No more typing reviews! Try our Samantha, our new voice AI agent.

Kaspersky Next XDR Optimum vs ReliaQuest GreyMatter comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Apr 9, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Ranking in Extended Detection and Response (XDR)
4th
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
115
Ranking in other categories
Endpoint Protection Platform (EPP) (4th), Endpoint Detection and Response (EDR) (5th), Ransomware Protection (2nd), AI-Powered Cybersecurity Platforms (1st)
Kaspersky Next XDR Optimum
Ranking in Extended Detection and Response (XDR)
15th
Average Rating
8.0
Reviews Sentiment
7.2
Number of Reviews
124
Ranking in other categories
Endpoint Protection Platform (EPP) (11th), Endpoint Compliance (3rd), Endpoint Detection and Response (EDR) (21st)
ReliaQuest GreyMatter
Ranking in Extended Detection and Response (XDR)
25th
Average Rating
9.6
Reviews Sentiment
8.1
Number of Reviews
2
Ranking in other categories
Digital Risk Protection (11th), Managed Detection and Response (MDR) (17th)
 

Mindshare comparison

As of August 2026, in the Extended Detection and Response (XDR) category, the mindshare of Cortex XDR by Palo Alto Networks is 4.5%, down from 5.0% compared to the previous year. The mindshare of Kaspersky Next XDR Optimum is 1.5%, down from 3.0% compared to the previous year. The mindshare of ReliaQuest GreyMatter is 0.9%, up from 0.5% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Extended Detection and Response (XDR) Mindshare Distribution
ProductMindshare (%)
Cortex XDR by Palo Alto Networks4.5%
Kaspersky Next XDR Optimum1.5%
ReliaQuest GreyMatter0.9%
Other93.1%
Extended Detection and Response (XDR)
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
SR
Group CIO at Thal Industries Corporation Ltd
Have maintained strong endpoint protection through behavioral analysis and daily monitoring
I previously mentioned that Kaspersky Endpoint Security for Business doesn't have built-in DLP, which was a concern. I think they could add it in the future; however, antivirus cannot provide a proper DLP solution, but they can offer a mix of DLP, similar to Trend Micro Apex One, which provides some sort of DLP file management. Nonetheless, we need a proper DLP solution such as Forcepoint or Symantec, whichever suits us. We'll be conducting performance evaluation in the next quarter while working on other projects. More value means a better GUI, user interface, and comprehensive reporting capabilities. In Sophos, we receive a daily system-generated report about what is happening, plus an alert system. The reporting system in Trend Micro is also excellent; I receive an email every day at 10:00 AM with a report for the last 24 hours.
MK
Senior Security Analyst at Tata Consultancy
Unified security monitoring has reduced alert fatigue and improves proactive threat hunting
I use real-time monitoring in ReliaQuest GreyMatter, which significantly improves my security posture. The unified interface helps reduce alert fatigue. I would estimate it saves around 20% in alert fatigue reduction. The automated threat hunting capabilities in ReliaQuest GreyMatter help me stay ahead of threats. The machine learning algorithm benefits my threat intelligence by providing deeper insights and predictions. I use various metrics to rate the success of the predictive threat intelligence in ReliaQuest GreyMatter.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The best feature of Cortex XDR by Palo Alto Networks is that it collects logs from different sections such as the endpoint, the network, and the cloud, making it easy to investigate alerts, collect some of the investigation packages related to the infected machines, and provide live response."
"My advice for others looking into using Cortex is that it is very easy to use and very useful for the customer environment, whether it's a public or private one."
"What I like about Cortex XDR by Palo Alto Networks is that it is a comprehensive solution that contains everything the organization may need when using endpoints."
"Palo Alto is the best security solution in the market."
"Cortex XDR by Palo Alto Networks saves time in various ways, although the user interface is fairly standard."
"My advice for anybody who is considering Cortex XDR is that it is a complete solution, and has very good features."
"These days it's machine-learning technology and behavior-based analytics features that make us more secure."
"I don't have to do much monitoring with it; I don't have to have anybody manually looking at this, it gives us reports, and it lets us know if something needs to be addressed, and we can easily address it."
"Kaspersky Endpoint Security protects us against viruses and dangerous software, and it's also great because it has a component that is useful for the deployment of software versions to the end user's computer."
"It performs quite well as a firewall protection provider."
"I think all the features of Kaspersky Endpoint Security for Business are beneficial because it offers unified endpoint management with security features."
"With updates, you'll be at least 90% protected."
"I like that this solution is pretty easy to use and also that it gives me some kind of granularity about the things I want to configure."
"The product can scale if you need it to."
"The most valuable feature is the central view, and with this view, I can see all of the data."
"The solution is scalable, we have 500 users using this solution."
"ReliaQuest GreyMatter saves around 60% of time or resources."
"ReliaQuest GreyMatter has helped us to reduce security incidents by 89%, which is a significant amount of incidents we have seen."
 

Cons

"When it comes to malware files, it should be a little quick because, at times, it would give a wrong result in the sense of what it might be on malware, even if it still might be a normal one."
"The technical support is not very good. I find the process difficult."
"The onboarding process could be better."
"The playbooks could be improved to include more functionalities or actions."
"It's not an ideal choice for smaller businesses, as you need a minimum of 200 endpoints to even use the solution at all."
"This is a very costly product."
"Basically, they don't provide customer support tools just to investigate the logs."
"There are some third-party solutions that are difficult to integrate with, which is something that can be improved."
"The performance of our machines tended to slow down under Kaspersky. That definitely needs to be addressed. I remember I had a pretty good Dell Notebook, and this product slowed it down quite a bit."
"Areas for improvement include signature update management and selecting the respective features on the endpoint side."
"It's does not have the architecture or structure to scale up."
"I'd like to see them improve encryption and remote management in the future. Kaspersky could also improve its scanning technology. Other solutions have adopted machine learning and deep learning, but Kaspersky still uses signature-based scanning."
"The support must provide quick responses."
"This product could be improved by integration with Linux. The one limitation this product has is that it's not compatible with and doesn't offer protection for Linux servers. It could also be easier to configure."
"They're restricted to endpoint protection for now, I'd like to see some additional products."
"Reaching their support team can be difficult."
"Areas that have room for improvement include user interface and integration."
 

Pricing and Cost Advice

"The solution is expensive. It's pricing is on a yearly-basis."
"We pay about $50,000 USD per year for a bundle that includes Cortex XDR."
"It is "expensive" and flexible."
"The return on investment is from the user side because we have seen the performance of it increase the delivery time of the product if we are using too many web-based and on-premise applications. In indirect ways, we saw the return of investment in terms of performance and user satisfaction increase."
"Its pricing is kind of in line with its competitors and everybody else out there."
"It has reasonable pricing for the use cases it provides to the company."
"It is cost-effective compared to similar solutions. It fits for the small businesses through to the big businesses."
"I did PoCs on products called Cylance and CrowdStrike. Although, I consider these products and they were also good, when it come to cost and budgetary factors, Traps has been proven to be better than the other two products. It is quite cost-effective and delivers all the entire solution which we require."
"I received a very good deal with Kaspersky."
"Pricing is very competitive and licensing is very much ethical."
"The price is reasonable. We evaluated some other vendors, but Kaspersky charges less and offers more."
"Kaspersky Endpoint Security for Business' pricing is reasonable, and licensing costs are annual."
"The price of this solution is affordable and there is only a standard license required."
"It would be beneficial if the price could be reduced, and improved management of the license allocation for adding additional Endpoint users would be advantageous."
"It is quite standard, because we use the volume licensing."
"The pricing is a bit more expensive than other products."
Information not available
report
Use our free recommendation engine to learn which Extended Detection and Response (XDR) solutions are best for your needs.
909,725 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Construction Company
12%
Comms Service Provider
10%
Financial Services Firm
10%
Manufacturing Company
10%
Outsourcing Company
12%
Construction Company
10%
Manufacturing Company
9%
Comms Service Provider
7%
Financial Services Firm
10%
Manufacturing Company
10%
Construction Company
8%
Retailer
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business46
Midsize Enterprise21
Large Enterprise54
By reviewers
Company SizeCount
Small Business63
Midsize Enterprise27
Large Enterprise33
No data available
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
What needs improvement with Kaspersky Endpoint Security?
Kaspersky Endpoint Security for Business does not have encryption tools. It uses the Windows BitLocker tool, which is...
What is your experience regarding pricing and costs for Kaspersky Endpoint Security for Business?
The pricing and licensing cost of Kaspersky Endpoint Security is cheaper compared to Trend Micro.
What is your primary use case for Kaspersky Endpoint Security for Business?
I have good experience in the sales part of Kaspersky Endpoint Security for Business, not the technical side. I am no...
What needs improvement with ReliaQuest GreyMatter?
Areas that have room for improvement include user interface and integration.
What is your primary use case for ReliaQuest GreyMatter?
I use ReliaQuest GreyMatter for detection and response, XDR, and SIEM. The best features I like about GreyMatter the ...
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
Kaspersky Work Space Security, Kaspersky Endpoint Security
No data available
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
ACMS, Arqiva, Pakistan International Airlines, RAO UES
Information Not Available
Find out what your peers are saying about Kaspersky Next XDR Optimum vs. ReliaQuest GreyMatter and other solutions. Updated: June 2026.
909,725 professionals have used our research since 2012.