No more typing reviews! Try our Samantha, our new voice AI agent.

Cisco Secure Network Analytics vs Secureworks Taegis XDR comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Nov 6, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cisco Secure Network Analytics
Ranking in Network Detection and Response (NDR)
6th
Average Rating
8.2
Reviews Sentiment
6.6
Number of Reviews
62
Ranking in other categories
Network Monitoring Software (33rd), Network Traffic Analysis (NTA) (5th), Cisco Security Portfolio (8th)
Secureworks Taegis XDR
Ranking in Network Detection and Response (NDR)
9th
Average Rating
8.8
Reviews Sentiment
6.1
Number of Reviews
10
Ranking in other categories
Extended Detection and Response (XDR) (14th)
 

Mindshare comparison

As of August 2026, in the Network Detection and Response (NDR) category, the mindshare of Cisco Secure Network Analytics is 5.5%, down from 6.9% compared to the previous year. The mindshare of Secureworks Taegis XDR is 1.9%, up from 1.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Network Detection and Response (NDR) Mindshare Distribution
ProductMindshare (%)
Cisco Secure Network Analytics5.5%
Secureworks Taegis XDR1.9%
Other92.6%
Network Detection and Response (NDR)
 

Featured Reviews

Muhammad Harun-Owr-Roshid - PeerSpot reviewer
CEO at BRIGHT-i SYSTEMS LIMITED
Have streamlined network visibility and troubleshooting while seeing benefits from AI integration
In terms of improvements for Cisco Secure Network Analytics, from the implementation point of view, now that AI is in use, some other features need to be upgraded considering AI solutions. Proper management of the database is also important; it should be centralized for easier data collection from a single database. When precise manual analysis is needed, it's sometimes difficult, so having a centralized database will allow network admins to find actual scenarios more effectively, especially since some information may not be visible on the GUI. Cisco should upgrade their hardware part to run the database, because sometimes it cannot handle the load while all features are running in the network. The database management should indeed be centralized because while AI runs behind the systems, central management is essential. For example, in a network with 100 Cisco switches, a few routers, firewalls, and access points, all data generated should be preserved in a central database. This approach simplifies management and analysis for troubleshooting, as GUI interfaces may not always provide visible information. Centralizing the database will allow for better understanding of which information is preserved for each specific device.
Mohammad Jundiah - PeerSpot reviewer
Solutions Architect at Qatar Datamation Systems
Centralized monitoring has strengthened threat hunting and improved ransomware protection
Threat hunting and SOC augmentation represent the most special features about Secureworks Taegis XDR, where some of the best people in cybersecurity proactively search, provide reports, and deliver indicators of compromise for any activity in your network. This monitoring and reporting can be conducted weekly or monthly. Centralized security monitoring and reporting is one of the most valuable aspects, as security fundamentally revolves around compliance. Having a centralized security monitoring platform that detects endpoints, networks, and cloud environments, including servers and switches, is essential. Secureworks Taegis XDR's architecture involves a collector device that collects all your data, even from small laptops, and allows you to monitor everything in one platform. This centralized system provides compliance and security visibility, ensuring evidence and visibility for your security and any compliance requirements you have. Analytics with Secureworks Taegis XDR give you a full preview of everything on your device. It takes all the inputs and outputs of your infrastructure; for example, if it is a firewall, it scans all of the traffic. While it is not a SIEM, it is an open XDR, which excels at conducting analytics. This represents one of its best features because Secureworks has implemented a machine learning model that can detect and analyze everything independently, providing AI-driven features. Integration with third-party tools is quite seamless. Secureworks Taegis XDR can integrate with virtually anything. One of the best features of this product is its integration capabilities with multiple sources of EDRs and any operating system, whether protecting Linux or Windows servers. It boasts very good integration, and if a specific integration is not available, you can raise a ticket to Secureworks, and they will work on your integration, whatever it is, even if it is custom-built software. Secureworks Taegis XDR absolutely aids in efficiency. SOC augmentation extends an organization's existing SOC, which helps reduce alert fatigue significantly. It provides additional threat intelligence and expert investigation, making it very useful for organizations that have a security team but lack twenty-four seven coverage.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"I believe this solution has reduced our incident response time."
"StealthWatch lets me see the ports running in and out and the country. It has excellent reporting, telemetry, and artificial intelligence features. With the telemetry, I can set thresholds to detect sudden changes and the alarms go through the PLC parts. I can see all the ports running on that trunk."
"The most valuable features provided by this solution are visibility and information."
"It provides good visibility to the customers. People are still evaluating it, but it provides visibility and helps them to take action to remediate and mitigate the issues that are highlighted on the dashboard. It has good integration with the Cisco switching platform."
"Stealthwatch reduced our incident response rate, as well as the amount of time it takes to detect and remediate threats by about 25%."
"The most valuable features of this solution are its reporting and mitigation capabilities."
"It has definitely helped us improve our mean time to resolution on network issues."
"Cisco Stealthwatch has improved our organization's analytics and threat protection capabilities by catching threats early on and it saved us a net fortune when we caught an employee constantly pulling three or four GBs of data from an FTP server."
"Sophos is a good XDR, and I recommend it for large companies since they have approximately 2,000 or 3,000 devices and can implement it as it is the best XDR."
"Using Secureworks Taegis XDR has positively impacted our organization overall."
"The price for Secureworks Taegis XDR is very competitive."
"The features I find most valuable are the fact that Secureworks Taegis XDR runs itself without any form of intervention."
"It's a complete solution package."
"Threat hunting and SOC augmentation represent the most special features about Secureworks Taegis XDR, where some of the best people in cybersecurity proactively search, provide reports, and deliver indicators of compromise for any activity in your network."
"The initial setup was straightforward."
"The auto-triage feature of Secureworks Taegis XDR makes my workflow easier and efficient, helping me shorten the time of responding to every alert, make my activities productive, and manage everything that I need to check every alert and detection."
 

Cons

"One update that I would like to see is an agent-based client. Currently, Stealthwatch is network-based. A local agent could help manage endpoints."
"Reliance on Java. Get away from that."
"Cisco could improve the administration for the customers."
"The GUI could use some improvement. Being able to find features more easily would be a great improvement if it was simplified."
"The version with the Dell server had iDRAC problems. Often, it reported iDRAC failure."
"Its granularity for RBAC roles-based access control needs improvement."
"One of the things which bugs me about Lancope is the licensing."
"This is a good solution, but Java is still in the SMC, the Firepower integration is not really there, and I would really appreciate people being told about the necessity of ISE beforehand."
"To improve Secureworks Taegis XDR, we need to enhance the support part."
"One negative aspect I always hear from customers is about the cost."
"The efficiency or the smooth navigation of the website or the application can be improved in Secureworks Taegis XDR."
"I do not see any other problems with Secureworks Taegis XDR besides pricing."
"Secureworks Taegis XDR is a good product, but it should include AI technology."
"Customer support for Secureworks Taegis XDR is not that bad; they are reachable but not super efficient."
"The pricing could be improved."
"We found limitations in the XDR's detections, lacking the ability to create customized detection and log parsing rules."
 

Pricing and Cost Advice

"This is an expensive product. We have quit paying for support because we don't want to have to upgrade it and keep paying for it."
"There are additional licenses needed for the number of so-called network flows. It's hard to plan the number of flows you need in the network, this is a problem. The price of the Cisco Stealthwatch is relatively inexpensive"
"On a yearly basis, licensing is somewhere around $30,000."
"Licensing is on a yearly basis."
"It has a subscription model. There is yearly support, and there is also three-year support. It depends on what the customers want."
"The licensing costs are outrageous."
"​Licensing is done by flows per second, not including outside (in traffic)."
"It is worth the cost."
"The pricing is six out of ten."
report
Use our free recommendation engine to learn which Network Detection and Response (NDR) solutions are best for your needs.
909,725 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
10%
Manufacturing Company
10%
Construction Company
9%
Government
8%
Financial Services Firm
16%
Manufacturing Company
12%
Computer Software Company
7%
Comms Service Provider
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business12
Midsize Enterprise7
Large Enterprise52
By reviewers
Company SizeCount
Small Business3
Midsize Enterprise1
Large Enterprise7
 

Questions from the Community

What is your experience regarding pricing and costs for Cisco Stealthwatch?
Regarding cost, for the Bangladesh context, Cisco Secure Network Analytics is a little bit high-priced because we are a developing country, making it tough to manage affordable solutions. However, ...
What needs improvement with Cisco Stealthwatch?
Several features often look very promising during evaluation or implementation but end up being used only lightly in day-to-day operations. Advanced reporting and scheduled compliance reports look ...
What is your primary use case for Cisco Stealthwatch?
My main use case for Cisco Secure Network Analytics has been network visibility and anomaly-based threat detection within the enterprise environment. In security operations and VAPT-related activit...
What needs improvement with Secureworks Taegis XDR?
If there were a next release of the product, I would like to see an increase in playbooks, specifically for augmentation and automation. Increasing the automation playbooks would be beneficial, as ...
What is your primary use case for Secureworks Taegis XDR?
Clients are primarily using Secureworks Taegis XDR for securing endpoints, networks, and extending to cloud, identity management, and email protection. It functions as an antivirus in enterprise te...
What advice do you have for others considering Secureworks Taegis XDR?
One of the best features of this product is its integration capabilities with multiple sources of EDRs and any operating system, whether protecting Linux or Windows servers. Secureworks Taegis XDR ...
 

Also Known As

Cisco Stealthwatch, Cisco Stealthwatch Enterprise, Lancope StealthWatch
Secureworks Taegis NDR
 

Overview

 

Sample Customers

Edge Web Hosting, Telenor Norway, Ivy Tech Community College of Indiana, Webster Financial Corporation, Westinghouse Electric, VMware, TIAA-CREF
Information Not Available
Find out what your peers are saying about Cisco Secure Network Analytics vs. Secureworks Taegis XDR and other solutions. Updated: August 2026.
909,725 professionals have used our research since 2012.