No more typing reviews! Try our Samantha, our new voice AI agent.
Dennis Niedling - PeerSpot reviewer
Head of Managed Services & IT Security at B.O.C.
User
Top 5
May 14, 2025
The CREM feature is an absolutely essential feature that helps us meet security requirements
Pros and Cons
  • "Trend Vision One has reduced the time we spend detecting and responding to threats; I'd say we're 80% faster than before."
  • "The features of Trend Vision One are fine—it's the integration that needs work. Especially at the endpoint level, we still feel like we're using an older product that just got plugged into Trend Vision One."

What is our primary use case?

We're in the retail business, we sell bicycles in physical stores, and our branches are our biggest attack surface. These locations are covered by our overall solution, including sensors and other protection.

We have 49 branches, a headquarters, and a central warehouse. That's about 1,200 users and 1,000 computers. Trend Vision One is used primarily by our IT team. We also integrate with Office 365, Azure, and our on-prem data center.

We use Trend Vision One for consolidated security in hybrid environments. We have both on-premise and cloud data centers, particularly in Azure. The platform consolidates all of that into one view.

What is most valuable?

Since we started using Trend Vision One, we've been able to enhance our security posture significantly.

Trend Vision One has improved significantly over time in providing centralized visibility and control. It started as a set of individual products, but now it feels like one integrated solution. This reduces the need for interfaces or multiple analysis tools. That's why we pursued the one-platform strategy.

Trend Vision One has definitely helped consolidate our use of security vendors. We previously used standalone products for endpoint and email protection that weren't integrated. Now, we get the benefits of an integrated solution. I'd estimate we're 50–70% better in security now than we were two years ago.

The Cyber Risk Exposure Management (CREM)feature is absolutely essential. Even though we're not critical infrastructure, the NIS2 directive gives us security guidelines. CREM helps us meet these requirements.

It is very important to our organization that Trend Vision One integrates AI into the platform. Pattern recognition in forensic data is no longer manageable by humans due to the volume of events. Machine learning is essential to process these and filter what needs human attention.

Trend Vision One has improved our organization significantly. Security tasks used to be manual. Now, technology prevents issues or supports staff in detecting them. This shift from manual to technical solutions greatly increased our security.

Trend Vision One has reduced the time we spend detecting and responding to threats. I'd say we're 80% faster than before. The platform gives us consolidated data upfront, so we don't have to search for event clues manually.

Trend Vision One has helped reduce false alarms. I'd estimate a 50–60% time saving. We have more alerts now than years ago, but also better systems to handle them, making the whole process more efficient. Trend Vision One has helped reduce our cyber risk overall. We now know where gaps are before they become problems, whereas in the past we had to guess. That's a massive improvement.

When it comes to operations, the CREM solution helps us identify vulnerabilities in systems. If we patch them, they disappear from the reports—this gives us actionable insights, which is incredibly helpful.

It took about half a year to realize the benefits of Trend Vision One after implementation.

What needs improvement?

The features of Trend Vision One are fine—it's the integration that needs work. Especially at the endpoint level, we still feel like we're using an older product that just got plugged into Trend Vision One. A fully integrated endpoint client is the next step.

What do I think about the stability of the solution?

My impression of the solution's stability is an eight out of ten.

Buyer's Guide
TrendAI Vision One
August 2026
Learn what your peers think about TrendAI Vision One. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
913,924 professionals have used our research since 2012.

What do I think about the scalability of the solution?

I'd rate the scalability of Trend Vision One a nine.

The platform scales well. Our growth over the past three years has never caused performance or expansion issues.

How are customer service and support?

The service support for Trend Vision One works well. The service desk and escalations function smoothly.

Which solution did I use previously and why did I switch?

We used Kaspersky before Trend Vision One and switched due to BSI recommendations.

How was the initial setup?

It took about half a year to realize the benefits of Trend Vision One after implementation. Migration processes took some time, but we quickly started seeing positive results.

What was our ROI?

A return on investment wasn't our goal with Trend Vision One. The goal was to achieve a high level of security at acceptable costs, not ROI calculation.

What's my experience with pricing, setup cost, and licensing?

The pricing and licensing model for Trend Vision One is fair overall, especially with the good discounts we got. Currently, no extra costs—though we pay a monthly fee that gets converted into credits. I find the credit model non-transparent—you can't always tell how many licenses apply to which product. Trend Micro is working on improving this. We'll renegotiate pricing in 2026.

Which other solutions did I evaluate?

I joined the company in 2022 and brought knowledge of Trend Vision One with me. Our partner also recommended it, and the pricing and offers were so good that we didn't seriously consider alternatives.

What other advice do I have?

We cover all areas of security with Trend Vision One, except for edge security—we use other firewalls there.

We deploy Trend Vision One sensors at the endpoint and for email, including Office 365, and we're expanding this further. We believe that having all data in one central system gives us better insight than using isolated solutions. That's why we initially looked for a one-platform solution.

In 2025, we can finally recognize risks effectively, especially in Azure, where we previously had to rely solely on Microsoft. With Trend Vision One's support, we can now detect and mitigate risks, especially with our core ERP system running in Azure starting this November.

My advice to others evaluating Trend Vision One is to understand the full value across all modules. Just using endpoint protection doesn't show the platform's real strength. The full benefits come when multiple modules are used together.

My overall rating for Trend Vision One is 8 out of 10.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Marcelo Marcondes - PeerSpot reviewer
Marcelo MarcondesCybersecurity Analyst
Real User

As an Information Security Analyst, I see this case as a clear demonstration of how adopting an integrate


d security platform like Trend Vision One can truly transform an organization's security posture. The shift from multiple isolated solutions to a unified platform brought not just operational efficiency but a significant improvement in threat detection, response, and overall risk management.


The centralized visibility and control offered by Trend Vision One are fundamental in today’s landscape, where the complexity and volume of threats exceed human capacity to manage data manually. Integrating AI and Machine Learning was a game-changer — it enables faster pattern recognition across forensic data, which is critical for prioritizing real threats amid noise.


The reported 50% to 70% improvement in security is aligned with what we often see when consolidating tools: fewer gaps between solutions, more consistent policies, and better data correlation across endpoints, emails, and network layers. Additionally, reducing false positives by up to 60% directly enhances SOC efficiency, allowing teams to focus on real threats without being overwhelmed by alerts.


The Cyber Risk Exposure Management (CREM) functionality stands out as a strategic component, especially under compliance frameworks like NIS2. Having actionable insights into vulnerabilities, and watching them disappear from reports once remediated, streamlines vulnerability management and strengthens compliance posture.


Also, the claim of being 80% faster in detection and response is a testament to the platform’s ability to provide consolidated, contextualized data early in the investigation process — reducing the traditional time wasted on fragmented log analysis.


In summary, this experience reflects the tangible benefits of adopting an XDR strategy: enhanced visibility, accelerated incident response, proactive risk management, and operational efficiency. It reaffirms the importance of evolving from manual, reactive security operations to an automated, intelligence-driven approach — essential for keeping up with modern cyber threats.

Manish Kumar Twinkle - PeerSpot reviewer
Security Engineer at itsipl
Real User
Top 5Leaderboard
Feb 18, 2026
Integrated XDR has strengthened endpoint protection and reduces false positives in daily incident response
Pros and Cons
  • "TrendAI Vision One has positively impacted our organization by giving us fewer false positive alerts, and with its support, we are securing our environment against upcoming vulnerabilities such as zero-day attacks."

    What is our primary use case?

    My main use case for TrendAI Vision One is for endpoint security and XDR, as we need to handle incidents effectively.

    What is most valuable?

    TrendAI Vision One provides all the details for incident handling in our bank security operations, such as identifying where a threat is coming from, its impact, and a workbench to manage responses, making it easy to mitigate issues. In my daily work, TrendAI Vision One helps us first on the endpoint by preventing threats, allowing us not to worry about the types of daily updates, which we schedule based on preferences. Additionally, with XDR, we receive all threat events and their impacts, which helps us mitigate cyber risks and create playbooks.

    The best features of TrendAI Vision One are its integration capabilities with third-party intelligence such as STIX and MISP, along with collaboration and integration with tools such as Splunk, IBM QRadar, and DSPM and SASE products. The integrations with third-party tools such as Splunk and QRadar help our team significantly; we utilize syslog to gather all endpoint logs and QRadar logs. We simply generate an API and API key to facilitate integration with Splunk or QRadar.

    TrendAI Vision One has in-depth analysis and recognition features that provide a diagram of a workbench if a preventive attack is happening or has occurred, allowing me to access all logs and additional information regarding the threat's origin, impact, and mitigation strategies.

    TrendAI Vision One has positively impacted our organization by giving us fewer false positive alerts, and with its support, we are securing our environment against upcoming vulnerabilities such as zero-day attacks. Reducing false positives and handling zero-day attacks has streamlined our team's daily workflow and improved our overall security posture. For example, we integrated with Netskope and IBM QRadar, which reduced our workload by decreasing alerts, as QRadar detects genuine files that may have been previously flagged.

    What needs improvement?

    I do not have any specific suggestions for improving TrendAI Vision One.

    For how long have I used the solution?

    I have been using TrendAI Vision One for three years.

    What do I think about the stability of the solution?

    In my experience, TrendAI Vision One is stable.

    What do I think about the scalability of the solution?

    The scalability of TrendAI Vision One is notably low maintenance, and their support for the agent is long-term. We update the agent quarterly, and their Basecamp services share a data lake, making information gathering effortless.

    How are customer service and support?

    The customer support for TrendAI Vision One is very good. We create a case, and Trend support connects remotely, typically within twenty-four hours.

    Which solution did I use previously and why did I switch?

    Previously, we used Sophos, which was very bulky and caused slowness issues, prompting us to switch to TrendAI Vision One.

    How was the initial setup?

    The setup cost is reasonable, and the licensing is relatively low.

    What about the implementation team?

    We have directly purchased TrendAI Vision One from Trend Micro and did not acquire it through the AWS marketplace.

    What was our ROI?

    We have seen a return on investment because it is easy to use. One agent installed on the endpoint saves both money and time, as we only need L1 engineers to support the endpoints, reducing the number of employees needed to manage them.

    What's my experience with pricing, setup cost, and licensing?

    In my opinion, the pricing for TrendAI Vision One is somewhat high.

    Which other solutions did I evaluate?

    Before choosing TrendAI Vision One, we evaluated other options such as SentinelOne and CrowdStrike.

    What other advice do I have?

    I rate TrendAI Vision One a ten out of ten. Most importantly, I chose ten out of ten because it is easy to control and install the product, and the support from Trend engineers is exceptional along with the help we receive from salespersons. I advise those looking into using TrendAI Vision One to consider it seriously, as it offers XDR features, endpoint security features, and ZTNA features, eliminating the need for multiple agents or plugins. TrendAI Vision One is a very good solution that is easy to use. Their knowledge-based articles are extremely helpful, allowing us as techies to troubleshoot issues independently without always relying on senior staff or support.

    Which deployment model are you using for this solution?

    Hybrid Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Disclosure: My company has a business relationship with this vendor other than being a customer. Partner, Reseller
    Last updated: Feb 18, 2026
    Flag as inappropriate
    PeerSpot user
    Buyer's Guide
    TrendAI Vision One
    August 2026
    Learn what your peers think about TrendAI Vision One. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
    913,924 professionals have used our research since 2012.
    Raj-Yadav - PeerSpot reviewer
    Network Security Administrator at Alethe Consulting Pvt. Ltd
    Real User
    Top 5
    Mar 16, 2026
    Centralized visibility has simplified web access control but user management still needs improvement
    Pros and Cons
    • "I would recommend everyone to use Trend Vision One because it is the simplest GUI management; a network engineer with one year of experience can also manage Trend Vision One, and it can be deployed in any environment such as AWS, Azure, GCP, and also in a hybrid model."
    • "Stability can also be improved. Sometimes when we perform user management or when we go to log in to create the user, there will be some lagging on the network or it will automatically log out, and then we have to log in again on the web page."

    What is our primary use case?

    We use TrendAI Vision One as a web proxy to block and allow users to access web pages. We are a customer and an end user.

    What is most valuable?

    The best feature about TrendAI Vision One is the GUI; the platform is very user-friendly. The GUI of TrendAI Vision One is amazing and very useful, simple to understand, and simple to configure and learn. It saves my time and money, reducing approximately 20% of my time. AI in TrendAI Vision One was very important. If we integrate AI in TrendAI Vision One, it will provide more detail; all the data can be fetched from the internet to provide detailed network scalability and threats details, vulnerability scans, and port scans. It would be very good if the OEM integrates AI in TrendAI Vision One.

    What needs improvement?

    Stability can also be improved. Sometimes when we perform user management or when we go to log in to create the user, there will be some lagging on the network or it will automatically log out, and then we have to log in again on the web page.

    When I tried to explore the web gateway and the email gateway, they are present under some options. If they can be provided in a simple interface, it will be very beneficial for the users and end users to understand and configure TrendAI Vision One.

    For how long have I used the solution?

    I have used TrendAI Vision One for approximately five to six months, and I have used it in the past 12 months.

    What do I think about the stability of the solution?

    I will rate the stability at six to seven.

    What do I think about the scalability of the solution?

    I will rate scalability at eight or nine, around eight.

    How are customer service and support?

    Technical support for TrendAI Vision One was perfect; I will rate it at nine.

    How would you rate customer service and support?

    Positive

    What was our ROI?

    The ROI is around 10 to 15%.

    What's my experience with pricing, setup cost, and licensing?

    The pricing of TrendAI Vision One is moderate.

    Which other solutions did I evaluate?

    In comparison to other vendors, the GUI is perfect; it is cost-effective and easy to understand and easy to operate. Overall, the comparison is good for TrendAI Vision One.

    What other advice do I have?

    TrendAI Vision One provides overall network performance, such as CPU utilization, how many ports are open in the network, and how we can configure the attack in the network. Blind spots in the network can be identified through the platform.

    The centralized visibility was also good; we can manage all things in a simple GUI management. It can be consolidated within a hybrid environment.

    I would recommend everyone to use TrendAI Vision One because it is the simplest GUI management; a network engineer with one year of experience can also manage TrendAI Vision One, and it can be deployed in any environment such as AWS, Azure, GCP, and also in a hybrid model.

    TrendAI Vision One provides detailed network performance, CPU utilization of devices, and malware functions in the devices; it is all the details in one simple GUI where we can manage it, and we can see which end user and which end system is at risk, which is not, and which has updated the antivirus or not. I rate TrendAI Vision One at eight overall. My review rating for this product is seven.

    Which deployment model are you using for this solution?

    Hybrid Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    Last updated: Mar 16, 2026
    Flag as inappropriate
    PeerSpot user
    Nauman Ahmed Shakeel - PeerSpot reviewer
    Sr. System Engineer at a healthcare company with 5,001-10,000 employees
    Real User
    Top 5
    Dec 9, 2025
    Integrated threat monitoring has strengthened risk visibility and improved vulnerability response
    Pros and Cons
    • "TrendAI Vision One is very effective and very market competitive, which is why we are using it."
    • "TrendAI Vision One needs to work on its logging system as the logging systems are very complex, and they need to reform their logs in a more informative way."

    What is our primary use case?

    My use case is to monitor my entire infrastructure, investigate the latest vulnerabilities, identify loopholes, and monitor live threat detections to mitigate these threats.

    What is most valuable?

    TrendAI Vision One's best features are the ESRM and its email gateways, along with its playbooks, which are useful for testing any threat or vulnerability.

    It helps in identifying blind spots by providing comprehensive knowledge about risk assessment and a method to compare our organization with others, allowing us to understand our current stage in cybersecurity.

    What needs improvement?

    TrendAI Vision One needs to work on its logging system as the logging systems are very complex, and they need to reform their logs in a more informative way.

    For how long have I used the solution?

    I have been using TrendAI Vision One for the last three years.

    What do I think about the stability of the solution?

    I would rate the stability an eight.

    What do I think about the scalability of the solution?

    I would rate the scalability a nine.

    How are customer service and support?

    Their response rate is approximately 80 to 90%, and they mitigate the issue.

    I would rate the technical support a nine.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    I compare TrendAI Vision One with Trellix and Kaspersky, and compared to both of these, TrendAI Vision One is very useful with one-window operation and is a market-gaining product.

    How was the initial setup?

    The deployment is easy and very moderate, taking approximately one month.

    What about the implementation team?

    It was a partner purchase.

    What was our ROI?

    The ROI is positive, and I see a reduction of 100%.

    What's my experience with pricing, setup cost, and licensing?

    TrendAI Vision One is not so expensive; it is very moderate.

    Which other solutions did I evaluate?

    TrendAI Vision One is very effective and very market competitive, which is why we are using it.

    What other advice do I have?

    I will definitely recommend this product because of its deep knowledge and deep features, such as ESRM, playbooks, and other email gateways.

    We have approximately 50 users.

    I do use TrendAI Vision One sensors, and they totally cover our network as we are using network sensors and service gateways to scan the whole network and gather information about our loopholes, mitigations, and vulnerabilities with respect to the latest CVEs.

    I give this product a rating of 9.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Other
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    AhmedEl-Tayeb - PeerSpot reviewer
    Sales Manager at a tech consulting company with 201-500 employees
    Real User
    Top 5Leaderboard
    Sep 9, 2026
    Centralized security visibility has improved threat response while kernel-level impact needs work
    Pros and Cons
    • "TrendAI Vision One has helped my customers consolidate their use of security vendors and reduce silos."
    • "There have been a few incidents where intruders could get into the network even while the product was deployed."

    What is our primary use case?

    TrendAI Vision One has helped my customers consolidate their use of security vendors and reduce silos. If you purchase multiple technologies or products provided by TrendAI, that unified visibility console gives you full visibility across all the products provided by TrendAI across the network. This facilitates management and policy deployment for customers.

    My customers do not purchase TrendAI Vision One directly from TrendAI or from any third party. TrendAI is not considering selling directly to end users unless it is a big corporate arrangement or an OEM agreement. Usually, sales should occur through a reseller, then a distributor, or directly through a distributor to TrendAI.

    What is most valuable?

    User behavior analysis is the most important feature of TrendAI Vision One, in addition to the zero-day feature within that application. When customers upsell or add an XDR license, the product becomes a closed, solid endpoint protection solution that wins against the competition.

    TrendAI Vision One has helped my customers consolidate their use of security vendors and reduce silos. If you purchase multiple technologies or products provided by TrendAI, that unified visibility console gives you full visibility across all the products provided by TrendAI across the network. This facilitates management and policy deployment for customers.

    What needs improvement?

    TrendAI Vision One should learn from its competitors that having everything managed in one single platform gives strength to the product itself. However, instead of focusing on easing access for administrators, they should pay more attention to development itself and staying up to date. There was an initiative in the early days called Zero-Day, which means that before a threat is announced, they would hire specialists who immediately learn about threats and push updates directly to the product.

    Customers are protected even before the threat is announced. Currently, the Zero-Day initiative is not as active as it once was.

    Additional features I expect from TrendAI Vision One in the future to make it more competitive could be more technical in nature. A product working on the kernel level of a PC, machine, or server consumes significantly more resources than other products that work on runtime memory. If an application is attached to the operating system of the machine itself, it consumes more resources from the PC or server than running that product on the memory level. Memory-level products read all running activities across the memory when the machine is on, and when they detect malicious activity, they cut or end the session, which is lighter on the operating system and does not consume many resources.

    For how long have I used the solution?

    I have been working with TrendAI Vision One for around five years.

    How are customer service and support?

    TrendAI Vision One's technical support is adequate because they recently implemented a good methodology of supporting their customers. They initiated a Major Service Center divided across the globe, with a dedicated support center for the Middle East, another for Europe, a third one in the American market, and a final one in Singapore dedicated to supporting Far East customers. This has enhanced their support.

    What gives more strength to their products is that they enable business partners, distributors, resellers, and others with sufficient tools to identify problems and provide first and second level support themselves. When an engineering intervention is needed, the case can be escalated to their support team, which is more effective than the old model. They initiated this Major Service Center two or three years ago, which makes it easier for customers and enhances support.

    What other advice do I have?

    My impressions of TrendAI's ability to provide centralized visibility and management across protection layers are positive. They had, in the early beginning, a unified management console called Apex One. The commercial name has changed over time, and it is now called Apex Central. TrendAI Vision One Apex Central gives full visibility across the customer network, including all solutions provided by TrendAI, with unified visibility, policy deployment, and plug-in extensibility.

    TrendAI Vision One has helped my customers reduce their time to detect and respond to threats. There have been a few incidents where intruders could get into the network even while the product was deployed. TrendAI ranks third globally as an endpoint or EDR solution. There are pros and cons to the product. I would rate TrendAI Vision One between seven and eight out of ten.

    My customers may use the Cyber Risk Exposure Management capabilities of TrendAI Vision One. However, I do not think they are using or activating that feature because it can conflict with other products. Most banking customers prefer not to activate EDR and endpoint protection from the same vendor, as a compromise could become a significant issue. Therefore, I did not use this feature.

    Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
    Last updated: Sep 9, 2026
    Flag as inappropriate
    PeerSpot user
    reviewer2754906 - PeerSpot reviewer
    Manager of Cyber Security at a university with 1,001-5,000 employees
    Real User
    Top 10
    Sep 6, 2025
    We've ease of configuration and customization and improvement in threat response
    Pros and Cons
    • "The ease of configuration, customization, and organization are what I appreciate the most about TrendAI Vision One."
    • "It is a bit slow to implement kernel support on the Linux side. When doing patching and upgrades on our Linux servers, we often find that the Trend agent doesn't support the kernel version."

    What is our primary use case?

    We use TrendAI Vision One for our endpoint protection in our data center, mostly focused around our server assets, and we do anti-malware, intrusion prevention, as well as firewall, host-based firewall capabilities.

    What is most valuable?

    The ease of configuration, customization, and organization are what I appreciate the most about TrendAI Vision One

    What needs improvement?

    It is a bit slow to implement kernel support on the Linux side. When doing patching and upgrades on our Linux servers, we often find that the Trend agent doesn't support the kernel version. It's usually not far behind, but we often are in a position where we may not be properly protected for a period.

    For how long have I used the solution?

    We started using Trend Deep Security, which was the product prior to TrendAI Vision One, seven or eight years ago, and then we transitioned to TrendAI Vision One two years ago. While we have been using TrendAI Vision One proper for two years, we had essentially the same product in an on-prem version for seven or eight years.

    What do I think about the stability of the solution?

    We've had performance issues with the agents of TrendAI Vision One at odd times, but I wouldn't say it's been a widespread issue or a common issue. Once in a while, there have been things that we've attributed to Trend.

    What do I think about the scalability of the solution?

    The scalability of TrendAI Vision One seems infinite. We're not a huge organization, so we haven't really run into any limitations, but it appears it can scale to accommodate and serve any of our purposes.

    How are customer service and support?

    The quality of support for TrendAI Vision One is generally very good. If we have any issues with support, we can leverage our sales engineer for support or escalation. I really haven't had any concerns. I have contacted the technical support or customer support via phone number or ticket.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    We have used Microsoft Defender, Sophos, as well as McAfee as alternatives to TrendAI Vision One. I prefer TrendAI Vision One more compared to those alternatives.

    How was the initial setup?

    We transitioned from our on-premises Deep Security deployment to Vision One, and the process was relatively smooth. However, we encountered a few challenges related to legacy configurations and ensuring proper connectivity to our server assets. With an on-premises software application, we didn’t have to worry about internet accessibility for some of our server nodes. Consequently, we faced issues getting non-internet-connected server endpoints to communicate with the cloud. Luckily, there is a solution for that, but it took some time to get everything functioning properly.

    TrendAI Vision One is a large product suite. There are many features that we don't have fully deployed, but the amount of time it took for us to go from on-prem to the cloud for similar services without onboarding anything new that TrendAI Vision One offered was two months for 400 assets, server nodes.

    What was our ROI?

    It has reduced our time to detect and respond to threats, but I don’t have a way to quantify that.

    What's my experience with pricing, setup cost, and licensing?

    I know the pricing for TrendAI Vision One. It's been a while, but it doesn't seem bad. They made some changes to their pricing in the past. It used to be a per-server node pricing structure, but now they do it by credits. I would say it's improved because we can, for the same investment, shift and adjust which capabilities we're leveraging within the platform. It's not super expensive. It's definitely an increased cost over leveraging Microsoft Defender, which we already have the licensing and capability for. We chose to spend money on this as opposed to leveraging a product that we already had, but the cost is fair.

    What other advice do I have?

    The sensors we're using include the anti-malware products, and we have the EDR sensors deployed on our server endpoints. They have network sensors and other features, but we're not leveraging any of those.

    We started onboarding some of our services in the last three or four months to TrendAI Vision One to gain more visibility, so it's early in that adoption. We haven't taken any action based on alerts or notifications from TrendAI Vision One, as we're still in the early stages of getting our third-party services set up and monitored.

    TrendAI Vision One hasn't helped us consolidate use of security vendors. This product is solely used for one purpose. We're not leveraging TrendAI Vision One for other areas within IT or at our company, so we haven't reduced silos. We had an opportunity to go with Defender, which would have reduced the number of products we use, but instead we decided to keep using Trend because we did appreciate it. I'm not sure if TrendAI Vision One has helped me to reduce the noise from false positives.

    I would rate TrendAI Vision One a nine out of ten.

    Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
    PeerSpot user
    reviewer2735652 - PeerSpot reviewer
    Associate Specialist Infrastructure and Support at a security firm with 501-1,000 employees
    Real User
    Top 20
    Jul 15, 2025
    Helps secure endpoints and quickly respond to incidents
    Pros and Cons
    • "Trend Vision One has improved the way our organization functions by acting as both a monitoring tool and an antivirus, giving us insight on potential threats and enhancing our response time to security incidents."
    • "Our developers were understandably frustrated that they couldn’t debug code for a month and a half, which impacted our project timelines."

    What is our primary use case?

    Our use cases for Trend Vision One are monitoring and alerts.

    How has it helped my organization?

    The biggest challenges we wanted to address with Trend Vision One were securing endpoints and enabling us to quickly respond to incidents or threats. This is the main goal for using this solution.

    Trend Vision One has improved the way our organization functions by acting as both a monitoring tool and an antivirus, giving us insight on potential threats and enhancing our response time to security incidents. It is hard to measure the time savings but we save a significant amount of time in responding to potential threats. For example, we don't expect employees to respond to emails, chat, or calls outside of working hours. Trend Vision One has a feature where we can block all access to the laptop or endpoints. It allows us to take immediate action without waiting for the user to respond.

    In terms of reducing noise from false positives, unfortunately, some behaviors can be mistaken for bad behaviors, but that isn't the fault of the software itself. It largely depends on how the developers of other applications implement their software and how it is run. We encountered an issue with another software called Rapid7, which periodically runs a command on MacBooks or Apple operating systems. This command, which is quite lengthy, searches for any unsecured credentials or API keys related to GitHub on the laptop. The way the application triggers is significant: it runs under root privileges, executing that command in the terminal for the user. Trend Vision One picks this up as a suspicious command, interpreting it as an attempt to find unsecured credentials. Despite having whitelisted the entire command in Rapid7, Trend Vision One still flagged it. We went back and forth on this issue, but ultimately we decided that it wasn't worth further troubleshooting to silence this alert due to the potential for actual malicious use of such commands. While we could whitelist it, we did not want to risk it being exploited maliciously. In the end, we chose to ignore the alert. They helped us reduce some other noise, but there was some noise that we weren't able to reduce.

    Vision One AI has been very useful. All IT people stay up to date with security risks, exposures, alerts, or attacks. Vision One AI helps us explain or understand the alerts and what actions are recommended.

    What is most valuable?

    The workbench alerts are something we find very useful, as they help us stay informed about various activities. Not all alerts are positive, but they provide valuable insights into the detection methods and help us understand how certain issues arise. For example, if someone attempts to run a piece of software that encrypts a file, one of our tools, which is used for evidence gathering in surveillance systems, may encrypt the file too quickly. As a result, Trend Vision One may trigger an alert. Although this is a false positive, it still gives us insight into the behavior involved. This allows us to investigate the alert further and provide feedback to the user or development team, letting them know that similar triggers are likely to occur with other security systems or software.

    Other useful features include intrusion and mailbox alerts, suspicious unauthorized access, tracing logs, website clicks, and email filtering for bad attachments.

    What needs improvement?

    The improvement I have been asking for is an easier way to create MDR requests. Not all alerts that come through Trend Vision One receive an investigation, and we would like the ability to easily request an investigation on lower-scored alerts without logging into the support portal to create a ticket.

    I would like to see Trend Vision One and OfficeScan consolidated into one platform. Currently, it is the same space but two different layers. It would be nice to have both combined instead of having two clients.

    There is room for improvement when it comes to support.

    For how long have I used the solution?

    I've been working with Trend Vision One for three years.

    What do I think about the stability of the solution?

    Trend Vision One is stable enough. We don't see many performance impacts on our endpoints, except for when our weekly scheduled scans happen. Our developers express that it limits how freely they can develop, but I personally appreciate the insight it gives us and the actions that allow us to take on our devices.

    How are customer service and support?

    I would rate their support a six out of ten. We encountered an issue with one of our tools—specifically, Visual Studio. One of our developers faced difficulties debugging code because Trend Vision One was blocking the debugging application or causing it to crash. This problem stemmed from a Windows update, and it took us a month and a half to identify the root cause. After we opened a ticket either at the end of March or early April, we waited several more weeks for a solution. Although the Windows update occurred back in February, we didn’t receive the fix until the end of May. The interaction between Windows and the application played a significant role in the issue, as the debugging application starts the code and injects itself into the running application, which Trend Micro flagged as problematic after the latest Windows update. Fortunately, this issue has now been resolved, but it was indeed a painful experience. Our developers were understandably frustrated that they couldn’t debug code for a month and a half, which impacted our project timelines.

    How would you rate customer service and support?

    Neutral

    Which solution did I use previously and why did I switch?

    The company previously had SentinelOne before my time, and I can say that SentinelOne was not effective. 

    We currently use Rapid7 as our Managed Detection and Response (MDR) service. In my experience, both Rapid7 and Trend Vision One serve similar purposes, but they have distinct differences. There are times when Rapid7 provides us with more detailed information, while at other times, Trend Vision One offers greater insights. This is partly because Trend Vision One collects more data from the devices, allowing it to better identify the root causes of alerts compared to Rapid7. 

    Additionally, I find that the MDR team at Trend is generally more responsive than that of Rapid7. However, there are some disadvantages as well. For instance, we haven't yet set up cloud monitoring capabilities with Trend Vision One. Rapid7 currently handles our cloud infrastructure monitoring and manages services like Office and Okta. While Rapid7 is equipped to monitor these services, Trend Vision One is not yet at that level. We are exploring ways to enhance its capabilities, and if it can provide the same level of service as Rapid7, we might consider discontinuing our use of Rapid7 altogether.

    How was the initial setup?

    We use the SaaS solution. I was not involved in the initial setup and deployment process, which occurred prior to my time here, but I have readjusted some policies.

    Previously, it was difficult to understand some alerts. However, as time goes by, we differentiate better between them, and the AI feature is an extremely good tool that explains things that are gibberish to the regular user. The learning curve is quite steep.

    What was our ROI?

    It has helped us understand some of the alerts that we did not comprehend.

    What other advice do I have?

    It is an all-around solution that includes various modules for comprehensive security monitoring and alerting. This solution is particularly effective when integrated with other hardware or on-premises solutions, such as Deep Discovery Inspector, which monitors your network.

    The interface is adequate, but it is constantly changing. New features are being added, and items are being rearranged almost daily. We might have missed some announcements regarding these frequent updates. As it is an evolving solution, such changes are to be expected. However, there are still features that are buried within menus, which previously required extensive searching to locate. For instance, until last year, isolating endpoints was only possible through the search function. Now, they have added a feature within the endpoint inventory that allows you to select devices and isolate them immediately, rather than having to jump through multiple hoops to access that option.

    The application has also become slightly more responsive. Regarding its functionality, the insights it provides are quite useful. The application displays various actions, and you can drill down into alerts to view the execution path associated with them. For example, if an application triggers an alert, you can right-click on that alert and select "Check Execution Profile." This feature shows you where the process started, what actions it took, and where it ended. This improvement is beneficial for understanding how tasks are executed.

    I would rate Trend Vision One an eight out of ten.

    Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
    PeerSpot user
    Works at Optigrün international AG
    User
    Top 10
    Mar 3, 2025
    Provides solid security, centralized visibility, and flexible licensing
    Pros and Cons
    • "The dashboard is valuable. It provides a comprehensive view of our security status and allows us to compare ourselves with other companies using Trend Vision."
    • "Our speed has increased significantly."
    • "Improving the user interface would be helpful—it can be confusing, especially if you do not use it daily."

    What is our primary use case?

    We have been in contact with Trend Micro for a very long time. We have a Domino server, which is the alternative to an Exchange server, and we have implemented their virus scanner there. Because of that, we decided to stick with the company and integrate Email Gateway Protection as well. It is important for us because we host our own mail server, and we receive a huge amount of spam. The goal was to reduce that. So far, we have reduced our email traffic by almost 50%—thanks to email filtering. This means our employees do not have to handle those emails anymore.

    We receive around 1,000,000 emails per year and 500,000 of those are junk. That was a key factor in saving work time. Every email that lands in an inbox has to be handled—either deleted or responded to. We tested this with different employees and found that deciding whether an email is relevant or junk takes about 10 to 15 seconds per email. With 500,000 unnecessary emails, you can imagine how much time we are saving company-wide.

    Another major reason we implemented this solution is phishing emails. This is a huge issue. Trend Micro offers phishing awareness training, but ideally, these phishing emails should not even reach our company, as they are highly dangerous. So far, Trend Micro has filtered out around 3,700 phishing emails for us.

    There is another extremely dangerous issue—malicious software hidden in attachments. If an employee clicks on such an attachment, files could get encrypted. In the past year, Trend Micro has intercepted 60 such cases, meaning 60 incidents where our files did not get encrypted.

    This is why we use this solution. Of course, there are other providers, but we find Trend Vision One's interface very user-friendly. We also have a dashboard where we can track everything and pull these statistics.

    How has it helped my organization?

    In Germany, such a security solution is very important. Due to a change in the law, company management is now obligated to ensure that IT security is based on best practices. If they fail to do so or are unaware of their security status and neglect it, they are now personally liable with their private assets. I also need a tool that allows my management and board to monitor our security status. One of the reasons why we chose Trend Vision One was that it provides the option for the board to check the dashboards. This means that every morning while having coffee, they can see the security status of the company on their phones. They can also ask, "Hey, why is our security score high? Is our IT department not working properly? Or do we have a real problem that requires additional software or other measures?" Additionally, negotiations become easier for the IT department, for management, and for us. If security gaps arise, we can say, "Hey, we need software or an investment of a certain amount." We now have a solid foundation for our case.

    We use email security and endpoint protection. Endpoint protection is installed on every computer and server, with enhanced sensors on the servers. These security tools are crucial for us—without them, we would be blind in IT. They allow us to monitor the health of each system and user activity, including preventing access to inappropriate websites.

    We have a lot of remote work, and we used to struggle because we could not properly monitor devices outside our network or firewall. Now, we can control things like applications, websites, USB sticks, and external hard drives, which was previously impossible. A key feature of our endpoint protection is that if a computer reaches a certain security risk score, it is automatically blocked by the software. This means that if an attack occurs, the affected computer is isolated from the network, preventing further spread.

    Our biggest challenge is not direct hacking attacks—our company is not a high-priority target. Instead, phishing emails are the main issue. These emails attempt to trick employees into making fraudulent payments or providing access to our systems, allowing ransomware installation. Email security is our biggest focus area.

    It has significantly reduced email volume, which is crucial, especially for our security team, as they do not have time to review every message. IT also receives fewer inquiries about whether emails are legitimate. Additionally, phishing training has helped—our employees recognize phishing attempts better, and our click rate on phishing simulations has dropped to zero. Previously, conducting a phishing simulation would have cost €2,500 per test, but now, we can run one or two tests per month at no additional cost. This provides great value.

    It is important for us that Trend Vision One has AI built into its platform. It is essential for detecting abnormalities quickly. Humans may not notice certain threats, but AI can. However, AI is not perfect and sometimes lets suspicious emails through, which we then manually review in quarantine. AI is constantly learning, and the more it improves, the less manual intervention is needed, which is beneficial for us.

    We now have visibility. Previously, we were blind and could not assess our security status.

    Trend Vision One helped reduce our time to detect and respond to threats. Previously, we relied on reading security forums and websites to identify vulnerabilities. Now, we get real-time alerts and can take immediate action.

    Our speed has increased significantly. We can update and patch security threats daily, whereas before, it took weeks or even months.

    Trend Vision One has helped our organization reduce its cyber risk, especially through endpoint protection. For example, our field employees used to connect unknown external hard drives, which posed a risk. That is no longer possible, eliminating a major threat vector.

    Trend Vision One has helped consolidate our use of security vendors. Previously, we only had basic endpoint protection from another provider, which we replaced with Trend Vision. We now have more security software, not less, because our company has grown significantly—from a small business to a mid-sized enterprise. The IT department was lagging behind, and security was not a priority. Now, we manage everything with one provider, rather than multiple vendors.

    What is most valuable?

    The dashboard is valuable. It provides a comprehensive view of our security status and allows us to compare ourselves with other companies using Trend Vision. We can immediately see if we need to take action when updates are released with high CVE scores, without having to check multiple websites. This saves time and enables faster decision-making.

    The platform provides not only visibility but also intervention capabilities, such as blocking threats. We are operating at a high level in this regard. I would rate Trend’s Vision One platform very high in providing centralized visibility and management across protection layers.

    What needs improvement?

    Improving the user interface would be helpful—it can be confusing, especially if you do not use it daily.

    We do not see a need for additional features. The tool has so many capabilities that it can be overwhelming at first, which is why we implemented it step by step to avoid overwhelming our administrators.

    For how long have I used the solution?

    We started with the Email Gateway Protection solution in December.

    What do I think about the stability of the solution?

    Its stability is very good. We have not had any failures so far.

    What do I think about the scalability of the solution?

    Its scalability is very good as we can work with it flexibly.

    We have an environment with 160 users and about 15 servers, all virtualized and running entirely on-premise.

    How are customer service and support?

    It is very good. If we have a problem, we call Mr. Weckwert or send him an email and receive a response.

    Which solution did I use previously and why did I switch?

    We used SonicWall’s endpoint protection before, but it had issues. For example, the endpoint protection conflicted with VPN installations, requiring us to uninstall security features before updating VPN settings—an unacceptable security risk. With Trend Vision, we feel much better protected.

    SonicWall is just a basic antivirus tool, whereas Trend Vision One provides more advanced features like software firewalls and the ability to block specific applications and websites, such as preventing employees from using Telegram or WhatsApp on work computers.

    A downside is that Trend Vision One requires more system resources, so we had to upgrade some computers with additional RAM. However, that is not just due to Trend Vision One but also Windows 11’s increased demands.

    How was the initial setup?

    We use a hybrid model—Trend Vision’s cloud solution with local installations on our devices. We operate entirely on-premise.

    We worked with a partner and now manage everything internally.

    What about the implementation team?

    For the implementation, all admins were present to understand how it works. It was like a training session for us.

    Fundamentally, there is one colleague responsible for it, and they spend about an hour to an hour and a half on it daily.

    In terms of maintenance, it only requires updates.

    What was our ROI?

    We have seen an ROI through time savings. The email filtering system paid for itself within a year.

    What's my experience with pricing, setup cost, and licensing?

    It is very good. The flexibility to temporarily exceed license limits when setting up new devices is helpful, as it allows us to ensure security before purchasing additional licenses.

    What other advice do I have?

    Try it out. Ultimately, everyone has to decide for themselves if it fits their admin team. What I always say is that this tool monitors you and provides insights—it exposes weaknesses in an IT department. If IT management cannot handle that level of transparency, they should avoid it. If they see value in having more insights, it is a very valuable tool.

    I would rate Trend Vision One an eight out of ten.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Works at Kreiskrankenhaus Grünstadt
    User
    Top 10
    Feb 6, 2025
    If a user mistakenly clicks on something they shouldn’t, the system can respond immediately and prevent damage before it occurs
    Pros and Cons
    • "The SOC team is the most valuable feature for us because having experts who monitor global threat landscapes and can respond accordingly is incredibly helpful."
    • "Sometimes it’s difficult to find your way around."

    What is our primary use case?

    Our primary use case is to secure our endpoints and servers via Managed Detection. We secure them using XDA and Trend Micro’s SOC. We secure it based on behavior so that we have someone to respond if there are unusual issues with PCs, even on weekends and holidays when we’re not onsite, and then they inform us. That’s why we chose Trend Vision One.

    We have it deployed on all of our PCs, both Windows and Linux laptops.

    The security coverage is very important for my company's network. It is a requirement under the NIS2 directive, which is now coming into effect in the EU. The coverage is also important for us because we operate 24/7, but our IT staff is not available around the clock. To fill this gap, we opted for Trend Micro’s XDR solution. Trend Micro’s SOC team can respond even when no one from our team is available.

    They also make sure we are properly notified because if an email comes in at 3 AM on a Sunday, no one will read it but if Trend Micro's SOC team calls, someone will check immediately. That’s why we chose this solution.

    The security coverage is also particularly important for us because, as a hospital running 24/7, we must ensure the security of patient data and maintain the IT infrastructure's operational capability. If our systems go down, it could directly impact patient treatment. Around 10 years ago, before we had Trend Micro, we experienced an attack and our IT systems were down for an entire week. That was incredibly difficult.

    With increasing digitalization and more medical processes relying on computers, doctors need easy access to X-rays, prior medical examinations, and other records. Since all of this data is stored digitally, solutions like Trend Vision One become even more essential. Availability must be guaranteed, and we cannot afford a situation where a system gets attacked and taken down. That’s why it is crucial for us to have this protection in place.

    The biggest security challenges in my organization are:

    1. Preventing unauthorized external access.

    2. Reducing the risk of employees unknowingly giving attackers access to the network due to inexperience.

    That’s why we use these solutions, in combination with Apex One and Deep Security, to prevent such incidents. If a user mistakenly clicks on something they shouldn’t, the system can respond immediately and prevent damage before it occurs.

    How has it helped my organization?

    With Trend Micro Vision One we now have a comprehensive overview of our entire network of all of our endpoints and Active Directory. We also have an industry comparison feature that allows us to gauge our security status.

    For example, our advisor recently reviewed our security score and confirmed that we are in a good position. That gives us peace of mind.

    What is most valuable?

    The SOC team is the most valuable feature for us. Having experts who monitor global threat landscapes and can respond accordingly is incredibly helpful. They keep an eye on our system and can intervene if necessary to prevent significant damage. That is the most important aspect for us.

    That’s a bit tricky to answer. Trend Vision One is a powerful tool that provides a vast amount of information. It requires some practice to filter out the most relevant insights and respond accordingly like investigating specific endpoints when necessary.

    Since we are still relatively new to the platform and have a small IT team, we haven’t been able to fully explore all of Vision One’s capabilities. However, the data we do utilize helps us react appropriately and address potential threats before they escalate.

    A major advantage is that we can integrate Active Directory into Vision One. This means we get alerts if something unusual happens in AD, and these notifications appear directly in Vision One. I believe firewalls can also be integrated, though we haven’t done that yet as we are currently upgrading our firewall infrastructure.

    Having a centralized platform where logs and security alerts from multiple systems converge is a huge benefit, as it allows us to react efficiently from a single interface.

    AI is beneficial because it can operate independently of predefined patterns, reacting based on behavior rather than fixed rules. It continuously learns and can detect threats that might not yet be covered by existing security protocols. This is a major step forward in cybersecurity.

    We realized Trend Vision One's benefits quite quickly. Within one to two weeks, we already saw improvements. We really noticed the full impact after receiving our first report. That allowed us to analyze incidents, track past threats, and understand what was happening within our network. After about four weeks, we fully realized the platform's value.

    It does save time when searching for an incident because you can simply display the incidents in the Vision One console. You can drill down to the task level and see which file was affected on which endpoint.

    That makes things much easier when tracking a specific incident. It saves more than fifty percent of the time because, as mentioned, you can drill down directly from the endpoint in the console, down to the task, down to the file, the DLL, or whatever it is. And you also get a display of what it is without having to access the computer and search on Google. As mentioned, everything is displayed clearly and neatly in the Vision One console, sometimes even with suggestions on what to do.

    My organization has reduced its cybersecurity risk. We have a centralized view of where the risks are, you can specifically access individual endpoints, and as mentioned, the SOC in the background immediately reports unusual behavior even when you’re not around. If it’s high-risk, we get a call.

    In this regard, cybersecurity has improved significantly because a lot of things that previously went unnoticed are now detected.

    What needs improvement?

    Trend Vision One is already very powerful. The clarity and usability could be improved a bit. Sometimes it’s difficult to find your way around.

    It’s such an important tool, and you can do a lot with it. With some practice and proper training, you can manage quite well.

    We are currently implementing, as a pilot hospital, an ICAP virus scanner through the Service Gateway via Vision One, which scans our KIM emails. This was an important feature and Trend Micro has now implemented it.

    For how long have I used the solution?

    I have been using Trend Vision One for about six months.

    What do I think about the stability of the solution?

    I would rate the stability a nine out of ten.

    What do I think about the scalability of the solution?

    We are currently working on scaling. We are integrating with ICAP functionality.

    The scalability is very good. You can integrate almost everything you need, including mail security, etc. I’d give scalability a 10 because nearly everything is integrated.

    How are customer service and support?

    The staff we have dealt with were always very competent. What I find a bit difficult is that there is no German support. Since my English isn’t the best, we usually go through our consultant, as he knows the Trend Micro support team well and handles these things daily. So, we rely on our partner for that.

    In terms of knowledge, the support is competent. The language barrier is just a bit challenging because when they speak fast in English and I don’t understand much.

    What about the implementation team?

    The initial setup was done by a consultant from SoftwareOne. He did a really good job, and everything went smoothly except for the hybrid installation with Deep Security.

    That went quite smoothly. Apex One had some issues, and we had to keep a support case open for a long time before it worked properly. But now, everything works fine.

    We are only four people in IT here, and everyone does a bit of everything for the setup.

    We install the agents ourselves, meaning we have to manually set them up on each computer or server.

    The clients are already rolled out, and everyone contributes when needed like whenever we work on something, another sensor gets installed, etc.

    We have around 400 endpoints and approximately 600 users with a Windows environment and a virtualized setup using VMware.

    Our server environment also includes VMware View in some areas.

    In terms of maintenance, I have to regularly check reports and see what needs to be done. Otherwise, everything updates itself in Vision One.

    Since Vision One is cloud-based, the console updates itself, as do the agents. Once everything is installed, there’s little to do.

    What's my experience with pricing, setup cost, and licensing?

    There are additional costs.

    Overall, the price-performance ratio is okay.

    Which other solutions did I evaluate?

    We looked at Sophos beforehand because we use it as a firewall. Since Vision One integrates well with existing solutions like Deep Security and Apex One, we chose an integrated solution and decided to go with Trend Vision One.

    We also deliberately opted against a purely web-based solution. We run a hybrid installation, meaning that Apex One and Deep Security are still managed locally and connected to Vision One.

    This is because we have been hacked before, and if I cut off internet access to our firewall, I wouldn’t be able to administer my security suite. With this setup, I can still manage and configure it before reconnecting to the internet.

    What other advice do I have?

    I would rate Trend Vision One a nine out of ten.

    My advice to anybody considering Trend Vision One is that the most important aspect is the integration with existing solutions like Apex One and Deep Security.

    It’s stable and provides a lot of information. The only downside is that it can be a bit complex to navigate.

    Which deployment model are you using for this solution?

    Public Cloud
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    reviewer2879538 - PeerSpot reviewer
    Soc Analyst at a consultancy with 11-50 employees
    Real User
    Top 20
    Jul 24, 2026
    Focused host investigations have become faster and triage now cuts threat response time in half
    Pros and Cons
    • "TrendAI Vision One has helped reduce our time to detect and respond to threats by approximately 50%."
    • "TrendAI Vision One can definitely do better in the XDR Data Explorer part, where it could expand its query language to allow for summarizations or some kind of table view, not just simple operators like AND, OR, IS, and IS NOT."

    What is our primary use case?

    My main use case for TrendAI Vision One is that I mostly rely on the Workbench section and working through alerts, viewing events. I also use XDR Data Explorer extensively, as well as the Response Management section.

    For example, we had a client who ran a script for the activation of Windows operating system and Office tools, but that script is somewhat illegal and sourced from GitHub. I received an alert that a script running from GitHub had been downloaded, so I opened my alert from the Workbench section and viewed the event. I saw the host name and searched the host name through the XDR Data Explorer to see how the user managed to access that GitHub repository. I discovered that it was actually a user execution, so the user genuinely performed that action. I made a response and also sent an email to my client explaining what happened.

    I use TrendAI Vision One extensively for response management in that way and for scanning the hosts for malware.

    What is most valuable?

    In my opinion, one of the best features of TrendAI Vision One is the fact that you can intuitively see what is happening on one host without getting a lot of noise in the way.

    There is not a specific function, but there is an option in XDR Data Explorer to investigate a certain host, so you can focus on one host and not query the whole environment.

    I have noticed that our triage with TrendAI Vision One is better, faster, and more concise.

    TrendAI Vision One helped us with its visualization. For example, when I view the event, there is a Process Timeline Tree, and I can see what happened. I can quickly see what assets are being affected by something.

    Regarding TrendAI Vision One's AI capabilities, I think its security aspect is strong because it gives you a good picture of how our sensors are deployed, the agents deployed, their versions, and if their versions are updated or not.

    I have used TrendAI Vision One's AI capabilities from time to time, and it is very good at explaining its events in a way that if I am not sure what happened in an event or alert, it can concisely tell me what is going on. I think it is pretty trustworthy since it is not jumping to conclusions.

    What needs improvement?

    TrendAI Vision One can definitely do better in the XDR Data Explorer part, where it could expand its query language to allow for summarizations or some kind of table view, not just simple operators like AND, OR, IS, and IS NOT. It could definitely improve by creating some sort of visualizations.

    When investigating a host, it might be better if the table shown is more readable or if the table would be exportable. When I investigate a host and it gives me a table, I could export the table and look at it through Excel.

    For how long have I used the solution?

    I have been working in my current field for about eight months.

    What do I think about the stability of the solution?

    TrendAI Vision One has been mostly reliable; it did have some downtimes, but they were temporary and short. They were not long-lasting, so I can say confidently that it has been pretty reliable.

    What do I think about the scalability of the solution?

    TrendAI Vision One's scalability handles growth and new clients well.

    How are customer service and support?

    Fewer employees are needed, but I do not have any other relevant metrics.

    Which solution did I use previously and why did I switch?

    We have not previously used different solutions for this client, so this is our first solution, and we are quite happy with it.

    How was the initial setup?

    I do not know which cloud provider is used; I was not on the engineering side when it was deployed, so I am not sure.

    What about the implementation team?

    The engineering team evaluated other options, but I do not know which ones.

    What was our ROI?

    TrendAI Vision One helped us reduce cyber risk through its metrics and telemetry; it showed us what kind of data we are dealing with when our clients are in question. We can focus on what matters and implement new filtering and rules to reduce the noise and focus on what is really important.

    TrendAI Vision One has helped reduce our time to detect and respond to threats by approximately 50%. It reduced the time to detect and respond because it has a really good way of showing what happened. The user interface is readable, and you get a lot of information just from the alert itself, so you do not need to do a lot of digging because the alerts are very detailed.

    What's my experience with pricing, setup cost, and licensing?

    I did not know about the pricing, setup cost, and licensing because I was not employed at the time when TrendAI Vision One was deployed and during the beginning of its use.

    Which other solutions did I evaluate?

    The engineering team evaluated other options, but I do not know which ones.

    What other advice do I have?

    Since I am not an engineer, I am not sure what kind of aspects someone would need to look for if they want to buy TrendAI Vision One, but I can say that I am happy using it as a SOC analyst.

    From an analyst perspective, TrendAI Vision One is useful for looking into alerts and incidents and exploring various data. I would say it is readable and easy to use, and also very intuitive. I would rate this product an 8.

    Which deployment model are you using for this solution?

    Private Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Other
    Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
    Last updated: Jul 24, 2026
    Flag as inappropriate
    PeerSpot user
    Buyer's Guide
    Download our free TrendAI Vision One Report and get advice and tips from experienced pros sharing their opinions.
    Updated: August 2026
    Buyer's Guide
    Download our free TrendAI Vision One Report and get advice and tips from experienced pros sharing their opinions.