No more typing reviews! Try our Samantha, our new voice AI agent.

Cyware Cyber Fusion vs NetWitness NDR comparison

Why PeerSpot?
Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 5, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Torq
Sponsored
Average Rating
8.8
Reviews Sentiment
6.6
Number of Reviews
20
Ranking in other categories
AI-SOC (1st), AI-Powered Security Automation (1st)
Cyware Cyber Fusion
Average Rating
7.0
Reviews Sentiment
6.8
Number of Reviews
2
Ranking in other categories
Threat Intelligence Platforms (TIP) (28th), Security Orchestration Automation and Response (SOAR) (21st)
NetWitness NDR
Average Rating
8.0
Reviews Sentiment
6.9
Number of Reviews
15
Ranking in other categories
Endpoint Protection Platform (EPP) (47th), Threat Intelligence Platforms (TIP) (34th), Endpoint Detection and Response (EDR) (57th), Security Orchestration Automation and Response (SOAR) (22nd), Network Detection and Response (NDR) (19th), Extended Detection and Response (XDR) (40th)
 

Featured Reviews

AD
Solutions Architect at ProArch
Automation has streamlined multi-tenant SOC workflows and improves alert handling efficiency
Although the reporting within Torq is not that great, we did ask for many features regarding reporting in Torq, but due to some platform constraints, they could not make the whole dataset available for us to be used in reporting. Except for that, we used some basic reporting. When I used Torq, it was indeed in the early stages of AI capabilities. Only a few customers were allowed to use it, and we were among them. It functioned well as long as we summarized the data properly. If you input garbage, you would get garbage out. Thus, we had to do significant fine-tuning regarding what data context we provided to the AI orchestrator to get meaningful results. In terms of Torq's unified platform approach to AI SOC automation and case management compared to managing multiple point solutions across my security stack, I find it case-centric. The unified view in case management is good since it provides clarity, although there are limitations regarding how many items in case management can be modified at once. Bulk operations are very limited, potentially due to their back-end database or data retrieval processes that can be improved. Regarding improvements for Torq, when we were onboarded, there were aspects we were uncertain about, such as the number of cases that could be generated, what data we could bring in, how many clients we could onboard, and similar concerns. Initially, we also lacked clarity about the number of playbooks or workflows we could build. Different triggers like system triggers, case-based triggers, and others can be employed without restrictions, but when it comes to on-demand and scheduled jobs, there is a limitation based on the subscription and pricing tier that notably caps the number of workflows we can create. No bulk editing across cases was one issue, along with limited filtering related to single grouping constraints. Additionally, the out-of-the-box case templates provided require substantial modifications before they become usable. There is also a feature in the cases for notes that cannot be searched. They are only visible through the UI, which is another area for improvement. The workflow and execution-based charges seem misleading as this was not discussed initially. I am not sure if new customers are made aware of this. It seems that workflows revolving around cases hinder functionality outside of case management, as we have many use cases needing on-demand triggers and schedules for functions like reporting or polling devices. Creating additional workflows to achieve basic functionalities raises costs significantly, which disadvantages customers. While they facilitate optimization and scaling, the support received tends to be very basic. Improvements can be made in that area as well.
AhmedKonsowa - PeerSpot reviewer
Senior Pre-Sales Engineer (Commercial Sector) at Cyber Knight
A stable solution with excellent features and a helpful technical support team
We use the solution for cyber fusion centers The product has a lot of strong points compared to other tools. The prices must be reduced. I have been using the solution for one year. I am using the latest version of the solution. I rate the tool’s stability a nine out of ten. In my company,…
reviewer1799727 - PeerSpot reviewer
Manager, IT Security Operations at a non-profit with 11-50 employees
Reliable and good support but can be expensive
I have no real complaints about the solution. Threat detection could be better. They need to enhance their threat intelligence feeds. We would like to have more IOCs or more trade intelligence to not only rely on the intelligence of the engineer in charge but to have some threat intelligence and some seeds of IOCs and to have the host have some artificial intelligence to reduce the number of false positives. I don't see this solution being very scalable. The solution is pricey.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Under one SOC tool in Torq, analysts get to know everything within the context of an alert or incident they are working on, and this ability to view the whole picture within Torq is one of the major breakthroughs and best offerings of Torq."
"Torq has changed the day-to-day experience for my security analysts and me by saving literally thousands of man-hours per month since we have implemented some of these use cases."
"What I liked the most about Torq is the actual workflow builder, which is really great because they offer a lot of features and convenience features that are useful for any automation engineer."
"We have seen fewer failures of automations from the time Torq came into the picture, we've had a more streamlined process of handling incidents, and at the same time, we've learned to embed the AI into our incident types, and that is how it has helped us in the automation."
"Since we started working with Torq, I am handling much fewer alerts, it is becoming really easy for me to handle an alert, I have all the information that I need, I do not need to connect to different vendors to receive this information, and the main thing I got from Torq is time, which now helps me to build another automated system and learn."
"Once I started to use the system and I saw the potential, it changed all of our work in IT."
"Torq offers the best feature through integration with AI."
"Using that one piece of AI, we auto-closed 511 cases in quarter four alone."
"The product is stable."
"The technical support team is helpful."
"The most valuable feature is the way it captures the traffic, and it contains every detail of the communication."
"This solution allows us to locate the malware in real-time."
"We use it for IT security purposes; this is our central log management solution, so we incorporate all of our servers and PCs into this software and can monitor the logs from there."
"The detection rate and tracking features including historical tracking, tracking of the fires on the desk, and tracking of the file last monitored are all quite valuable for us."
"The most valuable feature of RSA NetWitness Network is the single unified dashboard from which you can manage all the different products of RSA. Additionally, the integration with native applications is good."
"I would highly recommend the solution. Just go ahead and get it."
"Technical support is knowledgeable."
"The solution is stable."
 

Cons

"It was able to capture data but was unable to differentiate between the agent hostname we are using and the hostname that resides on the back end of the Internet."
"I wish Torq's AI assistant for building templated workflows from scratch worked better; when you start with a blank slate, asking AI to help you build or template the workflow out does not go well."
"Torq does extensive marketing saying that SOAR is dead and markets itself as an all-in-one solution, but this is not actually true."
"The workflow and execution-based charges seem misleading as this was not discussed initially, and creating additional workflows to achieve basic functionalities raises costs significantly, which disadvantages customers."
"We have MCP that we are working with our cloud security platform, and we wanted to connect this MCP to the case management."
"Torq can be improved by adding some more features, such as adding more automation and providing a no-code option so I don't have to code for everything."
"The initial deployment of Torq was not easy."
"Regarding stability, I have noticed some lagging, crashing, and downtime, which is one of my largest gripes."
"The tool doesn't integrate well with ServiceNow."
"The prices must be reduced."
"The integration of the solution needs to be improved. The dashboard needs lots of updates as well. In the next release, we would like to see advanced fraud detection features."
"NetWitness Endpoint's blocking feature does not work properly - if there's a malicious process, it's not possible to kill it via a custom rule unless and until it's flagged as malicious."
"The solution is modular, for example you can buy the RSA ePack, which you buy as a module is not part of the conduit solution. They could include it and have it as an all-in-one solution."
"The solution doesn't have a reporting engine which would be helpful."
"The initial setup requires a high level of skill, then the setup is good and smooth."
"The contamination feature could be improved."
"RSA NetWitness Network could improve on integration with non-native application integration."
"The solution lacks a reporting engine."
 

Pricing and Cost Advice

Information not available
Information not available
"NetWitness Endpoint is less costly than its competitors, but it offers fewer features."
"It is an expensive product."
"It is highly scalable. It can be bought based on your requirements."
"With RSA, there is flexibility in choosing the service, products, and the range that meets your requirement, as well as they are flexible in terms of pricing."
"The cost depends on the number of endpoints that you want to monitor, but it is not expensive."
"We are on a three-year contract to use RSA NetWitness Network."
"The price of the solution depends on the environment. If the environment is large then it will cost more. However, the larger the environment with more endpoints, you will receive an increased discount. If the environment is very small, then you might think it is expensive. It is always better to buy in bulk to receive a discount. The minimum number of assets is usually 500, with discounts on 1000 and 2000."
"I do not have any opinion on the pricing or licensing of the product."
report
Use our free recommendation engine to learn which Threat Intelligence Platforms (TIP) solutions are best for your needs.
915,341 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Outsourcing Company
12%
Financial Services Firm
11%
Comms Service Provider
10%
Manufacturing Company
9%
Comms Service Provider
20%
Healthcare Company
11%
Construction Company
11%
Outsourcing Company
9%
Financial Services Firm
11%
Outsourcing Company
10%
Comms Service Provider
9%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business6
Midsize Enterprise5
Large Enterprise13
No data available
By reviewers
Company SizeCount
Small Business10
Midsize Enterprise2
Large Enterprise6
 

Questions from the Community

What needs improvement with Torq?
There are some bugs in Torq, of course. They can be present in data transformation, some UI debugging, and other area...
What is your primary use case for Torq?
My main use case for Torq is the automation of cyber security processes through a SOAR platform and APIs. A main exam...
What advice do you have for others considering Torq?
Regarding someone thinking about using Torq, I recommend looking into their provided academy to start working with th...
Ask a question
Earn 20 points
Ask a question
Earn 20 points
 

Also Known As

No data available
CSOL, Fusion and Threat Response, Threat Intelligence eXchange, Security Orchestration and Automation (SOAR)
RSA ECAT, NetWitness Network
 

Overview

 

Sample Customers

Information Not Available
Information Not Available
ADP, Ameritas, Partners Healthcare
Find out what your peers are saying about Cyware Cyber Fusion vs. NetWitness NDR and other solutions. Updated: September 2026.
915,341 professionals have used our research since 2012.