Darktrace Room for Improvement
It would be good if they can include some endpoint protection for remote workers. Nowadays, most people are working remotely. Therefore, they should include some type of sensors that can be installed on the endpoint in order to directly report the main usage and protect remotely. Phone protection will also be a great feature to add to Darktrace.
In an upcoming release, there could be more customizable playbooks or a library of playbooks to choose from. Since it is collecting all scenarios that might happen from any threat, new playbooks may be discovered and customers will have the privilege to use them in their environment. Other than that, Darktrace is leading in every aspect.View full review »
Founder and Director at a tech services company with 11-50 employees
In terms of improvements, fine-tuning is the area where we have to spend some time because it works on unsupervised machine learning. It would be good if they can improve their algorithm or technical functionality to reduce the fine-tuning effort.
They can also come up with something at the endpoint level. So far, Darktrace has been a network detection response (NDR) solution. It does not offer much at the endpoint level or on user-client devices or servers. There should be more visibility at the endpoint level. It would be good to have the detection and response at the endpoint level by Darktrace.
It should also have integration with an agile environment so that we can have continuous development and continuous integration in the application development environment. This is currently not there. It should also have internet-facing platform visibility, which is currently missing.
They also need to improve the reporting and management dashboards. Currently, these are not so easy for a non-technical person. All these features would make Darktrace much better, and they would also be helpful in selling more solutions.View full review »
Senior Security & Infrastructure Architect at a retailer with 10,001+ employees
The product is really excellent all around and I can not fault it. The only thing that I can think of that would improve it would be if they had a better visualization and a reporting portal.
What I mean by better visualization is it could help map our services and endpoints in a better way. At the moment it is fairly complex in the way that it represents our network devices. It would help if there was in a slightly more logical way of visualizing the assets as opposed to the way it is currently being done.
We are talking to Dartrace at the moment about putting in a reporting portal so we can have technical reports separate from management reports. Some of our management gets information in reports that they do not need to see. When they see it they will not understand what it means. Targeting — or customizing — the reports that we make can allow us to have the content fit what the recipient needs to see without distracting extras.
Apart from those potential additions, this product is absolutely excellent. It has given us everything we have wanted. Darktrace, as a company, has been really good. Our account manager is totally responsive. The support teams have been really conscientious.
Fingers crossed. So far Darktrace has proven to be a great asset.View full review »
Director Of Information Technology at a security firm with 1-10 employees
The initial setup is more complex and time-consuming than some solutions.View full review »
Security Engineer at a real estate/law firm with 1,001-5,000 employees
They just need to make it a little bit more accurate as far as their alerts are concerned. It does generate some false positives that you have to tune. You have to do a lot of tuning when you first get it because of the false positives, but once it is all tuned up and ready to go, it will do its thing from there.
One thing that I would like to look at going forward is to have a fully automated network infrastructure that is monitored automatically real-time, and that gives me this kind of capability where I would be able to look at my network at any given time and see the state of my network. With Darktrace, at the moment, I have to almost put in a date and tell them that want you to give me data from this date to this date. I don't want that. I want a fast solution in which it doesn't matter when I log into the application. Whenever I log in, I must be able to see my network and run a report. In other words, if I go in now and I say, "Give me a full report of what happened today, it must be able to give me that. It mustn't just be limited to a seven-day period, for argument's sake. It must be able to give me real-time and day-to-day tracking of what has happened within my network.
System Architect at a energy/utilities company with 51-200 employees
There are some automation capabilities, however, they could be presented better.
The manual is difficult to follow. While it presents some use cases, it's not very clear. There may also be some language barriers, as it's not available in my language.
Some aspects of the initial setup are complex.
It would be useful if there was a way to check to see if there are certain devices that are not in sync with the solution. I'm not sure if this is an option or not.
The cost of the solution is quite high.
I'm very interested in ISO 27001 and these processes. I'd like to better understand how it supports this kind of workflow.
The solution could be easier to use.
The user interface is a bit too detailed. They should work to pare it down and simplify it. They seemed to have designed it for an expert user and not a layman. If there are some system administrators who are not experts and they just want to just get sensors reports and escalate, it should be easier for them to do so.View full review »
Director Of Information Technology at a computer software company with 501-1,000 employees
The licensing model has room for improvement. The license by IP rather than node or device, even if it's a single Mac address. If I have three people who are constantly in three different locations, they want to charge you three licenses. My only criticism of the product is that its licensing model isn't flexible.
I would like to see a Darktrace EDR client, a true EDR client that integrates into it, and not a third-party EDR.View full review »
Network Security Engineer at a performing arts with 201-500 employees
The interface is too mathematical and it should be simplified. If you are a seasoned user then you would know where to go, but you have to learn it first. The terminologies being used are mostly numbers. In general, it could be more user-friendly. The GUI can be more simplified and the sections on the interface can be better organised. Usability and visibility of features can improve the skills of administrators and the product will be a preferred solution and ratings will increase.View full review »
Security Manager at a computer software company with 11-50 employees
It can always improve here and there, however, in general, it's already quite complete.
The solution could have better integration capabilities. There aren't so many third-party vendor platforms natively integrated with the platform.
They need a better-automated response setup.View full review »
The need to simplify the analysis from a user perspective. In a few cases, you have to be a specialist in order to understand what's happening. It would be helpful if they could recognize incidents and simplify the customer's challenge to identify what is happening.View full review »
Firstly, the integration should be improved.
In terms of what additional features I would like included in the next release of Darktrace, I would like to see more protection in the endpoint. Especially because we have a lot of people using VPNs. If they would improve end point security, it would give more control there.View full review »
Customer Solution Manager at a tech services company with 51-200 employees
The module can improve so that every time it's more intelligent.
Wong Soon Tai
IT Manager at SJ Securities Sdn Bhd
It's good as a solution, however, for me, it's quite complicated. They've got a lot of features there. You need a lot of time to learn it.
It's quite expensive to have.View full review »
I am just a manager and I do not really have a technical viewpoint. The tool really suits me perfectly for now for all my basic security needs and what I expect it to do. It does not need any major changes right now to do what I need it to do. It is not missing anything.
If I am thinking about improvement, everything can be improved somewhat. Maybe the interface and dashboards could be better. I would be glad if they could make these easier from the point of view of management. It could save some time.
The price is also a little high and could be more enticing.View full review »
They just need to work on their price. In terms of features, we are trying to understand all the features that we have. We're still exploring everything that we have so that we can fully utilize it. At this point in time, it is not about the features. It is more about utilization. We're just trying to utilize everything to full capacity.View full review »
Team Lead Manager with 501-1,000 employees
This product needs more in terms of prevention. The detection capabilities work well but once a threat has been detected, Darktrace should work to prevent it from doing anything malicious.
Integration with SOAR systems may be helpful, depending on the SOAR.View full review »
Darktrace could improve by being more user-friendly.View full review »
Consultant at a computer software company with 5,001-10,000 employees
Its documentation is not up to the mark. At times, I have a lot of trouble finding a solution. Even when I posted questions on the community chats, it took a lot of time for me to get answers. That's something that can be improved. Darktrace can focus on creating a more interactive community. If there are more people from Darktrace to focus on community chats, it would be better.View full review »
It's sometimes a challenge getting logs from different sources. I would probably want to see if there was a way to improve that, to enable gathering of more information.
Networking & Security Specialist at a tech services company with 51-200 employees
Its threat analyzer could be better. It should also have agents. They should improve this product by installing agents for the machine to get more visibility. Currently, they are monitoring only the network. They should also monitor the agents from inside.
It should also have a better pricing plan because it is an expensive product.View full review »
It can have more integration with orchestration or event management solutions. They can provide more knowledge or research information for analysts for investigating cases and detecting anomalies in networks.View full review »
Founder and CEO at a tech services company with 51-200 employees
The user interface and the configuration are a bit complex and should be improved or simplified.
It's user-friendly, but it could be easier.
The pricing could be better and the scalability should be simplified for the customers.
The integration could be better, as it's not that interactive. They could make it more interactive for the customer's daily use.View full review »
ICT Coordinator at a tech services company with 51-200 employees
It is expensive, but everything else has been great so far. It is fine for now for what we need it to do.View full review »
It's a very complex platform.View full review »
Network Security Engineer at a tech services company with 51-200 employees
I think there is some MSSP missing. The market as a whole needs to enhance this area. Some additional integration would be helpful. They need to focus on having additional tools based on how competitive the market currently is.View full review »
Security Operations Manager at a financial services firm with 5,001-10,000 employees
There are numerous false positives.
Darktrace requires numerous configurations. It would be beneficial if the configuration could be made simpler.View full review »