IBM Resilient could integrate better with my tools.
IT Specialist at a government with 501-1,000 employees
It's a scalable cloud-based solution
Pros and Cons
- "IBM Resilient is scalable."
- "IBM Resilient could integrate better with my tools."
What needs improvement?
For how long have I used the solution?
I have used IBM Resilient for about six months.
What do I think about the scalability of the solution?
IBM Resilient is scalable.
Which solution did I use previously and why did I switch?
The company previously used Palo Alto Cortex XSOAR, but I didn't use it.
Buyer's Guide
IBM Resilient
January 2026
Learn what your peers think about IBM Resilient. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,757 professionals have used our research since 2012.
What other advice do I have?
I rate IBM Resilient eight out of 10.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
SOC Manager at a comms service provider with 5,001-10,000 employees
It has a complete stack, so you don't need to use different OEM products because you have all you need under one umbrella
Pros and Cons
- "What I like most about IBM Resilient is that it has a complete stack, which means you don't need to use different OEM products because you have all you need under the IBM Resilient umbrella. You don't need to worry much about integrations and components because you're working with tested and proven architecture."
- "What could make IBM Resilient better is if IBM increased the number of built-in integrations with different products from other vendors or third-party products."
What is our primary use case?
IBM Resilient is used primarily for security, particularly cybersecurity in operation centers. My company uses it to monitor the data security-related aspects of the IT infrastructure.
How has it helped my organization?
IBM Resilient is beneficial to my company because it gives endpoint visibility through the system's audited security and data logs. At the same time, you can monitor the communication between the systems at the network and endpoint level through IBM Resilient. Using the data from the solution, you can coordinate security data and activities, and you can audit activities from all angles, from different perspectives.
What is most valuable?
What I like most about IBM Resilient is that it has a complete stack, which means you don't need to use different OEM products because you have all you need under the IBM Resilient umbrella.
You don't need to worry much about integrations and components because you're working with tested and proven architecture.
I also like that IBM Resilient is feature-rich and has undergone a lot of iterations in different types of environments, which means that the solution is one of the most mature SIEMs in the market today.
What needs improvement?
What could make IBM Resilient better is if IBM increased the number of built-in integrations with different products from other vendors or third-party products.
In a way, IBM Resilient is an orchestration platform, so it should allow you to orchestrate other OEMs or products from non-IBM vendors. If there were a pre-built function that lets you integrate third-party solutions with IBM Resilient, the initial setup for the solution would become easier and more flexible. Implementing or integrating other platforms with IBM Resilient would also take less time.
After the solution is implemented, that's the time my company can give more recommendations on which features to add to improve IBM Resilient.
For how long have I used the solution?
My experience with IBM Resilient is four years.
What do I think about the scalability of the solution?
Scalability depends on the infrastructure, not IBM Resilient as a product, but my company set up the platform so that it can scale for future requirements.
Scalability-wise, my company has some challenges because of the unavailability of experts or lack of the required expertise, so if scalability is part of the initial implementation challenges, that's a five. Still, if it's more of a product capability, then I'm giving IBM Resilient an eight in terms of how scalable it is.
How are customer service and support?
My company raised some tickets with IBM Resilient technical support, and the team gave good responses. The technical support side is okay, but the support from the business side could be better.
Technical support-wise, my rating for IBM Resilient is eight out of ten.
How would you rate customer service and support?
Positive
How was the initial setup?
A SIEM solution has two sides, security information and event management, and in SIEM, implementing the system isn't an issue. However, to get visibility, you must onboard your platforms, so the complexity level for that varies.
Depending on the vendor, a SIEM solution usually has pre-built normalization or passes, but many small customizations will be needed. Onboarding, particularly getting the visibilities, is not a big deal, but you'll face some challenges with the implementation because of the lack of deployment experts. In my part of the world, it's tough to find top-level experts because the experts typically leave and go to other parts of the world. It's a real challenge to retain people in this space. If you're careful and able to manage that challenge, it would be easy to onboard the platforms and implement a SIEM product.
For the SOAR side, the same problem exists, but with a higher level of intensity because SOAR is new to security operations. It's the latest development, so implementing it is a massive challenge because it requires a lot of expertise and experience in different areas of IT operations. SIEM implementation is easier to manage than SOAR implementation.
Implementation would be more straightforward if you have initial awareness or get good training from an experienced team. However, training newbies in the field will be challenging because the newcomers only have product knowledge. Newbies won't know the exact requirements of the IT world or have enough IT experience, so the deployment task should be entrusted to experienced people.
It isn't easy to give a generic or worldwide applicable rating for IBM Resilient because it has a lot of customizations and integrations. Still, based on my experience, I found the initial setup challenging, so it's a five out of ten.
Six months passed, and the implementation for IBM Resilient is still incomplete. It's ongoing, but if you include the time it took to source hardware and other steps, it's more than six months. It's been challenging to gather resources and source hardware because my country is facing a terrible financial crisis. The environment is difficult right now, affecting my rating of IBM Resilient setup-wise, but it's a good product.
What about the implementation team?
My company hired a service partner to implement IBM Resilient, and that service partner works back-to-back with some experts from outside the country. Still, the implementation had some challenges, and it's still ongoing.
What was our ROI?
It's too early to talk about ROI from IBM Resilient, and it's challenging to compute the ROI without first ensuring that my company has the expertise needed for the product to work.
What's my experience with pricing, setup cost, and licensing?
The licensing cost for IBM Resilient is not too expensive, but it's not affordable, so it's moderately expensive. Regarding price, I'm rating the solution seven out of ten.
The company pays for the license yearly, based on the number of users.
Apart from the cost of the license you need to pay for each user, you also need to spend an initial investment for the base platform. You also have to pay for IBM Resilient support.
What other advice do I have?
My company has not provided IBM Resilient to customers, but it proposed the solution to some. Right now, IBM Resilient is being implemented internally for the company.
My company uses the latest product version.
Based on its features and capabilities, my rating for IBM Resilient is a nine out of ten. Overall, as a solution, it's a nine.
IBM Resilient requires enrollment from different teams in operations, implementation, etc., because the process involves more integrations and customizations. In the current environment, forty to fifty engineers enrolled part-time, with ten people full-time, and then another forty contribute from the operations side. I work in Telco, so the IBM Resilient project is enormous and requires a lot of infrastructure. It's been challenging resource-wise and time-wise.
IBM Resilient, or any SOAR product, can be operated as a standalone product. Right now, my company hasn't observed any capacity limitations because it only has a limited number of users. Eventually, the company will add more users to IBM Resilient when it integrates the solution to the ticketing system that handles many people.
My advice to anyone looking into using IBM Resilient is to find good resources to implement the solution, particularly one with experience in general IT, a product of the same type as IBM Resilient, and he should have some scripting and programming experience, mainly because IBM Resilient runs on Python programming. The implementer should have Python programming experience or at least general programming and scripting experience.
My company is an end user of IBM.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
IBM Resilient
January 2026
Learn what your peers think about IBM Resilient. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,757 professionals have used our research since 2012.
Country Manager at a tech services company with 11-50 employees
Stable, but needs customization flexibility and better integration
Pros and Cons
- "This is a good solution that we recommend for customers."
- "This product could be improved with better customization. This product isn't the best on the market like QRadar, but it's actually a good solution. However, some competitors' solutions contain more integration, support, automation, or flexibility."
What is our primary use case?
Each customer will have different use cases for this solution. We develop use cases based on customer requirements and our technical team builds a playbook for the customer. Resilient is deployed on-premises.
What is most valuable?
This is a good solution that we recommend for customers.
What needs improvement?
This product could be improved with better customization. This product isn't the best on the market like QRadar, but it's actually a good solution. However, some competitors' solutions contain more integration, support, automation, or flexibility.
For how long have I used the solution?
I have been working with Resilient for over a year.
What do I think about the stability of the solution?
This solution is stable.
How are customer service and support?
The technical support is good.
How was the initial setup?
The installation is straightforward, but customization requires an understanding of programming as well as CTI integration. For implementation, I had a team of two engineers.
What about the implementation team?
I implemented through an in-house team.
What's my experience with pricing, setup cost, and licensing?
There is a license you need to pay for in order to use this product.
What other advice do I have?
I rate IBM Resilient a seven out of ten because the customization and integration could be improved. It needs more support metrics for integration and more flexibility in customizing the playbook. I recommend this product to others who are considering implementation.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Head - Global SOC at a tech services company with 201-500 employees
Stable, with good User Behaviour Analytics and has the ability to interlink offenses
Pros and Cons
- "The UBA, User Behavior Analytics, is very good."
- "The initial setup is complex."
What is our primary use case?
We basically use all of the basic functionality, including the entire MITRE ATT&CK tactics, et cetera.
What is most valuable?
The interlinking of the offenses is the most valuable aspect of the solution for us.
The UBA, User Behavior Analytics, is very good.
The solution has been stable so far. The performance is good.
The product can scale if you need it to. It's an easy process.
What needs improvement?
In terms of the whole analysis aspect, if we can get any additional information and ensure it's contextual information, that would be quite helpful to us.
The initial setup is complex.
For how long have I used the solution?
I've been using the solution for four years or so. It's been a while. I have a few years of experience with the product at this point.
What do I think about the stability of the solution?
The solution has been quite stable. There are no bugs or glitches. It doesn't crash or freeze. It's reliable and the performance is quite good.
What do I think about the scalability of the solution?
We have about 100 users on the solution right now. The solution is quite easy to scale. If a company needs to expand it, it can do so with relative ease.
How was the initial setup?
The initial setup is not straightforward or simple. It's quite complex. It can be difficult. The whole deployment, as well as the configuration, takes some work.
The deployment itself took about two months in total.
What about the implementation team?
We handled everything in-house. We didn't enlist the help of any consultants or integrators. Our team handled every aspect themselves.
What other advice do I have?
We have a business partnership with IBM.
I'm working with the latest version of the solution. I'm not sure which version number it is.
I'd recommend the product to other users and companies.
I'd rate the solution at a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
AGM, Enterprise Solutions at a tech services company with 51-200 employees
Easy to use with good stability but needs more documentation
Pros and Cons
- "The solution is very easy to use."
- "The product needs a bit more development."
What is our primary use case?
We have delivered a couple of Resilient solutions to our customers.
The product is primarily used for incident response automation and orchestration.
What is most valuable?
The solution is very easy to use.
It's a very stable product. The performance has been very good.
What needs improvement?
The product needs a bit more development.
We've had some compatibility issues that need to be resolved. There needs to be a bit more research done into that to figure out why it won't work. For example, my customer had some specific requirements, however, due to a lot of compatibility issues, some devices were not available to upgrade or add to the system. They say they are working on adding it to the solution, however, the compatibility still isn't available, and may not be for a while. They are unclear on the timelines.
We've had issues surrounding the deployment of the product.
The solution needs to try and develop more custom playbooks or documentation to help the customer with the initial setup.
Technical support is not pro-active enough and they take too long to provide solutions to problems.
The solution needs to have a physical deployment as well. It would be ideal if it wasn't just on the cloud.
For how long have I used the solution?
We have been selling the solution for the past three years at this point.
What do I think about the scalability of the solution?
There are some aspects of the solution that we can scale. There are certain things we can customize if we need to. We can also scale, for example, the number of actions per month. You can expand it if you need to.
Currently, we have six clients using the solution. These companies differ in size.
I personally have five team members in my organization who are supporting the customer in the support portal.
How are customer service and technical support?
We use the IBM support portal. The need to be much more proactive in supporting the customer. They don't necessarily ever say "this is not possible". Instead, they say "we are developing a solution". However, the process of developing a fix takes far too long. They need to be more aggressive in dealing with issues. Right now, sometimes it can take up to two to three months to resolve an issue, which is far too long.
I wouldn't say that we are satisfied with the level of service they provide.
How was the initial setup?
We've had issues with the setup process. We have Palo Alto, and for some reason, there isn't good compatibility.
That said, for the most part, the installation is fairly straightforward. It's not too complex.
We have five team members capable of handling implementations.
What about the implementation team?
We handle the implementation for our clients.
What's my experience with pricing, setup cost, and licensing?
The pricing is pretty good, however, the downside is that it is not a very mature product.
When a company needs a playbook, they have to create one, and then they have to pay someone for that service. However, it might be something that IBM could develop and template for others. They may be in the process of doing this already.
What other advice do I have?
I would rate the solution seven out of ten.
It's an okay product, however, it needs more maturity.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Administrator at a university with 1,001-5,000 employees
Helpful incident response monitoring but the pricing and integration could be better
Pros and Cons
- "It's really simple and has a flexible interface."
- "The integration could be improved so that it is easy to integrate with other solutions."
What is our primary use case?
We are using this solution for research and to integrate it into security solutions on the platform.
What is most valuable?
It's really simple and has a flexible interface.
It has been helpful with incident response monitoring and has good security features.
What needs improvement?
The integration could be improved so that it is easy to integrate with other solutions.
We need better pricing. It is very expensive to facilitate the students for research purposes for one month.
For how long have I used the solution?
I have been using IBM Resilient for a few months.
We are using the latest version.
What do I think about the stability of the solution?
It's a stable solution.
What do I think about the scalability of the solution?
This product is scalable.
How are customer service and technical support?
We have not contacted technical support.
Which solution did I use previously and why did I switch?
We are using many other solutions for research purposes such as Red Connect, Rapid7, and Siemplify.
How was the initial setup?
The initial setup is straightforward.
It's simple to install and doesn't take very long to deploy.
What about the implementation team?
We researched the internet on how to install and use this solution. There is a lot of information available on the internet.
What's my experience with pricing, setup cost, and licensing?
It is very expensive.
I haven't purchased this solution yet, I downloaded the community version.
What other advice do I have?
This is a very useful tool, and I recommend it.
I would rate IBM Resilient a six out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Director, Commercial at a tech services company with 51-200 employees
It is easy to set up and flexible
Pros and Cons
- "Its flexibility is the most valuable."
- "Its price needs improvement."
What is our primary use case?
We use it to manage security services.
What is most valuable?
Its flexibility is the most valuable.
What needs improvement?
Its price needs improvement.
For how long have I used the solution?
I have been using IBM Resilient for five years.
How are customer service and technical support?
We have contacted their technical support. I would rate them as average.
How was the initial setup?
The initial setup was straightforward. It took us a month to deploy.
What about the implementation team?
We have our own team.
What other advice do I have?
I would rate this solution an eight out of ten. Its price and technical support need improvement.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Cyber Security Consultant at a tech services company with 51-200 employees
Simple to use and integrates with IBM QRadar, but the configuration Need lot of hard work
Pros and Cons
- "The solution is simple to use and to integrate with IBM QRadar."
- "The implementation could be a bit simpler."
What is our primary use case?
We've integrated the solution with IBM QRadar. We collect data and analyze it. We then send the results to IBM QRadar for action through IBM Resilience. It allows us to take action against attacks.
How has it helped my organization?
As of right now, IBM Resilient helps our search analysts in making action against attacks and to manage the tickets.
What is most valuable?
The solution is simple to use and to integrate with IBM QRadar.
IBM QRadar sends alerts, and Resilient takes action.
What needs improvement?
IBM Resilient helps the company to automate responses against cyber-attacks using dynamic playbooks by sending actions to other IT solutions like firewalls, antivirus, Microsoft Teams, etc. The concept is to develop functions that you can find in IBM X-Force Exchange, and there are making lot of hard work to develop these functions, but for now, they need to add more functions to respond with other security solutions (Cisco ASA, ForcePoint, WAF...), so for now, all we can do is to wait for these functions, and I see that every month they add more functions.
For how long have I used the solution?
I've been using the solution for six months.
What do I think about the stability of the solution?
I can see that the solution is almost stable.
What do I think about the scalability of the solution?
The solution is scalable, and the best part is that IBM Resilient gives you the opportunity to develop your own scripts using the python language to make an action.
How are customer service and technical support?
We've been in contact with technical support. They're okay, but they sometimes take a lot of time to respond.
Which solution did I use previously and why did I switch?
We hadn't previously used a different solution. We chose IMB Resilient because it's the best SOAR solution if you are implementing IBM QRadar.
How was the initial setup?
The solution isn't hard to set up if you have a good understanding of IBM QRadar. It's also easy to integrate with it. Deployment takes about one hour. The configuration is a bit more complex; you'll need to understand how the unit works. Configuration usually takes about three days, but it can take up to one month. It depends on the network.
Typically, you just need one person to handle the deployment process, but it depends on the network. We have a team of ten people who handle the maintenance. They work on all of the solutions, not just Resilient.
What about the implementation team?
We handled the implementation ourselves.
What was our ROI?
We haven't seen any ROI by using this solution.
What's my experience with pricing, setup cost, and licensing?
Talk to our pre-sales consultants.
Which other solutions did I evaluate?
We didn't evaluate other options. We were already using IBM QRadar and the best solution to implement with it was IBM Resilient.
What other advice do I have?
We use the on-premises deployment model. We are IBM resellers.
The solution is limited, but it needs lots of development, especially when we talk about making actions with other security solutions.
I'd recommend that users implement the solution with IBM Radar; otherwise, they'll face a lot of limitations.
I'd rate the solution seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free IBM Resilient Report and get advice and tips from experienced pros
sharing their opinions.
Updated: January 2026
Popular Comparisons
Microsoft Sentinel
IBM Security QRadar
Palo Alto Networks Cortex XSOAR
Splunk SOAR
ThreatConnect Threat Intelligence Platform (TIP)
ServiceNow Security Operations
Fortinet FortiSOAR
Swimlane
VMware Carbon Black Cloud
SECDO Platform
D3 Security
Proofpoint Threat Response
DFLabs IncMan SOAR
Hexadite
Buyer's Guide
Download our free IBM Resilient Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What are the pros and cons of internal SOC vs SOC-as-a-Service?
- What are the Top 5 cybersecurity trends in 2022?
- How do you decide about the alert severity in your Security Operations Center (SOC)?
- What is the difference between cyber resilience and business continuity?
- What is an incident response playbook and how is it used in SOAR?
- What is the difference between mitigation and remediation in incident response?
- What does the Log4j/Log4Shell vulnerability mean for your company?
- What tools and solutions do you use for automated incident response in an enterprise in 2022?
- What are the latest trends in Security Operations Center (SOC)?
- What are the best practices for Security Operations Center (SOC)?
















