No more typing reviews! Try our Samantha, our new voice AI agent.
reviewer1778676 - PeerSpot reviewer
Vice President, Head of Infrastructure, Information Systems Group at a financial services firm with 10,001+ employees
Real User
Top 10
Feb 21, 2022
Good in terms of malware detection and scalability, but unpredictable pricing is a cause of concern
Pros and Cons
  • "It is mostly used for malware detection and antivirus purposes."
  • "It is stable."
  • "It would be good if it can anticipate zero-day attacks. I don't know how it can be done and if it is even a feature of this product."
  • "The unpredictability of the pricing is a cause of concern."

What is most valuable?

It is mostly used for malware detection and antivirus purposes.

What needs improvement?

The unpredictability of the pricing is a cause of concern.

It would be good if it can anticipate zero-day attacks. I don't know how it can be done and if it is even a feature of this product.

For how long have I used the solution?

I have been working with this solution for more than three years. 

What do I think about the stability of the solution?

It is stable.

Buyer's Guide
Symantec Endpoint Detection and Response
May 2026
Learn what your peers think about Symantec Endpoint Detection and Response. Get advice and tips from experienced pros sharing their opinions. Updated: May 2026.
900,644 professionals have used our research since 2012.

What do I think about the scalability of the solution?

We haven't had any issue with scaling the product. Its scalability has not been an issue.

Which solution did I use previously and why did I switch?

I have used Sophos in another company, but that was almost 10 years ago.

How was the initial setup?

I was not a part of the installation team. When I arrived, it was already there.

What's my experience with pricing, setup cost, and licensing?

Of late, because of the Broadcom purchase, its price has been increasing.

What other advice do I have?

I would rate it a seven out of 10.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Project Manager at a consultancy with 501-1,000 employees
Real User
Jul 3, 2020
Threat protection that is priced well, easy to deploy, and allows you to use the same agent for detection and response
Pros and Cons
  • "The most valuable feature is that the same agent can act as the endpoint detection and response agent."
  • "Previously, I was working with Trend Micro; before the detection and response were included, I would have recommended Trend Micro, however Symantec Endpoint has now taken the lead."
  • "Reporting is a major issue, as it is not user friendly."
  • "The technical support is very bad. It's been outsourced."

What is our primary use case?

The primary use case of this solution is for protection.

What is most valuable?

The most valuable feature is that the same agent can act as the endpoint detection and response agent. You don't need to deploy an additional agent. As you do with other solutions.

If you try to deploy a new solution you have to replace the existing agent with a new agent, but with Symantec, you can use the same agent.

What needs improvement?

Reporting is a major issue, as it is not user friendly. It's the biggest challenge we are facing. I have raised this issue multiple times.

With virus detection, if one OEM vendor is detecting the virus at 1:10 am, within 24 hours all others will detect it. For example, Symantec will detect the virus, then McAfee will detect it then Trend Micro, all within 24 hours, everyone will have it covered.

In the next release, I would like to see the option to customize the report as per our needs, and better reporting in general.

For how long have I used the solution?

I have worked with all Symantec products. Detection and response is a new technology that they have come up with and I have been working with it for two years.

What do I think about the stability of the solution?

If the solution is updated regularly then there is no challenge with stability.

What do I think about the scalability of the solution?

This solution is definitely scalable.

How are customer service and technical support?

The technical support is very bad. It's been outsourced. The level one support does not have the expertise to support people properly, from a technical perspective. 

I'd say that the level of understanding has been reduced as a result of outsourcing to a third party.

Which solution did I use previously and why did I switch?

Previously, I was working with Trend Micro. Before the detection and response were included, I would have recommended Trend Micro. However, Symantec Endpoint has now taken the lead.

Endpoint detection and response have not been developed into Trend Micro.

How was the initial setup?

The initial setup is straightforward. It's not complex. You will have to license it, then you are good to go.

If you try to establish the replication then you should plan it properly. If you do proper planning then it manages well. As an example, with one of my customers, I updated 3,000 machines that were in remote sites in less than a month's time.

What's my experience with pricing, setup cost, and licensing?

The price is okay, but it really depends on the customer's requirements.

What other advice do I have?

I am a user of Symantec as well as an admin with the Symantec support team. I was the technical support account manager and I would support other customers.

Symantec release updates two or three times per day. If you have a low bandwidth it will never get updated, although there are options to resolve this.

First, you have to decide on your requirements and what features you are looking for, then you can consider any endpoint detection and response solution.

There are good products on the market; there is one in particular that is cloud-based, where you don't need a single investment, but you will need to have good bandwidth. 

Before looking for any solutions the planning must be done.

Overall, this is a good product but it is still in the early stages and there are some improvements that need to be made.

I would rate this solution an eight out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Symantec Endpoint Detection and Response
May 2026
Learn what your peers think about Symantec Endpoint Detection and Response. Get advice and tips from experienced pros sharing their opinions. Updated: May 2026.
900,644 professionals have used our research since 2012.
Vishnu Ramachandra - PeerSpot reviewer
Security Engineer at Suraksha
Real User
Jun 18, 2020
IPS and user interface are great; includes deception technology component as part of SEP
Pros and Cons
  • "IPS and the user interface are good features."
  • "I would definitely recommend Symantec because the company provides great support from its engineers."
  • "I think the network forensics feature could be improved."

What is our primary use case?

In the past, we deployed for Government organizations and right now we are dealing with a financial institution that is considering implementing Symantec. We primarily work in the Middle East and Australia. We are Symantec partners and implement the solution for our clients. I'm a security engineer. 

What is most valuable?

I like the IPS , GIN and the user interface, they are good features and simple to use. In addition to that, I believe that Symantec is the only vendor that actually includes the deception technology component as part of SEP.

What needs improvement?

I think the network forensics feature could be improved. It's not part of SEP, but it's part of the package and I think that could be improved because we need the decryptor. Without  that you can't actually decrypt the SSL traffic going in the network. If the solution could be completely software-based, it would be a formidable product.

Symantec could include that as an additional feature, it's something that other solutions provide. Secondly, instead of just making it endpoint deception, they could make it network deception as well and that would make it a complete endpoint protection solution.

For how long have I used the solution?

I've been using this solution for the last 12 months. 

What do I think about the stability of the solution?

The stability of the solution is fine. 

What do I think about the scalability of the solution?

We haven't had any issues with scalability. Three months ago we put in a bid where they initially wanted 300 users, but then decided they wanted to scale up to 7,000 users. Symantec had no problem with that. It just requires preparation by taking into account the increased number of endpoints. 

How are customer service and technical support?

Technical support is very good.

Which solution did I use previously and why did I switch?

We used McAfee and Trend-Micro previously, but we didn't get many good reviews for the product. Once we switched to Symantec, the market responded well so we switched to pushing that. We depend a lot on market feedback and after speaking to a lot of cyber experts in the information security field, they said they wanted Symantec. It's pretty much based on market feedback. 

What's my experience with pricing, setup cost, and licensing?

Deploying on-prem makes Symantec a very expensive product but if it's being deployed on cloud it's quite cheap. We lost a lot of bids when we proposed on-prem deployment because of the high cost. 

What other advice do I have?

I would definitely recommend Symantec because the company provides great support from its engineers. Whenever we've had any issues, we give them a call and 10 or 20 minutes later, they make contact. They're also very good at helping us quote for tenders and they negotiate well. 

I would rate this solution an eight out of 10. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. partner
PeerSpot user
Senior Information Security Engineer at Herbalife
Real User
May 31, 2020
Dashboard shows new and unknown threats in the environment but support isn't so responsive
Pros and Cons
  • "The most valuable features are that it is easy to connect and global settings are good."
  • "This feature is very good for EDR monitoring and management."
  • "That's why I wouldn't recommend it for other systems. It works only with SAP clients. That's why I'm giving it a six. It would get higher if it worked on all networks without the help of SAP."

What is most valuable?

The most valuable features are that:

  • It is easy to connect
  • Global settings are good

What needs improvement?

I don't see much room for improvement. I am not an analyst for this product. I just manage this product for an analyst. I like the dashboard, it has lots of information like threats and we can see activity on the dashboard. It shows new and unknown threats in the environment. This feature is very good for EDR monitoring and management.

For how long have I used the solution?

We have been using Symantec EDR for the last year. We also have Symantec Endpoint Protection

What do I think about the stability of the solution?

We are facing our own issues that we are checking to see if it's secure. We are working on this with support but they are not able to fix that now. We haven't had any issues regarding the features. It works perfectly. 

What do I think about the scalability of the solution?

Scalability is good. 

How are customer service and technical support?

We have contacted technical support multiple times. They are good but not excellent. We had a few issues and it took them a long time to respond. 

How was the initial setup?

We did the POC within one week and the entire deployment took one month.

What other advice do I have?

It's a good product if you have a lot of SAP solutions. 

I would rate it a six out of ten. Not a 10 because it works on version 14 but SAP clients have some issues and EDR is different on SAP. That's why I wouldn't recommend it for other systems. It works only with SAP clients. That's why I'm giving it a six. It would get higher if it worked on all networks without the help of SAP.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
PeerSpot user
Consultant Cybersecurity & SD WAN at a computer software company with 201-500 employees
Reseller
Apr 17, 2023
A market leader with a broad presence internationally and easy to set up
Pros and Cons
  • "The solution can scale well."
  • "They need to improve their cloud presence."

What is our primary use case?

The solution is mainly used for antivirus. When clients don't want a heavy agent on their system, they like to use a solution like this. This isn't a signature-based approach which isn't very effective.

What is most valuable?

Symantec has been a leader in the space. The threat intel they gather is very good. 

They have a wide presence across the globe. They often are the first to pick up on threats and malware. 

They have the capability to address zero-day vulnerabilities. 

They do have managed service offerings.

It is easy to set up.

The solution can scale well.

It is stable.

The pricing is reasonable. 

What needs improvement?

They need to improve their cloud presence. They need to keep developing prevention. Many OEMs are focusing on the detection part only.  They need to address the challenge of gathering false positives.

We do not need any extra features. 

For how long have I used the solution?

I've been using the solution for two years now. 

What do I think about the stability of the solution?

The stability and performance are great. It is very stable. I'd rate it nine out of ten in terms of reliability. 

What do I think about the scalability of the solution?

The solution is very scalable. I'd rate it nine out of ten. It extends easily.

They are leaders in this entire segment, and they have a good understanding of malware and antiviruses is very strong and their presence across the globe is very robust.

We tend to work with medium-sized organizations.

Which solution did I use previously and why did I switch?

I've used CrowdStrike and they have done a good job in terms of using AI and ML behavior-based analysis. No signature is required on endpoint devices. When you scan devices, it does not decrease user performance. 

How was the initial setup?

The initial setup is very easy to set up. I'd rate the initial setup eight out of ten in terms of ease of the process. 

Most customers are on-premises, although they do now have a cloud option.

The deployment generally takes a few days. 

What's my experience with pricing, setup cost, and licensing?

The pricing is pretty reasonable. I'd rate it nine out of ten. 

What other advice do I have?

I am a reseller. 

I'd rate the solution nine out of ten. Depending on the use case and the problem you are trying to solve, this is a decent solution. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer.
PeerSpot user
MilindKule - PeerSpot reviewer
Data Protection Specialist at CompuCom
MSP
Jun 29, 2022
Integration with antivirus provides better security posture
Pros and Cons
  • "A great feature of this solution is that it is very well-integrated with antivirus software. Other ADR solutions are implemented as single technologies and are not integrated with the provider, but Symantec offers AV plus ADR."
  • "I think we have experienced some technical issues because the company focuses mainly on bigger clients. Also, sometimes the solution fails to detect zero-day attacks, so that feature needs some enhancement because it is lacking compared to other solutions."

What is most valuable?

A great feature of this solution is that it is very well-integrated with antivirus software. Other ADR solutions are implemented as single technologies and are not integrated with the provider, but Symantec offers AV plus ADR.

What needs improvement?

I think we have experienced some technical issues because the company focuses mainly on bigger clients. They should treat every client equally instead of only targeting high-profile or high-revenue-generation clients. The focus should be client-centric, not only revenue-centric. 

Also, sometimes the solution fails to detect zero-day attacks, so that feature needs some enhancement because it is lacking compared to other solutions.

For how long have I used the solution?

I have been implementing this solution for almost four years.

What do I think about the stability of the solution?

The stability of the solution is good. 

What do I think about the scalability of the solution?

The scalability of the solution is quite good.

How are customer service and support?

The turnaround time of the technical support team is quite good. 

How was the initial setup?

The initial setup is a little bit complex because the solution gets integrated with the existing antivirus software.

What's my experience with pricing, setup cost, and licensing?

The licensing costs depend on the number of endpoints that are involved. 

What other advice do I have?

To anyone looking into Symantec Endpoint Detection and Response, I would say that it's the best solution that can be integrated with AV, thus providing better security posture.

I would rate this solution as an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Implementer
PeerSpot user
Faisal Mian - PeerSpot reviewer
CTO at ABM Info. tech
Real User
Dec 5, 2021
Effective, and has good support, but it could be more compatible
Pros and Cons
  • "The Detection vulnerability is very effective."
  • "The Detection vulnerability is very effective and distinguishes Symantec Endpoint Detection and Response from its competitors."
  • "It would be beneficial to have more integration and compatibility with other platforms."

What is our primary use case?

Symantec Endpoint Detection and Response is primarily applied to endpoints in the banking and telecom sectors.

If you want to protect yourself from zero-day threats, one option is to have Endpoint and the EDP, and if you don't want to have that combination, EDR is the best way to detect any exfiltration into the network, and then to respond accordingly.

What is most valuable?

The Detection vulnerability is very effective. It distinguishes Symantec Endpoint Detection and Response from its competitors.

What needs improvement?

It would be beneficial to have more integration and compatibility with other platforms.

For how long have I used the solution?

I have been working with Symantec Endpoint Detection and Response since 2018.

What do I think about the scalability of the solution?

We have two customers who are using this solution.

How are customer service and support?

I am very comfortable with technical support. It is good for whatever product they have.

How was the initial setup?

To deploy this solution, you will definitely require technical knowledge. It is not as straightforward and simple as other endpoints, but it is not difficult to deploy as long as you are aware of the technical aspects of it.

We need three sales engineers and backroom support to maintain this solution.

What's my experience with pricing, setup cost, and licensing?

It's a yearly subscription.

What other advice do I have?

I would recommend this solution to others.

I would rate Symantec Endpoint Detection and Response a seven out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Senior Security Architect at a tech services company with 11-50 employees
Real User
Oct 21, 2021
Easy to scale and setup, but should offer more granular timeline analysis
Pros and Cons
  • "The setup is quite easy."
  • "There is no need to do an additional installation for the EDR, as the one belonging to Symantec is pretty much dependent on the endpoint agent, which is already deployed."
  • "It would be nice to see more granular timeline analysis."
  • "The tech support was very bad in the immediate aftermath of the merger, although it is now slightly better."

What is our primary use case?

We employ the latest version. 

Our clients make general use of the solution for endpoint detection. They are interested in its EDR capabilities. 

What is most valuable?

There is no need to do an additional installation for the EDR, as the one belonging to Symantec is pretty much dependent on the endpoint agent, which is already deployed. This is my favorite feature, as it saves a person from the complexity involved in the deployment of additional EDR agents. 

What needs improvement?

The solution should offer more features, such as ones which are forensic and timeline. 

The tech support was very bad in the immediate aftermath of the merger, although it is now slightly better. The problem came down to the ownership of the case. Support was horrible when the Broadcom entered the picture, but they have done much work in this area and things are mostly better. 

It would be nice to see more granular timeline analysis. 

For how long have I used the solution?

We have been using Symantec Endpoint Detection and Response for ten years. 

What do I think about the stability of the solution?

While the earlier version had many bugs, the current version is relatively quite stable.

What do I think about the scalability of the solution?

The solution is easy to scale and its methods of deployment are totally up to the needs of one's organization, be them on-cloud, on-premises or hybrid. 

How are customer service and support?

Just following the merger, the tech support was very bad, although it has since slightly improved. Ownership of the case was the real issue. At the time when the Broadcom came into the picture, the support was terrible, yet much work in this area has since been undertaken and things are, for the most part, better.   

How was the initial setup?

The setup is quite easy. 

What's my experience with pricing, setup cost, and licensing?

I do not deal with the pricing. As such, I cannot comment on it. 

What other advice do I have?

The method of deployment varies with the client. 

Rather than handling the implementation on one's own, it is important to engage a good system integrator. Although a person's expertise may make the process seem straightforward, the experience a good system integrator brings to bear can benefit one beyond what is written in the documentation. Such a person can evaluate one's infrastructure and advise on the best approach. 

I rate Symantec Endpoint Detection and Response as a seven out of ten. 

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Director General at MPR "Sarmatia" sp. z o.o.
Real User
Feb 14, 2021
Reliable, fast customer service, and priced fair
Pros and Cons
  • "I have had absolutely no problem with using this solution, it really works well."
  • "It is not possible to buy it from the company itself, or resellers in other countries. If it is available, I see that it is offered as part of a larger service. For me, this was not suitable."

What is our primary use case?

We are mainly using the solution to protect our computers from malware and other dangerous occurrences.

What is most valuable?

I have had absolutely no problem with using this solution, it really works well.

For how long have I used the solution?

I have been using the solution for three years.

What do I think about the stability of the solution?

The solution is stable.

What do I think about the scalability of the solution?

We are a small company and we did not branch out to know how scalable it is. We have under 10 people in the company using the solution.

How are customer service and technical support?

Once or even twice I used the technical support and I was assisted almost immediately.

Which solution did I use previously and why did I switch?

We have used McAfee and Trend Micro in the past.

How was the initial setup?

The installation was very easy, the deployment took a couple of weeks.

What's my experience with pricing, setup cost, and licensing?

We have a yearly subscription, and the pricing is fair.

What other advice do I have?

I would recommend this solution to others. However, it is not possible to use it for small companies at this moment. It is not possible to buy it from the company itself, or resellers in other countries. If it is available, I see that it is offered as part of a larger service. For me, this was not suitable.

I rate Symantec Endpoint Detection and Response a ten out of ten.

Which deployment model are you using for this solution?

Private Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Nikhilesh Verma - PeerSpot reviewer
IT Security Specialist at TT Systems LLC
Real User
Feb 12, 2021
Customizable Application and Device control, but it is expensive and there are a lot of false positives
Pros and Cons
  • "In Symantec, we have found that the most important feature is Application and Device Control."
  • "Technical support is not as good as we expect, and resolving problems should be more timely."

What is our primary use case?

We were using this product for our endpoint protection.

What is most valuable?

In Symantec, we have found that the most important feature is Application and Device Control. You can customize it to help stop attacks, and we have done that many times in our different environments.

What needs improvement?

Some fine-tuning is required because we often see false positives.

For how long have I used the solution?

I had been working with Symantec Endpoint Detection and Response for more than six years. However, we are no longer using it because we are transitioning to another product.

What do I think about the stability of the solution?

This is a stable solution in our experience. We have read in the community communications that there are some corruptions that occur, which is something that should be fixed.

What do I think about the scalability of the solution?

This product is scalable. We have approximately 3,700 users.

How are customer service and technical support?

Technical support is not as good as we expect, and resolving problems should be more timely.

Which solution did I use previously and why did I switch?

We are currently doing a PoC with Trend Micro. We are looking at Apex One and Deep Security. We are switching because we are interested in using a central management console in a cloud-based deployment.

Symantec has a cloud-based solution, but it not compatible with all of the departments in our organization.

I also have experience with the Websense solution.

How was the initial setup?

Installing on a Windows Server was straightforward.

What about the implementation team?

We have two people for maintenance.

What's my experience with pricing, setup cost, and licensing?

We are currently using the trial version of the latest release. The price is really high and it should be lower.

What other advice do I have?

I would rate this solution a seven out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Symantec Endpoint Detection and Response Report and get advice and tips from experienced pros sharing their opinions.
Updated: May 2026
Buyer's Guide
Download our free Symantec Endpoint Detection and Response Report and get advice and tips from experienced pros sharing their opinions.