

Based on user reviews, Trellix Active Response is a superior product due to its robust features, despite users being happier with the pricing and support of Code42 Incydr.
Features: Code42 Incydr offers strong data loss prevention capabilities, endpoint protection, and insider threat detection. Trellix Active Response provides advanced threat detection, automated response features, and a more comprehensive feature set which users find particularly valuable.
Room for Improvement: Users of Code42 Incydr suggest enhancements in cross-platform support, real-time alert capabilities, and additional integrations. For Trellix Active Response, feedback points to the need for a more intuitive setup process, enhanced integration with other security tools, and improved dashboard usability.
Ease of Deployment and Customer Service: Code42 Incydr is noted for its straightforward deployment process and responsive customer service. Trellix Active Response, while powerful in defense mechanisms, has a more complex deployment and less satisfactory customer service.
Pricing and ROI: Users find Code42 Incydr's pricing more attractive and aligned with its offerings, highlighting a favorable ROI. Trellix Active Response, although higher in price, is seen as worth the investment due to its superior feature set. Pricing specifics were not disclosed in the reviews.
Mimecast Insider Risk Management and Data Protection eases the workload through automation, through policies and rules that are pre-configured to handle complex tasks that would take hours and days for a team to initiate.
With Mimecast Insider Risk Management and Data Protection, our investigation time for high-risk incidents has been cut in half, and overall management now takes us less than four hours a week.
There have been scenarios where we have stopped users from sharing data, and that data has been successfully protected from leaving the premises, adding tremendous value for us.
While we haven't yet quantified the financial benefits, we recognize that there has been a return on investment, particularly with operational efficiencies provided by the alerts.
I would rate the customer support a perfect 10.
I have never had any problems with the customer support, and they are very responsive.
They resolve issues according to their established SLA.
I would rate technical support from Trellix Active Response as a seven because sometimes we face difficulties finding engineers quickly, leading to customer frustration.
The tool effectively detected both malware and spam, ensuring that only a few emails categorized as malware reached user mailboxes.
I would rate the scalability of Mimecast Insider Risk Management and Data Protection around 9.5, as it is highly scalable and widely used by many organizations, including large enterprises.
As the organization grows, Mimecast scales its cloud resources to handle increased demand.
The scalability of Active Response is satisfactory.
Mimecast Insider Risk Management and Data Protection is stable in my experience.
Mimecast Insider Risk Management and Data Protection is definitely stable without fail based on my experience.
If Mimecast could provide more information about how they store the data and whether the agents are local agents or cloud-hosted agents, that would be of great help for the organizations to consider its AI capabilities while adhering to the compliance needs of a particular organization.
Mimecast Insider Risk Management and Data Protection should incorporate features to detect if a URL is malicious or generated by AI, especially since many attackers use scripts to bypass mail gateways.
The policies are solid, they work effectively, the implementation time is not very long, integrations with SIEM are quite easy, and the Glassbreak account is something I have tested.
We would like Trellix to optimize the technology for these systems similarly to how it is deployed for normal endpoints.
There is room for improvement in the platform area and security area to make the dashboard visibility clearer and easier for customers to monitor malicious activities occurring in their environment.
The setup cost is a one-time investment that will stay with us forever.
After migrating, the cost is almost a 50% discount.
My experience with pricing, setup cost, and licensing indicates that pricing is always very expensive.
Based on our evaluations, Trellix Active Response's pricing was the most feasible from a cost perspective.
Mimecast Insider Risk Management and Data Protection has positively impacted our organization as it has helped us identify a lot of phishing emails and stopped many unauthorized disclosures or accidental disclosures of information.
The second thing is that the alert getting triggered is very fast. There is no latency issue that we have observed.
If you want to secure your communication through email, you have to deploy Mimecast Insider Risk Management and Data Protection in your network infrastructure.
They notify us immediately of any vulnerabilities on the endpoints, allowing us to deploy a response quickly.
The most valuable feature of Trellix Active Response is that whenever any incident occurs, it allows us to disconnect from that particular network or area and shut down the system using commands.
| Product | Mindshare (%) |
|---|---|
| Mimecast Insider Risk Management and Data Protection | 2.7% |
| Microsoft Purview Data Loss Prevention | 5.7% |
| Forcepoint Data Loss Prevention | 4.4% |
| Other | 87.2% |
| Product | Mindshare (%) |
|---|---|
| Trellix Active Response | 0.6% |
| CrowdStrike Falcon | 7.1% |
| Microsoft Defender for Endpoint | 5.5% |
| Other | 86.8% |

| Company Size | Count |
|---|---|
| Small Business | 33 |
| Midsize Enterprise | 30 |
| Large Enterprise | 44 |
Mimecast Incydr protects organizations against insider risk and data exfiltration, whether accidental, negligent, or malicious. It monitors endpoint, cloud, browser, and email activity to see when files move to places you don't trust, without requiring policies, proxies, or content classification to work. Administrators get a single dashboard for data flow visibility, adaptive controls ranging from education to blocking, and integrations with HR, endpoint detection, and identity systems to automate response as risk changes.
What key features should users explore?
What benefits can impact ROI?
Industries and use cases
Mimecast Incydr is used across industries to address insider risk, departing employee data theft, and shadow AI exposure. Enterprises use it to monitor data movement across endpoint, cloud, and browser channels, automate watchlisting during employee offboarding, and gain visibility into how employees and AI tools interact with sensitive data, supporting both security operations and compliance requirements in regulated industries.
Trellix Active Response is designed for efficient endpoint protection and incident handling, with features like advanced analytics and user behavior monitoring. It allows swift identification of vulnerabilities and supports effective incident management through seamless system commands.
Focused on enabling secure corporate workstations, Trellix Active Response offers quick incident responses, comprehensive threat hunting, and defense visualization. The system prioritizes rapid log collection and correlation via the ePO dashboard, aiming to protect approximately 1,300 endpoints, especially on remote worker desktops and laptops. While it brings robust monitoring and investigation capabilities, the solution seeks improvements in analytics, interface clarity, and memory performance. There is a need for enhanced integration with on-premises deployments and AI functionalities.
What are the key features of Trellix Active Response?In corporate settings, Trellix Active Response is deployed for endpoint security, particularly for remote workstations that require robust protection. Companies transitioning from existing setups to Trellix benefit from its integration capabilities and threat hunting efficiency, supporting better management of active response tasks. Industry users appreciate the visual dashboard for improved threat response.
We monitor all Data Loss Prevention (DLP) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.