


NetWitness NDR and IBM Resilient compete in the cybersecurity market. Customers favor NetWitness NDR for its support and pricing, while IBM Resilient is valued for its robust features despite higher costs.
Features: NetWitness NDR provides real-time network traffic analysis, extensive reporting capabilities, and detailed network visibility. IBM Resilient offers incident response automation, strong workflow management, and comprehensive incident response capabilities.
Room for Improvement: NetWitness NDR could enhance integration capabilities and expand third-party system compatibility. Some users suggest improving its interface flexibility and reducing configuration complexity. IBM Resilient might benefit from a more user-friendly setup process, additional customization options, and improvements in ease of integration with more external tools.
Ease of Deployment and Customer Service: NetWitness NDR is known for its straightforward deployment and efficient customer support. In contrast, IBM Resilient may involve a longer setup but provides rich training resources and comprehensive documentation, helping users fully utilize its features.
Pricing and ROI: NetWitness NDR is appreciated for its competitive pricing and favorable ROI through cost-effective deployment. IBM Resilient has a higher initial cost, justified by extensive capabilities in addressing complex security threats, offering substantial ROI for those needing advanced incident management features.
| Product | Mindshare (%) |
|---|---|
| Torq | 3.7% |
| IBM Resilient | 2.2% |
| NetWitness NDR | 1.7% |
| Other | 92.4% |

| Company Size | Count |
|---|---|
| Small Business | 1 |
| Midsize Enterprise | 4 |
| Large Enterprise | 4 |
| Company Size | Count |
|---|---|
| Small Business | 9 |
| Midsize Enterprise | 2 |
| Large Enterprise | 7 |
| Company Size | Count |
|---|---|
| Small Business | 10 |
| Midsize Enterprise | 2 |
| Large Enterprise | 6 |
Torq is the enterprise AI SOC solution that effectively combines adaptive insights and automation to handle critical threats efficiently. It manages threat lifecycles, swiftly moving from triage to response, ensuring effective risk management.
Torq is designed to streamline security operations by aggregating telemetry across your security stack. It investigates significant risks and manages threats from triage to containment and remediation. This AI-driven tool enhances the capabilities of your SecOps team, allowing them to achieve more impactful results without introducing complicated processes.
What are the key features of Torq?In industries like finance and healthcare, Torq shows effectiveness by adapting to specific risk scenarios often encountered in these fields. Its integration with existing infrastructures makes it a valuable asset for maintaining stringent security standards, essential for protecting critical data and operations in diverse high-stakes environments.
IBM Resilient is renowned for its ease of use, flexibility, and stability, seamlessly integrating with IBM QRadar to support comprehensive incident response.
IBM Resilient excels in facilitating dynamic playbook creation and managing security threats effectively with a mature, scalable architecture. Its integration capabilities and complete stack make it pivotal for incident response automation and orchestration. However, it requires enhanced integration with third-party applications, improved technical support, and better pricing strategies. Users have noted complexities in setup, necessitating more detailed documentation and customization efforts.
What are IBM Resilient's most important features?IBM Resilient is deployed across sectors like finance and governance, aiding in incident response automation. It supports security services management, integrates with IBM QRadar, and leverages the MITRE ATT&CK tactics. Benefiting from its flexibility, it's ideal for case management, research, and integrating with other security controls, allowing organizations to handle incidents effectively.
NetWitness NDR provides robust network security features, offering full visibility and effective incident response. Its seamless integration and user-friendly interface support malware detection and real-time threat tracking.
NetWitness NDR stands out for its comprehensive traffic details and compatibility across operating systems. It features a unified dashboard and lightweight installation, making it user-friendly without IT support. The system supports orchestration features and user behavior analytics. While deployment is somewhat modular and complex, it serves well for network security, malware analysis, and digital forensics. NetWitness integrates smoothly with third-party apps using its intuitive API, though improvements could be made in areas like SOAR integration, hunting features, and scalability, alongside addressing pricing and licensing complexities.
What are NetWitness NDR's Key Features?Banks and telecom companies utilize NetWitness NDR for detecting indicators of compromise, analyzing intrusion history, and providing risk scores. It functions as both a SIEM tool and a network forensic instrument, proving essential for sectors focused on network security and threat prevention.
We monitor all Security Orchestration Automation and Response (SOAR) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.