Try our new research platform with insights from 80,000+ expert users

BlackBerry Cylance Cybersecurity vs Symantec Endpoint Security comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Feb 8, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Ranking in Endpoint Protection Platform (EPP)
5th
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
106
Ranking in other categories
Endpoint Detection and Response (EDR) (7th), Extended Detection and Response (XDR) (6th), Ransomware Protection (2nd), AI-Powered Cybersecurity Platforms (2nd)
BlackBerry Cylance Cybersec...
Ranking in Endpoint Protection Platform (EPP)
24th
Average Rating
8.0
Reviews Sentiment
4.6
Number of Reviews
44
Ranking in other categories
No ranking in other categories
Symantec Endpoint Security
Ranking in Endpoint Protection Platform (EPP)
16th
Average Rating
7.6
Reviews Sentiment
6.8
Number of Reviews
146
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of March 2026, in the Endpoint Protection Platform (EPP) category, the mindshare of Cortex XDR by Palo Alto Networks is 3.5%, down from 4.0% compared to the previous year. The mindshare of BlackBerry Cylance Cybersecurity is 1.3%, up from 1.2% compared to the previous year. The mindshare of Symantec Endpoint Security is 3.3%, down from 4.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Endpoint Protection Platform (EPP) Market Share Distribution
ProductMarket Share (%)
Cortex XDR by Palo Alto Networks3.5%
Symantec Endpoint Security3.3%
BlackBerry Cylance Cybersecurity1.3%
Other91.9%
Endpoint Protection Platform (EPP)
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
Sooraj Makkancherrry - PeerSpot reviewer
Security Operations Manager at Philips
Doesn't have daily updates, which is important for healthcare IT
I face challenges with the exclusion policy - it still scans folders we told it not to, causing issues. When we contact support, they tell us to update the latest agent, but we can't do that immediately due to medical device protocols and validation testing. I wish support would try to understand our issues better instead of giving this standard response. The machine learning feature they use often tells us to upgrade the agent or add things to the exclusion list, which isn't unacceptable. It's a very good and new technology as a tool and antivirus. But sometimes, it doesn't work properly with our medical devices and products, quarantining files it shouldn't even after we add them to exclusions. This is tricky for us.
Kumbesh Rajagopal - PeerSpot reviewer
Senior Security Delivery Analyst at Accenture
Management becomes easier with minimal complications, but improvement in support tools needed
Regarding areas of improvement for Symantec Endpoint Security, there are many changes, and the support portal tool is complicated compared to other tools. When trying to get service from Symantec, the process is complex. I'm not sure whether it's because of my project or something else. Though it is easy to manage, easy to get, easy to install, and works efficiently for managing policies, we faced a significant disadvantage. We wanted to add multiple hashes because of numerous new alerts coming, but we could only add them one by one, which is a considerable disadvantage in Symantec.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The solution allows us to make investigations. Other XDR solutions also provide similar capabilities but for investigation, Cortex XDR is better."
"Stability is a primary factor, and then there's the ease of distribution and policy management."
"If any application performs suspicious activities, such as changing registries or modifying other applications, Cortex XDR detects and blocks the entire application."
"One thing that I like about Cortex XDR by Palo Alto Networks, it is detecting all the suspicious or malicious binaries, and it has integration with Palo Alto Firewall."
"The tool is designed to scale for large enterprises and handle large volumes of data."
"Cortex Xnor's playbooks predefine the workflow of the automation, such as response processes, alert triggering, and enriching the context, collecting relevant indicators such as hashes, IP addresses, or domains efficiently and can detect and block malicious attacks with firewalls."
"The dashboard is customizable."
"The main benefit of using Cortex XDR by Palo Alto Networks while employing Palo Alto Firewall at the internet edge is that it improves security on our endpoint devices, integrating seamlessly with Palo Alto Firewalls to deliver comprehensive network, analyst, and security details all in a single dashboard, which allows us to manage everything from our network devices."
"​Centralized dashboard online which can be used for managing a huge product."
"The solution’s AI is its most valuable feature."
"Does malware analysis. Blocks WannaCry and other attacks that have come out."
"In most cases, the solution's ability to detect in the MITRE framework, and its ability to be able to detect attacks in any one of seven or eight different areas of the life cycle of an attack is very useful."
"The platform's most valuable features are the malware detection capabilities."
"It secures different entry points into the network."
"I've found the AI engine in CylancePROTECT to be particularly effective for technology and in preventing unknown threats."
"We are quite security-focused. Blackberry Protect as an endpoint solution for our service really delivers what we are expecting."
"No maintenance is required after a successful installation phase."
"The initial setup is straightforward."
"The solution's application control feature is very, very powerful."
"The solution offers very good security features and is comparable to Sophos."
"The product has valuable features for insights."
"The product has been quite stable."
"The installation was very easy."
"Can detect and prevent attacks that are exploring common software vulnerabilities."
 

Cons

"It is not easy to sell Cortex XDR, not because it isn't a good tool. Its marketing needs to be improved."
"It is an enterprise-level solution. Its price could be less expensive."
"It's not an ideal choice for smaller businesses, as you need a minimum of 200 endpoints to even use the solution at all."
"Cortex XDR by Palo Alto Networks could improve by adding a sandbox feature to better compete with their competitors which have it."
"Impact on system performance is horrible, adding a lot of delays for users."
"I would like to see improvement in the tool's user interface, particularly in the area of managing alerts and providing more reporting capabilities."
"I would like to see some additional features related to email protection included."
"If you compare it to SentinelOne, which has more functionalities and detection capabilities on an open platform, the pricing on SentinelOne is far more reasonable and cheaper than Cortex XDR by Palo Alto Networks."
"CylancePROTECT's dashboard could be more user-friendly."
"​Work on the math model. We are catching a lot of false positives, which gets to be a pain at the start of a deployment."
"The price for this EPP platform is expensive and could be improved."
"The process of whitelisting a script that you want to be able to run can be a little bit difficult, or awkward."
"It's a good solution but some features just need to be updated."
"I would like to see them fix the alerting system so that the endpoint reporting is a bit more streamlined."
"Having worked with SentinelOne, Cylance is good, however, it probably needs to add a feature similar to SentinelOne's rollback functionality. With this feature, if you get infected, with a click, you can go back to the pre-infection state. If Cylance could add this functionality to their offering as well, that would be ideal."
"Reporting is an area with shortcomings in CylancePROTECT that needs to be improved."
"Is not a full anti-ransomware solution."
"The reporting could be improved."
"It is only available to use on computers with higher-end specs."
"I would like to be able to migrate to the cloud so that the end-users outside the company offices don't need a VPN to connect to the Symantec server to update the policies. They should be able to connect to the admin center directly through the internet to get updated policies. There is some integration issue with the other security appliances or tools. Other hardware, firewall, or Network Detection and Response (NDR) solution vendors are not willing to integrate with Symantec. They only mention products from other vendors such as CrowdStrike and Carbon Black. Symantec is not there. Symantec should work on integration with products from other security vendors."
"When, Microsoft releases a new OS version twice a year, you never know if the current version of Symantec Endpoint Protection will support it. You can have a lag between when Microsoft releases a new client - and then the current version doesn't work correctly - and it could be some months between updates from Symantec."
"Since the division of the company, we have experienced a lack of support."
"The monitoring capabilities could be further developed."
"The enterprise edition does not report attacks on external devices."
 

Pricing and Cost Advice

"I feel it is fairly priced."
"I don't like that they have different types of licenses."
"I did PoCs on products called Cylance and CrowdStrike. Although, I consider these products and they were also good, when it come to cost and budgetary factors, Traps has been proven to be better than the other two products. It is quite cost-effective and delivers all the entire solution which we require."
"The tool's price is moderate."
"The price of the product is not very economical."
"Cortex XDR’s pricing is very reasonable."
"The solution has one subscription for endpoint protection and one subscription for detection and response. The two licenses combined give you the BRO version."
"Our customers have expressed that the price is high."
"The product cost is about $5, per user, per month."
"CylancePROTECT is an affordable solution."
"The license price for this solution could be better. It's on the expensive side."
"The price is reasonable for us at the moment. I rate the overall solution an eight out of ten."
"The tool is not that expensive."
"Currently, we have competitive pricing for Cylance, which is affordable enough to consider."
"The solution provides me with competitive pricing."
"Review closely how many endpoints you actually need before buying into a pricing level. Deal and deal with the VAR of your choice."
"It provides a good solution at a good price."
"The price of Symantec is on the higher end. They face some competition from a company called Quick Heal, which is much cheaper than Endpoint Security. They offer three years of protection at just 900 rupees."
"Licensing is based on a yearly subscription."
"It could be cheaper."
"We receive a discounted price for this solution because we are a non-profit organization."
"The prices fluctuate, but this year I think it was maybe around $12,000."
"There is a yearly license."
"Its price is fair."
report
Use our free recommendation engine to learn which Endpoint Protection Platform (EPP) solutions are best for your needs.
883,448 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
10%
Financial Services Firm
9%
Manufacturing Company
9%
Comms Service Provider
6%
Computer Software Company
9%
Manufacturing Company
8%
Government
6%
Comms Service Provider
6%
Comms Service Provider
11%
Manufacturing Company
10%
Financial Services Firm
9%
Computer Software Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business44
Midsize Enterprise20
Large Enterprise47
By reviewers
Company SizeCount
Small Business33
Midsize Enterprise5
Large Enterprise13
By reviewers
Company SizeCount
Small Business69
Midsize Enterprise32
Large Enterprise63
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
What do you like most about Blackberry Protect?
It is a good endpoint solution. It is very easy to manage and detect the threat immediately. It will take the necessa...
What is your experience regarding pricing and costs for Blackberry Protect?
The price is reasonable for us at the moment. I rate the overall solution an eight out of ten.
What needs improvement with Blackberry Protect?
I face challenges with the exclusion policy - it still scans folders we told it not to, causing issues. When we conta...
Which is better - Cortex XDR or Symantec End-User Endpoint Security?
Aqua Security is easy to use and very manageable. Its main focus is on Kubernetes and Docker. Security is a very valu...
Which offers better endpoint security - Symantec or Microsoft Defender?
We use Symantec because we do not use MS Enterprise products, but in my opinion, Microsoft Defender is a superior sol...
What do you like most about Symantec End-User Endpoint Security?
Symantec have everything – documentation, videos, data sheets.
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
Blackberry Protect
Symantec EPP, Symantec Endpoint Protection (SEP)
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
Panasonic, Noble Energy, Apria Healthcare Group Inc., Charles River Laboratories, Rovi Corporation, Toyota, Kiewit
Audio Visual Dynamics, Red Deer Advocate, Asia Pacific Telecom Co. Ltd., Kibbutz Ein Gedi, and AMETEK, Inc.
Find out what your peers are saying about BlackBerry Cylance Cybersecurity vs. Symantec Endpoint Security and other solutions. Updated: February 2026.
883,448 professionals have used our research since 2012.