Try our new research platform with insights from 80,000+ expert users

Picus Security vs XM Cyber comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Picus Security
Average Rating
9.0
Reviews Sentiment
7.9
Number of Reviews
6
Ranking in other categories
Breach and Attack Simulation (BAS) (4th)
XM Cyber
Average Rating
8.6
Reviews Sentiment
6.9
Number of Reviews
5
Ranking in other categories
Continuous Controls Monitoring (3rd), Vulnerability Management (32nd), Cloud Security Posture Management (CSPM) (22nd), Continuous Threat Exposure Management (CTEM) (4th)
 

Mindshare comparison

Picus Security and XM Cyber aren’t in the same category and serve different purposes. Picus Security is designed for Breach and Attack Simulation (BAS) and holds a mindshare of 14.6%, down 19.0% compared to last year.
XM Cyber, on the other hand, focuses on Continuous Threat Exposure Management (CTEM), holds 12.2% mindshare, down 14.7% since last year.
Breach and Attack Simulation (BAS) Market Share Distribution
ProductMarket Share (%)
Picus Security14.6%
Pentera24.9%
Cymulate17.0%
Other43.5%
Breach and Attack Simulation (BAS)
Continuous Threat Exposure Management (CTEM) Market Share Distribution
ProductMarket Share (%)
XM Cyber12.2%
Pentera16.9%
Cymulate16.3%
Other54.6%
Continuous Threat Exposure Management (CTEM)
 

Featured Reviews

KA
Information Security System Manager at CS-Consulting
A tool with great integration capabilities and a good support team
Picus Security has been implemented in our organization to enhance threat detection by allowing us to test some of the other security tools in our company. I recommend the product to others who plan to use it. The tool has not had an impact on our company's overall security posture since the time of implementation since we just used it for some testing purposes, during which it did show some interesting results. I rate the overall tool a nine out of ten.
Stephen Owen - PeerSpot reviewer
Group CISO at a insurance company with 51-200 employees
Has significantly improved risk visibility and optimized remediation efforts across dynamic environments
We tightly integrate with APIs, consuming feeds and open source data. We have integrated with XM Cyber, and we are elevating ourselves with AI and MCP tools as we view this as a forerunner to reducing the workload for our agents and IT staff. We're pushing all our security partners to provide AI and MCP tools. Our vision is for them to offer a chat interface where a junior IT or an experienced infrastructure engineer can ask for what needs to be patched next without using an interface. Their current interface is very usable and professional, ranking in the top tier of applications. Their reporting is good, offering custom reports, and their API integration is a new capability that serves us well. We have high expectations for the next generation, such as a chat interface to ask questions. However, everything has been very good. We push the boundaries with digital twins; I understand XM Cyber uses a similar concept of graph databases to map environments. I would like access to that and querying languages, enabling more informed business decisions. XM Cyber sees much of our estate, which is beneficial for making informed decisions, and we can harness those insights and data for business analytics. For instance, it could help us gain insights into change management—if a particular server impacts another and that server is supported by yet another server, we could glean significant insights for change management meetings.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable feature of Picus Security is its threat intelligence, providing suggestions to block and prevent attacks by identifying malicious files and providing threat IDs."
"You have the liberty of physically executing a specific set of rules in your environment."
"It's very useful software because the customer mostly configures their IPS and manages their firewalls, WAF, and the DBS according to the latest update, latest news, or according to the situation."
"It provides good reports and offers signature-based solutions."
"The most valuable feature of the solution is its integration capabilities with the other security tools."
"One of the most valuable features would be the detection capability, specifically the ability to detect alarms and logs collected from SIEM tools."
"The platform's most valuable feature is attack simulation."
"What I personally like very much, from my experience, is that it is very reliable."
"XM Cyber made it clear that browser vulnerabilities were the top priority because the platform was able to examine how vulnerabilities within our estate could be exploited and what the path would be from some bad actor in order to exploit those vulnerabilities."
"Six weeks into using XM Cyber, we saw a compelling return on investment—primarily in risk reduction, with a specific issue our other security tooling did not pick up but XM Cyber did, reducing IT remediation time and saving over 60,000 US dollars per year while significantly lowering our loss exposure amount."
"Since implementing XM Cyber, we have improved the way we are doing patching, focusing on the choke points in our patching cycle, and it improves the way we assess the risk."
 

Cons

"The amount of integrations that the product can handle is an area of concern, making it one of the aspects where improvements are required."
"According to the attack vectors, you cannot specify which product is failing or which product is working well because there's no agent."
"Let's say if a customer's environment has 10 security devices and they need to know that there is an attack that has bypassed their devices, they cannot go and inspect every device and every rule in their security devices."
"The reporting and data analysis could be improved. Specifically, the analysis of the results."
"To improve, Picus Security could consider establishing a data center in India to address trust issues and increase interest from Indian customers."
"There is room for improvement in the response rate provided by customer support."
"XM Cyber could identify all areas of vulnerability. They could expand the identification span for different areas."
"There are many interesting things about XM Cyber, but the part that can be improved is the mobile exposure and the IBM i specific equipment."
"We have not saved any time or effort, but we can prove that the effort involved around vulnerability management has been better spent to greater effect, and we've been able to demonstrate that vulnerabilities that do represent a high risk have been remediated more rapidly and more effectively."
"We have high expectations for the next generation, such as a chat interface to ask questions."
"We'd like to see a cheaper price."
 

Pricing and Cost Advice

"They have certain price ranges for their products, depending upon the use cases, and the number of applications the customer wants to try."
"There is a yearly license according to the number of vectors. The pricing is moderate."
"We have to pay standard licensing fees."
report
Use our free recommendation engine to learn which Breach and Attack Simulation (BAS) solutions are best for your needs.
879,986 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
18%
Computer Software Company
9%
Manufacturing Company
7%
Government
7%
Computer Software Company
12%
Financial Services Firm
10%
Manufacturing Company
9%
Retailer
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
No data available
 

Questions from the Community

What do you like most about Picus Security?
The most valuable feature of Picus Security is its threat intelligence, providing suggestions to block and prevent attacks by identifying malicious files and providing threat IDs.
What is your experience regarding pricing and costs for Picus Security?
The pricing of Picus Security is average, and it offers a good value for money.
What needs improvement with Picus Security?
There is room for improvement in the response rate provided by customer support. Picus Security could improve the response time.
What do you like most about XM Cyber?
The platform's most valuable feature is attack simulation.
What is your experience regarding pricing and costs for XM Cyber?
My experience with pricing, setup cost, and licensing was that we have a large, complicated estate, and in the licensing discussions, we were keen not to have the cost balloon because of the compli...
What needs improvement with XM Cyber?
There are many interesting things about XM Cyber, but the part that can be improved is the mobile exposure and the IBM i specific equipment.
 

Comparisons

 

Overview

 

Sample Customers

Akbank, Exclusive Networks, Garanti, ING Bank, QNB Finansbank, Turkcell, Vodafone, Yapı Kredi
Hamburg Port Authority, Plymouth Rock Corporation
Find out what your peers are saying about Picus Security vs. XM Cyber and other solutions. Updated: December 2024.
879,986 professionals have used our research since 2012.