Try our new research platform with insights from 80,000+ expert users

Cisco Secure Endpoint vs Fortinet FortiEDR vs VMware Carbon Black Endpoint comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
7.4
Cisco Secure Endpoint enhances productivity and reduces costs by streamlining threat detection, integrating tools, and minimizing manual intervention.
Sentiment score
4.6
Fortinet FortiEDR offers enhanced security and ROI with minimal weekly effort, boosting visibility and customer satisfaction over four years.
Sentiment score
6.0
VMware Carbon Black Endpoint delivers strong ROI with enhanced security, reducing costs and malware incidents within six months.
 

Customer Service

Sentiment score
6.1
Cisco Secure Endpoint support is praised for responsiveness and expertise, providing quick issue resolution and valuable user guidance.
Sentiment score
5.5
Fortinet FortiEDR's customer service is responsive but faces occasional delays due to broader reach and non-integrated support.
Sentiment score
6.3
VMware Carbon Black Endpoint support is knowledgeable but inconsistent, with varied satisfaction and room for improvement in response times.
Cisco has good technical support, especially considering these are newer solutions compared to traditional routing and switching products.
For setting up some proper solutions for issues at the customer site, it can take about one week.
 

Scalability Issues

Sentiment score
8.4
Cisco Secure Endpoint is scalable, integrates with SecureX for efficient management, and supports diverse industries without extra resources.
Sentiment score
6.0
Fortinet FortiEDR is highly scalable for enterprises, though some limitations exist with external integrations and cloud environments.
Sentiment score
7.3
VMware Carbon Black Endpoint is highly scalable, supporting diverse environments efficiently, despite some data extraction and management complexities.
Cisco Secure Endpoint is definitely scalable.
When implemented in a Fortinet environment with an existing firewall, FortiAnalyzer, and FortiManager, it is straightforward to install and scale by adding more EDR for endpoints.
 

Stability Issues

Sentiment score
6.5
Cisco Secure Endpoint is highly stable, reliable, and trusted for performance, earning high ratings from users in various enterprises.
Sentiment score
8.4
Fortinet FortiEDR is stable and reliable but requires maintenance, with occasional issues like memory concerns and false alerts.
Sentiment score
7.5
VMware Carbon Black Endpoint offers reliable security, but some users experience stability issues and update-related challenges for resource allocation.
We have not encountered any problems.
After that, I stopped scanning the Cisco AnyConnect and switched to Fortinet VPN. Everything worked fine afterward.
 

Room For Improvement

Cisco Secure Endpoint requires better integration, reporting, and UI enhancements, alongside improved pricing, AI capabilities, and IoT support.
Fortinet FortiEDR needs improved cloud security, automation, and user interface for better market acceptance and competitive advantage.
VMware Carbon Black Endpoint needs better integration, UI, mobile support, pricing, responsiveness, threat detection, and stability improvements.
The forensic capabilities need enhancement, especially for deep forensic data collection.
Fortinet could consider reducing the minimum order quantity for EDR, currently set at 500 pieces.
 

Setup Cost

Cisco Secure Endpoint offers competitive and flexible pricing with value-rich features, despite some complexity in licensing.
Fortinet FortiEDR offers competitive pricing but may have high setup costs, with potential savings through Fortinet's channel model.
VMware Carbon Black Endpoint is seen as pricey, varying by deployment size, with mixed views on its value and flexibility.
Cisco is aggressive in pricing, making it competitive and sometimes even cheaper than other good products like CrowdStrike, Microsoft Defender, or SentinelOne.
It's reasonably priced compared to other vendors' similar products.
 

Valuable Features

Cisco Secure Endpoint provides advanced security features, cross-platform support, and ease of use with strong threat intelligence and support.
Fortinet FortiEDR offers robust EDR capabilities, efficient resource use, and seamless integration, ensuring scalable, user-friendly cybersecurity for organizations.
VMware Carbon Black Endpoint excels in threat detection, management, and integration, providing scalable and efficient security with minimal resource use.
Cisco Secure Endpoint is very good in machine learning, which allows it to secure offline contents even if not connected to the internet.
 

Mindshare comparison

As of September 2025, in the Endpoint Detection and Response (EDR) category, the mindshare of Cisco Secure Endpoint is 1.6%, down from 1.7% compared to the previous year. The mindshare of Fortinet FortiEDR is 3.8%, down from 4.1% compared to the previous year. The mindshare of VMware Carbon Black Endpoint is 1.9%, down from 2.7% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Endpoint Detection and Response (EDR) Market Share Distribution
ProductMarket Share (%)
Fortinet FortiEDR3.8%
Cisco Secure Endpoint1.6%
VMware Carbon Black Endpoint1.9%
Other92.7%
Endpoint Detection and Response (EDR)
 

Featured Reviews

Mark Broughton - PeerSpot reviewer
Tighter integration with Umbrella and Firepower gave us eye-opening information
We were using a third-party help desk. One of the ways that they were fixing problems was to delete the client and then add the client back if there was an issue where the client had stopped communicating. Any improvement in the client communicating back to the server would be good, particularly for machines that are offline for a couple of weeks. A lot of our guys were working on a rotation where the machine might be offline for that long. They were also terrible about rebooting their machines, so those network connections didn't necessarily get refreshed. So, anything that could improve that communication would be good. Also, an easier way to do deduplication of machines, or be alerted to the fact that there's more than one instance of a machine, would be useful. If you could say, "Okay, we've got these two machines. This one says it's not reporting and this one says it's been reporting. Obviously, somebody did a reinstall," it would help. That way you could get a more accurate device count, so you're not having an inflated number. Not that Cisco was going to come down on you and say, "Oh, you're using too many licenses," right away. But to have a much more accurate license usage count by being able to better dedupe the records would be good. I also sent over a couple of other ideas to our technical rep. A lot of that had to do with the reporting options. It would be really nice to be able to do a lot more in the reporting. You can't really drill down into the reports that are there. The reporting and the need for the documentation to be updated and current would be my two biggest areas of complaint. Also, there was one section when I was playing with the automation where it was asking for the endpoint type rather than the machine name. If I could have just put in the machine name, that would have been great. So there are some opportunities, when it comes to searching, to have more options. If I wanted to search, for example, by a Mac address because, for some reason, I thought there was a duplication and I didn't have the machine name, how could I pull it up with the Mac address? When you're getting to that level, you're really starting to get into the ticky tacky. I would definitely put the reporting and documentation way ahead of that.
Jovan Jovanovic - PeerSpot reviewer
Collects valuable endpoint data with good analytics and helpful scalability
This is a question for the partners who implement and install it. I am not involved in the implementation process, so I cannot suggest improvements. As mentioned, this is a query for my presales team, not me. I am part of the security team lead, focusing mainly on sales. Regarding the product, Fortinet could consider reducing the minimum order quantity for EDR, currently set at 500 pieces. In smaller markets like Serbia, Bosnia, Montenegro, and Slovenia, it can be challenging to find customers with 500 endpoints. My suggestion to Fortinet would be to lower this minimum order quantity to one.
Nikunj Kamboj - PeerSpot reviewer
Integrates well with our existing SIEM tool and helps in identifying suspicious activities
The solution's integration with our existing security infrastructure is good. Whenever we have any alert in VMware Carbon Black Endpoint, we can easily that alert in our SIEM tool and check logs from the SIEM tool itself. VMware Carbon Black Endpoint is just a secondary security tool for us, and we are just monitoring the alerts from it. The solution's behavioral analytics feature helps in identifying suspicious activities pretty well. Whenever we have even a small thing, we get an alert. The solution is deployed on the cloud in our organization. Performance-wise, the solution is doing great in terms of connecting to the host directly. Performing a malware scan usually takes a lot of time, more than 24 hours. A malware scan is something that we do only on Carbon Black for the old endpoint devices and servers. It used to take sometimes three days to perform. I would recommend the solution to other users. Overall, I rate the solution an eight out of ten.
report
Use our free recommendation engine to learn which Endpoint Detection and Response (EDR) solutions are best for your needs.
867,676 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
21%
Manufacturing Company
9%
Government
7%
Financial Services Firm
6%
Computer Software Company
16%
Manufacturing Company
9%
Government
8%
Financial Services Firm
8%
Computer Software Company
12%
Financial Services Firm
12%
Government
9%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business21
Midsize Enterprise14
Large Enterprise21
By reviewers
Company SizeCount
Small Business19
Midsize Enterprise9
Large Enterprise13
By reviewers
Company SizeCount
Small Business31
Midsize Enterprise10
Large Enterprise29
 

Questions from the Community

What do you like most about Cisco Secure Endpoint?
The product's initial setup phase was very simple.
What is your experience regarding pricing and costs for Cisco Secure Endpoint?
Cisco is aggressive in pricing, making it competitive and sometimes even cheaper than other good products like CrowdS...
What needs improvement with Cisco Secure Endpoint?
Cisco Secure Endpoint lacks features like DLP which other vendors offer. XDR is new, so integration capabilities with...
What's the difference between Fortinet's FortiEDR and FortiClient?
I suggest Fortinet’s FortiEDR over FortiClient for several reasons. For starters, FortiEDR guarantees solid protectio...
What do you like most about Fortinet FortiEDR?
We have FortiEDR installed on all our systems. This protects them from any threats.
What is your experience regarding pricing and costs for Fortinet FortiEDR?
It's reasonably priced compared to other vendors' similar products.
What to choose: an endpoint antivirus, an EDR solution or both?
I can recommend Carbon Black, an award-winning next-gen anti-virus (NGAV) and endpoint detection and response (EDR) s...
What's the difference between Carbon Black CB Response and Carbon Black CB Defense?
Carbon Black offers two different levels of Endpoint Detection and Response. One is the VM Carbon Black Cloud Endpoin...
What do you like most about Carbon Black CB Defense?
VMware Carbon Black Endpoint is a highly stable solution.
 

Also Known As

Cisco AMP for Endpoints
enSilo, FortiEDR
Carbon Black CB Defense, Bit9, Confer
 

Overview

 

Sample Customers

Heritage Bank, Mobile County Schools, NHL University, Thunder Bay Regional, Yokogawa Electric, Sam Houston State University, First Financial Bank
Financial, Healthcare, Legal, Technology, Enterprise, Manufacturing ... 
Netflix, Progress Residential, Indeed, Hologic, Gentle Giant, Samsung Research America
Find out what your peers are saying about CrowdStrike, SentinelOne, Microsoft and others in Endpoint Detection and Response (EDR). Updated: January 2025.
867,676 professionals have used our research since 2012.