We changed our name from IT Central Station: Here's why
Cliff Matonda
System Administrator at a non-tech company with 10,001+ employees
Real User
Top 5Leaderboard
Reasonably prices, stable, and straightforward to set up
Pros and Cons
  • "The ability to detect activity on the network is very useful to us. Even if it's not necessarily an illegal activity, if it is abnormal activity, it is able to detect it and notify us."
  • "The solution could be easier to use."

What is our primary use case?

We are primarily using the solution for network monitoring as well as cybersecurity.

What is most valuable?

The ability to detect activity on the network is very useful to us. Even if it's not necessarily an illegal activity, if it is abnormal activity, it is able to detect it and notify us.

The solution is stable.

The product scales well within a network.

The initial setup is pretty simple.

The solution isn't too expensive.

What needs improvement?

The solution could be easier to use.

The user interface is a bit too detailed. They should work to pare it down and simplify it. They seemed to have designed it for an expert user and not a layman. If there are some system administrators who are not experts and they just want to just get sensors reports and escalate, it should be easier for them to do so.

For how long have I used the solution?

I've been using the solution for three years at this point.

What do I think about the stability of the solution?

The solution is very stable. As far as we've been using it, we've not had any major issues. It doesn't crash or freeze. There are no bugs or glitches. It's reliable.

What do I think about the scalability of the solution?

The solution is scalable within the network. If a company needs to expand it, it can do so.

For our particular office, we have around 100 users.

I cannot say if we will increase usage. We have many offices and decisions in relation to usage increases would come from our UK office.

How are customer service and technical support?

Technical support is great. They are very responsive and helpful. We are very satisfied with the level of support they provide to us.

Which solution did I use previously and why did I switch?

We did not previously use a different solution. For cybersecurity, this is our first product. We were using the traditional endpoint protection as well, and we still do. For that, we use Sophos.

How was the initial setup?

The installation was straightforward, from what I understand. I didn't actually handle ht process. That was done by a consultant. 

The deployment was fast. In less than an hour, everything was up and running.

I handle the maintenance myself.

What about the implementation team?

We had a consultant that assisted us with the implementation. They made the process very easy.

What's my experience with pricing, setup cost, and licensing?

We typically do yearly or three-year licensing, however, I can't speak to the exact costs or arrangements.

It's not too expensive. The price is good for what it offers.

What other advice do I have?

We're just a customer and an end-user.

Overall, I'd rate the solution at an eight out of ten. We've mostly been quite happy with the product.

I'd recommend it to other users and organizations.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
Guido Pellillo
Head of Cybersecurity Business Unit at S2E
Real User
Top 20
Provides a visual representation of attack history, with a nice GUI, but the analysis could be simplified
Pros and Cons
  • "I find it very good in the way that they show the past events, including the attack history."
  • "It would be helpful if they could recognize incidents and simplify the customer's challenge to identify what is happening."

What is our primary use case?

We are a system integrator and we pose solutions, including this one, to our clients.

It is mainly used to reinforce response capabilities with respect to network security.

What is most valuable?

I find it very good in the way that they show the past events, including the attack history. You are able to visualize all of the attack paths and connectivity to see what's happened.

The GUI interface is very good.

They are using the best machine learning and AI at the moment.

What needs improvement?

The need to simplify the analysis from a user perspective. In a few cases, you have to be a specialist in order to understand what's happening. It would be helpful if they could recognize incidents and simplify the customer's challenge to identify what is happening.

For how long have I used the solution?

I was been working with Darktrace for two years.

What do I think about the stability of the solution?

Stability-wise, we have not had any issues and it has been quite good.

What do I think about the scalability of the solution?

We haven't had any trouble with scalability.

How are customer service and technical support?

We have had contact with technical support and help was quite straightforward. Our feedback for them is good.

Which solution did I use previously and why did I switch?

We work with a variety of products in the security space including Darktrace, Splunk, Elastic, and others.

How was the initial setup?

The initial setup is really simple. This product is normally deployed as an on-premises appliance and it normally takes less than one day. It depends on how complex the network is, but it's usually quite simple.

What's my experience with pricing, setup cost, and licensing?

Our customers feel that the price of Darktrace is quite high compared to other solutions. However, I feel that they are one of the top solutions in this space and they want to be paid for that.

What other advice do I have?

They are currently working on improving their interface by including AI to help simplify things, but it does not work on real-time data. Rather, it works on historical events.

This is definitely a product that I can recommend, although I would probably be using it together with a SOC service or somebody else who can manage it properly.

I would rate this solution a seven out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Learn what your peers think about Darktrace. Get advice and tips from experienced pros sharing their opinions. Updated: January 2022.
564,997 professionals have used our research since 2012.
Gerald Segura
Seguridad de la Información at Banco Davivienda (Costa Rica) S.A.
Real User
Top 20
Allows us to monitor our network 24/7 without a lot of analysts
Pros and Cons
  • "The main valuable feature is that we don't need a lot of analysts. With few analysts, we have all the network monitored, 24/7."
  • "I would like to see more protection in the endpoint. Especially because we have a lot of people using VPNs. If they would improve end point security, it would give more control there."

What is our primary use case?

Darktrace is deployed on our LAN, inside the network. No site, no internet, it's just for monitoring the LAN, local access network. It helps us to find a lot of threats inside the network. We are very happy with the solution. You don't need to have a lot of analysts with Darktrace who are making or following the incident. This solution helps you to send the notification and avoid threats.

What is most valuable?

The main valuable feature is that we don't need a lot of analysts. With few analysts, we have all the network monitored, 24/7.

What needs improvement?

Firstly, the integration should be improved. 

In terms of what additional features I would like included in the next release of Darktrace, I would like to see more protection in the endpoint. Especially because we have a lot of people using VPNs. If they would improve end point security, it would give more control there.

For how long have I used the solution?

We have been using Darktrace for three years.

What do I think about the stability of the solution?

In terms of stability, Darktrace is an excellent product.

What do I think about the scalability of the solution?

Darktrace's scalability is very good. We have about 1,200 users on it currently.

How are customer service and technical support?

Their technical support is excellent.

Which solution did I use previously and why did I switch?

We have more than an SOC, a security operation center, so we switched to Darktrace because they use artificial intelligence and they are more sophisticated in preventing threats.

How was the initial setup?

The initial setup is straight forward. Deployment took one day.

What about the implementation team?

We implemented with a consultant. It required two people.

What was our ROI?

Our ROI as a result of Darktrace is excellent. The return of the cost of the solution for preventing threats is very good.

What's my experience with pricing, setup cost, and licensing?

Darktrace is expensive, but its results are invaluable.

What other advice do I have?

Because of all it does, Darktrace is a very good solution, and it doesn't take a lot of time to implement and to get results. You can learn the behavior of the network and take actions, not based in signatures. I think this is very, very good.

On a scale of one to ten, I would give Darktrace a nine.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Network Security Engineer at a performing arts with 201-500 employees
Real User
Top 5Leaderboard
Antigena feature offers immediate and helpful response
Pros and Cons
  • "I like the Antigena feature in Darktrace, as it offers immediate response and is helpful."
  • "The interface is too mathematical and it should be simplified."

What is our primary use case?

Darktrace makes up part of our security solution and it is able to operate without intervention from IT staff.

How has it helped my organization?

You can have a one-person IT team and with Darktrace, you can get notification of potential threats that are incoming or are already happening on the network.

What is most valuable?

I like the Antigena feature in Darktrace, as it offers immediate response and is helpful.

This product collects more data than your traditional type of software, which is useful for us.

What needs improvement?

The interface is too mathematical and it should be simplified. If you are a seasoned user then you would know where to go, but you have to learn it first. The terminologies being used are mostly numbers. In general, it could be more user-friendly. The GUI can be more simplified and the sections on the interface can be better organised. Usability and visibility of features can improve the skills of administrators and the product will be a preferred solution and ratings will increase

For how long have I used the solution?

My experience with Darktrace is short because we are just implementing it now.

What do I think about the stability of the solution?

The stability of Darktrace is fine.

What do I think about the scalability of the solution?

We do not intend to scale. Scalability is more of a contract issue that comes into play if you want to add nodes to the system. We are opting for a specific number of nodes or endpoints, which we would be able to keep for quite a number of years. I don't expect that we will expand that much, so scalability should not be an issue.

How are customer service and technical support?

We have been in contact with technical support using different platforms. We have dealt with them using Microsoft Teams, Zoom, and via email.

How was the initial setup?

The initial setup was quite simple and straightforward, taking about an hour to complete. After that, the port modeling took perhaps an hour or two.

What's my experience with pricing, setup cost, and licensing?

If you consider the features and the cost of market leaders, we are satisfied with the pricing.

What other advice do I have?

I would rate this solution an eight out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Otniel Agostinho
CTO at CyberSecur, Lda
Real User
Top 20
Get a comprehensive view of your network and whatever is happening inside it in real-time
Pros and Cons
  • "It provides a comprehensive, detailed view of network activity and whatever is happening inside it."
  • "It is a stable solution without downtime."
  • "The pricing model is a little too high and could be more flexible."
  • "The interface and dashboards could be improved for ease-of-use."

What is our primary use case?

The primary use case for Darktrace is for tracking intruders and alerting for network threats.  

What is most valuable?

The most valuable feature in Darktrace is that it gives me a comprehensive, detailed view of my network and whatever is happening inside it. It is a very good tool for me that helps me to remain aware of security vulnerabilities. I know what is happening on my network in real-time and it responds quickly. It is really very useful.  

What needs improvement?

I am just a manager and I do not really have a technical viewpoint. The tool really suits me perfectly for now for all my basic security needs and what I expect it to do. It does not need any major changes right now to do what I need it to do. It is not missing anything.  

If I am thinking about improvement, everything can be improved somewhat. Maybe the interface and dashboards could be better. I would be glad if they could make these easier from the point of view of management. It could save some time.  

The price is also a little high and could be more enticing.  

For how long have I used the solution?

We have been using Darktrace for about two years.  

What do I think about the stability of the solution?

Darktrace is very stable. It provides 99.9% of our security needs and it does not have downtime. It is a very good, stable solution.  

What do I think about the scalability of the solution?

We did not have the opportunity to test the scalability because our organization has not grown much over the period of time that we have been using the product. I think that scalability is built into the product, but for now, we have not experienced how scaling the product works firsthand.  

What's my experience with pricing, setup cost, and licensing?

I am not so satisfied with the pricing model for Darktrace. The price is a little bit high compared to other solutions. The pricing model should be more flexible.  

What other advice do I have?

On a scale from one to ten where one is the worst and ten is the best, I would rate Darktrace as an eight-out-of-ten.  

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: partner
ciso at SDIS49
Real User
Top 5Leaderboard
A clever solution that spots problems that cannot be found by other solutions but it would benefit from having automation
Pros and Cons
  • "The solution is stable. We've never had any problems with it."
  • "The solution would benefit from automation. Currently, you have to know what you are searching for."

What is our primary use case?

Primarily we use the solution to spot problems that cannot be found by other solutions. 

How has it helped my organization?

Darktrace has improved our knowledge of abnormal phenomenen which could have potentially be hazardous for the organization.You have to be vigilant with GDPR compliance rules in Europe 

What is most valuable?

The most valuable aspect of the solution is that you can see all the process mistakes. You can see all the different types of unusualcsituations that you usually don't see in a traffic solution.

What needs improvement?

The solution would benefit from automation. Currently, you have to know what you are searching for.

For how long have I used the solution?

I've been using the solution for one month.

What do I think about the stability of the solution?

The solution is stable. We've never had any problems with it.

What do I think about the scalability of the solution?

The solution is scalable. So far, we have 12 networks done. We have about 500 users on it currently.

How are customer service and technical support?

I haven't had too much interaction with technical support. Technical support was in France but the experts were in England. It's good generally, but we haven't used the solution for too long.

Which solution did I use previously and why did I switch?

We didn't previously use a different solution.

How was the initial setup?

When you have an expert, the initial setup is easy, but if you do it on your own, it could be complex. Deployment takes at least a month.

Which other solutions did I evaluate?

We didn't evaluate another solution. We met the solution's team in Cannes for an IT meeting and decided to pursue discussions with implementation.

What other advice do I have?

We use the on-premises deployment model.

It's a quite clever solution. It has a lot of potential, but I'd advise those considering to hold off implementing the solution until after a newer version is released.

I'd rate the solution seven out of ten. If they added automation and included it in the price, I'd rate it higher.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Team Lead Manager with 501-1,000 employees
Real User
Top 10
Gives us visibility of rogue network traffic, prevents data exfiltration, good technical support
Pros and Cons
  • "The most valuable feature is that it gives us visibility of rogue traffic that is on the network."
  • "This product needs more in terms of prevention. The detection capabilities work well but once a threat has been detected, Darktrace should work to prevent it from doing anything malicious."

What is our primary use case?

We use Darktrace for security, and to give us better visibility.

How has it helped my organization?

If a user is exfiltrating data, normally we don't have the tools to detect it. With Darktrace, it detects this data. Also, if there is any command-and-control then this solution will highlight that.

What is most valuable?

The most valuable feature is that it gives us visibility of rogue traffic that is on the network.

The detection capabilities are good.

What needs improvement?

This product needs more in terms of prevention. The detection capabilities work well but once a threat has been detected, Darktrace should work to prevent it from doing anything malicious.

Integration with SOAR systems may be helpful, depending on the SOAR.

What do I think about the stability of the solution?

Stability-wise, Darktrace is very good. It runs in the background 24/7.

What do I think about the scalability of the solution?

The scalability is good because it covers our whole network.

We have 1,000 business and IT users and for our environment, the scalability is very good. 

How are customer service and support?

The technical support is good. I would rate them an eight out of ten.

Which solution did I use previously and why did I switch?

We did not use another similar solution prior to Darktrace.

How was the initial setup?

The initial setup was very straightforward. It took approximately two months to complete the implementation and deployment.

What about the implementation team?

We used a consultant to assist us with the implementation.

One person is enough for the deployment and maintenance.

Which other solutions did I evaluate?

There may have been others that we looked at but this is the main one we evaluated.

What other advice do I have?

My advice for anybody who is looking into implementing Darktrace is to do a proof of concept first. Try to out because it's quite useful for providing visibility in the network.

Overall, this is a good product that seems to be working well.

I would rate this solution an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
Andre Walke
Project Co-Ordinator at Ministry of Innovation, Science and Smart Technology
Real User
Top 5
Excellent AI and machine learning functionalities for reviewing and predicting network attacks
Pros and Cons
  • "Artificial intelligence and machine learning functionalities are valuable."
  • "Getting logs from different sources can be a challenge."

What is our primary use case?

Our primary use case of this solution is for visibility. We try to get the global view of our network from an audit perspective on any given day, and figure out how that will impact our business. I'm a project coordinator and we are customers of Darktrace. 

What is most valuable?

The primary feature we are using is the artificial intelligence and machine learning functionality for reviewing and predicting network traffic and network attacks. Although we're not yet fully using the product, I like the Antigena feature which is their proactive or reactive feature, depending on the deployed antivirus center. Darktrace is for people who understand network security very well, and who have probably been in that scene for quite some time. If you're inclined towards mathematical machine learning, artificial intelligence, and to some degree, data science, this is definitely a tool for you.

What needs improvement?

It's sometimes a challenge getting logs from different sources. I would probably want to see if there was a way to improve that, to enable gathering of more information.

For how long have I used the solution?

We've been using this solution for close to four months. 

What do I think about the scalability of the solution?

Full deployment took around two weeks, mainly because the solution takes a little time to learn about your network.

How are customer service and technical support?

The technical support is excellent. They walk you through the process and do a great job. 

How was the initial setup?

The initial setup was quite simple; plug in two or three cables, they give you the requirements that you need and off you go. The configuration and learning how to tweak it is a little more complicated and involved, but the initial setup was easy. Deployment took around two to three weeks because the solution sat on the network for about 14 days doing some variable analysis and trending.

What other advice do I have?

It's a good solution. I would suggest that if it's suitable for your requirements, get it. 

I would rate this solution a nine out of 10. 

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Download our free Darktrace Report and get advice and tips from experienced pros sharing their opinions.