Our customers use Darktrace to monitor network traffic.
Cyber Security Engineer at Natica IT Consulting at Natica IT Consulting
A user-friendly cyber defense solution with useful dashboards
Pros and Cons
- "I like the dashboards, which are cool. They are more user-friendly, in my experience. Its learning capabilities are really good."
- "It should be easier to access the Darktrace portal and its documentation. Only the customer can access their portal and support. It could be cheaper."
What is our primary use case?
What is most valuable?
I like the dashboards, which are cool. They are more user-friendly, in my experience. Its learning capabilities are really good.
What needs improvement?
It should be easier to access the Darktrace portal and its documentation. Only the customer can access their portal and support. It could be cheaper.
What do I think about the stability of the solution?
Darktrace is relatively stable.
Buyer's Guide
Darktrace
October 2026
Learn what your peers think about Darktrace. Get advice and tips from experienced pros sharing their opinions. Updated: October 2026.
915,817 professionals have used our research since 2012.
What do I think about the scalability of the solution?
Darktrace is scalable. It's very good. We have two big banks in Turkey using this solution.
How was the initial setup?
The initial setup is straightforward. It takes me about half an hour to deploy this solution.
What about the implementation team?
We implement this solution.
What's my experience with pricing, setup cost, and licensing?
Darktrace is expensive. You can pay for the license yearly.
What other advice do I have?
I would recommend this solution to potential users. But the cloud solution is challenging to use in Turkey.
On a scale from one to ten, I would give Darktrace an eight.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Team Lead - Cyber Security & Compliance at Al Tuwairqi Group
Easy to deploy, stable, and scalable
Pros and Cons
- "The AI-based pattern is the most valuable feature."
- "There is a high ratio of false positive information."
What is our primary use case?
The solution is used as an anti-phishing tool.
What is most valuable?
The AI-based pattern is the most valuable feature. The AI monitors users' patterns in how they draft and send emails, so if there is a change in the pattern the email is flagged.
What needs improvement?
There is a high ratio of false positive information. For example, AI capabilities can sometimes make it difficult to distinguish between a legitimate email and a phishing email. This is one of the features that need to be manually sorted out and aligned. We need to improve this feature by putting DNS into the micro.
For how long have I used the solution?
I have been using the solution for three years.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
The solution is scalable.
How are customer service and support?
The technical support team is good and they provide support on a priority level.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup is easy.
What's my experience with pricing, setup cost, and licensing?
The cost is moderate.
What other advice do I have?
I give the solution an eight out of ten.
Our organization chose Darktrace because of its phishing capabilities.
Darktrace is the best way to secure a gateway and I recommend the solution to others.
Which deployment model are you using for this solution?
Private Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company has a business relationship with this vendor other than being a customer.
Buyer's Guide
Darktrace
October 2026
Learn what your peers think about Darktrace. Get advice and tips from experienced pros sharing their opinions. Updated: October 2026.
915,817 professionals have used our research since 2012.
Network Administrator at a healthcare company with 501-1,000 employees
Detailed interface and good granularity but too expensive
Pros and Cons
- "t was pretty as far as the granularity of what you were getting out of it."
- "The price point for the product was too high for what our possible use case could be."
What is our primary use case?
We're part of our regional hospital group in Northwestern Ontario. One of our group members was using the DarkTrace product suite. It was brought forward that other hospitals within the group may want to try it. A couple of us did a demo, which basically involved getting the appliance installed in our data center and routing all the traffic through it.
We basically had the product running for a company, however, it really didn't pop up or offered anything that we were not already aware of.
What is most valuable?
It has a very detailed interface - almost too detailed. It was pretty as far as the granularity of what you were getting out of it.
The solution is very detailed. It has lots of fancy graphics that don't necessarily lead to a good outcome regarding knowing what's going on.
What needs improvement?
The only problem with these kinds of demos is that unless something actually goes wrong or you have something in the data center already; you don't see any difference. However, no news is good news.
The price point for the product was too high for what our possible use case could be. The demo might have gone more favorably in their direction if something had actually occurred during the demo. However, nothing did, and management decided that it was not worth the very high price.
The interface didn't really give you a whole bunch of insight into actually what was going on.
They did have some AI that they claimed could tell if traffic was malicious or what the intent of the traffic was. We never got to see that actually do anything. They identified some traffic. They said it was malicious. However, it turns out it was a known traffic that we had occurring, and it wasn't malicious. So there were a few missteps that way.
The UI is too dark.
We ultimately didn't find any value in the product.
For how long have I used the solution?
We did a demo for two or three months. We did not use the solution for a very long time.
What do I think about the scalability of the solution?
In terms of scalability, you would need a separate device for every location. For our particular hospital, we actually have three or four main facilities, or what we would consider main facilities. You'd actually need to have a physical box for every deployment in order for traffic to be efficiently detected. They did say that we could route the traffic from the site through the box. However, essentially, that would be doubling the traffic load, which didn't really seem like it was a wise decision. As far as scalability, the box that we had was very capable of handling the traffic load that we were producing. I would say we are probably using maybe ten percent of it at the most at peak levels.
How are customer service and support?
We had some interactions with them during setup and during the demo. They were fine.
How would you rate customer service and support?
Neutral
How was the initial setup?
The initial setup depends on the network. We had a mature infrastructure which made it a bit more challenging.
It took us a few hours to set everything up and make sure it was capturing everything it needed to.
If you had a straightforward Cisco environment where you could easily forward traffic and CDP needed, it would be pretty easy.
What's my experience with pricing, setup cost, and licensing?
I'd rate the pricing two or three out of ten. It is pretty expensive. For us, it just wasn't worth it.
What other advice do I have?
We are customers and end-users.
I'd rate the solution five out of ten. It's an interesting maturing market. They do have potential, however, they do need to work a fair bit on their AI models and their interface.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network Security Engineer at Social Security Commission
Can be deployed in half a day and is scalable
Pros and Cons
- "I have found the automation and AI features to be valuable. If someone were to come in to the office at midnight and log in, Darktrace would flag it."
- "It takes time to go through the interface and pick up things. If it were a more straightforward interface, then it would free up time."
What is our primary use case?
We have a layered approach to our cyber security. We have unified threat management and use several solutions such as Kaspersky, FortiGate, and Mimecast. However, we felt that we needed something on top of all of these and decided to go with Darktrace. We only have one in-house IT security person and were looking for a solution like Darktrace that was more automated.
What is most valuable?
I have found the automation and AI features to be valuable. If someone were to come in to the office at midnight and log in, Darktrace would flag it.
What needs improvement?
It takes time to go through the interface and pick up things. If it were a more straightforward interface, then it would free up time.
For how long have I used the solution?
We did a proof of concept with Darktrace for a year.
What do I think about the scalability of the solution?
It is a scalable solution.
How are customer service and support?
Darktrace's technical support staff were responsive. We did not have to wait long for feedback on anything.
How was the initial setup?
We were able to deploy it in half a day. One person can handle the maintenance of the solution.
What about the implementation team?
We implemented the solution with the help of Darktrace representatives.
What's my experience with pricing, setup cost, and licensing?
We had an issue with pricing initially and had to cancel some of the features of the projects to fit the budget. I would like to see pricing that is not broken up into parts so that we can buy the whole package once.
Darktrace is more expensive than an average solution, but it's functionality won't match that of an average solution.
What other advice do I have?
I would rate Darktrace at nine out of ten. It is a growing product that helps with an ever changing threat landscape. Traditional endpoint antivirus solutions will not be able to keep up.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Head of Infrastructure, Security and Communications at a construction company with 5,001-10,000 employees
Easy to set up with good integration capabilities and useful UI
Pros and Cons
- "We have found the product to be stable and issue-free."
- "This is something that is really easy to implement in an organization, gives us good visibility about what is happening in our networks and on the system, and we like the transparency available within our infrastructure now."
- "We'd like threat hunting, and we'd like to see a global solution that can automate vulnerability scans. I know it is something they are working on."
What is our primary use case?
We're using it in a complete security solution yet still within a different product that Darktrace has that's related to the network or email.
What is most valuable?
The most valuable aspect of the product would be that it's a product that is quite easy to integrate. It's quite easy to start working with it, which is working well. The concept of artificial intelligence that is behind the solution is the most interesting feature for us.
The sense of detection and monitoring and topics within security is good.
It was easy to set up the product.
We have found the product to be stable and issue-free.
It is scalable.
What needs improvement?
We need them to ensure they will detect new attacks and pick up anomalies.
We, of course, would love more threat intelligence, and more integration with vulnerability scanners. We'd like threat hunting, and we'd like to see a global solution that can automate vulnerability scans. I know it is something they are working on.
They're working in different modules that could be related to threat intelligence and to the tech vulnerabilities or functionalities related to EDR.
For how long have I used the solution?
We've been working with the solution for the last couple of years.
What do I think about the stability of the solution?
We've had no issues with stability. It's reliable. There are no bugs or glitches. It doesn't crash or freeze.
What do I think about the scalability of the solution?
It is scalable and easily expands.
The whole of the organization leverages the product, however, I do not have a clear picture of how many people we are working it. That said, we have a company of 2,000.
How are customer service and support?
I've dealt with technical support in the past. I found them to be helpful.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We did previously use a different solution. That said, I don't remember what it was called.
How was the initial setup?
The product is easy to set up.
After deployment, we spent three months, which is the time that this solution needs to learn about what's happening in our network. In one day, once we had defined all the configurations and once they have been seen on the appliance, we were able to start running it.
It's an easy product to maintain.
What about the implementation team?
We handled the initial setup ourselves. We did not need any outside assistance from integrators or consultants.
What's my experience with pricing, setup cost, and licensing?
The pricing is okay. I'd rate it seven out of ten in terms of affordability.
You have different modules which you have to pay for. If you want to expand functionality, it ends up costing more.
Which other solutions did I evaluate?
Looked at Microsoft, Proofpoint, and Minecraft when we were looking into Darktrace. We decided on this product based on the available features.
What other advice do I have?
We are using the last version of the solution, although I don't know the exact version number. We plan to upgrade in the next couple of weeks. We might be on version five, with the latest being six.
This is something that is really easy to implement in an organization. It gives us good visibility about what is happening in our networks, and on the system. We like the transparency available within our infrastructure now. We can also personalize it to fit our needs. You can either choose plug and play or you can go deeper. They have artificial intelligence you can start working with. You can define more by leveraging modules. Overall, it's very interesting.
I'd rate the solution eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Vice President | Head of Information Systems & Manufacturing Engineering at a manufacturing company with 51-200 employees
Self-maintaining, works autonomously, and prevents data excavation
Pros and Cons
- "The most valuable feature is that it works autonomously."
- "The solution automatically monitors everything on the network to prevent anti-phishing by monitoring, responding, and restoring the system."
- "The solution can improve the reporting. Currently, it only runs weekly and the reporting is complex."
What is our primary use case?
The solution automatically monitors everything on the network to prevent anti-phishing by monitoring, responding, and restoring the system. It prevents data excavation.
What is most valuable?
The most valuable feature is that it works autonomously. So you only need to look at the exceptions.
What needs improvement?
The solution can improve the reporting. Currently, it only runs weekly and the reporting is complex. It is more of a network monitoring system, basically AI.
For how long have I used the solution?
I have been using the solution for four years.
What do I think about the stability of the solution?
The solution is stable and solid.
What do I think about the scalability of the solution?
The solution is scalable and designed to be enterprise-wide.
Which solution did I use previously and why did I switch?
Previously we used Intercept X which is more at the virus level endpoint, but Darktrace is an overall network and phishing solution.
How was the initial setup?
The initial setup did not appear complex.
What about the implementation team?
The implementation was completed by a vendor technician. The setup was simple and took a couple of hours.
What's my experience with pricing, setup cost, and licensing?
The solution is about $6,000 per quarter.
What other advice do I have?
I give the solution ten out of ten.
Our organization has about 50 nodes and there is no maintenance involved because it is self-maintaining. I recommend the solution, it is better than SIM.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT Security Manager at a construction company with 201-500 employees
Beneficial viability, simple installation, and responsive support
Pros and Cons
- "The most valuable features of Darktrace are its full capabilities, as you have visibility of everything happening on your network, emails, and SaaS applications."
- "Darktrace could improve by being more user-friendly."
What is our primary use case?
Darktrace is an appliance that has been installed in our network, and it is connected to the database SaaS applications and they're collecting the data from there.
We are using Darktrace for tracking our network and if any suspicious activity happens, we will be notified or we can check it on our tenant.
What is most valuable?
The most valuable features of Darktrace are its full capabilities. You have visibility of everything.
What needs improvement?
Darktrace could improve by being more user-friendly.
For how long have I used the solution?
I have been using Darktrace for approximately six months.
What do I think about the stability of the solution?
Darktrace is stable.
What do I think about the scalability of the solution?
The scalability of Darktrace is good.
We have approximately 350 users using the solution in my company. Everyone is using it.
How are customer service and support?
The support from Darktrace is responsive and speedy.
I rate the support of Darktrace a nine out of ten.
How was the initial setup?
Darktrace is simple to install and the full process took approximately three weeks.
What about the implementation team?
The deployment of Darktrace was done by the vendor.
What's my experience with pricing, setup cost, and licensing?
The price of Darktrace is high and could be reduced. We pay approximately $30,000 to $54,000 annually.
The cost of the solution is high making it an issue for smaller companies. We are a small organization and it is difficult to afford. We are not a large organization. For this reason, the solution's price must be reduced. Having 350 users is not a large organization. It's a small organization and paying approximately $30,000 to $54,000 annually, is a lot. However, sometimes we had too many services to have more visibility and be secure, this is the idea why we went with Darktrace without negotiating the prices.
What other advice do I have?
I recommend Darktrace to others, it is a helpful service you will have full visibility of what's happening on your network, emails, and SaaS applications.
I rate Darktrace an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Director Of Information Technology at a security firm with 1-10 employees
Responsive support, good alerting, but the initial setup is complex and time-consuming
Pros and Cons
- "The models, triggers, and alerts are customizable."
- "It's beneficial to me and I can see that with more time and energy put into optimizing it and personalizing the unit, it can be much more powerful than the way I am using it now."
- "The initial setup is more complex and time-consuming than some solutions."
What is our primary use case?
We use Darktrace to analyze our network traffic.
What is most valuable?
Darktrace is a good product, although it depends on how much time you put into it.
The models, triggers, and alerts are customizable.
What needs improvement?
The initial setup is more complex and time-consuming than some solutions.
For how long have I used the solution?
I have been working with Darktrace for more than a year.
What do I think about the stability of the solution?
Darktrace is quite stable, but potentially expensive.
What do I think about the scalability of the solution?
The vendor has different options for scaling. I use the appliance; they also offer a cloud service but I prefer the appliance. I put it between the router and the core switch and it picks up all of the traffic.
How are customer service and support?
The technical support is better than Check Point. They respond more quickly.
Which solution did I use previously and why did I switch?
I am currently using Darktrace and Vectra in addition to Check Point. I've been using all three and I find that Check Point is the one where I get the most information from. I will stop using Vectra this year but I will retain Darktrace, as long as they keep it at a certain price.
Darktrace requires a lot more configuration; unlike Check Point, there are a lot more changes that need to be made. In general, it's more sophisticated. As far as getting the settings and the configuration and the models that you want, it would help if you spent some time on that. We're a small team. It's beneficial to me and I can see that with more time and energy put into optimizing it and personalizing the unit, it can be much more powerful than the way I am using it now. That said, it's my secondary device. We're working on a lot of different projects, so I haven't assigned any of my guys to it yet. Ultimately, when it's fully integrated, it may end up being as useful as the Check Point.
The reason I keep all three is that they all give me a different kind of view. They all give me different information. If they gave the same information, it'd be useless to keep them.
With respect to similar security products, I have demoed CrowdStrike and worked with Symantec.
How was the initial setup?
You have to customize it to the way you want, in order for it to work best for your environment. Definitely take time to train while you can during deployment.
Some things do work well, out of the box. However, this would be better suited for somebody that can take the time to configure it correctly during deployment.
What's my experience with pricing, setup cost, and licensing?
Prior to negotiating, Darktrace offered their appliance and service for $80,000 per year.
I suggest negotiating either at the end of their fiscal year or at the end of every quarter. At the end of the quarter, they have an incentive to lower the prices to sell as many units as possible in order to meet their end-of-quarter quota.
What other advice do I have?
My advice for anybody who is implementing Darktrace is that you definitely need to take your time. Sit down and understand how to use the model breach customization. They use models and if something hits that model, it triggers an alert.
I would rate this solution a six out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT Manager at SJ Securities Sdn Bhd
Quick to deploy with great detection capabilities and quick-responding support
Pros and Cons
- "We are able to detect a lot of things, actually, and see what is happening in our network."
- "It's quite expensive to have."
- "The pricing is expensive. It costs over $100,000 a year."
What is our primary use case?
The product is a type of intrusion detection and prevention software. It is for network traffic monitoring.
What is most valuable?
We are able to detect a lot of things, actually, and see what is happening in our network.
It offers good protection.
The deployment is quick.
What needs improvement?
It's good as a solution, however, for me, it's quite complicated. They've got a lot of features there. You need a lot of time to learn it.
It's quite expensive to have.
For how long have I used the solution?
I've used the solution for around a year.
What do I think about the stability of the solution?
The core is stable. There are no bugs or glitches and it doesn't crash or freeze.
What do I think about the scalability of the solution?
It's not high on scalability, in the box itself. You don't need scalability to scale out the server like that.
There is one that is able to monitor the entire network. Our entire IT department is on the product. We have a three-person technical team. We may expand usage later this year.
How are customer service and support?
Technical support is quite good. Every quarter, they will contact us for a meeting, however, any issue actually is reported online and their response is quite fast.
How was the initial setup?
The deployment was very fast. They just put the appliance in and connect our call switch and do everything else that is needed. It's all very fast.
What about the implementation team?
We used the SI to help us with the implementation.
What's my experience with pricing, setup cost, and licensing?
The pricing is expensive. It costs over $100,000 a year. There are no additional costs beyond the price of the license.
Which other solutions did I evaluate?
I'm currently exploring other solutions as a comparison. We are looking for Sangfor Cyber Command.
What other advice do I have?
We're a customer and end-user.
It's my understanding that we are on version five.
I'd advise users that it's a good solution, however, they need to be prepared for a large learning curve.
I'd rate the solution eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Director Of Information Technology at a computer software company with 501-1,000 employees
Intuitive, has excellent technical support, and has good visibility
Pros and Cons
- "The active threat dashboard is the most valuable feature of this solution."
- "It provides a comprehensive cybersecurity solution that monitors my cloud accounts as well as my local network."
- "I believe their network monitoring device licensing module could use some improvement."
- "My only criticism of the product is that its licensing model isn't flexible."
What is our primary use case?
Darktrace is a cybersecurity solution that is essentially an AI-driven ecosystem. Call it network monitoring with telemetry SaaS cloud connections.
How has it helped my organization?
It provides a comprehensive cybersecurity solution that monitors my cloud accounts as well as my local network. It monitors local network traffic, VPN's and it connects to my firewalls, allowing me to see what's going on in my environment. I have visibility into pretty much everything that's going on now.
What is most valuable?
The active threat dashboard is the most valuable feature of this solution.
What needs improvement?
The licensing model has room for improvement. The license by IP rather than node or device, even if it's a single Mac address. If I have three people who are constantly in three different locations, they want to charge you three licenses. My only criticism of the product is that its licensing model isn't flexible.
I would like to see a Darktrace EDR client, a true EDR client that integrates into it, and not a third-party EDR.
For how long have I used the solution?
I have been working with Darktrace for six months.
We are working with the most recent version.
What do I think about the stability of the solution?
Darktrace is very stable. It's very reliable.
What do I think about the scalability of the solution?
Darktrace is a very scalable solution.
We have 650 users in our organization.
It's extensively used.
How are customer service and support?
I give them five stars from the sale cycle to the support cycle.
Which solution did I use previously and why did I switch?
I considered other options, but this is the one I chose, because of the flexibility and the ease of use.
How was the initial setup?
The initial set is very simple and intuitive. With the instructions provided, it took about 10 minutes to set up.
It requires no maintenance. It is managed by Darktrace, they push down the updates. I don't have to do anything with it.
What's my experience with pricing, setup cost, and licensing?
I think it's mostly the licensing on the network monitoring piece that I don't like. All of the other modules, such as the licensing modules, are on par. It's one for one.
Which other solutions did I evaluate?
I evaluated Endpoint protection solutions, such as CrowdStrike Falcon, Darktrace, and SentinelOne. We decided on Darktrace.
What other advice do I have?
I'm a partner with Darktrace.
I would advise them to engage with their sales team and their sales engineering team to make sure they understand the license model.
It's very intuitive. It's a fantastic product, and the only reason they don't get a 10 is because of their licensing. I believe their network monitoring device licensing module could use some improvement.
I would rate Darktrace an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Parnter
Buyer's Guide
Download our free Darktrace Report and get advice and tips from experienced pros
sharing their opinions.
Updated: October 2026
Product Categories
Network Detection and Response (NDR) Email Security Intrusion Detection and Prevention Software (IDPS) Network Traffic Analysis (NTA) Extended Detection and Response (XDR) Cloud Security Posture Management (CSPM) Cloud-Native Application Protection Platforms (CNAPP) Attack Surface Management (ASM) AI-Powered Cybersecurity Platforms AI ObservabilityPopular Comparisons
Fortinet FortiGate
Cortex XDR by Palo Alto Networks
Cloudflare
Datadog
Cloudflare One
Qualys TotalCloud
SentinelOne Singularity Endpoint
Dynatrace
Microsoft Defender for Cloud
SentinelOne Singularity Cloud Security
Wazuh
IBM Security QRadar
Prisma Cloud by Palo Alto Networks
Buyer's Guide
Download our free Darktrace Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- I'm building a next-gen AI powered threat intelligence platform. What's missing from existing solutions?
- Which is better - SentinelOne or Darktrace?
- What are the pros and cons of Darktrace vs CrowdStrike Falcon vs alternative EPP solutions?
- Which alternative solutions (other than Darktrace) do you recommend for an SMB?
- How does Crowdstrike Falcon compare with Darktrace?
- How does Network Detection and Response (NDR) Differ from SIEM?
- What aspects of network security are more concerning to small and medium-sized enterprises?
- What are the best practices for Security Operations Center (SOC)?
- What is the future of the Network Operation Center (NOC)?
- Which alternative solutions (other than Darktrace) do you recommend for an SMB?
















