No more typing reviews! Try our Samantha, our new voice AI agent.

CylanceOPTICS vs Sangfor Endpoint Secure comparison

Why PeerSpot?
Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jun 3, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Ranking in Endpoint Detection and Response (EDR)
5th
Average Rating
8.4
Reviews Sentiment
6.7
Number of Reviews
118
Ranking in other categories
Endpoint Protection Platform (EPP) (4th), Extended Detection and Response (XDR) (3rd), Ransomware Protection (2nd), AI-Powered Cybersecurity Platforms (1st)
CylanceOPTICS
Ranking in Endpoint Detection and Response (EDR)
63rd
Average Rating
7.4
Reviews Sentiment
5.2
Number of Reviews
13
Ranking in other categories
No ranking in other categories
Sangfor Endpoint Secure
Ranking in Endpoint Detection and Response (EDR)
27th
Average Rating
8.2
Reviews Sentiment
7.4
Number of Reviews
11
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of October 2026, in the Endpoint Detection and Response (EDR) category, the mindshare of Cortex XDR by Palo Alto Networks is 3.7%, down from 3.9% compared to the previous year. The mindshare of CylanceOPTICS is 0.6%, up from 0.3% compared to the previous year. The mindshare of Sangfor Endpoint Secure is 0.8%, up from 0.7% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Endpoint Detection and Response (EDR) Mindshare Distribution
ProductMindshare (%)
Cortex XDR by Palo Alto Networks3.7%
Sangfor Endpoint Secure0.8%
CylanceOPTICS0.6%
Other94.9%
Endpoint Detection and Response (EDR)
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
GauthamVakapalli - PeerSpot reviewer
Account Manager at Teksalah
Provides reliable threat detection and response but requires better regional support
One improvement I suggest for CylanceOPTICS is more robust marketing efforts from their side. Many customers gravitate towards popular EDRs like CrowdStrike or Sophos, largely due to better marketing, despite BlackBerry Cylance being a superior product. The lack of marketing from distributors or vendors is a critical area where they are falling short. Apart from marketing, it would be beneficial for CylanceOPTICS to establish a dedicated team in GCC since I coordinate with the UK team to handle support. Whenever a ticket is raised by one of our customers, we have to wait for responses which can take a whole day due to the time zone differences, and a local team could expedite this process. In terms of scalability, CylanceOPTICS is indeed easy to scale, but one issue I face is related to visibility; while it is scalable, the security teams struggle with limited visibility as we need to gather data from multiple sources.
HD
Cloud Engineer at REDtone Digital Services
Robust security with features like antivirus protection and centralized management, but it may have limitations in supporting migrations from public clouds
While it excels in migrating VMs from on-premises and local infrastructure, it does not provide support for public cloud migrations. Attempting to migrate from public clouds like AWS encountered challenges, and Sangfor's support team clarified that they don't offer assistance for migrations from public cloud environments. It would be much more convenient if the migration tool could be installed directly on the customer's VMs, enabling a smoother migration process to the new infrastructure, with potential restrictions addressed accordingly.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The dashboard is customizable."
"In one single alert, we are getting the network telemetry, endpoint telemetry, email security telemetry, and proxy telemetry all in one single ticket, making it very easy."
"I recognize that Cortex XDR by Palo Alto Networks is one of the best products in its category regarding capabilities."
"Palo Alto Networks Traps improves our security posture and lowers risk by providing next-gen methods to combat against modern threats on all the major platforms."
"It blocks malicious files, prevents attacks, and doesn't require many updates because it is a very light application."
"The product's initial setup phase is very easy."
"The product is mostly automated, and we do not have to make decisions, because all the decisions are made by the product itself and we are not required to create any custom policies since the policies that are created are well defined in the product itself."
"Cortex XDR lets us manage several clients from the same console, and its endpoint defense is more advanced than traditional antivirus."
"Cylance is not a signature-based protection solution and instead works proactively using AI and ML models to patrol for malicious behavior."
"The solution has a high level of trust in the industry."
"You can use the solution to query certain things."
"The initial setup was fairly straightforward. To get a large health care organization sorted, we had to create exemptions because some of the scripts and some of the automations were broken."
"CylanceOPTICS is easy to use."
"The most valuable part of this solution is that it is advanced technology, as Cylance is an engine that is not a signature-based antivirus protection solution but is based on AI and ML models and could really not be more proactive in the way it works."
"They are well-known for their efficacy, which is a huge plus."
"The technical support personnel I interacted with were good."
"The tool's most valuable features are control access, endpoint security, and load balancing of ISPs."
"I like the tool's honeypot feature. Some features include having a honeypot to detect attacks in a certain area. Additionally, there is RDP protection, which means that when we remote into our server or any endpoint, we must enter a password as a second layer of security. It can also integrate with next-generation firewalls."
"It has a quick response time, threat intelligence, cybersecurity features, quick report generation, behavior analysis, dynamic detection, and quarantine features."
"Sangfor Endpoint Secure has some good policy certificates."
"The real-time monitoring feature of Sangfor Endpoint Secure is truly real-time, with no delay compared to other solutions."
"The user-friendliness of Sangfor Endpoint Secure is particularly impressive. Even with basic technical knowledge, users can easily navigate the system, make changes, and implement updates."
"What stands out to me is the dual-end user interface they provide."
"The most valuable feature I have found in the system is its comprehensive end-to-end protection."
 

Cons

"Cortex XDR should have a lightweight agent, and the agent size should not be heavy."
"There are some false positives."
"A little bit more automation would be nice."
"There is also no recovery feature; if some endpoint is under attack there must be the possibility of recovering it or restoring it to a normal state."
"In some cases, there are too many options for me, and it is a bit too hard to find some settings which I really need to implement."
"The connection to the internet has not performed as expected."
"There is a severe gap in functionality between Windows, Linux, and Mac versions. For example all folder restriction settings are Windows only. Traps 5.0+ does not have SAML / LDAP integration."
"It is an enterprise-level solution. Its price could be less expensive."
"One minor issue that somebody mentioned was that they didn't like their management console."
"The product's technical support is slow."
"False positives could be improved. Cylance picks up a lot of them."
"The product's initial setup process could be easy."
"Our customers would like to see more automation with respect to how threats are handled once they have been detected."
"Too many false positives are reported."
"It takes more time to investigate or dig up and understand what's going on."
"The support is inadequate because their technical people are not supportive. Since the support is not based in India, there are numerous issues."
"Sometimes, the VPN is not secure and doesn't work properly in Sangfor Endpoint Secure."
"The interface has too many buttons, making it cluttered."
"When an issue occurs, the response time for first-level support and the time taken for meetings could be improved."
"Sangfor Endpoint Secure performs poorly."
"Sangfor Endpoint Secure should include healing capabilities."
"It would be much more convenient if the migration tool could be installed directly on the customer's VMs, enabling a smoother migration process to the new infrastructure, with potential restrictions addressed accordingly."
"There are a few areas for improvement. We have encountered licensing issues on occasion, and sometimes updates don't apply properly."
"Currently, the tool lacks reporting functionalities."
 

Pricing and Cost Advice

"When we first bought it, it was a bit expensive, but it was worth it. The licensing was straightforward."
"This is an expensive solution."
"In terms of the cost Cortex XDR by Palo Alto Networks is very expensive because we are a Mexican company and when you translate dollars to pesos the cost is very high. The solution is very expensive for Mexican companies. I understand that they have international prices, but I do not think it offsets the price enough for many companies in countries, such as Mexico. The amount it is reduced is not a massive percentage."
"We didn't have to pay any additional fee for the cloud instance. It just came with the renewal, which was nice."
"Cortex XDR by Palo Alto Networks is an expensive solution."
"The return on investment is from the user side because we have seen the performance of it increase the delivery time of the product if we are using too many web-based and on-premise applications. In indirect ways, we saw the return of investment in terms of performance and user satisfaction increase."
"It's the most expensive solution, but features-wise, it's quite strong. It's very good for protection, so the results are very good in the case of protection. I would rate it a two out of ten in terms of pricing."
"It's about $55 per license on a yearly basis."
"The pricing for CylanceOPTICS is very good; I would rate it around a nine on a scale of one to ten, with ten being the lowest. It's one of the most affordable options I've seen."
"We pay for the number of endpoints we have and that is about it. On a monthly basis, the licensing cost is $55 per user."
"CylanceOPTICS is probably priced equal to other EDRs in the market."
"I would rate the pricing a three out of five."
"The solution is cheap. It is cheaper than other products by 15-20 percent."
"Sangfor Endpoint Secure's pricing is cheap. I rate it seven out of ten."
"We were using Hyper-V. So, we switched to Sangfor because of the pricing."
"The product is expensive compared to other vendors."
"Sangfor Endpoint Secure is not a cheap solution."
"Its "pay as you grow" model offers cost-effectiveness compared to major cloud providers."
"Price-wise, Sangfor Endpoint Secure can be considered a competitively priced product in the market as it offers quite low prices compared to other solutions."
report
Use our free recommendation engine to learn which Endpoint Detection and Response (EDR) solutions are best for your needs.
915,341 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Outsourcing Company
12%
Comms Service Provider
12%
Construction Company
11%
Manufacturing Company
10%
Manufacturing Company
12%
Outsourcing Company
11%
Financial Services Firm
11%
Comms Service Provider
11%
Financial Services Firm
16%
Comms Service Provider
12%
Outsourcing Company
7%
Media Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business47
Midsize Enterprise21
Large Enterprise55
By reviewers
Company SizeCount
Small Business7
Midsize Enterprise2
Large Enterprise4
By reviewers
Company SizeCount
Small Business5
Midsize Enterprise3
Large Enterprise3
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
What is your experience regarding pricing and costs for Blackberry Optics?
In terms of cost, I find CylanceOPTICS to be reasonable; it's not overly expensive, nor is it at the lower end of the...
What needs improvement with Blackberry Optics?
One improvement I suggest for CylanceOPTICS is more robust marketing efforts from their side. Many customers gravitat...
What is your primary use case for Blackberry Optics?
One of the main use cases for CylanceOPTICS is endpoint detection and response, which even works without internet, un...
What needs improvement with Sangfor Endpoint Secure?
The interface has too many buttons, making it cluttered. It would be better if it were a simplified version with fewe...
What is your primary use case for Sangfor Endpoint Secure?
Sangfor Endpoint Secure is easy to handle with its user-friendly interface. The four engines it utilizes for endpoint...
What advice do you have for others considering Sangfor Endpoint Secure?
At first, people might not understand the interface, which is why it should be simplified. However, once they underst...
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
No data available
No data available
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
Cerdant, Washoe County School District
Information Not Available
Find out what your peers are saying about CylanceOPTICS vs. Sangfor Endpoint Secure and other solutions. Updated: September 2026.
915,341 professionals have used our research since 2012.