We use this solution for the malware features, to protect our network and our endpoint users. We deployed this solution for security.
Network security engineer at a tech services company with 1,001-5,000 employees
Secure, feature-rich reliable protection, and offers the best technical support
Pros and Cons
- "The most valuable feature is signature-based malware detection."
- "The GUI needs improvement, it's not good."
What is our primary use case?
What is most valuable?
The most valuable feature is signature-based malware detection. They are updating the signatures for malware from time to time.
With every protection malware, there are issues, because it takes time to detect the malware, but Cisco is very fast in detection compared to other products.
The security is awesome and they have very good features.
What needs improvement?
The GUI needs improvement, it's not good.
There are false positives in emails. At times, the emails are blocked and detected as malware when they are not.
They should work on some of the signatures because of the emails that have been blocked and detected as malware that can never be opened.
For how long have I used the solution?
I have been using Cisco AMP for Endpoints within the last year.
Buyer's Guide
Cisco Secure Endpoint
June 2025

Learn what your peers think about Cisco Secure Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
856,873 professionals have used our research since 2012.
What do I think about the stability of the solution?
Cisco AMP for Endpoints is very reliable.
What do I think about the scalability of the solution?
I am not familiar with scalability. I have never tried to scale it.
We have more than 400 users in our organization.
We have plans to increase our usage.
How are customer service and support?
Cisco has the best technical support and marketing.
How was the initial setup?
The initial setup was very complex.
It will take a month to complete the deployment if you want to complete the parameters.
What's my experience with pricing, setup cost, and licensing?
Licensing fees are on a yearly basis and I am happy with the pricing.
What other advice do I have?
If you are looking for deep security and malware for your endpoint users and network then I would recommend Cisco AMP.
I would rate Cisco AMP for Endpoints a ten out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Service Security Lead at Salam Technology
Good sandboxing features but the technical support could be better
Pros and Cons
- "It is a very stable program."
- "The technical support is very slow."
What is our primary use case?
We mainly use this program for our business operations.
What is most valuable?
The feature I find most valuable is the sandboxing.
What needs improvement?
I think there should be better support and I would also like to see an easier implementation of the solution. The support should be cheaper and more available during the implementation stage. It would be great if they could have support teams that involve an AMP team because there's a specific team for AMP.
For how long have I used the solution?
I have been using Cisco AMP for Endpoints for around three years now.
What do I think about the stability of the solution?
Cisco AMP for Endpoints has been very stable so far.
What do I think about the scalability of the solution?
I believe the solution is scalable. We have around 200 end users working on this program, and then we have a team of 15 that is responsible for technical and maintenance issues.
How are customer service and technical support?
I will rate the technical support a six out of ten because their response time was very slow. Not as fast as they used to be.
Which solution did I use previously and why did I switch?
We also use Micro, so we use two programs simultaneously.
How was the initial setup?
I did the initial setup myself and it was really easy and straightforward.
What other advice do I have?
I will recommend this solution to others. I would, however, like to see better features and implementation to cover some points. It would be nice if they could add more protocols to support encrypted files, and be able to inspect an encrypted file, or at least be able to support that. Better and faster technical support is also necessary.
On a scale from one to 10, I rate this solution a seven.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: partner
Buyer's Guide
Cisco Secure Endpoint
June 2025

Learn what your peers think about Cisco Secure Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
856,873 professionals have used our research since 2012.
Deputy General Manager (GM) at Oregon Systems
A solution that's easy to implement, is highly scalable and is extremely user-friendly
Pros and Cons
- "The stability of the solution is perfect. I believe it's the most stable solution on the market right now."
- "The reporting and analytics areas of the solution need to be improved."
What is our primary use case?
We're in the banking sector. We use AMP to protect security endpoints.
What is most valuable?
The ease of implementation is a very valuable aspect of the solution. It's also very user-friendly.
What needs improvement?
The reporting and analytics areas of the solution need to be improved.
For how long have I used the solution?
I've been using the solution for four years.
What do I think about the stability of the solution?
The stability of the solution is perfect. I believe it's the most stable solution on the market right now.
What do I think about the scalability of the solution?
The solution is highly scalable. It's the best part of the solution because we have done the sizing. We have focused on the sizing, which was highly scalable. And it's very clean, clear and very transparent in this area.
How are customer service and technical support?
We're very satisfied with technical support. It's one of the best.
How was the initial setup?
The initial setup was straightforward. We're well-versed in the solution, so for us, it was easy.
What about the implementation team?
We handle the implementation ourselves.
What other advice do I have?
We use the hybrid deployment model.
I would advise other potential users that if they are looking for a long term security solution, this particular solution is going to add value to their cybersecurity strategy. Cisco AMP is one of the solutions that adds value to your cybersecurity roadmap. It should not be considered as a solution, but rather as a strategy.
I would rate the solution nine out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
CISO & COO at a tech services company with 1-10 employees
Improves our security using network segmentation, IPS, and integration with ISE
Pros and Cons
- "The most valuable features of this solution are the IPS and the integration with ISE."
- "In the next version of this solution, I would like to see the addition of local authentication."
What is our primary use case?
We use this solution as part of our organization security.
How has it helped my organization?
This solution has allowed us to segment the organization to provide better security.
What is most valuable?
The most valuable features of this solution are the IPS and the integration with ISE.
What needs improvement?
In the next version of this solution, I would like to see the addition of local authentication.
How are customer service and technical support?
Technical support for this solution is good.
What about the implementation team?
We did the integration ourselves.
What was our ROI?
We have seen ROI with this solution.
What's my experience with pricing, setup cost, and licensing?
The licensing fees for this solution are paid on a yearly basis.
Which other solutions did I evaluate?
We chose this product based on research and for its integration with other Cisco security products.
What other advice do I have?
This is a good product but there are always going to be some issues.
I would rate this solution an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Deputy General Manager (GM) at Oregon Systems
Cloud-based, highly scalable and highly integrated
Pros and Cons
- "For the initial first level of support, we provide it from our side. If there's escalation required, we use Cisco tech for the AMP. And again, they are perfect. I mean, one of the best, compared to any other vendors."
- "The solution needs more in-depth analytics."
What is most valuable?
The most important thing is that they're cloud-based. And Cisco has introduced Cisco Umbrella, which includes AMP, Open DNS, and they integrated certain solutions, and AMP is part of their portfolio. That's why it's adding value.
What needs improvement?
When we're talking about anti-malware protection, AMP is a very good solution, but again, the CSO level reports are not generated. There is a dashboard, there is a report, but again, those reports have to be taken to the CSO, because when it comes to security, we always want to have high-level reports. So if we had a system that generated reports from the AMP itself, that would be great for us.
Also, the solution needs more in-depth analytics. Right now they have implemented AMP, so, monitoring is happening, but you need to see what exactly is happening, the updates and then the mode of attacks that have happened and have been prevented. An in-depth report could be generated, and it should be on a CSO level. That's the value should be added to AMP solution.
For how long have I used the solution?
I've been using the solution for 4 years.
What do I think about the stability of the solution?
The solution's stability is perfect. It's the best. All the customers we have sold it to have been super happy. We mostly work with SMEs, small and medium-sized enterprises.
What do I think about the scalability of the solution?
It is scalable. Since it is part of the umbrella family, it is highly scalable, and highly integrated as well.
How are customer service and technical support?
For the initial first level of support, we provide it from our side. If there's escalation required, we use Cisco tech for the AMP. And again, they are perfect. I mean, one of the best, compared to any other vendors.
How was the initial setup?
The initial setup was straightforward and user-friendly.
What's my experience with pricing, setup cost, and licensing?
If you talk about the commercial aspect, this solution is not the Gartner one. We have a challenge because there are other solutions which are Gartner solutions, where we have competition. So we have to justify, explain, show the value propositions and then we sell are able to sell.
What other advice do I have?
I would say that if you have a vision or plan for security, and want to have an integrated solution, AMP can be a very integral part of this digitization roadmap. AMP should be considered if you have digitization or a digitalization plan, which most if not all organizations are going for. So I think AMP is good for that, from the security standpoint.
I would give this solution an 8 out of 10. It has all the solutions.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner.
Chief Information Officer at Sacramento County
The sheer volume of the number of emails that it blocks has increased staff productivity
Pros and Cons
- "I am told that we get over 100 million emails a month. This filters them down and allows only somewhere about three million emails, which is a great help."
- "I would like them to add whatever makes filtering more advanced in scanning and blocking for malware in emails."
What is our primary use case?
The primary use case is email filtering.
We are using the latest version.
How has it helped my organization?
I am told that we get over 100 million emails a month. This filters them down and allows only somewhere about three million emails, which is a great help.
What is most valuable?
We are a Cisco shop, so it just integrates with everything else that we are doing.
What needs improvement?
I would like them to add whatever makes filtering more advanced in scanning and blocking for malware in emails. It would just improve the product further. I think they are working on this, the continuous improvement aspect.
For how long have I used the solution?
One to three years.
What do I think about the stability of the solution?
The stability seems to work well.
What do I think about the scalability of the solution?
The scalability is fine.
How are customer service and technical support?
The technical support is sufficient. Every time that we have had an issue, we call the tech support, and they are very responsive.
Which solution did I use previously and why did I switch?
We wanted to get a homogeneous environment where everything works together and is integrated well together. This was a big advantage and big driver for us.
How was the initial setup?
The initial setup was straightforward.
What about the implementation team?
We used Dimension Data for the deployment. The experience was positive.
What was our ROI?
This solution has helped increase staff productivity, e.g., if you get 1000 emails a day and 95 percent of those are garbage, then the savings that you receive from going through those emails is immense.
We have seen a measurable decrease in the mean time to detect or respond to threats by 90 percent, blocking a vast majority of threats.
What other advice do I have?
Seriously consider it. It blocks a lot of emails. Look at the market, do your evaluation, and pick the right solution for you.
We are fairly mature in our security program maturity, but there is always room for improvement.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT Security Services Owner at Atea AS
Its most valuable features are its scalability and advanced threat protection for customers
Pros and Cons
- "Its most valuable features are its scalability and advanced threat protection for customers."
- "We would like to have an API integration with a SIEM solution, because as far as I know, it currently hasn't yet been released."
What is our primary use case?
We are trying to provide managed security services. This solution would be part of those managed security services.
How has it helped my organization?
We are on proof of concept phase and will see how it works.
I hope it will help decrease mean time to detect and respond, because it provides scalability, and we could make an efficient, effective service providing it for customers.
What is most valuable?
- Scalability
- Ability to integrate with SIEM.
- Advanced threat protection for customers.
What needs improvement?
We would like to have an API integration with a SIEM solution, because as far as I know, it currently hasn't yet been released. We are looking forward to it because it's important for us to integrate the product with a SIEM solution in order to provide our customers a good, robust solution.
It needs major improvement with its ease of integration.
For how long have I used the solution?
Trial/evaluations only.
What do I think about the stability of the solution?
So far, so good.
What do I think about the scalability of the solution?
The scalability is good.
How are customer service and technical support?
We have not had any technical cases.
Which solution did I use previously and why did I switch?
We are providing our customers multiple solutions depending on their needs. So, it's more like what our customer needs. We could go with Cisco or maybe we could with another vendor (we will see). Right now, we are quite satisfied with Cisco.
How was the initial setup?
For what we have already set up, the process has been straightforward.
What was our ROI?
We are estimating 5 to 10 percent staff productivity increases.
What's my experience with pricing, setup cost, and licensing?
Our partner in Norway does the price negotiation.
Which other solutions did I evaluate?
We are looking for cost-effective, efficient solutions for our customers, and Cisco happens to be one of the vendors who fits into that scope.
Microsoft is another vendor who offers a similar licensing model for this type of solution. There is also McAfee and Trend Micro. It depends on the customer's requirements.
What other advice do I have?
We have some mature security services, like anti-malware. We are looking to broaden our service portfolio and are on the first steps to climb further.
You should always assess your customers' needs. Once you get that information, you just look for respective vendors.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner.
Solution Sales Specialist at a tech services company with 5,001-10,000 employees
Real-time threat prevention using sandboxing, file trajectory, and retrospective security
Pros and Cons
- "Real-time threat prevention using sandboxing, file trajectory, and retrospective security."
- "It does not include encryption and decryption of local file shares."
What is our primary use case?
Endpoint security prevents malware and exploit kits coming into your mobile devices, and when you are outside the corporate network and not protected by the firewall.
How has it helped my organization?
Provides enhanced security, lowering IT risks, and IT operational costs by integrating with Cisco NGFW, network security and email security.
What is most valuable?
Real-time threat prevention using sandboxing, file trajectory, and retrospective security. On the prevention side, AMP has nine engines.
New feature AMP Visibility (beta) is an IR orchestration tool, where the local AMP for Endpoint Intelligence, Talos Intelligence, Threat Grid, AMP global intelligence, Umbrella Investigate, and VirusTotal are correlated. This gives a visual IR tool where you can search by file (SHA256), IP, or domain.
AMP for Endpoints is not a point solution. The AMP architecture also support ISR routers, IPSs, and NGFWs, Email and web security from Cisco is making common cloud threat architecture for all customers checkpoints.
What needs improvement?
It does not include:
- Encryption
- Decryption of local file shares
- Disks and URL filtering are done by separate product (Umbrella/OpenDNS).
For how long have I used the solution?
Less than one year.
What's my experience with pricing, setup cost, and licensing?
Pricing can be more expensive than similar software that does less functionality, but not recognized by customers.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Buyer's Guide
Download our free Cisco Secure Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2025
Product Categories
Endpoint Protection Platform (EPP) Endpoint Detection and Response (EDR) Cisco Security PortfolioPopular Comparisons
CrowdStrike Falcon
Microsoft Defender for Endpoint
Fortinet FortiEDR
Cisco Umbrella
SentinelOne Singularity Complete
Cisco Identity Services Engine (ISE)
Microsoft Defender XDR
Cortex XDR by Palo Alto Networks
Fortinet FortiClient
Elastic Security
HP Wolf Security
Symantec Endpoint Security
Trellix Endpoint Security Platform
Kaspersky Endpoint Security for Business
Buyer's Guide
Download our free Cisco Secure Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What is the biggest difference between EPP and EDR products?
- Can Cylance be used with Symantec or Kaspersky endpoint solutions without conflict?
- When evaluating Endpoint Security, what aspect do you think is the most important to look for?
- What's the best way to trial endpoint protection solutions?
- What are the threats associated with using ‘bogus’ cybersecurity tools?
- Which Endpoint Protection Solution offers Zero Trust (ZTN) as a feature?
- What to choose: an endpoint antivirus, an EDR solution or both?
- Which ransomware is the biggest threat in 2020?
- Are you aware of SIEM platforms that integrate both Active Directory auditing and security monitoring tools?
- What is the best solution for ransomware attack?