IBM Security QRadar vs Sophos MDR comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Binary Defense MDR
Sponsored
Ranking in Managed Detection and Response (MDR)
7th
Average Rating
9.2
Number of Reviews
15
Ranking in other categories
No ranking in other categories
IBM Security QRadar
Ranking in Managed Detection and Response (MDR)
10th
Average Rating
8.0
Number of Reviews
198
Ranking in other categories
Log Management (6th), Security Information and Event Management (SIEM) (4th), User Entity Behavior Analytics (UEBA) (1st), Endpoint Detection and Response (EDR) (19th), Security Orchestration Automation and Response (SOAR) (4th), Extended Detection and Response (XDR) (11th)
Sophos MDR
Ranking in Managed Detection and Response (MDR)
6th
Average Rating
8.6
Number of Reviews
24
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of July 2024, in the Managed Detection and Response (MDR) category, the mindshare of Binary Defense MDR is 0.8%, up from 0.6% compared to the previous year. The mindshare of IBM Security QRadar is 0.7%, up from 0.1% compared to the previous year. The mindshare of Sophos MDR is 6.0%, down from 6.7% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Managed Detection and Response (MDR)
Unique Categories:
No other categories found
Log Management
5.0%
Security Information and Event Management (SIEM)
9.5%
No other categories found
 

Featured Reviews

BP
Jun 9, 2023
Gives us visibility into current critical security events and improves our time to respond
They send us alerts and have done a really good job of eliminating the false positives. Early on, there were quite a few. But as they learned about our organization and the roles of individuals within it, that has drastically gone down. For example, initially, they would say so-and-so ran a script. Now, they know who our sys admins are and that running that script is typical for them. The benefits are the visibility into current critical security events and the effect on our time to respond. Binary Defense has helped reduce our security alerts because we know where our trouble points are, or if we're missing things, and what we need to deploy. It has given us visibility into what to put in and that is how it has helped us the most. I would estimate it has reduced our security alerts by 60 to 70 percent. It has improved our security posture significantly. And because they do a lot of the management for us, it has reduced our team's workload. We only have to work on the stuff that's identified as something we need to work on, so it has definitely helped performance.
Anto Sebastin - PeerSpot reviewer
Jul 17, 2023
A scalable and easy-to-deploy incident management tool that provides good support
The product is a threat detection and response solution. It is useful for consultants or security analysts. It is an incident management tool We had enabled federated search. It allows us to search data both on-premises and on the cloud. We can check the functional insights. We use keywords for…
Kalyan  Chowdhury - PeerSpot reviewer
Dec 1, 2023
Offers good security parameters, stability and remote deployment available
There are lots of benefits because it includes real-time network threat detection (RNT), IP spoofing prevention, and a 24/7 support system. There is also protection against ransomware attacks.  So basically, customers will benefit greatly after purchasing and using this sophisticated anti-malware…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The biggest aspect for us is that they are able to conform to our environment and utilize our tools. That way, we still maintain ownership of all the data and access to the applications, and we never lose control of the ability to run the solution ourselves if we need to."
"One of the main benefits of Binary Defense MDR is the ability to easily meet with their support team to discuss any issues we encounter."
"The most valuable feature is reviewing tickets and the notes added by technicians."
"The case interface is Binary Defense MDR's most valuable feature."
"Binary Defense is comprehensive. We see most of the questionable activity. Once you see things a couple of times and are familiar with the processes, you know what those are. The level of activity is definitely favorable."
"The most valuable features are the SIEM and the ticketing function; the latter is very smooth and easy to read and understand. We don't have any issues looking at the ticketing information when we're trying to identify what's going on."
"Binary Defense's most valuable feature is the 24/7 monitoring and threat hunting. Their team checks the latest breaches and how they're done."
"With Binary Defense, we don't just get an alert, but also a detailed rundown of why they're alerting us on it. They tell us what was executed, or the username, script, or IP. That way, we're not wasting time investigating."
"Overall a great solution."
"One of the most valuable features of this solution is it has very good data correlation."
"The event collector, flow collector, PCAP and SOAR are valuable."
"It has a logical, user-friendly GUI."
"This console gives you the entire view, which makes life easier and allows you to take precautionary measures."
"The threat protection network is the most valuable feature, because when you get an offense, you can actually trace it back to where it originated from, how it originated, and why."
"We've found the solution to be scalable."
"It does good correlation for events. It does good general analysis, and it has good apps as well."
"The product's most valuable feature is its ability to view environmental activities."
"The solution is stable."
"I like Sophos MDR's inbuilt feature for DLP (Data Loss Prevention)."
"The product gives us good visibility into what is happening inside the company."
"The product’s most valuable features are integration and endpoint protection."
"The authentication it offers minimizes the risk of access."
"The tool's ability to work with security threats is competitive. The best part is monitoring and the way we receive automated emails and updates. When an issue arises, a ticket automatically gets raised, clearly outlining the necessary actions to be taken from our end."
"There is a feature called XDR Central. With this, Sophos can connect to third-party security solutions."
 

Cons

"The only area I see for improvement with Binary Defense is their service portal. It could benefit from some enhancements."
"I would like to see more frequent check-ins with our security status."
"It's hard to think of anything that they need to improve on, but just to point out something, I would like to see them provide advanced XDR."
"I don't find any downside to them, but if I have to put one, it would be consistent manpower or staffing. The only area where the solution can be improved is going to be with people. As they grow, they are struggling with the same thing that every other company is, which is getting talent and getting that talent to stay, but they've just revised their tiering system to go from a flat analyst and manager to a three-tier solution where it goes through two or three before it gets elevated. That seems to have worked out well, so if one level misses it, the next one picks it up, and it works out fine."
"The current reporting system could benefit from improvement."
"We should be able to isolate devices faster. They should shorten the time between clicking on a device to contain it and carrying out the action. That would be a welcome improvement."
"We found that an earlier version of the agent had high memory usage and that was a bit concerning, but we raised the concern with their support team and they immediately replied that they had noticed the same thing and had a candidate fix already available... it totally fixed the issue."
"We found a couple of bugs in the user interface."
"IBM needs to invest more into the collaboration with other vendors."
"QRadar log integration of various applications can be a tough job at times. There may be occasions when you will not find any QRadar guide on adding logs of a particular application. Even if you come across one, adding a log process is not an easy one."
"QRadar's performance has room for improvement because it cannot handle the volume. I need massive amounts of logs from various devices in our existing network architecture. IBM needs to improve QRadar's capacity to handle more logs."
"Dashboards and reports could provide better visualization of SIEM activity."
"While the interface is easy to use, it could be a little more responsive."
"It doesn't have a SOAR system by default. You need to purchase it additionally, which is the main problem with QRadar."
"IBM Security QRadar’s GUI could be improved."
"The whole process for support is something that needs to be improved."
"There is room for improvement in performance and upgrades."
"Endpoint protection is very slow."
"Sophos MDR’s pricing is the biggest factor that needs improvement per customers and technical professionals."
"It could be more secure."
"The product's stability needs improvement."
"The integration with third-party solutions as an area for slight improvement"
"They should improve XDR and threat protection capabilities for zero-day attacks."
"The product's pricing could be less expensive."
 

Pricing and Cost Advice

"The pricing is very good. They are definitely competitive and they were lower at the time that we went with them."
"Binary Defense MDR is priced competitively and may be slightly lower than CrowdStrike."
"It's valued at the right price. Even with the number of endpoints we have, we don't feel that it's a lot more than any competitor. In fact, it might be less expensive when you look at the fact that you're getting a full flex SOC out of it along with the tools."
"The pricing is on target. Working with their sales team on pricing negotiations was a pleasant process. They were very respectful of the constraints we had and I feel that we're paying a fair price."
"After we acquired this platform, we met with a number of different vendors. Binary Defense came in with a proposal that was surprisingly affordable. In fact, we were able to recoup the cost of their services within a short period of time. This is because Binary Defense is able to provide the same level of security as a team of two or three in-house analysts but at a fraction of the cost. As a result, Binary Defense is saving us an estimated $250,000 to $300,000 per year."
"From the initial cost that Binary Defense came in with, we pared it down quite a bit over the course of 30 or 60 days. My leadership would say that their cost was high, but realistically, they were in line with the market."
"The pricing isn't that bad, it's very competitive. I don't feel that it's over-priced and I don't feel that it's under-priced."
"Binary Defense has changed its pricing model from being primarily based on the volume of data to one based on escalations and incidents they handle."
"On a scale from one to ten, where one is cheap and ten is expensive, I rate IBM Security QRadar's pricing a five out of ten."
"The solution is costly and the price differs depending on the vendor you use."
"It's too expensive."
"Pricing is good."
"In terms of additional costs, it depends on the subscription that you choose. There are plenty of options to choose from."
"The maintenance costs are high."
"The price of this solution is reasonable."
"Only enterprise businesses can afford the tool."
"It is an expensive platform."
"The solution is expensive."
"The price falls somewhere in the middle range."
"The cost of the solution is based on how many users use it."
"Compared to other tools, Sophos has a pretty good price."
"MDR is a complete enterprise solution, and compared to other OEMs, it is one of the cheapest."
"The tool is too expensive for small companies."
"I would rate the price of Sophos MDR as a nine out of ten, with ten being the most expensive."
report
Use our free recommendation engine to learn which Managed Detection and Response (MDR) solutions are best for your needs.
793,295 professionals have used our research since 2012.
 

Comparison Review

VS
Jun 28, 2015
Qradar vs. ArcSight
Continuing with the SIEM posts we have done at Infosecnirvana, this post is a Head to head comparison of the two Industry leading SIEM products in the market – HP ArcSight and IBM QRadar Both the products have consistently been in the Gartner Leaders Quadrant. Both HP and IBM took over niche SIEM…
 

Top Industries

By visitors reading reviews
Computer Software Company
18%
Healthcare Company
8%
Manufacturing Company
7%
Financial Services Firm
7%
Educational Organization
20%
Computer Software Company
15%
Financial Services Firm
10%
Government
7%
Computer Software Company
21%
Manufacturing Company
8%
Government
7%
Financial Services Firm
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Binary Defense MDR?
The most valuable feature is reviewing tickets and the notes added by technicians.
What is your experience regarding pricing and costs for Binary Defense MDR?
Binary Defense is reasonably priced, considering that it saves us from hiring personnel and deters threats that could...
What needs improvement with Binary Defense MDR?
The only area I see for improvement with Binary Defense is their service portal. It could benefit from some enhanceme...
What are the biggest differences between Securonix UEBA, Exabeam, and IBM QRadar?
It mostly depends on your use-cases and environment. Exabeam and Securonix have a stronger UEBA feature set, friendli...
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is a...
What do you like most about IBM QRadar?
The event collector, flow collector, PCAP and SOAR are valuable.
What do you like most about Sophos MDR?
The user doesn't need a technician; it offers 24/7 support to identify and manage your infrastructure and take comple...
What needs improvement with Sophos MDR?
The product must provide zero trust security. The security tools for the endpoints must communicate with the firewalls.
What advice do you have for others considering Sophos MDR?
We use the tool in our company. Our customers also use it. We are partners and resellers. I recommend the product to ...
 

Also Known As

Binary Defense Vision, Binary Defense Managed Detection and Response, Binary Defense Managed Detection & Response
IBM QRadar, QRadar SIEM, QRadar UBA, QRadar on Cloud, QRadar, IBM QRadar User Behavior Analytics, IBM QRadar Advisor with Watson
Sophos Managed Threat Response
 

Overview

 

Sample Customers

Securitas USA, Black Hills Energy, Lincoln Electric,The J.M. Smuckers Company, New York Community Bank, State of Connecticut, NCR
Clients across multiple industries, such as energy, financial, retail, healthcare, government, communications, and education use QRadar.
Information Not Available
Find out what your peers are saying about IBM Security QRadar vs. Sophos MDR and other solutions. Updated: May 2024.
793,295 professionals have used our research since 2012.