Try our new research platform with insights from 80,000+ expert users

Picus Security vs XM Cyber comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Picus Security
Average Rating
9.0
Reviews Sentiment
7.9
Number of Reviews
6
Ranking in other categories
Breach and Attack Simulation (BAS) (3rd)
XM Cyber
Average Rating
8.6
Reviews Sentiment
7.4
Number of Reviews
5
Ranking in other categories
Continuous Controls Monitoring (3rd), Vulnerability Management (30th), Cloud Security Posture Management (CSPM) (20th), Continuous Threat Exposure Management (CTEM) (3rd)
 

Mindshare comparison

Picus Security and XM Cyber aren’t in the same category and serve different purposes. Picus Security is designed for Breach and Attack Simulation (BAS) and holds a mindshare of 17.2%, down 18.6% compared to last year.
XM Cyber, on the other hand, focuses on Continuous Threat Exposure Management (CTEM), holds 16.2% mindshare, down 26.2% since last year.
Breach and Attack Simulation (BAS) Market Share Distribution
ProductMarket Share (%)
Picus Security17.2%
Pentera28.5%
Cymulate20.0%
Other34.3%
Breach and Attack Simulation (BAS)
Continuous Threat Exposure Management (CTEM) Market Share Distribution
ProductMarket Share (%)
XM Cyber16.2%
Cymulate16.3%
Wiz Code14.6%
Other52.9%
Continuous Threat Exposure Management (CTEM)
 

Featured Reviews

AkashDeshpandey - PeerSpot reviewer
Simulate attacks to test and validate security controls effectively
I can simulate an attack into a live environment and test whether my controls are working properly. It checks if the controls can stop and mitigate the attacks One valuable feature of Picus Security is security control validation. It provides good reports and offers signature-based solutions. I…
Stephen Owen - PeerSpot reviewer
Has significantly improved risk visibility and optimized remediation efforts across dynamic environments
We tightly integrate with APIs, consuming feeds and open source data. We have integrated with XM Cyber, and we are elevating ourselves with AI and MCP tools as we view this as a forerunner to reducing the workload for our agents and IT staff. We're pushing all our security partners to provide AI and MCP tools. Our vision is for them to offer a chat interface where a junior IT or an experienced infrastructure engineer can ask for what needs to be patched next without using an interface. Their current interface is very usable and professional, ranking in the top tier of applications. Their reporting is good, offering custom reports, and their API integration is a new capability that serves us well. We have high expectations for the next generation, such as a chat interface to ask questions. However, everything has been very good. We push the boundaries with digital twins; I understand XM Cyber uses a similar concept of graph databases to map environments. I would like access to that and querying languages, enabling more informed business decisions. XM Cyber sees much of our estate, which is beneficial for making informed decisions, and we can harness those insights and data for business analytics. For instance, it could help us gain insights into change management—if a particular server impacts another and that server is supported by yet another server, we could glean significant insights for change management meetings.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It's very useful software because the customer mostly configures their IPS and manages their firewalls, WAF, and the DBS according to the latest update, latest news, or according to the situation."
"The most valuable feature of the solution is its integration capabilities with the other security tools."
"You have the liberty of physically executing a specific set of rules in your environment."
"One of the most valuable features would be the detection capability, specifically the ability to detect alarms and logs collected from SIEM tools."
"The most valuable feature of Picus Security is its threat intelligence, providing suggestions to block and prevent attacks by identifying malicious files and providing threat IDs."
"It provides good reports and offers signature-based solutions."
"Six weeks into using XM Cyber, we saw a compelling return on investment—primarily in risk reduction, with a specific issue our other security tooling did not pick up but XM Cyber did, reducing IT remediation time and saving over 60,000 US dollars per year while significantly lowering our loss exposure amount."
"Since implementing XM Cyber, we have improved the way we are doing patching, focusing on the choke points in our patching cycle, and it improves the way we assess the risk."
"What I personally like very much, from my experience, is that it is very reliable."
"XM Cyber made it clear that browser vulnerabilities were the top priority because the platform was able to examine how vulnerabilities within our estate could be exploited and what the path would be from some bad actor in order to exploit those vulnerabilities."
"The platform's most valuable feature is attack simulation."
 

Cons

"The reporting and data analysis could be improved. Specifically, the analysis of the results."
"There is room for improvement in the response rate provided by customer support."
"The amount of integrations that the product can handle is an area of concern, making it one of the aspects where improvements are required."
"According to the attack vectors, you cannot specify which product is failing or which product is working well because there's no agent."
"To improve, Picus Security could consider establishing a data center in India to address trust issues and increase interest from Indian customers."
"Let's say if a customer's environment has 10 security devices and they need to know that there is an attack that has bypassed their devices, they cannot go and inspect every device and every rule in their security devices."
"We have high expectations for the next generation, such as a chat interface to ask questions."
"There are many interesting things about XM Cyber, but the part that can be improved is the mobile exposure and the IBM i specific equipment."
"XM Cyber could identify all areas of vulnerability. They could expand the identification span for different areas."
"We'd like to see a cheaper price."
"We have not saved any time or effort, but we can prove that the effort involved around vulnerability management has been better spent to greater effect, and we've been able to demonstrate that vulnerabilities that do represent a high risk have been remediated more rapidly and more effectively."
 

Pricing and Cost Advice

"There is a yearly license according to the number of vectors. The pricing is moderate."
"They have certain price ranges for their products, depending upon the use cases, and the number of applications the customer wants to try."
"We have to pay standard licensing fees."
report
Use our free recommendation engine to learn which Breach and Attack Simulation (BAS) solutions are best for your needs.
868,787 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
18%
Computer Software Company
10%
Manufacturing Company
8%
Retailer
6%
Computer Software Company
14%
Financial Services Firm
11%
Manufacturing Company
10%
Retailer
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
No data available
 

Questions from the Community

What do you like most about Picus Security?
The most valuable feature of Picus Security is its threat intelligence, providing suggestions to block and prevent attacks by identifying malicious files and providing threat IDs.
What is your experience regarding pricing and costs for Picus Security?
The pricing of Picus Security is average, and it offers a good value for money.
What needs improvement with Picus Security?
There is room for improvement in the response rate provided by customer support. Picus Security could improve the response time.
What do you like most about XM Cyber?
The platform's most valuable feature is attack simulation.
What is your experience regarding pricing and costs for XM Cyber?
We have to pay standard licensing fees. There are no additional costs. It is an expensive product. I rate the pricing a seven out of ten.
What needs improvement with XM Cyber?
XM Cyber could identify all areas of vulnerability. They could expand the identification span for different areas.
 

Comparisons

 

Overview

 

Sample Customers

Akbank, Exclusive Networks, Garanti, ING Bank, QNB Finansbank, Turkcell, Vodafone, Yapı Kredi
Hamburg Port Authority, Plymouth Rock Corporation
Find out what your peers are saying about Picus Security vs. XM Cyber and other solutions. Updated: December 2024.
868,787 professionals have used our research since 2012.