Try our new research platform with insights from 80,000+ expert users

Cybereason Managed Detection & Response vs IBM Security QRadar comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jul 13, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cybereason Managed Detectio...
Ranking in Managed Detection and Response (MDR)
22nd
Average Rating
8.0
Reviews Sentiment
6.9
Number of Reviews
4
Ranking in other categories
No ranking in other categories
IBM Security QRadar
Ranking in Managed Detection and Response (MDR)
8th
Average Rating
8.0
Reviews Sentiment
6.7
Number of Reviews
211
Ranking in other categories
Log Management (7th), Security Information and Event Management (SIEM) (4th), User Entity Behavior Analytics (UEBA) (1st), Endpoint Detection and Response (EDR) (18th), Security Orchestration Automation and Response (SOAR) (4th), Extended Detection and Response (XDR) (11th)
 

Mindshare comparison

As of October 2025, in the Managed Detection and Response (MDR) category, the mindshare of Cybereason Managed Detection & Response is 0.5%, up from 0.3% compared to the previous year. The mindshare of IBM Security QRadar is 1.0%, up from 0.7% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Managed Detection and Response (MDR) Market Share Distribution
ProductMarket Share (%)
IBM Security QRadar1.0%
Cybereason Managed Detection & Response0.5%
Other98.5%
Managed Detection and Response (MDR)
 

Featured Reviews

Peter Nowak - PeerSpot reviewer
Quick response and reliable restoration enhance security operations
If the language barrier was addressed, it would lower the barrier for a number of German customers. It would take away a unique selling point for our own specialist managed service. I'm a bit hesitant, however, this would improve the product or the offering. Detection time already is very quick. The completeness of the offering was integrating more data. I am discussing with a customer who wishes to include identity data. Detecting early when someone tries to compromise your ID would be a nice feature.
Mahmoud Younes - PeerSpot reviewer
Reliable installation and diverse use cases provide strong value
IBM Security QRadar has some areas for improvement. We have missed some DSM components. We need to customize logs where there is no DSM or connector for certain products. We can integrate but we have missed the DSM, which is the connector to pass logs coming from different applications. For example, with a university customer, we tried onboarding Canvas service. IBM Security QRadar does not support Canvas, so we had to create custom scripts and workarounds to pull logs from Canvas.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable feature of the solution is endpoint management...The solution's support team is quite good at giving us feedback if there is an issue."
"Automated information on zero-day threats is provided without us needing to ask."
"The quick reaction and the ability to restore the state before within a short time are significant."
"The quick reaction and the ability to restore the state before within a short time are significant."
"The visibility it gives you into your infrastructure has been great."
"The most valuable feature is user behavior analytics (UBA)."
"An engineer can live-monitor all the flow happening in real-time. This would help us a lot while investigating a case, and it would even help us with preventive actions."
"I have found the most important features to be the flexibility, tech framework, and disk manager."
"The tool's most valuable feature is real-time detection."
"We can easily monitor many things using this tool."
"It's built around Red Hat Linux, which is highly robust."
"The most valuable feature is the DSM Editor. The custom parsing tool is very nice, outstanding."
 

Cons

"For every new client or every new case, my company has to spin up a new instance, because of which there is a new URL."
"If the language barrier was addressed, it would lower the barrier for a number of German customers."
"The interface, particularly the dashboard we use for looking at alerts, could be improved."
"If the language barrier was addressed, it would lower the barrier for a number of German customers. It would take away a unique selling point for our own specialist managed service."
"The quality of technical support depends on the IBM support person. Sometimes, it's hard to get the right person on the other side. A ticket coordinator could be the key to better quality delivery."
"The price of IBM Security QRadar is an area of concern where improvements are required."
"I would like the rule creation interface to be much more user-friendly in the next release."
"It is not app based."
"Each module requires a separate license and a separate cost."
"Technical support is good, but not great."
"It's resource-intensive."
"IBM Qradar could improve the reporting. The tool is not designed to report. It's a great operational monitoring tool. You put it on a screen and you watch it. If you want to have analytics out of it, that's a whole different story. You're going to need more people and tools. What should be added is reporting and integration into Power BI, into some capability that produces analytical reports from the source data. IBM does not seem to care to add these features."
 

Pricing and Cost Advice

"Price-wise, Cybereason Managed Detection & Response is effective for larger companies, but if you have a small company with less than 1,000 employees, then it gets expensive."
"The pricing is higher but cheaper than others and there are no additional costs."
"The licensing is also overly complex, as there is a need to buy the work load performance monitoring separately."
"The price of this product is high."
"QRadar UBA's price is a little more than street price and could be reduced."
"You have a one-time payment, and you also can purchase it for one year as a subscription. We have it on-premise, and we have a permanent license for it. We have to pay for the support on a yearly basis. If you compare its cost with Sentinel for one year, QRadar would seem more expensive, but if you compare its cost over five or ten years, Azure Sentinel will be more expensive than QRadar. If you compare its cost with Sentinel for one year, QRadar would seem more expensive, but if you compare its cost over five or 10 years, Azure Sentinel can be more expensive than QRadar."
"On a scale of one to ten, I rate the price a one, where one is an extremely expensive product, and ten is a cheap product."
"Pricing (based on EPS) will be more accurate."
"It's too expensive."
report
Use our free recommendation engine to learn which Managed Detection and Response (MDR) solutions are best for your needs.
869,566 professionals have used our research since 2012.
 

Comparison Review

VS
Jun 28, 2015
Qradar vs. ArcSight
Continuing with the SIEM posts we have done at Infosecnirvana, this post is a Head to head comparison of the two Industry leading SIEM products in the market – HP ArcSight and IBM QRadar Both the products have consistently been in the Gartner Leaders Quadrant. Both HP and IBM took over niche SIEM…
 

Top Industries

By visitors reading reviews
Performing Arts
17%
Financial Services Firm
9%
Educational Organization
7%
Manufacturing Company
6%
Computer Software Company
15%
Financial Services Firm
11%
Government
7%
Manufacturing Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
By reviewers
Company SizeCount
Small Business89
Midsize Enterprise36
Large Enterprise102
 

Questions from the Community

What is your experience regarding pricing and costs for Cybereason Managed Detection & Response?
The valuable aspect of pricing is that we do not need our own data center and software licensing, which reduces costs.
What needs improvement with Cybereason Managed Detection & Response?
Initially, we observed multiple false positive alerts with Cybereason Managed Detection & Response. We've worked with Cybereason to whitelist and fine-tune alerts, particularly those related to...
What is your primary use case for Cybereason Managed Detection & Response?
We have configured multiple scenario-based alerts for Cybereason Managed Detection & Response, such as known malware, potential unwanted programs, and PowerShell execution. We monitor suspiciou...
What are the biggest differences between Securonix UEBA, Exabeam, and IBM QRadar?
It mostly depends on your use-cases and environment. Exabeam and Securonix have a stronger UEBA feature set, friendlier GUI and are not licensed based on capacity (amount of logs and information in...
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What is your experience regarding pricing and costs for IBM Security QRadar?
When comparing with Splunk, IBM Security QRadar's cost is reasonable. Splunk is more expensive than IBM Security QRadar.
 

Also Known As

Cybereason MDR
IBM QRadar, QRadar SIEM, QRadar UBA, QRadar on Cloud, IBM QRadar Advisor with Watson
 

Overview

 

Sample Customers

CONNECTICUT WATER, BEAM SUNTORY, CADWALADER, WICKERSHAM & TAFT, RTI Surgical, HOSPITAL REVENUE CYCLE MANAGEMENT COMPANY, MCBEE ASSOCIATES, FORTUNE 500 BANK
Clients across multiple industries, such as energy, financial, retail, healthcare, government, communications, and education use QRadar.
Find out what your peers are saying about Cybereason Managed Detection & Response vs. IBM Security QRadar and other solutions. Updated: September 2025.
869,566 professionals have used our research since 2012.