No more typing reviews! Try our Samantha, our new voice AI agent.
reviewer2005038 - PeerSpot reviewer
Operations Manager, Global Information Security at a hospitality company with 10,001+ employees
Real User
Nov 10, 2023
Reduces the time to detect, investigate, and respond
Pros and Cons
  • "We had previously deployed on-premises, and all we had to do was access the designated console and click a button to migrate all on-premises agents to cloud agents."
  • "I would like to have the capability to export the information we receive from the XDR into Microsoft Excel."

What is our primary use case?

We have deployed Trend Micro XDR on all our endpoints. It is deployed as an agent because we are using Trend Micro Apex, the antivirus agent, and the SaaS agent. This means that we receive notifications from XDR for any suspicious activity related to endpoints. For example, if a user connects to a suspicious website, XDR should alert us based on our rules. It can also generate alerts for malicious Windows activities.

In addition to deploying XDR on our endpoints, we have connected Vision One XDR to our Office 365 email platform. This allows XDR to read incoming emails. We can then configure rules to remove emails from mailboxes if they have certain properties or are particularly suspicious.

We have also connected XDR to our Azure platform, which is our user authentication platform. XDR can monitor for risky user sign-ins, such as sign-ins from unusual locations. If it detects any risk, it will notify us.

Finally, we have integrated XDR with a third-party tool to receive indicators of compromise. When we receive an IOC, Vision One will automatically run a check in our environment to see if any endpoints have been compromised. It will also check to see if any emails have been sent from any of the senders in the IOC listing. If it finds any matches, it will notify us.

We can also configure playbooks to automatically take action when XDR detects a threat. For example, we could configure a playbook to force a user to reset their password or isolate an endpoint from the network.

We are using the Trend Micro Vision One XDR agent. This agent component is installed on all of our endpoints, including servers, workstations, desktops, and any other computer elements. Vision One also has an API-based element, which we have connected to our email system, such as Azure.

How has it helped my organization?

Before Vision One, we had limited visibility into our security posture. Things were happening all around us, but we couldn't see them. With Vision One, we have centralized visibility and management across all of our protection layers, so we can see and respond to threats quickly and effectively.

I cannot imagine my day-to-day operations without the visibility that Vision One provides. It makes all the difference. No other platform compares to Vision One in terms of simplicity, ease of use, and importance.

Vision One has improved our efficiency with centralized visibility. Before Vision One, we had to go to different platforms and tools in our environment. Sometimes the information was missing and sometimes we were searching with the wrong terms. But because I can now see everything at once, it has helped. The decision we are making now is simply to go there, and whatever we have been faced with, the console is enough to make a decision.

We just signed a contract for Managed XDR services. We were managing our security before, but we'll start using their managed services next year. We've received a few escalations from them already, but that's because they're proactively searching for threats, which is a good thing. For example, I got an escalation from them last week for something that we wouldn't have discovered on our own. It wasn't something that the tool would have generated an alert for either, because it was very similar to what a user would normally do. But they were able to find it because they're looking into all of the addresses that they have. This led to us being able to control incidents that would have happened otherwise.

The XDR service has saved us time, enabling us to work on other tasks. The environment is quite complex, so before we had XDR, we didn't have any tool that considered all possibilities or provided any visibility into our environment. When we first started using the tool, it was new to us, but after a couple of years of using it, we've found that it is a legitimate tool that provides valuable information. Instead of seeing it as adding more work to our workload, we see it as helping us to be more proactive and prevent future incidents. For me, it has been a great help and has added real value to our work.

XDR helped us reduce our time to detect and respond to threats. With a single click, I can isolate a computer from the rest of the compliant environment. I had to do this last week when I had to support two escalated computers. Without XDR, there would be hundreds of things that we would not have seen or known about. But with XDR, we can see everything. And that even includes coverage of devices or computers that are not owned by us, such as those used by vendors. If a vendor brings a malicious device onto the property and downloads something malicious, we can detect it as early as possible.

Trend Micro XDR has helped us reduce the time we spend investigating false positive alerts. I am 100 percent confident that everything that comes out of the platform is legitimate. We had a few false positives when we first started using the solution, but because Trend Micro allows us to whitelist specific items, we were able to build our policy accordingly. Sometimes, there are malicious items that we need to allow because of our environment, such as certain security tools. Trend Micro allows us to build a policy that excludes these items from alerts, so we no longer receive alerts for them.

We use the XDR automation capabilities extensively, including playbook automation for tasks like isolating computers, and API-based automation for most other tasks. For example, we are a member of the retail ISAC information-sharing platform, and we have automated scripts from that platform that pull in all malicious senders, IPs, and domains, and pool them into XDR. XDR then automatically scans all computers to see if any of these malicious entities exist. If they do, XDR generates an alert and allows us to take action, such as removing the file. We generally set XDR to allow only, so that we have visibility into all malicious activity, even if we don't take action on it.

What needs improvement?

I would like to have the capability to export the information we receive from the XDR into Microsoft Excel.

For how long have I used the solution?

I have been using Trend Micro XDR for almost four years.

Buyer's Guide
TrendAI Vision One
August 2026
Learn what your peers think about TrendAI Vision One. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
913,924 professionals have used our research since 2012.

What do I think about the stability of the solution?

Trend Micro XDR is stable. We have not experienced any stability issues when using the console. 

What do I think about the scalability of the solution?

I do not have access to the backend, so I am not aware of the specific technical details. However, from an end-user perspective, the scalability of the system appears to be excellent.

How are customer service and support?

I reach out to technical support almost every week to address any questions I have. I also have a bi-weekly meeting with their technical team. They guide open tickets and address any concerns we may have. Additionally, we have a monthly meeting with Vision One developers where they discuss upcoming features and seek input. I know exactly who to contact for any assistance I may need. Sometimes, I can simply email them directly instead of opening a ticket. The process is always straightforward and efficient. At times, the prompt responses make me wonder if they are using AI assistance, but I hope that's acceptable. I usually receive a response within a minute or two, which suggests AI involvement. However, the signature at the end of the IT person's email confirms that an actual person is handling my request.

Which solution did I use previously and why did I switch?

We had Carbon Black, but we're using it only for application control. With Trend Micro XDR we can detect and respond.

How was the initial setup?

The initial deployment was straightforward. I have extensive experience in deployments across various companies and platforms. However, Trend Micro XDR surpassed all my expectations. We had previously deployed on-premises, and all we had to do was access the designated console and click a button to migrate all on-premises agents to cloud agents. It was incredibly easy. My team of two and I handled the entire process without any involvement from the teams and properties. I right-clicked and moved everything over. A few agents remained unmovable due to their outdated versions, but we successfully migrated close to 99 percent of all agents.

What about the implementation team?

The implementation was completed in-house. Trend Micro provided a document link to help with the deployment.

What's my experience with pricing, setup cost, and licensing?

Trend Micro XDR is reasonably priced for its value, comparable to other products like VMware Carbon Black.

Which other solutions did I evaluate?

We evaluated an additional option with Carbon Black because we already had that agent in our environment. We also considered Cisco, which has its own XDR platform.

What other advice do I have?

I would rate Trend Micro XDR ten out of ten.

We tried to use the risk index feature, but I didn't have the resources to focus on it at the time. I was more focused on the actual findings that were happening. I have since hired someone who will focus on the risk index, as the primary reason I hired them is to focus on the risk element coming from Vision One, as well as from other third-party intelligence platforms that we work with or have contracts with. Now that I have someone here, we will be focusing on the risk index.

No maintenance is required.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Product Owner at a tech consulting company with 11-50 employees
Real User
Top 20
Nov 24, 2024
It gives us a single, intuitive console for threat management
Pros and Cons
  • "The organizational view simplifies management and improves visibility, helping us identify areas for action."
  • "Vision One could improve its area networking and email security."

What is our primary use case?

I use Trend Vision One for banking, retail, and government clients. We sell it with other technologies. It provides more sources for alerts and visibility into threats and vulnerabilities. We have all Trend Micro's modules, including full asset protection, EPS, IDS, endpoint protection, and email security.

How has it helped my organization?

Vision One has reduced our detection time by approximately 30 percent, enabling us to use our human resources more effectively. The solution has allowed us to consolidate 90 percent of security tools across hybrid environments, improving our operational efficiency. We've reduced our administration and management tasks by half.  Vision One has also decreased our risk.

What is most valuable?

The most critical feature of Vision One is that it gives us a single console for threat management. The organizational view simplifies management and improves visibility, helping us identify areas for action. The solution is intuitive and easy to manage. 

The solution's ransomware protection with runtime machine-learning capabilities gives us peace of mind. We also get total protection and fewer false positives than in other solutions we sell. Vision One integrates well with our other security products.

What needs improvement?

Vision One could improve its area networking and email security.

For how long have I used the solution?

I have been using the solution for around three years.

What do I think about the stability of the solution?

Trend Vision One is stable.

How are customer service and support?


How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We have not previously used a tool like Trend Vision One, but we have used individual tools for various functions, such as EDR and EPS. For example, we used Vicarius and Ivanti for virtual patching and other tools by Palo Alto, CrowdStrike, Sophos, and Kaspersky. Trend Micro consolidates all these features into one platform, so that's one advantage it offers. 

How was the initial setup?

Setting up Vision One was straightforward. 

What other advice do I have?

I rate Trend Vision One nine out of 10. 

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Buyer's Guide
TrendAI Vision One
August 2026
Learn what your peers think about TrendAI Vision One. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
913,924 professionals have used our research since 2012.
Matthew Guzzi - PeerSpot reviewer
Information Systems Administrator at a government with 10,001+ employees
Real User
Nov 20, 2023
Provides great visibility, saves us time, and integrates well
Pros and Cons
  • "Drilling down further, we can analyze how our users are utilizing their workstations, including the websites they visit."
  • "While the continuous addition of features is commendable, the sheer volume of changes makes it difficult to stay abreast of the latest developments."

What is our primary use case?

We utilize Trend Vision One to identify and neutralize malicious activities on our network. This comprehensive security solution extends beyond traditional antivirus software, which relies on pattern matching, by actively monitoring endpoint behavior for anomalies and deviations from established norms.

In 2020, we transitioned to remote work like many other companies. During this transition, we conducted an internal Trend Micro office scan, which revealed that many of our users' devices were out of date due to their inability to connect to the VPN for extended periods. This prompted us to switch to Apex One later that year. As part of the Apex One implementation, we were given a complimentary trial of Vision One. During this trial, we received an alert that demonstrated the product's effectiveness, leading us to purchase a subscription. Vision One has been an excellent addition to our security arsenal. Trend Micro continuously adds new features and updates, making it an ever-evolving and valuable tool. The product's capabilities, functionality, and incident response capabilities have improved significantly over the past several years. We can set up playbooks to automate our response to specific incidents, which is a tremendous asset. Vision One is an outstanding security solution.

How has it helped my organization?

We are a state government agency that is subject to oversight by the state. Vision One has detected attempted attacks that the state SOC has missed, enabling us to swiftly halt these attacks and address the vulnerabilities before they escalate into more widespread problems.

The integrations have been great. There have been a couple of issues, but overall they've been very helpful. Vision One recently added the ability to connect to our on-premises AD. This was a sticking point for us for a year or so because we didn't have Azure. So we were stuck in a situation where we couldn't tie Vision One to our AD. But since they added the on-premises integration, it's been easy to set up.

Trend Vision One has saved us ten percent of our time. It has eliminated the need for us to rebuild machines. It has helped us even more than that because the few times we have had a threat, it has stopped it in its tracks. This has prevented the threat from spreading and compromising multiple machines. Without Trend Vision One, we would have had to investigate the threat, which would have taken time and resources. Additionally, we would have had to rebuild the compromised machines, which would have taken them offline and impacted our users. In some cases, a widespread outbreak could have occurred, causing even more disruption.

What is most valuable?

The dashboard provides great visibility into our risk profile. We receive a daily email report that outlines our risk score and identifies the machines with the highest risk. This information is based on usage patterns, vulnerabilities, and non-compliance issues. This helps us prioritize which machines require patching or further investigation.

Drilling down further, we can analyze how our users are utilizing their workstations, including the websites they visit. While we don't track specific website URLs, we can categorize website types and identify any potentially risky or inappropriate usage patterns. This allows us to proactively address any potential security concerns.

For instance, we identified a user who was using ChatGPT for work-related tasks. This flagged our system, and we were able to discuss the user's usage of ChatGPT to gain a better understanding of how our users are working and identify any areas that require additional attention.

What needs improvement?

Trend Vision One offers training sessions every few weeks or every month to showcase new features. However, the product's rapid development and the introduction of numerous new features make it challenging to keep track of the evolving interface and maintain a consistent understanding of its usability. While the continuous addition of features is commendable, the sheer volume of changes makes it difficult to stay abreast of the latest developments.

For how long have I used the solution?

I have been using Trend Vision One for two years.

What do I think about the stability of the solution?

Trend Vision One has proven to be extremely stable in our environment. We have deployed the Trend Micro client across all workstations. Additionally, we utilize a tool for vulnerability scanning, one for application whitelisting, and FireEye, as mandated by state regulations. These security solutions coexist harmoniously, causing no compatibility issues. We have also implemented laptop encryption and other security measures to further enhance protection. Throughout our experience, Trend Micro has not caused any conflicts with Microsoft or our other security tools.

What do I think about the scalability of the solution?

Trend Vision One is scalable. We can add another 150 machines with no problems.

How are customer service and support?

The technical support is excellent. We experienced what we initially thought was a technical issue, but it turned out to be a state update that triggered alerts across all of our machines. I contacted the support team and our sales representative. Within an hour, the incident response team was on the phone with me, examining the file hashes of the updated DLL to determine the cause of the issue. They quickly identified that the update was not malicious. Their promptness and thoroughness were outstanding. The incident was resolved within three hours of receiving the alerts.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We lacked an XDR tool. Instead, we relied on FireEye, which offers similar capabilities, but it doesn't provide us with the same level of visibility as Vision One. Vision One has consistently detected threats that FireEye missed. While we were mandated to use FireEye by state regulations, we sought a more robust solution that could effectively identify anomalies and patterns. Vision One's utilization of the MITRE ATT&CK framework has been particularly advantageous. We've found great value in Vision One's comprehensive feature set, particularly its well-designed playbooks.

How was the initial setup?

The initial deployment was straightforward. I was able to deploy Trend Vision One with the vendor's assistance within one week.

What about the implementation team?

The vendor guided us through the implementation process and continues to conduct periodic check-ins to verify that everything continues to function effectively in accordance with industry best practices.

What was our ROI?

Our return on investment does not stem from direct cost savings but from the fact that Vision One has mitigated issues before they escalated into larger problems. This has saved us time, which is a valuable asset.

What's my experience with pricing, setup cost, and licensing?

The pricing for Trend Vision One is reasonable. I am not sure of the exact amount we pay, but it is not excessively expensive.

What other advice do I have?

I would give Trend Vision One a perfect score of ten out of ten. It is undoubtedly the best product in the market today. While I appreciate CrowdStrike and its offerings, I believe Trend Vision One stands out as the leader. In my opinion, these two products are the clear frontrunners in the XDR space at this moment.

Trend Vision One is deployed at a single location. We have approximately 50 endpoints. Most of our devices are laptops because we have a large number of employees who travel frequently.

Trend Vision One is maintenance-free, which is convenient because patching is handled seamlessly from the backend in the cloud. Trend Micro proactively notifies users about upcoming patching schedules and provides detailed information about the patches, new features, and updates. The patching process is managed entirely by Trend Micro, eliminating the need for user intervention. A client installed on the machines receives updates from the cloud server, ensuring that all devices remain protected and up-to-date without any manual effort.

I highly recommend Trend Vision One. Contact Trend Micro and they'll be happy to schedule a demo. I suggest installing the demo, testing it out, and seeing if it's a good fit for the organization's needs before purchasing. Trend Vision One is worthwhile.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Meako-Anna Marlow - PeerSpot reviewer
Security Operations Analyst at Compugen
MSP
Jul 28, 2024
Offers centralized oversight, improved efficiency, and is user-friendly
Pros and Cons
  • "It is so helpful to have something that pulls all the data into one visual representation of the events."
  • "Vision One generates numerous false positives, forcing unnecessary investigations and highlighting a need for improved filtering options."

What is our primary use case?

Trend Vision One functions as our XDR solution. I spend considerable time within it conducting reconnaissance on any security incidents requiring investigation. This tool allows me to quickly search for information that might be difficult to locate using our other tools.

We implemented Trend Vision One to improve our security posture by creating multiple layers of protection. This tool addresses security gaps our existing solutions, like Defender, may miss, providing deeper insights into potential threats.

How has it helped my organization?

We have implemented the product on both our cloud environment and endpoints. While we utilize a different Trend product for email, we also leverage Trend for this purpose. Trend's complete coverage is invaluable, as it centralizes data that would otherwise be difficult to locate, and its robust search function has been instrumental in our decision to continue using the platform. Although our organization is always exploring alternatives, the all-in-one nature of this solution has proven highly effective for our needs.

Vision One offers centralized oversight and control across our protective layers. It provides valuable insights into our various Trend applications, though its visibility into other layers is understandably limited. This limitation isn't a concern at this time.

Vision One has significantly improved our efficiency. For example, we recently faced a critical situation where a rule change on a client-server posed a potential security breach. Using Vision One, we quickly identified the employee responsible for the shift and resolved the incident without an extensive investigation. This would have been highly challenging without the tool, as determining the culprit would have been much more difficult.

We've been using the risk index feature to try to chip away at the risks within the environment and identify the vulnerabilities that need to be prioritized because that's been one area that has been more invisible to us with the other tools.

Vision One offers a valuable new perspective on our risk profile. While we receive reports from other tools like Nexus IQ, Vision One's unique risk classification and ranking system allows us to prioritize issues differently. This enables more informed decision-making as we can identify risks that other tools might underestimate. We've fully leveraged Vision One's benefits since our team's formation over two years ago. Though the tool existed previously, its impact was limited due to the absence of a dedicated team focused on its utilization.

It's able to detect things that other tools don't detect. We use a layered approach, so those tools have found stuff it hasn't detected. But that's to be expected. That's the goal of using the layered approach to it. But it's helpful because it catches things we might have been unaware of. Additionally, it might rank things differently than the other tools, and that's the same for this piece. And that can be very helpful for us to catch things we might have otherwise missed because it gives us that extra detail.

Trend Micro XDR has significantly reduced the time needed to detect and respond to threats. It offers capabilities that other security solutions lack, enabling us to address challenges innovatively. Additionally, built-in features such as insights and endpoint protection provide valuable tools that enhance our security posture compared to other systems.

Despite having a fifteen-year career in cybersecurity, I joined this role with limited hands-on experience. However, I quickly became proficient with Trend Vision One through self-directed learning, and my team soon recognized my expertise in the tool, making it a positive experience overall.

What is most valuable?

The Workbench feature is fantastic. It is so helpful to have something that pulls all the data into one visual representation of the events.

What needs improvement?

Vision One generates numerous false positives, forcing unnecessary investigations and highlighting a need for improved filtering options. A recurring false positive in our environment cannot be safely filtered, preventing us from ignoring it without risking overlooking genuine threats. This issue arises from a script that renames computers, which behaves suspiciously like malware but lacks a unique identifier within Trend for precise filtering. We cannot exclude the entire script due to potential exploitation by attackers who could embed malicious code within it, bypassing our security measures. While this scenario requires a targeted attack, the sensitive nature of our client's data, including threats from nation-state actors, necessitates a cautious approach to avoid compromising our security posture.

We want the ability to download and inspect emails from clients' mailboxes. Microsoft's platform supports this functionality, and we possess the necessary license. However, some clients lack the required license, prompting us to recommend Trend. If we could directly access and inspect client emails, it would eliminate the need to sell additional licenses to those clients, streamlining the process.

For how long have I used the solution?

I have been using Trend Vision One for over two years.

What do I think about the stability of the solution?

Trend Vision One is stable.

What do I think about the scalability of the solution?

As we've added employees and removed employees and added servers and removed servers, I haven't had to think about the scalability of Vision One. It has been very smooth.

How are customer service and support?

We had a script that was not right and kept triggering false positives. I had reached out for help with that. The help I got took a lot of time to get responses. And in the end, they closed out the ticket I had opened without resolving it. I also found the communication experience to be rather frustrating. My biggest complaint about my experience with Trend has been the support. There's a lot of good to be said, but there's room for improvement in the support. The people were very polite, so I'm not giving them a five because that goes a long way for me. Having support that is snippy makes the experience significantly worse. So, I am grateful for that part.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

We used a Microsoft XDR in conjunction with Trend Vision One. The main pros for Vision One are that the interface is typically a lot easier and a lot less confusing. 

The overall experience of the interface is a lot more positive. The details I can pull out of Trend are much better than I can typically pull out from Microsoft. I'm able to get results that Microsoft doesn't seem to gather. The cons are that it's in such flux right now because they're moving all their other products into the Vision One console, which can sometimes make it a bit confusing. 

It can also mean that we're unable to access the tools we previously did as rapidly. For example, many of the Apex One stuff is now within Vision One. So we had to relearn how to do that, which cost us time during security incidents. And Microsoft does change things, but they typically change things by adding extra bloat. So that ends up being a con for Trend compared to Microsoft.

What was our ROI?

While I cannot confirm the specific return on investment for Vision One without firsthand data, I expect it to be positive, given our organization's tendency to quickly discontinue partnerships that fail to deliver value.

What other advice do I have?

I would rate Trend Vision One eight out of ten. There is room for improvement, but with the tools I've used, Vision One is one of the better.

I don't do much regarding the maintenance of Trend Vision One, but I also know that because I get emails about stuff that goes down, it's relatively low maintenance compared to other tools.

We have Trend Vision One deployed across multiple locations internationally. Because the number fluctuates, we have roughly 1,500 to 2,000 users at any given time. Three people on our network team use Vision One. We have also used Trend products, other than Vision One, for a couple of our clients, which would expand those numbers significantly.

My experience with Trend Vision One has taught me many valuable details, and I strongly recommend that new users carefully review the provided documentation.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Julio Velasco - PeerSpot reviewer
Information Security Coordinator at a maritime company with 10,001+ employees
Real User
Feb 7, 2024
Its real-time analysis has impacted our security incident response time
Pros and Cons
  • "I can prevent my environment from different types of attacks based on what I see in the Vision One console."
  • "It is very expensive."

How has it helped my organization?

Its real-time analysis has impacted our security incident response time. We use the Workbench console and dashboards. We are normally able to analyze an incident in a few hours, understand what is going on, and provide a specific solution for any type of incident.

A few days ago, a user opened something with malware on their machine. In a few seconds, I received an email, and I received a pop-up in the console. To mitigate this, we removed the machine from the network and checked it.

In terms of integration, we intend to integrate more solutions with Trend Micro, but so far, we have just integrated the firewall.

What is most valuable?

Telemetry is very useful. They provide all the information. I can see specific details about any malware and various types of attacks. I can prevent my environment from different types of attacks based on what I see in the Vision One console.

Log inspection is also very useful for me. We check the logs all the time. In certain cases, it is necessary to analyze with more detail. It is very useful to understand what is going on in my environment with log inspection.

What needs improvement?

It is very expensive. 

For how long have I used the solution?

I have been using this solution for ten years.

What do I think about the stability of the solution?

We do not have any problems with the stability of this solution.

What do I think about the scalability of the solution?

It scales well. We do not have any problems with scalability.

At the moment, we do not have any plans to increase its usage.

How are customer service and support?

Their technical support is good. They take some time to give me the answers, but in the end, they fix and solve all my problems. I would rate their support a nine out of ten.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We were not using any other solution previously. We have been using Trend Micro's solutions from the beginning of our operations in Brazil.

How was the initial setup?

It is a SaaS solution. Its initial setup is not complex. It is very easy to deploy. It is not complicated. It is very user-friendly. It took around 15 days.

In terms of implementation strategy, we prepared some test machines and servers. After that, we deployed it for the entire company.

They do the maintenance, but we do not have any downtime in this maintenance mode.

What about the implementation team?

We had a Brazilian reseller.

What was our ROI?

We have not seen an ROI.

What's my experience with pricing, setup cost, and licensing?

Trend Micro's cost is higher than other solutions. That is the main reason why we need to switch to another solution.

We are using a full license that provides different types of features, but CrowdStrike does not provide some of the features such as MDM or anti-spam. We do not have these options or features with CrowdStrike. If we switch to CrowdStrike, we would have to buy other solutions to have a complete solution.

In addition to the license, there are no extra costs.

Which other solutions did I evaluate?

Its cost is high for us, so we are checking other options and other companies to provide the same solution. We are evaluating CrowdStrike, Trellix, McAfee, and Sophos. We have not yet received the quotation, but their cost is lower than Trend Micro.

What other advice do I have?

Trend Vision One is very useful. It has many functionalities and integrations. Its integration with other products is growing. In the future, it will probably be the biggest console in the world.

Trend Micro is making some changes to the console. At the moment, it is a little bit confusing for our use case because we are using three or four consoles from Trend Micro. We intend to migrate to just one, which is the Vision One console, but at the moment, we are using the Apex One console for the workstations and the Cloud One console for the servers. I do not know if the integration is complicated for Trend Micro, but at this moment, it is not so easy for me to manage all devices.

I would rate Trend Vision One an eight out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1656681 - PeerSpot reviewer
Chief Technology Officer at a healthcare company with 10,001+ employees
Real User
Jan 8, 2024
Provides centralized visibility, eliminates blind spots, and saves us a significant amount of time
Pros and Cons
  • "The automatic EDR system that notifies us when something is wrong is valuable."
  • "The information captured by Trend Vision One needs to be more detailed."

What is our primary use case?

We use Trend Vision One for our endpoint detection and antivirus solution.

The endpoint agents are deployed locally on our computers and the centralized controller is in the cloud.

How has it helped my organization?

Trend Vision One's centralized view boosts our visibility into harmful malware, viruses, and ransomware. Before Trend Vision One it was impossible to protect against attacks but the centralized management now makes it easy for us to focus on one platform.

The centralized visibility and management across protection layers have improved our efficiency. Now we have multiple tools to monitor our computers across our enterprise.

The executive dashboard is important because it allows us to dive into advanced functions.

I use the risk index feature daily and report the information weekly. This helps us address the risk factors.

Ransomware and intrusion attacks are common these days and Trend Vision One has helped us protect our devices and prevent these types of attacks.

The attack surface risk management eliminates blind spots.

Trend Micro XDR helps decrease our time to detect and respond because everything is available in one dashboard eliminating the need to use multiple dashboards and look at multiple locations.

Trend Vision One has saved us 80 percent of our time by constantly monitoring our environment and reducing our investigation time.

What is most valuable?

The automatic EDR system that notifies us when something is wrong is valuable.

What needs improvement?

The information captured by Trend Vision One needs to be more detailed.

For how long have I used the solution?

I have been using Trend Vision One for two years.

What do I think about the stability of the solution?

Trend Vision One is stable and I would rate it ten out of ten.

What do I think about the scalability of the solution?

Trend Vision One is scalable.

How are customer service and support?

The technical support is good but 20 percent of the time the response is slow or they assume our issue is solved so they stop communicating with me.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial deployment is straightforward. We run the program and it deploys automatically.

What about the implementation team?

We used a reseller for the implementation.

What was our ROI?

We have seen a return on investment.

What's my experience with pricing, setup cost, and licensing?

The price for Trend Vision One is reasonable compared to Microsoft and Symantec.

What other advice do I have?

I would rate Trend Vision One a nine out of ten.

We have Trend Vision One deployed across 250 endpoints.

Minimal maintenance is required.

I recommend Trend Vision One because it is easy to deploy and includes rich content. 

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer2295564 - PeerSpot reviewer
Security Consultant at a tech services company with 10,001+ employees
Real User
Oct 24, 2023
Has a good workbench feature and observed attack technique
Pros and Cons
  • "I like XDR's workbench feature and observed attack technique. It generates an alert once certain conditions are met. For example, let's say there's a threat called malicious.exe being deployed on your system. It will generate an alert with information like the file path, location, hash, etc. You also see a relational matrix showing how that file was executed and which processes were installed."
  • "Also, XDR should improve its coverage of the latest IOCs. Their suspicious object management works, but the coverage should be improved. It will take one or two months to get those things covered. XDR will detect on a behavioral basis, but these databases will not get updated daily like some other solutions. If you're dealing with new ransomware or malware, it may take around a month before it's covered by Trend Micro."

What is our primary use case?

We had a SIEM in place, but we wanted to do some behavioral analysis of the files that are getting deployed. We wanted to check to ensure that it was nothing with the external registration side. We needed an EDR solution for checking and monitoring everything deployed on this target machine or our host machine site. It will check and detect if any malicious files are there or not. We are getting alerts related to that kind of thing. So we used to check those alerts on the XDR, and we used to, like, do the incident and response to that kind of thing there.

How has it helped my organization?

If you have a SIEM in place, you will only get the network logs. XDR gives you more control over what files are getting deployed, how they are being executed, and how they can potentially harm your system. XDR doesn't work like a normal antivirus solution, which uses signatures to detect and block threats. XDR detects based on behavioral analysis and blocks most things.

It reduces the investigation time because it gives you everything, including how the file was executed, which processes it called, the file name, the stemming, and the time. When we have the endpoint name, we can reach out directly to the endpoint owners and communicate with them regarding those alerts.

What is most valuable?

I like XDR's workbench feature and observed attack technique. It generates an alert once certain conditions are met. For example, let's say there's a threat called malicious.exe being deployed on your system. It will generate an alert with information like the file path, location, hash, etc. You also see a relational matrix showing how that file was executed and which processes were installed.

It's a SaaS solution that covers endpoints, email, and cloud. We have agents installed wherever data is being pushed, so it used to give us a payload. Cloud functionality is one of the most critical things because we don't generally have visibility for cloud applications. Once we install the agents, we gain visibility into all the things integrated on the cloud or any SSH attempts.

XDR offers visibility across layers. This is critical when you want to implement some policies and apply exclusions for particular parts of the system that should not get scanned. It's easy to implement those things. Let's say you want to deploy policies for multiple systems. Using Apex Central, you can directly push the policy to various systems and cover the logs of several systems at a time. 

What needs improvement?

Sometimes, there are some false positives. For example, once a user had a file in their system named recovery.txt. The solution was flagging that as a ransom note, so we were confused. It isn't that serious, but it should be improved. 

Also, XDR should improve its coverage of the latest IOCs. Their suspicious object management works, but the coverage should be improved. It will take one or two months to get those things covered. XDR will detect on a behavioral basis, but these databases will not get updated daily like some other solutions. If you're dealing with new ransomware or malware, it may take around a month before it's covered by Trend Micro. 

For how long have I used the solution?

I have used XDR for two years.

What do I think about the stability of the solution?

Trend Micro XDR is stable. We've never had downtime. 

What do I think about the scalability of the solution?

Trend Micro XDR is scalable if you can pay more for licenses. 

How are customer service and support?

I rate Trend Micro support seven out of 10. Their technical support is good. They reply regarding your cases. However, if you don't reply to them properly, they may close your case if you are not reviewing that kind of thing. 

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

 I previously used Crowdstrike, which is an MDR, so it was totally managed by the Crowdstrike team. They were monitoring every alert that was generated, so it's hard to compare it to Trend Micro XDR. It was somewhat similar, but CrowdStrike is more proactive than Trend Micro, and it has greater coverage of IOCs. I have also used SentinelOne.

How was the initial setup?

It's a SaaS solution deployed across multiple locations covering 20,000 endpoints. It doesn't require any maintenance aside from updates. 

What other advice do I have?

I rate Trend Micro XDR seven out of 10. If you plan to implement XDR you should be aware of the IOC coverage and follow up with the Trend Micro team. Most things are covered, but it takes time to add and deploy all that stuff. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
IT Architect at a outsourcing company with 11-50 employees
Real User
Oct 15, 2023
Great network protection, a centralized view, and user-friendly
Pros and Cons
  • "The most valuable feature is the network protection shield on every server, which isolates attacks and prevents our clients from being affected."
  • "The deployment process could be more streamlined over the existing infrastructure, as it was not as easy as we thought."

What is our primary use case?

We use Trend Micro XDR to enhance our security framework.

One of our partners was the victim of a major attack, and we realized that our environment was susceptible to the same thing because we were only using an antivirus solution. 

Trend Micro XDR is deployed on-premises, and we use it on our core business servers, clients, and the management portal to protect all of our network nodes from attacks.

How has it helped my organization?

Trend Micro Vision One provides centralized visibility and management across protection layers, which is important. It is part of our monitoring tool. The visibility gives us a centralized view of our network nodes, activities, and possible attacks.

The risk index feature plays an important role in our KPIs, which we report to the management team. Our business is dependent on our systems running 24/7.

Trend Micro XDR has helped decrease our time to detect and respond to threats.

Trend Micro XDR has reduced the time we spend investigating false positive alerts by 50 percent.

What is most valuable?

The most valuable feature is the network protection shield on every server, which isolates attacks and prevents our clients from being affected.

What needs improvement?

The deployment process could be more streamlined over the existing infrastructure, as it was not as easy as we thought. We are working with an expert from Trend Micro to improve the rollout process, but it has taken some time and we do not yet have a concrete understanding of the issue. There are some features that we have to install repeatedly before they start running.

For how long have I used the solution?

I have been using Trend Micro XDR for one year.

What do I think about the stability of the solution?

Trend Micro XDR is stable.

What do I think about the scalability of the solution?

Trend Micro XDR is scalable.

How are customer service and support?

The technical support is good.

How would you rate customer service and support?

Positive

How was the initial setup?

The deployment took six to eight weeks to complete. We had around five part-time people involved in the deployment.

What's my experience with pricing, setup cost, and licensing?

Trend Micro XDR is expensive but we got a good deal from Trend Micro. We pay for an annual license.

Which other solutions did I evaluate?

Currently, we are researching the question of whether to use Trend Micro XDR when we switch from our classic NPLS internal corporate lines to an SD-WAN solution. Or if we should use an integrated solution from the SD-WAN and firewall provider, such as Palo Alto or Fortinet.

What other advice do I have?

I would rate Trend Micro XDR eight out of ten.

We have 300 people in our organization that use the solution.

Maintenance is easy and done by two people, who update, patch, and install new servers; client-side, they also update user stations and analyze logs.

I recommend Trend Micro XDR. It is user-friendly.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
PeerSpot user
IT Securiy Administrator at a transportation company with 1,001-5,000 employees
Real User
Top 20
Aug 21, 2024
Easy to set up with good support and great threat intelligence
Pros and Cons
  • "The most valuable feature is how the stack fully integrates all components of a solution."
  • "The SOAR features (Security Playbooks) are quite limited."

What is our primary use case?

We use Vision One to detect to detect and respond to malware incidents. With endpoints (Apex One/Cloud One Workload Security), network (Deep Discovery Inspector) and Office365 (Cloud Email and Collaboration Security).

The environment is complex, distributed in more than +100 locations. Some locations are just offices, some others are industrial facilities with ICS and SCADA. Besides Windows, we deal with a lot of operating systems, including Solaris on SPARC. And our users are diverse, with lots of employees roaming around the country.

With CREM, we tackle important use cases around identity protection and risk management in general. Identification, prioritization, and remediation.

How has it helped my organization?

The full stack of Vision One has delivered what "SIEM 2.0" couldn't deliver. The capability to monitor threats and discover attack vectors before they are exploited and across all our workspace (on-prem, IaaS, PaaS and SaaS). We have invested well over a million into SIEM during the last decade. A full ArcSight upgrade and then a Splunk migration assisted with a large MSSP. Vision One is still ahead at a fraction of the cost.

Going through a capable, single-vendor solution was necessary, given our small team. Choosing the best solutions for every task and building all the integrations was not an option.

Vision One is much more than just EDR for us; it is a threat intelligence platform and a SOAR too. And even with the limited capabilities in this area, we find ways to tackle challenges our MSSP and SOC haven't been able to accomplish on a very large budget.

What is most valuable?

I like everything. The most valuable feature is how the stack fully integrates all components of a solution. Then, integrations with third parties will be provided.

As an example, I am capable of sending a suspicious file directly to my Deep Discovery Analyzer appliance (a sandbox) while investigating a suspicious download/file interaction, and I can then quickly push the IOCs in the suspicious object lists to protect both managed endpoints, and the rest of the network too! Yes, you can push domains and IP addresses to Palo Alto through a Trend Micro Service Gateway, ensuring you can protect even what cannot receive an endpoint. And all this without writing a single line of code. The ease of use and ease of deployment for use cases like this are my favourite features.

What needs improvement?

The SOAR features (Security Playbooks) are quite limited. At the moment, it is impossible to execute a simple piece of Python code that would pull or push something to an API, for example. While you can tackle some use cases, a SOAR from another vendor is still a must-have.

To assist with complex use case integrations, having all the data from the SIEM inside XDR would be great, too. That's where the market is moving with solutions like Falcon Logscale and Cortex XSIAM. Pivoting from XDR to Splunk or vice-versa can be time-consuming during incidents.

For how long have I used the solution?

I was actually an early beta tester of the Apex One Endpoint Sensor before Vision One appeared in 2021. That would be three solid years of using it.

What do I think about the stability of the solution?

Quite reliable. In the last three years, only one incident created memory leaks on Windows Servers. We didn't see too much impact (fortunately) as a workaround could be quickly provided.

Support is quite responsive when something does work well. However, we do pay for Premium support.

What do I think about the scalability of the solution?

The scalability is really good.

How are customer service and support?

My experience is generally good, but I have had the chance to deal with premium support. I'd say I get the support I expect for the price that I pay.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Although we have been dealing with other security vendors (McAfee, Symantec, Proofpoint, and more), Vision One was really our first EDR.

How was the initial setup?

The initial setup was a breeze. It is realistically one of the strong points of the solution.

What about the implementation team?

We implemented the solution in-house. Although with premium support, you do get a lot of help from Trend Micro if you ask for it. You'll be able to talk to actual experts.

What was our ROI?

It is very hard to quantify an ROI on a security product. It doesn't generate revenues, and you can't quantify the cost of incidents that didn't happen.

What's my experience with pricing, setup cost, and licensing?

Product names are changing all the time. Lots of changes in the last three years. They introduced the concept of credits, too, which did not make anything easier.

It's also easy to underestimate the credits required with Cloud Email and Collaboration Security: people invited from third-party tenants will count.

The credit usage and allocation tool has been improving, at least.

Which other solutions did I evaluate?

We had a look at Carbon Black and CrowdStrike Falcon.

What other advice do I have?

It's probably the best solution for a small team that cannot absorb the complexity of a multivendor solution. The ability to execute VS the cost is surprisingly good.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Information Technology Security Manager at Mewah International Inc
Real User
Jul 14, 2024
What would previously take us two to three hours to fix, we can do in one hour or even half an hour
Pros and Cons
  • "The user interface is very good."
  • "We'd like to see more use of AI around analytics and controls."

What is our primary use case?

I primarily use the solution to prevent attacks. 

How has it helped my organization?

It's good for detecting malware and anomalies. We use it on our endpoints. 

What is most valuable?

The user interface is very good. Everything is all on one single platform.

With this product, we get centralized visibility and management across all of our protection layers. With a central platform, we don't have to look around across different websites or platforms. We can go right on the portal and manage things. It also helps us reduce the learning curve. We can manage and monitor products from the same place instead of learning different platforms. It's also helped us increase efficiency.

We have made use of the executive dashboard. It greatly increased visibility. We get a risk management view and metrics that help us narrow down and find issues. It helps us reduce risks. The risk index feature gives us a score to help us in our security goals. With it, we know what's the baseline or standard, so now we know what we need to do in order to meet the standards out there in the industry. We can see everything we need to in one glance. 

It's kept up to date and is consistently improving. This helps us protect our environment. 

The patch management has been very useful. They help recommend what needs to be installed.

We leverage the attack surface risk management capabilities. It shows the entire incident, including how it happened. We can use the information when we're doing forensics.

We've been able to reduce our mean time to detect and mean time to respond. What would previously take us two to three hours to fix, we can do in one hour or even half an hour. We've also been able to reduce the amount of time we spend investigating false positives. 

What needs improvement?

We'd like to see more use of AI around analytics and controls. 

For how long have I used the solution?

I've been using the solution for five years. 

What do I think about the stability of the solution?

The stability is good; I'd rate it eight out of ten.

What do I think about the scalability of the solution?

We're a small-to-medium-sized company. We have it deployed to less than 5,000 users. 

I'm not sure of the scalability. It works for us and our company size.

How are customer service and support?

Support is okay. They could be more responsive and could provide more communication channels. 

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We did not previously use a different solution. 

How was the initial setup?

I'm more of an end-user. I do not handle the installation aspect. The deployment was done a long time ago. 

The tool does not require much maintenance. 

What's my experience with pricing, setup cost, and licensing?

I'm not familiar with the exact pricing of the solution. My understanding is the licensing is reasonable. 

What other advice do I have?

I'm an end-user and customer. 

I'd rate the solution eight out of ten. It has very good management and monitoring benefits. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free TrendAI Vision One Report and get advice and tips from experienced pros sharing their opinions.
Updated: August 2026
Buyer's Guide
Download our free TrendAI Vision One Report and get advice and tips from experienced pros sharing their opinions.