable solution."
"The solution is reliable in our usage."
"The solution is easy to use."
"The UBA, User Behavior Analytics, is very good."
"Its flexibility is the most valuable."
"As a whole, the product is stable...Technical support is very good."
"The detection rate and tracking features including historical tracking, tracking of the fires on the desk, and tracking of the file last monitored are all quite valuable for us."
"We like the solution doesn't have to be managed by an IT department; it's easy to use and you can still check the machine without the IT department being involved."
"Technical support is knowledgeable."
"We use it for IT security purposes; this is our central log management solution, so we incorporate all of our servers and PCs into this software and can monitor the logs from there."
"The log correlation is good."
"The stability of the RSA NetWitness Endpoint is very good."
"They have recently updated the features and the most valuable ones are the instant threat response, ease of use, web interface, integration, and easy access. RSA NetWitness Endpoint is very compatible with other solutions and technologies. However, they do not rely on third-party solutions and have most features built-in."
"The solution is stable."
 

Cons

"We have MCP that we are working with our cloud security platform, and we wanted to connect this MCP to the case management."
"The initial deployment of Torq was not easy."
"However, we did encounter some problems with custom steps, which definitely affected our progress, and the speed of bug fixes is also a bit slower than expected."
"If Torq could enhance its AI features, it would benefit customers significantly by making the platform even more user-friendly."
"The workflow and execution-based charges seem misleading as this was not discussed initially, and creating additional workflows to achieve basic functionalities raises costs significantly, which disadvantages customers."
"It was able to capture data but was unable to differentiate between the agent hostname we are using and the hostname that resides on the back end of the Internet."
"Additionally, the documentation for Torq is not very clear. Most of the information is presented in videos, which are not ideal for reading; there are mostly paragraphs and other text-based content."
"Torq does extensive marketing saying that SOAR is dead and markets itself as an all-in-one solution, but this is not actually true."
"IBM Resilient is quite complex, including its configuration."
"The initial setup is complex."
"What could make IBM Resilient better is if IBM increased the number of built-in integrations with different products from other vendors or third-party products."
"The integration could be improved so that it is easy to integrate with other solutions."
"It is not very straightforward to set up custom integrations, especially with services like Azure. You need an additional server for integration."
"This product could be improved with better customization. This product isn't the best on the market like QRadar, but it's actually a good solution. However, some competitors' solutions contain more integration, support, automation, or flexibility."
"Its price and technical support need improvement."
"IBM Resilient could integrate better with my tools."
"I don't see this solution being very scalable."
"The integration of the solution needs to be improved. The dashboard needs lots of updates as well. In the next release, we would like to see advanced fraud detection features."
"The contamination feature could be improved."
"Threat detection could be better."
"NetWitness Endpoint's blocking feature does not work properly - if there's a malicious process, it's not possible to kill it via a custom rule unless and until it's flagged as malicious."
"We would like to see the hunting and investigation features of this solution improved, in order to provide better visibility of issues."
"RSA NetWitness Network could improve on integration with non-native application integration."
"The threat intelligence could improve in RSA NetWitness Endpoint."
 

Pricing and Cost Advice

Information not available
"It is very expensive."
"The licensing cost for IBM Resilient is not too expensive, but it's not affordable, so it's moderately expensive. Regarding price, I'm rating the solution seven out of ten. The company pays for the license yearly, based on the number of users. Apart from the cost of the license you need to pay for each user, you also need to spend an initial investment for the base platform. You also have to pay for IBM Resilient support."
"I would rate the tool’s pricing a three out of ten. The tool’s pricing is on a yearly basis."
"There are no costs except for the support services that our company pays in addition to the licensing charges attached to the solution."
"We could create unlimited users using the license we had purchased."
"I feel it is an expensive product when my company pays annually for renewal, support, and follow-up."
"There is a license you need to pay for in order to use this product."
"Pricing for the solution is good, in my opinion."
"NetWitness Endpoint is less costly than its competitors, but it offers fewer features."
"They can easily adjust if you have the requirements which are required. If you have a budget cut or a budget constraint, they can bend."
"I do not have any opinion on the pricing or licensing of the product."
"We are on a three-year contract to use RSA NetWitness Network."
"It is an expensive product."
"It is highly scalable. It can be bought based on your requirements."
"With RSA, there is flexibility in choosing the service, products, and the range that meets your requirement, as well as they are flexible in terms of pricing."
"The cost depends on the number of endpoints that you want to monitor, but it is not expensive."
report
Use our free recommendation engine to learn which Security Orchestration Automation and Response (SOAR) solutions are best for your needs.
913,683 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Outsourcing Company
12%
Financial Services Firm
12%
Comms Service Provider
10%
Manufacturing Company
8%
Financial Services Firm
23%
Outsourcing Company
10%
Construction Company
9%
Government
8%
Financial Services Firm
11%
Outsourcing Company
10%
Comms Service Provider
9%
Construction Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business4
Midsize Enterprise5
Large Enterprise11
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise2
Large Enterprise7
By reviewers
Company SizeCount
Small Business10
Midsize Enterprise2
Large Enterprise6
 

Questions from the Community

What needs improvement with Torq?
There are some bugs in Torq, of course. They can be present in data transformation, some UI debugging, and other area...
What is your primary use case for Torq?
My main use case for Torq is the automation of cyber security processes through a SOAR platform and APIs. A main exam...
What advice do you have for others considering Torq?
Regarding someone thinking about using Torq, I recommend looking into their provided academy to start working with th...
What is your experience regarding pricing and costs for IBM Resilient?
I am not the one in charge of pricing, so I am not sure about the costs.
What needs improvement with IBM Resilient?
Integration with some devices, including Cisco PowerPower and certain antivirus products, has limitations.
Ask a question
Earn 20 points
 

Also Known As

No data available
No data available
RSA ECAT, NetWitness Network
 

Overview

 

Sample Customers

Information Not Available
Golden Living, Health Equity, USA Funds
ADP, Ameritas, Partners Healthcare
Find out what your peers are saying about IBM Resilient vs. NetWitness NDR and other solutions. Updated: September 2026.
913,683 professionals have used our research since 2012.