


IBM Security QRadar and ThreatConnect Threat Intelligence Platform (TIP) are both key players in the security management and threat intelligence category. Based on the comparison, IBM Security QRadar might have the upper hand due to its integration capabilities with Watson, which enhances threat detection.
Features: IBM Security QRadar excels in integrating various tools, offering extensive log management, and providing predefined templates and reports. It also enhances efficiency with a robust app exchange for customization. ThreatConnect TIP is known for centralizing threat data aggregation and providing automation and playbooks for improved threat response.
Room for Improvement: IBM Security QRadar faces challenges in technical support, licensing structure, and handling large datasets. ThreatConnect TIP could improve its user interface for smoother operations and expand its integration with other security tools to enhance efficiency.
Ease of Deployment and Customer Service: IBM Security QRadar offers both on-premises and cloud deployment options with varied user experiences in configuration complexity. Customer service responsiveness varies by region. ThreatConnect TIP, with its cloud focus, simplifies deployment, though support responsiveness is noted as an area needing improvement.
Pricing and ROI: IBM Security QRadar is priced on events per second, which can be costly yet justified by its features. TIP positions itself as a mid-to-higher cost option, offering value through automation and flexible licensing, scaling with company size for potential ROI enhancement.
Since we started working with Torq, I am handling much fewer alerts. It is becoming really easy for me to handle an alert.
We have seen a return on investment, targeting a $600,000 ROI for the year.
I have seen a return on investment with Torq, as the automation reduces the number of employees needed and significantly saves both time and resources.
With SOAR, the workflow takes one minute or less to complete the analysis.
AWS gives the chance to implement a solution out of the box with use cases that are already in IBM Security QRadar.
Investing this amount was very much worth it for my organization.
We have reduced manual analyst effort by thirty to forty percent.
My impression of their technical support during the initial setup was that they were helpful, responded within a reasonable timeframe, and provided exactly what we needed.
The speed and quality of their answers have been pretty good, as I usually get a response within 24 hours, and they follow up well.
We can always get an answer, and the support team are experts in their own system.
They assist with advanced issues, such as hardware or other problems, that are not part of standard operations.
Support needs to understand the issue first, then escalate it to the engineering team.
The support is really good; for instance, if a critical ticket is submitted, you will get paged right away as it gets logged, and their analyst will look into it, letting you know as soon as possible so you can work on it.
They have been responsive, knowledgeable, and helpful.
Its scalability is good because it has a cloud-native architecture and it expands dynamically to handle thousands of alerts at the same time.
Our case management is super scalable.
In terms of scalability, you can do as long as you can build it, and they can support it.
For EPS license, if you increase or exceed the EPS license, you cannot receive events.
We have been using Torq for one and a half years, but we have experienced no downtime.
Most of the time, the system is stable as long as the components that they integrate with are stable.
I have never faced any downtime or issues.
On cloud, you don't see any disconnections or instability.
I think QRadar is stable and currently satisfies my needs.
The product has been stable so far.
Torq should offer default templates that can directly scan firewall data and automate actions.
The AI value depends on maturity. Real value depends heavily on telemetry, integration depth, and workflow design, all of which rely on how mature customers are in their SOC department.
It was able to capture data but was unable to differentiate between the agent hostname we are using and the hostname that resides on the back end of the Internet.
We receive logs from different types of devices and need a way to correlate them effectively.
If AI-related support can suggest rules and integrate with existing security devices like MD, IPS, this SIM can create more relevant rules.
IBM Security QRadar does not support Canvas, so we had to create custom scripts and workarounds to pull logs from Canvas.
ThreatConnect Threat Intelligence Platform (TIP) could be improved by simplifying the user interface to better fit day-to-day analyst workflow.
When they bring more and more value into the platform, it makes more sense to pay that price, but still, it is expensive.
Before deciding to implement Torq, I considered that compared to our old case management platform, Torq was a much better price and had a lot better value for what you get out of the platform, which was a key consideration for the company.
It is an expensive solution, not an inexpensive solution, but we get through the flexibility.
Splunk is more expensive than IBM Security QRadar.
It was costly mainly because of the value you can get right now compared to other solutions.
It depends on how much you want to spend.
Generally, the pricing and setup cost are on the higher side.
Torq's unified platform approach to AI SOC automation and case management has significantly benefited us by integrating the case management platform with the automation, which saves time compared to managing multiple point solutions across our security stack.
The fact that I can build whatever I want within my own imagination and skills without relying on code is the best thing about Torq.
You can copy and paste a cURL command. If you have documentation or APIs, you usually have an example on the side. You basically have all the information on how the API call should be. You can just copy that and paste it into a step, and it will just build the step for you.
Recently, I faced an incident, a cyber incident, and it was detected in real time.
IBM Security QRadar gives the opportunity to improve the time to market of the releases with a great evaluation of cybersecurity breaches.
Compared to ArcSight, Splunk, or any other SIEM tools where you need their processing language such as structured query language, SPL, and in Sentinel there is KQL query languages, IBM Security QRadar doesn't require reliance on query languages.
The API-first architecture that enables us to perform custom integration with other products and real-time distribution.
| Product | Mindshare (%) |
|---|---|
| Torq | 3.6% |
| IBM Security QRadar | 5.7% |
| ThreatConnect Threat Intelligence Platform (TIP) | 3.1% |
| Other | 87.6% |


| Company Size | Count |
|---|---|
| Small Business | 4 |
| Midsize Enterprise | 5 |
| Large Enterprise | 11 |
| Company Size | Count |
|---|---|
| Small Business | 92 |
| Midsize Enterprise | 39 |
| Large Enterprise | 107 |
| Company Size | Count |
|---|---|
| Small Business | 7 |
| Midsize Enterprise | 23 |
| Large Enterprise | 5 |
Torq is the enterprise AI SOC solution that effectively combines adaptive insights and automation to handle critical threats efficiently. It manages threat lifecycles, swiftly moving from triage to response, ensuring effective risk management.
Torq is designed to streamline security operations by aggregating telemetry across your security stack. It investigates significant risks and manages threats from triage to containment and remediation. This AI-driven tool enhances the capabilities of your SecOps team, allowing them to achieve more impactful results without introducing complicated processes.
What are the key features of Torq?In industries like finance and healthcare, Torq shows effectiveness by adapting to specific risk scenarios often encountered in these fields. Its integration with existing infrastructures makes it a valuable asset for maintaining stringent security standards, essential for protecting critical data and operations in diverse high-stakes environments.
IBM Security QRadar offers real-time threat detection, data correlation, and integration with third-party solutions, providing a user-friendly interface, scalability, and extensive reporting capabilities for SIEM needs.
IBM Security QRadar is designed for comprehensive security monitoring in diverse environments, aiding sectors like telecom and finance with advanced threat detection and breach management. It aggregates data and analyzes user behavior, while its customizable and out-of-the-box rules deliver robust security insights and vulnerability management. The platform seeks enhancements in integration, performance, and user interface, with a focus on AI and cloud service compatibility.
What are the most important features of IBM Security QRadar?Telecom, finance, and cloud-based industries implement IBM Security QRadar for threat detection, compliance, and security monitoring. It is deployed for log collection and correlation, user behavior analytics, and ensuring secure data transfer and incident management, focusing on compliance and anomaly detection.
ThreatConnect Threat Intelligence Platform provides a comprehensive solution for operational threat intelligence. It effectively ingests and enriches data, aligning with intelligence requirements for seamless application across security operations.
ThreatConnect TIP stands out by integrating threat intelligence with orchestration for streamlined threat management. It simplifies the user experience with a customizable interface assisting security teams in operationalizing insights across multiple teams without disruption. The platform automates threat scoring and optimizes threat correlation and response, ensuring timely threat detection and protection. Collaboration with Polarity and Risk Quantifier accelerates actionable intelligence, while support and patch management enhance overall user experience. Although improvements in integration processes and training accessibility are necessary, the platform aggregates threat data for efficient threat mitigation.
What are the key features of ThreatConnect TIP?In industries focusing on security, ThreatConnect TIP supports teams in identifying and mitigating security threats through automation. Integrated with cybersecurity networks, it assists in endpoint protection, SOC management, and vulnerability management, being pivotal in threat investigation and intelligence dissemination.
We monitor all Security Orchestration Automation and Response (SOAR) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.