Try our new research platform with insights from 80,000+ expert users

BlackBerry Cylance Cybersecurity vs Microsoft Defender for Endpoint vs Symantec Endpoint Security comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Mindshare comparison

As of May 2025, in the Endpoint Protection Platform (EPP) category, the mindshare of BlackBerry Cylance Cybersecurity is 1.1%, down from 1.4% compared to the previous year. The mindshare of Microsoft Defender for Endpoint is 10.8%, down from 14.4% compared to the previous year. The mindshare of Symantec Endpoint Security is 4.0%, down from 4.8% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Endpoint Protection Platform (EPP)
 

Featured Reviews

Sooraj Makkancherrry - PeerSpot reviewer
Doesn't have daily updates, which is important for healthcare IT
I face challenges with the exclusion policy - it still scans folders we told it not to, causing issues. When we contact support, they tell us to update the latest agent, but we can't do that immediately due to medical device protocols and validation testing. I wish support would try to understand our issues better instead of giving this standard response. The machine learning feature they use often tells us to upgrade the agent or add things to the exclusion list, which isn't unacceptable. It's a very good and new technology as a tool and antivirus. But sometimes, it doesn't work properly with our medical devices and products, quarantining files it shouldn't even after we add them to exclusions. This is tricky for us.
AnuragSrivastava - PeerSpot reviewer
Provides detailed visibility into threats but the ability to add exceptions needs improvement
One major item for improvement is the ability to add exceptions. We can add some exceptions, but not at the level we need to. The second major area for improvement involves enhanced capabilities for different operating systems or platforms. That is, even though we have coverage for different operating systems or platforms such as Linux, we don't get all of the controls and enhanced capabilities that are available with Windows devices. Reporting could also be improved because, at present, we get limited results at times. For example, in an environment with more than 100,000 devices, you may just get 10,000 results when you run a report.
Hakeem_Abdulkareem - PeerSpot reviewer
The solution has given us visibility into compliance within our whole system and helped us ensure everything is updated
Symantec's application security module needs some improvement. You need to create a lot of fingerprints for application security. For instance, let's say I have different brands of ATMs in my environment, like Wincor and NCR. I use GRG to deploy an application control to whitelist some applications. I have to get the exact image of the different models of ATMs. When I tested in the past, some machines would not connect to the server without that. Only the approved software on the ATM should run. Anything outside that should not even come up at all. We did this so that an outside person doesn't introduce malicious software to the ATM. That's the essence of locking down with application control. Using Symantec for application control has been hectic, so I use Carbon Black to do the lockdown. Checking that data security will work fine with Carbon Black. Carbon Black worked fine. Setting up approval in Carbon Black works differently than Symantec. In Symantec, we first need the fingerprints of the applications running underneath. Before setting up Carbon Black, you first install the agent, allowing it to learn the environment. It will analyze all the software's behavior and provide recommendations for what should be allowed. It's more straightforward, whereas configuring application control in Symantec is a bit cumbersome.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It is a good endpoint solution. It is very easy to manage and detect the threat immediately. It will take the necessary actions."
"The solution is easy to deploy."
"The most valuable features are script blocking and macros within Word documents for stopping unwanted applications from running in the background."
"The solution is stable."
"Two or three years ago when the WannaCry virus struck, the people that were on Cylance were the ones that weren't affected."
"The solution’s AI is its most valuable feature."
"The most valuable features of CylancePROTECT are its powerful machine-learning capabilities and predictive intelligence."
"CylancePROTECT is very stable - we've had no issues with performance and no errors or bugs."
"Defender for Endpoint provides good visibility into threats and has favorable threat intelligence."
"Easy to understand and easy to set up endpoint security solution. It's a multifeatured product with web content filtering and automated investigation features. It also has a fantastic vulnerability management dashboard."
"The solution can scale as needed."
"We use Microsoft Defender for the antivirus."
"The solution has good performance, I have not seen a problem."
"We have very good visibility on our endpoints. The level of information it throws back is helpful."
"The stability keeps getting better and better."
"The most valuable feature is that it comes with the package, so there is no additional installation of third-party software. It's also easy to use."
"Symantec's detection capabilities are strong. It involves run protection and behavioral analysis."
"The solution is easy to manage."
"Offers good antivirus and local firewall."
"The most valuable feature of Symantec Endpoint Security is the protection of our systems."
"The dashboard view and reporting are valuable. It is stable and easy to integrate, and it provides custom options."
"This product is valuable for ransomware protection, general malware protection, and network exploitation protection."
"It is very easy to managing everything in relation to the implementation and processing. The initial setup is very easy."
"I like the malware threat control policy and USB blocker. In Symantec Manager, we use multiple available features, so we created firewall policies to prevent any malware attack from the network or device controls."
 

Cons

"It is hard to manage."
"It could have integration with industrial base HMIS or Human Machine Interfaces Solutions. This is the industrial environment where you have a control center for all the automation that's happening, whether it is oil, gas, or chemical manufacturing. They often have to set up a computer at the back and watch the other stuff to get alerts. In these autonomous or on-premises environments, they often don't have access to email readily. Integration with other industrial solutions, such as HMIS, will allow them to communicate and get an alert that something has been found. This way, they can react to it sooner than having somebody watch the screen and keep checking the screen. Rockwell has its own suite. Similarly, Honeywell has its own suite. There's also an independent HMI/historian solution provider out there called VTSCADA. We actually get asked if we can get it to show up on a screen, which is difficult. Getting those alerts to work within an industrial environment would be a huge plus."
"While you are working, you are finding these things that were supposed to be waived have come back to being blocked. That's frustrating."
"The solution’s user interface could be improved."
"They could improve on the false positives, reporting and whitelisting features."
"Having worked with SentinelOne, Cylance is good, however, it probably needs to add a feature similar to SentinelOne's rollback functionality. With this feature, if you get infected, with a click, you can go back to the pre-infection state. If Cylance could add this functionality to their offering as well, that would be ideal."
"It's a good solution but some features just need to be updated."
"An area for improvement in CylancePROTECT is its pricing, as it's a bit costly."
"I miss having an executive dashboard or a simple view for viewing things. Everything is extensive in this solution. Everything is configurable and manageable, but the environment of Microsoft 365 has about 13 administrative dashboards, and in each of the dashboards, there are a gazillion things to set up. It is good for a large enterprise, but for a 200-seat client, you need to see 5% of that."
"We encountered some issues when we were trying to enable automatic updates from our group policy."
"The solution could improve by providing more integration."
"Lowering the price would be an improvement."
"Microsoft Defender for Endpoint is secure but when it comes to security all solutions could improve security."
"If they integrate with the EDR then it will benefit this solution."
"I'm not too sure of its current capabilities, but I'm pretty sure they are doing a good job on Windows and Mac. However, I'm not sure whether they covered Linux. If I remember correctly, Microsoft Defender didn't have anything proper on Linux back then, but if they have improved it from that aspect, it would already be ticking all the boxes."
"With the XDR dashboard, when you're doing an investigation and you're drilling down to obtain further details it tends to open many different tabs that take you away from your main tabs. You can end up having 10 tabs open for one investigation. This is another area for improvement because you can end up getting lost in the multiple tabs. Therefore, the central console can be improved so that it does not take you to several different pages for each investigation."
"The enterprise edition does not report attacks on external devices."
"It would be nice to see more antivirus features for USB control."
"If Symantec wants to improve, they should have a single event for all their products."
"I rate Symantec Endpoint Security a four out of ten. This rating stems primarily from the subpar user interface, which significantly delays my response time when managing firewall rules or investigating issues."
"The Sandboxing and ATP functionality does not integrate very well, improving this would be helpful."
"Symantec needs to develop some reporting features and notifications. For instance, if the server is not on or it's shut down. There should also be time-based USB control."
"Sometimes, when we are creating a new policy, some of the clients are not being updated with the latest policy."
"Since the acquisition by Broadcom, we are no longer receiving the proper support."
 

Pricing and Cost Advice

"The license price for this solution could be better. It's on the expensive side."
"We would just add more if there are new users, but right now you just need one license for per user."
"The monthly fee is $55 USD per user."
"The price is reasonable for us at the moment. I rate the overall solution an eight out of ten."
"CylancePROTECT is an affordable solution."
"I think that the price we are paying is good for what it is."
"CylancePROTECT is worth the money, but I'm not sure of its exact price. I can't remember off the top of my head."
"We went through a third party initially to do the renewal, but we won't be renewing, we will move on to something else."
"It is an expensive solution. It would be nice if it could be included with the Microsoft Office package."
"The product is free of charge and comes integrated into Windows."
"Microsoft Defender for Endpoint is included with a Microsoft E5 license."
"It is within the same range as other products. It is not too expensive, and it is also not cheap. Its price can be better, but, well, it is Microsoft."
"The price is fair for the features Microsoft delivers. If you want tailor-made features, you have to mix different licenses. It isn't straightforward."
"The price for Microsoft Defender for Endpoint is about three euros, which is considered reasonably priced."
"If we are acquiring everything in a single place, the front end becomes cost-effective."
"You do not need to pay any additional costs for antivirus and anti-malware solutions for endpoint protection."
"We receive a discounted price for this solution because we are a non-profit organization."
"We have some customers on a one-year license and others on a three-year license."
"What we have paid for this product is good value for the work and the services that they are providing to us."
"We pay on a yearly basis..."
"There is a yearly license."
"The EDR options are costlier than other products."
"When it comes to pricing, Sophos is preferrable to Symantec."
"It could be cheaper."
report
Use our free recommendation engine to learn which Endpoint Protection Platform (EPP) solutions are best for your needs.
850,076 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
14%
Manufacturing Company
11%
Government
8%
Financial Services Firm
7%
Educational Organization
25%
Computer Software Company
12%
Government
7%
Financial Services Firm
7%
Computer Software Company
15%
Financial Services Firm
12%
Manufacturing Company
10%
Government
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Blackberry Protect?
It is a good endpoint solution. It is very easy to manage and detect the threat immediately. It will take the necessa...
What is your experience regarding pricing and costs for Blackberry Protect?
The price is reasonable for us at the moment. I rate the overall solution an eight out of ten.
What needs improvement with Blackberry Protect?
I face challenges with the exclusion policy - it still scans folders we told it not to, causing issues. When we conta...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
Which offers better endpoint security - Symantec or Microsoft Defender?
We use Symantec because we do not use MS Enterprise products, but in my opinion, Microsoft Defender is a superior sol...
How does Microsoft Defender for Endpoint compare with Crowdstrike Falcon?
The CrowdStrike solution delivers a lot of information about incidents. It has a very light sensor that will never pu...
Which is better - Cortex XDR or Symantec End-User Endpoint Security?
Aqua Security is easy to use and very manageable. Its main focus is on Kubernetes and Docker. Security is a very valu...
What do you like most about Symantec End-User Endpoint Security?
Symantec have everything – documentation, videos, data sheets.
What is your experience regarding pricing and costs for Symantec End-User Endpoint Security?
Symantec Endpoint Security's pricing is better than most offerings based on my research. It seems to be half the cost...
 

Also Known As

Blackberry Protect
Microsoft Defender ATP, Microsoft Defender Advanced Threat Protection, MS Defender for Endpoint, Microsoft Defender Antivirus
Symantec EPP, Symantec Endpoint Protection (SEP)
 

Interactive Demo

Demo not available
Demo not available
 

Overview

 

Sample Customers

Panasonic, Noble Energy, Apria Healthcare Group Inc., Charles River Laboratories, Rovi Corporation, Toyota, Kiewit
Petrofrac, Metro CSG, Christus Health
Audio Visual Dynamics, Red Deer Advocate, Asia Pacific Telecom Co. Ltd., Kibbutz Ein Gedi, and AMETEK, Inc.
Find out what your peers are saying about Microsoft, CrowdStrike, SentinelOne and others in Endpoint Protection Platform (EPP). Updated: April 2025.
850,076 professionals have used our research since 2012.