We've integrated the solution with IBM QRadar. We collect data and analyze it. We then send the results to IBM QRadar for action through IBM Resilience. It allows us to take action against attacks.
Cyber Security Consultant at a tech services company with 51-200 employees
Simple to use and integrates with IBM QRadar, but the configuration Need lot of hard work
Pros and Cons
- "The solution is simple to use and to integrate with IBM QRadar."
- "The solution is simple to use and to integrate with IBM QRadar."
- "The implementation could be a bit simpler."
- "The solution is limited, but it needs lots of development, especially when we talk about making actions with other security solutions."
What is our primary use case?
How has it helped my organization?
As of right now, IBM Resilient helps our search analysts in making action against attacks and to manage the tickets.
What is most valuable?
The solution is simple to use and to integrate with IBM QRadar.
IBM QRadar sends alerts, and Resilient takes action.
What needs improvement?
IBM Resilient helps the company to automate responses against cyber-attacks using dynamic playbooks by sending actions to other IT solutions like firewalls, antivirus, Microsoft Teams, etc. The concept is to develop functions that you can find in IBM X-Force Exchange, and there are making lot of hard work to develop these functions, but for now, they need to add more functions to respond with other security solutions (Cisco ASA, ForcePoint, WAF...), so for now, all we can do is to wait for these functions, and I see that every month they add more functions.
Buyer's Guide
IBM Resilient
April 2026
Learn what your peers think about IBM Resilient. Get advice and tips from experienced pros sharing their opinions. Updated: April 2026.
893,164 professionals have used our research since 2012.
For how long have I used the solution?
I've been using the solution for six months.
What do I think about the stability of the solution?
I can see that the solution is almost stable.
What do I think about the scalability of the solution?
The solution is scalable, and the best part is that IBM Resilient gives you the opportunity to develop your own scripts using the python language to make an action.
How are customer service and support?
We've been in contact with technical support. They're okay, but they sometimes take a lot of time to respond.
Which solution did I use previously and why did I switch?
We hadn't previously used a different solution. We chose IMB Resilient because it's the best SOAR solution if you are implementing IBM QRadar.
How was the initial setup?
The solution isn't hard to set up if you have a good understanding of IBM QRadar. It's also easy to integrate with it. Deployment takes about one hour. The configuration is a bit more complex; you'll need to understand how the unit works. Configuration usually takes about three days, but it can take up to one month. It depends on the network.
Typically, you just need one person to handle the deployment process, but it depends on the network. We have a team of ten people who handle the maintenance. They work on all of the solutions, not just Resilient.
What about the implementation team?
We handled the implementation ourselves.
What was our ROI?
We haven't seen any ROI by using this solution.
What's my experience with pricing, setup cost, and licensing?
Talk to our pre-sales consultants.
Which other solutions did I evaluate?
We didn't evaluate other options. We were already using IBM QRadar and the best solution to implement with it was IBM Resilient.
What other advice do I have?
We use the on-premises deployment model. We are IBM resellers.
The solution is limited, but it needs lots of development, especially when we talk about making actions with other security solutions.
I'd recommend that users implement the solution with IBM Radar; otherwise, they'll face a lot of limitations.
I'd rate the solution seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer.
CEO at a tech services company with 11-50 employees
Streamlined processes with automation and integration but needs device compatibility improvements
Pros and Cons
- "The integration with IBM SIM and the ability to block users during brute force attacks are particularly effective."
- "Integration with some devices, including Cisco PowerPower and certain antivirus products, has limitations."
What is our primary use case?
The primary use case is automation.
How has it helped my organization?
The solution allows for seamless integration with other IBM products, like IBM SIM, which helps manage alerts and incidents more efficiently. This automation has improved response times and streamlined processes.
What is most valuable?
The integration with IBM SIM and the ability to block users during brute force attacks are particularly effective.
What needs improvement?
Integration with some devices, including Cisco PowerPower and certain antivirus products, has limitations.
For how long have I used the solution?
I have been using IBM Resilient for the past two years.
How are customer service and support?
They provide limited technical support, which may be based on our license. The response time could improve, and sometimes they defer issues to third parties.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
This is the first solution of its kind that I have used.
How was the initial setup?
The initial setup took three months.
What about the implementation team?
The implementation involved four plumbing engineers and was completed with the assistance of a consultant or reseller.
What's my experience with pricing, setup cost, and licensing?
I am not the one in charge of pricing, so I am not sure about the costs.
What other advice do I have?
For smaller companies, I do not recommend using IBM Resilient.
I'd rate the solution six out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free IBM Resilient Report and get advice and tips from experienced pros
sharing their opinions.
Updated: April 2026
Popular Comparisons
IBM Security QRadar
Microsoft Sentinel
Palo Alto Networks Cortex XSOAR
Exabeam
VMware Carbon Black Endpoint
Splunk SOAR
Google Security Operations
ThreatConnect Threat Intelligence Platform (TIP)
ServiceNow Security Operations
Trellix Helix Connect
Fortinet FortiSOAR
VMware Carbon Black Cloud
Swimlane
SECDO Platform
Cyble Vision
Buyer's Guide
Download our free IBM Resilient Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What are the pros and cons of internal SOC vs SOC-as-a-Service?
- What are the Top 5 cybersecurity trends in 2022?
- How do you decide about the alert severity in your Security Operations Center (SOC)?
- What is the difference between cyber resilience and business continuity?
- What is an incident response playbook and how is it used in SOAR?
- What is the difference between mitigation and remediation in incident response?
- What does the Log4j/Log4Shell vulnerability mean for your company?
- What tools and solutions do you use for automated incident response in an enterprise in 2022?
- What are the latest trends in Security Operations Center (SOC)?
- What are the best practices for Security Operations Center (SOC)?















