Try our new research platform with insights from 80,000+ expert users
Network Administrator at a healthcare company with 501-1,000 employees
Real User
Detailed interface and good granularity but too expensive
Pros and Cons
  • "t was pretty as far as the granularity of what you were getting out of it."
  • "The price point for the product was too high for what our possible use case could be."

What is our primary use case?

We're part of our regional hospital group in Northwestern Ontario. One of our group members was using the DarkTrace product suite. It was brought forward that other hospitals within the group may want to try it. A couple of us did a demo, which basically involved getting the appliance installed in our data center and routing all the traffic through it. 

We basically had the product running for a company, however, it really didn't pop up or offered anything that we were not already aware of. 

What is most valuable?

It has a very detailed interface - almost too detailed. It was pretty as far as the granularity of what you were getting out of it. 

The solution is very detailed. It has lots of fancy graphics that don't necessarily lead to a good outcome regarding knowing what's going on.

What needs improvement?

The only problem with these kinds of demos is that unless something actually goes wrong or you have something in the data center already; you don't see any difference. However, no news is good news.

The price point for the product was too high for what our possible use case could be. The demo might have gone more favorably in their direction if something had actually occurred during the demo. However, nothing did, and management decided that it was not worth the very high price.

The interface didn't really give you a whole bunch of insight into actually what was going on.

They did have some AI that they claimed could tell if traffic was malicious or what the intent of the traffic was. We never got to see that actually do anything. They identified some traffic. They said it was malicious. However, it turns out it was a known traffic that we had occurring, and it wasn't malicious. So there were a few missteps that way.

The UI is too dark.

We ultimately didn't find any value in the product.

For how long have I used the solution?

We did a demo for two or three months. We did not use the solution for a very long time. 

Buyer's Guide
Darktrace
June 2025
Learn what your peers think about Darktrace. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
857,028 professionals have used our research since 2012.

What do I think about the scalability of the solution?

In terms of scalability, you would need a separate device for every location. For our particular hospital, we actually have three or four main facilities, or what we would consider main facilities. You'd actually need to have a physical box for every deployment in order for traffic to be efficiently detected. They did say that we could route the traffic from the site through the box. However, essentially, that would be doubling the traffic load, which didn't really seem like it was a wise decision. As far as scalability, the box that we had was very capable of handling the traffic load that we were producing. I would say we are probably using maybe ten percent of it at the most at peak levels.

How are customer service and support?

We had some interactions with them during setup and during the demo. They were fine.

How would you rate customer service and support?

Neutral

How was the initial setup?

The initial setup depends on the network. We had a mature infrastructure which made it a bit more challenging.

It took us a few hours to set everything up and make sure it was capturing everything it needed to. 

If you had a straightforward Cisco environment where you could easily forward traffic and CDP needed, it would be pretty easy. 

What's my experience with pricing, setup cost, and licensing?

I'd rate the pricing two or three out of ten. It is pretty expensive. For us, it just wasn't worth it. 

What other advice do I have?

We are customers and end-users. 

I'd rate the solution five out of ten. It's an interesting maturing market. They do have potential, however, they do need to work a fair bit on their AI models and their interface.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Network Security Engineer at Social Security Commission
Real User
Can be deployed in half a day and is scalable
Pros and Cons
  • "I have found the automation and AI features to be valuable. If someone were to come in to the office at midnight and log in, Darktrace would flag it."
  • "It takes time to go through the interface and pick up things. If it were a more straightforward interface, then it would free up time."

What is our primary use case?

We have a layered approach to our cyber security. We have unified threat management and use several solutions such as Kaspersky, FortiGate, and Mimecast. However, we felt that we needed something on top of all of these and decided to go with Darktrace. We only have one in-house IT security person and were looking for a solution like Darktrace that was more automated.

What is most valuable?

I have found the automation and AI features to be valuable. If someone were to come in to the office at midnight and log in, Darktrace would flag it.

What needs improvement?

It takes time to go through the interface and pick up things. If it were a more straightforward interface, then it would free up time.

For how long have I used the solution?

We did a proof of concept with Darktrace for a year.

What do I think about the scalability of the solution?

It is a scalable solution.

How are customer service and support?

Darktrace's technical support staff were responsive. We did not have to wait long for feedback on anything.

How was the initial setup?

We were able to deploy it in half a day. One person can handle the maintenance of the solution.

What about the implementation team?

We implemented the solution with the help of Darktrace representatives.

What's my experience with pricing, setup cost, and licensing?

We had an issue with pricing initially and had to cancel some of the features of the projects to fit the budget. I would like to see pricing that is not broken up into parts so that we can buy the whole package once.

Darktrace is more expensive than an average solution, but it's functionality won't match that of an average solution.

What other advice do I have?

I would rate Darktrace at nine out of ten. It is a growing product that helps with an ever changing threat landscape. Traditional endpoint antivirus solutions will not be able to keep up.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Darktrace
June 2025
Learn what your peers think about Darktrace. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
857,028 professionals have used our research since 2012.
IT Manager at SJ Securities Sdn Bhd
Real User
Quick to deploy with great detection capabilities and quick-responding support
Pros and Cons
  • "We are able to detect a lot of things, actually, and see what is happening in our network."
  • "It's quite expensive to have."

What is our primary use case?

The product is a type of intrusion detection and prevention software. It is for network traffic monitoring.

What is most valuable?

We are able to detect a lot of things, actually, and see what is happening in our network.

It offers good protection.

The deployment is quick. 

What needs improvement?

It's good as a solution, however, for me, it's quite complicated. They've got a lot of features there. You need a lot of time to learn it.

It's quite expensive to have.

For how long have I used the solution?

I've used the solution for around a year.

What do I think about the stability of the solution?

The core is stable. There are no bugs or glitches and it doesn't crash or freeze. 

What do I think about the scalability of the solution?

It's not high on scalability, in the box itself. You don't need scalability to scale out the server like that. 

There is one that is able to monitor the entire network. Our entire IT department is on the product. We have a three-person technical team. We may expand usage later this year. 

How are customer service and support?

Technical support is quite good. Every quarter, they will contact us for a meeting, however, any issue actually is reported online and their response is quite fast.

How was the initial setup?

The deployment was very fast. They just put the appliance in and connect our call switch and do everything else that is needed. It's all very fast.

What about the implementation team?

We used the SI to help us with the implementation. 

What's my experience with pricing, setup cost, and licensing?

The pricing is expensive. It costs over $100,000 a year. There are no additional costs beyond the price of the license. 

Which other solutions did I evaluate?

I'm currently exploring other solutions as a comparison. We are looking for Sangfor Cyber Command.

What other advice do I have?

We're a customer and end-user.

It's my understanding that we are on version five.

I'd advise users that it's a good solution, however, they need to be prepared for a large learning curve. 

I'd rate the solution eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1776540 - PeerSpot reviewer
Director Of Information Technology at a computer software company with 501-1,000 employees
Real User
Intuitive, has excellent technical support, and has good visibility
Pros and Cons
  • "The active threat dashboard is the most valuable feature of this solution."
  • "I believe their network monitoring device licensing module could use some improvement."

What is our primary use case?

Darktrace is a cybersecurity solution that is essentially an AI-driven ecosystem. Call it network monitoring with telemetry SaaS cloud connections.

How has it helped my organization?

It provides a comprehensive cybersecurity solution that monitors my cloud accounts as well as my local network. It monitors local network traffic, VPN's and it connects to my firewalls, allowing me to see what's going on in my environment. I have visibility into pretty much everything that's going on now.

What is most valuable?

The active threat dashboard is the most valuable feature of this solution. 

What needs improvement?

The licensing model has room for improvement. The license by IP rather than node or device, even if it's a single Mac address. If I have three people who are constantly in three different locations, they want to charge you three licenses. My only criticism of the product is that its licensing model isn't flexible.

I would like to see a Darktrace EDR client, a true EDR client that integrates into it, and not a third-party EDR.

For how long have I used the solution?

I have been working with Darktrace for six months. 

We are working with the most recent version.

What do I think about the stability of the solution?

Darktrace is very stable. It's very reliable.

What do I think about the scalability of the solution?

Darktrace is a very scalable solution.

We have 650 users in our organization.

It's extensively used.

How are customer service and support?

I give them five stars from the sale cycle to the support cycle.

Which solution did I use previously and why did I switch?

I considered other options, but this is the one I chose, because of the flexibility and the ease of use.

How was the initial setup?

The initial set is very simple and intuitive. With the instructions provided, it took about 10 minutes to set up.

It requires no maintenance. It is managed by Darktrace, they push down the updates. I don't have to do anything with it.

What's my experience with pricing, setup cost, and licensing?

I think it's mostly the licensing on the network monitoring piece that I don't like. All of the other modules, such as the licensing modules, are on par. It's one for one.

Which other solutions did I evaluate?

I evaluated Endpoint protection solutions, such as CrowdStrike Falcon, Darktrace, and SentinelOne. We decided on Darktrace.

What other advice do I have?

I'm a partner with Darktrace.

I would advise them to engage with their sales team and their sales engineering team to make sure they understand the license model.

It's very intuitive. It's a fantastic product, and the only reason they don't get a 10 is because of their licensing. I believe their network monitoring device licensing module could use some improvement.

I would rate Darktrace an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Parnter
PeerSpot user
Tichaona Ndoreka - PeerSpot reviewer
Infrastructure Sup at Capital Development Services
Real User
Provides visibility into our infrastructure and helps in identifying most vulnerable devices
Pros and Cons
  • "The ability to see what we have not seen before is most valuable. It is very interesting to find out the most vulnerable devices in our network."
  • "They just need to work on their price. In terms of features, we are trying to understand all the features that we have. We're still exploring everything that we have so that we can fully utilize it. At this point in time, it is not about the features. It is more about utilization. We're just trying to utilize everything to full capacity."

What is our primary use case?

We use it to understand our network and traffic. We are basically getting visibility into our infrastructure.

We are using its latest version. It has both deployments. There is one cloud, and there is one on-prem.

What is most valuable?

The ability to see what we have not seen before is most valuable. It is very interesting to find out the most vulnerable devices in our network. 

With Antigena Email, you know from where most of your spam is coming and which country is spamming you a lot. 

What needs improvement?

They just need to work on their price. In terms of features, we are trying to understand all the features that we have. We're still exploring everything that we have so that we can fully utilize it. At this point in time, it is not about the features. It is more about utilization. We're just trying to utilize everything to full capacity.

For how long have I used the solution?

I have been using it for three months.

What do I think about the stability of the solution?

It is stable.

What do I think about the scalability of the solution?

It is scalable. Currently, we have just two users of this solution, but it covers all the devices that we have.

How are customer service and support?

The customer success manager has been helpful. Their support is pretty good.

Which solution did I use previously and why did I switch?

We used Microsoft.

How was the initial setup?

It was straightforward. The installation took 30 minutes to an hour. We had training before doing the installation.

What about the implementation team?

We used a consultant. We have just two engineers who are doing the deployment and maintenance.

What's my experience with pricing, setup cost, and licensing?

It is pretty expensive, but it is worth it. Its licensing is yearly.

What other advice do I have?

I would recommend it, but you just need to make sure that your organization is big enough. It's not worth it when the organization is small. I would recommend it for organizations with more than 5,000 devices on their network.

I would rate it an eight out of 10.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1666347 - PeerSpot reviewer
Security Engineer at a real estate/law firm with 1,001-5,000 employees
Vendor
Provides a higher level of threat detection, detects any type of attack, and very useful for an autonomous response
Pros and Cons
  • "The Antigena feature is most valuable. Once it learns your environment, Antigena can step in and block a denial of service attack, a ransomware attack, or just about anything that doesn't belong in the environment. It can detect any type of attack that hits the environment because it understands what normal looks like for the network. It is very useful for an autonomous response."
  • "They just need to make it a little bit more accurate as far as their alerts are concerned. It does generate some false positives that you have to tune. You have to do a lot of tuning when you first get it because of the false positives, but once it is all tuned up and ready to go, it will do its thing from there."

What is our primary use case?

We use it to protect IoT devices. Darktrace does network traffic analysis. So, by analyzing all traffic patterns in your environment, you can detect any type of anomalous activity, as far as the network is concerned. 

I have been using its latest version. Its deployment depends on the environment. It can do sensors in the cloud, and it can also do on-prem.

How has it helped my organization?

It provided a higher level of threat detection.

What is most valuable?

The Antigena feature is most valuable. Once it learns your environment, Antigena can step in and block a denial of service attack, a ransomware attack, or just about anything that doesn't belong in the environment. It can detect any type of attack that hits the environment because it understands what normal looks like for the network. It is very useful for an autonomous response. 

What needs improvement?

They just need to make it a little bit more accurate as far as their alerts are concerned. It does generate some false positives that you have to tune. You have to do a lot of tuning when you first get it because of the false positives, but once it is all tuned up and ready to go, it will do its thing from there. 

For how long have I used the solution?

I used it for about a year.

What do I think about the stability of the solution?

It is a very stable product. We didn't have any issues.

What do I think about the scalability of the solution?

It has sensors that you can install. So, it can scale on-prem and off-prem in the cloud.

It is being used extensively. We have 2,000 employees. We use it to protect IoT devices. We also use it to protect Windows servers, desktops, and laptops. Its usage would increase if the net grows, but it's probably not going to grow too much bigger than 2,000 employees.

How are customer service and technical support?

The support from Darktrace is very helpful.

Which solution did I use previously and why did I switch?

We didn't use any other solution previously. 

How was the initial setup?

It was pretty straightforward. You just monitor everything from your core switch. It monitors everything in and out.

We got it up in half an hour, but it still has to learn. You still have to give it some time to learn about the environment, and that's usually going to be at least two weeks.

What about the implementation team?

We brought in their guy to the site. In terms of maintenance, it is automatically set up to reach out to their website and pull down updates and stuff. We don't have to worry about that too much.

What's my experience with pricing, setup cost, and licensing?

It was $3,600 a month or $2,000 plus or so. I am not sure. 

Its licensing is pretty simple.

Which other solutions did I evaluate?

We were thinking about getting another solution called Vector, but we didn't. We brought Darktrace in.

What other advice do I have?

Darktrace is a pretty good company. The only thing that they need to really work on is just being able to get rid of some of those false positives. Once the solution is tuned up, it pretty much just runs.

I would advise making sure that you do a really good PoC of the product so that you can be sure that it makes sense in your environment.

I would rate it a nine out of 10. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Group IT Manager at a manufacturing company with 1,001-5,000 employees
Real User
Advanced Cybersecurity Artificial Intelligence, plenty of features, and impressive threat detection
Pros and Cons
  • "I have found the most valuable features to be artificial intelligence for cybersecurity, advanced machine learning capabilities, enterprise Immune System, Antigena Network, and Antigena Email. The way the solution detects the threat over the network before it spreads is very good. It notifies you of what the threat is exactly doing and gives you all the details about the execution of that application that had created the threat over your network."
  • "In an upcoming release, there could be more customizable playbooks or a library of playbooks to choose from."

What is our primary use case?

Darktrace is used for cybersecurity, you can buy it as a physical appliance or solution as a service on the cloud. I tried the on-premises solution to detect any threat over our network.

How has it helped my organization?

Darktrace played an important role in the security detection strategy by reducing the time lost in detecting, analyzing, and incident resolving. This is due to its friendly user interface that shows you in simple graphs and analytics the output for any log over your network whether it is computer, device, switch, access point, etc...

What is most valuable?

I have found the most valuable features to be artificial intelligence for cybersecurity, advanced machine learning capabilities, enterprise Immune System, Antigena Network, and Antigena Email. The way the solution detects the threat over the network before it spreads is very good. It notifies you of what the threat is exactly doing and gives you all the details about the execution of that application that had created the threat over your network.

There is an included library of threat detections, not only locally, but threats being experienced all around the world. It is similar to a database of all the threats and what is done by cybersecurity administrators across the internet. By collecting events and information all around the world makes Darktrace more proactive in dealing with threat notifications and cybersecurity detection. The service is very comprehensive and can cover all security areas.

It has simple tracking capabilities and a graphical interface that can assist you with coding, you do not need to be a guru. The dashboards are user-friendly and you do not need an application to access your work, it is all done through any browser. Additionally, there is a mobile application that is one of the best features because you can see any threats from your phone. There is a playbook that can give you instructions. For example, if you see your network servers are being injected by ransomware you can stop the session and be notified of which person on what computer triggered the threat.

The solution is very professional. Everybody would like to have an application on their phone to be more proactive about security anywhere and this solution delivers.

What needs improvement?

In an upcoming release, there could be more customizable playbooks or a library of playbooks to choose from. Since it is collecting all scenarios that might happen from any threat, new playbooks may be discovered and customers will have the privilege to use them in their environment. Other than that, Darktrace is leading in every aspect.

For how long have I used the solution?

I have been using this solution for one month.

What do I think about the stability of the solution?

Very Stable

What do I think about the scalability of the solution?

We have a number of employees using the solution in my organization which includes administrators and management.

How are customer service and technical support?

Technical support is excellent. You can communicate with them by sending an email, WhatsApp messages, or other types of communication. They have their support in many places around the world so what ever your time zone is, they are available.

The support you do receive is excellent.

Which solution did I use previously and why did I switch?

I have used other solutions previously but non had this intelligence,

How was the initial setup?

The installation is very easy. I was shocked by the simplicity of the management, implementation, and dashboards. 

What about the implementation team?

I have implemented it using Darktrace Team who were very professional.

What's my experience with pricing, setup cost, and licensing?

The price of the solution is not cheap. It is not a one-time purchase, there is a subscription that needs to be paid every one to five years depending on your choice. It is expensive but you can reduce the price by only using the services that you want. There is some flexibility, for example, if you only want to have email inspections, network inspections, endpoint inspections, or brief analytics of the reports and controls over your infrastructure, can reduce the prices accordingly. Not choosing all the features can reduce the price. When comparing this solution to competitors in the market it is expensive. However, you are paying for a valuable solution with plenty of features. Their artificial and cyber intelligence is working extremely well. I am a consultant and work with a variety of solutions by myself, attend training, and understand people who are working with these solutions.

I need to know the advantage, disadvantages, weaknesses, and what makes the solution better than the others. Darktrace proves at some point that the value of money you are paying for the solution is reasonable for the advanced technology you are receiving as it covers many solutions that can cost much  much more than darktrace where as i you bought Darktrace you reducing all the complexity to one simple solution. 

Which other solutions did I evaluate?

I have evaluated many other solutions.

What other advice do I have?

My advice to those wanting to implement this solution is if they want to experience artificial intelligence, advanced cybersecurity, and high-level detection, this solution is the one. 

I rate Darktrace a nine out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
System Administrator at Finlays
Real User
Reasonably prices, stable, and straightforward to set up
Pros and Cons
  • "The ability to detect activity on the network is very useful to us. Even if it's not necessarily an illegal activity, if it is abnormal activity, it is able to detect it and notify us."
  • "The solution could be easier to use."

What is our primary use case?

We are primarily using the solution for network monitoring as well as cybersecurity.

What is most valuable?

The ability to detect activity on the network is very useful to us. Even if it's not necessarily an illegal activity, if it is abnormal activity, it is able to detect it and notify us.

The solution is stable.

The product scales well within a network.

The initial setup is pretty simple.

The solution isn't too expensive.

What needs improvement?

The solution could be easier to use.

The user interface is a bit too detailed. They should work to pare it down and simplify it. They seemed to have designed it for an expert user and not a layman. If there are some system administrators who are not experts and they just want to just get sensors reports and escalate, it should be easier for them to do so.

For how long have I used the solution?

I've been using the solution for three years at this point.

What do I think about the stability of the solution?

The solution is very stable. As far as we've been using it, we've not had any major issues. It doesn't crash or freeze. There are no bugs or glitches. It's reliable.

What do I think about the scalability of the solution?

The solution is scalable within the network. If a company needs to expand it, it can do so.

For our particular office, we have around 100 users.

I cannot say if we will increase usage. We have many offices and decisions in relation to usage increases would come from our UK office.

How are customer service and technical support?

Technical support is great. They are very responsive and helpful. We are very satisfied with the level of support they provide to us.

Which solution did I use previously and why did I switch?

We did not previously use a different solution. For cybersecurity, this is our first product. We were using the traditional endpoint protection as well, and we still do. For that, we use Sophos.

How was the initial setup?

The installation was straightforward, from what I understand. I didn't actually handle ht process. That was done by a consultant. 

The deployment was fast. In less than an hour, everything was up and running.

I handle the maintenance myself.

What about the implementation team?

We had a consultant that assisted us with the implementation. They made the process very easy.

What's my experience with pricing, setup cost, and licensing?

We typically do yearly or three-year licensing, however, I can't speak to the exact costs or arrangements.

It's not too expensive. The price is good for what it offers.

What other advice do I have?

We're just a customer and an end-user.

Overall, I'd rate the solution at an eight out of ten. We've mostly been quite happy with the product.

I'd recommend it to other users and organizations.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Darktrace Report and get advice and tips from experienced pros sharing their opinions.
Updated: June 2025
Buyer's Guide
Download our free Darktrace Report and get advice and tips from experienced pros sharing their opinions.