Tamunoibiton Adoki - PeerSpot reviewer
Information Security Officer at a financial services firm with 201-500 employees
Real User
Top 10
Saves a lot of hours, has good detection and remediation capabilities, and is worth the investment
Pros and Cons
  • "AI-driven phishing detection and incident remediation are valuable. It saves time from having to do manual analysis and investigation, and we also get alerts for phishing emails."
  • "Even though they have been continuously improving it, it is not 100% there. We have had a few incidents where legitimate emails were getting blocked, and we had to manually remove those emails from quarantine. It is 90% effective or accurate because, on rare occasions, some emails from customers were not getting delivered. In one or two instances, their emails got blocked by IRONSCALES, and we had to manually remove the emails from quarantine. I would like them to improve their algorithm to avoid flagging genuine emails as malicious. I would also like to be able to whitelist certain email addresses. I'd love to be able to whitelist a particular customer."

What is our primary use case?

The main challenge that we wanted to solve with this solution was the email-based attacks. They are a major threat for our staff and customers. So, we are using this solution for protection from threats and remediation of phishing emails. We also use it for simulation to train our staff to recognize a phishing email. For those users who click on the phishing email, we provide the training content to improve their awareness.

How has it helped my organization?

Its artificial intelligence and machine learning capabilities are really important and helpful in saving time. It saves a lot of hours, and we don't have to do a manual review of each incident or email. Without IRONSCALES, we will have to rely on our staff to report emails that might be malicious, but you can't always depend on the staff to do that.

It is an important part of our security infrastructure. It gives us confidence that we are protected from email threats.

It allows us to report an email as spam. If our staff suspects an email to be malicious, they can report it as spam.

It is helpful in assessing the awareness level of our staff. We compare the metrics of every new phishing campaign with the metrics of previous campaigns. We also determine if the awareness training we are conducting for our staff is effective. We can see all the data. If a lot of people have clicked on the phishing email, we get to know that we need to step up our efforts on phishing awareness.

Its automated detection and response capabilities save a lot of time. We are a financial institution, and we get quite a lot of emails. If someone has to manually review and investigate each alert or email event, it would be a full-time job. On a daily basis, it would take more than three hours of analysis work. A financial institution like ours receives quite a lot of emails from customers and internal staff, and IRONSCALES saves a lot of our time. We don't have to dedicate someone to manually review alerts or emails.

The time that we have saved by not having to manually review each incident can now be used to focus on other tasks. 

It has also helped reduce the number of people or analysts needed to deal with and respond to email incidents.

It allows us to customize the automated detection and response capabilities. Each email that IRONSCALES detects has a confidence level rating. For example, it has 90% or 70% confidence in a phishing email. We have the ability to configure the threshold for automatic remediation. For example, we can say that for emails with a 70% or higher confidence level, it can automatically remediate, but for emails with a 69% confidence level, it should raise an alert, and we'll manually investigate. It gives us the ability to raise or reduce the threshold.

What is most valuable?

AI-driven phishing detection and incident remediation are valuable. It saves time from having to do manual analysis and investigation, and we also get alerts for phishing emails.

What needs improvement?

Even though they have been continuously improving it, it is not 100% there. We have had a few incidents where legitimate emails were getting blocked, and we had to manually remove those emails from quarantine. It is 90% effective or accurate because, on rare occasions, some emails from customers were not getting delivered. In one or two instances, their emails got blocked by IRONSCALES, and we had to manually remove the emails from quarantine. I would like them to improve their algorithm to avoid flagging genuine emails as malicious. I would also like to be able to whitelist certain email addresses. I'd love to be able to whitelist a particular customer.

It is good for user awareness, but I would love to have more content for our staff that is related to not only phishing but also general awareness. I don't know whether it is a functionality that is already available and we have not subscribed to it, but I would love to be able to send awareness emails to staff on different topics related to email security. They should provide us with more security awareness content. Based on the current trends in the security landscape, they can give us security content in emails that I can easily share with my staff to keep them aware.

I use IRONSCALES' mobile app. The mobile app doesn't notify me about the incidents, but I get email alerts instantly, which are helpful when I'm on the move. I get them a lot on my mobile. I get notifications in the email that an incident has been automatically remediated. If an email doesn't have the specified threshold level, I can quickly log in to the IRONSCALES app and do a manual authentication. It helps a lot when I'm on the go, or I don't have my PC with me. Email alerts are fine with me, but it probably would be good to have push notifications from the mobile app. If someone doesn't have an email client on their mobile, they can get notifications through the app.

Buyer's Guide
IRONSCALES
March 2024
Learn what your peers think about IRONSCALES. Get advice and tips from experienced pros sharing their opinions. Updated: March 2024.
768,740 professionals have used our research since 2012.

For how long have I used the solution?

I have been using this solution for just under a year. I joined the department in September, and I started using the product in September last year.

What do I think about the scalability of the solution?

It is a cloud-based solution. So, I expect it to scale well regardless of the number of users we have. We don't expect to experience a drop in performance. Cloud-based solutions generally scale well.

We use it for every email account we have. We currently have between 700 to 800 users, and it is being used for all our departments, users, and group mailboxes.

We definitely have plans to increase its usage. We are currently growing, and we are expecting a significant addition to the number of users in Q3 and Q4.

How are customer service and support?

We haven't had an issue so far. So, we haven't contacted their support. During implementation, we got full support from them, and we loved the support we got. We have no issues with their support. I would rate them a nine out of ten.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I am not aware of any other solution being used previously. IRONSCALES was already in the company when I joined.

How was the initial setup?

It was already in place when I joined. In terms of maintenance, it doesn't require any maintenance from our end. All we have to do is integrate our Outlook email server with IRONSCALES, and that's it. 

What was our ROI?

We have definitely seen an ROI. The amount that we pay for licenses is definitely way less than what we would pay if we are hit by a ransomware attack. So, it definitely provides a return on investment.

We were able to realize its benefits immediately after the deployment. We started analyzing emails and getting alerts right from the time it was activated. You have to do a bit of tuning for the threshold, but the effect was immediate. We didn't have to wait even a bit for it to be effective.

What's my experience with pricing, setup cost, and licensing?

Considering the value it provides, it is definitely worth the cost. We don't have to do manual analysis and remediation of phishing emails, which saves us a lot of hours.

Its licensing is based on the number of users being supported and the number of email addresses being protected. I'm not aware of any additional costs.

What other advice do I have?

I would definitely recommend the product. It is definitely worth the investment.

I would rate it an eight out of ten because I would like to have some of the features. We don't have them currently, and I'm not sure whether these features are available with an additional license.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Endpoint Cyber Security Analyst at a tech company with 51-200 employees
Real User
The automated detection and response feature handles most of the job
Pros and Cons
  • "The biggest benefit is that we get fewer phishing and spam emails, so using IRONSCALES has made our environment much safer."
  • "There's room for improvement in the campaign management. IRONSCALES has many built-in templates that I use, but you can also build templates from scratch. However, the interface for creating custom templates needs to be updated."

What is our primary use case?

Phishing emails and spam are challenges companies of all sizes face. IRONSCALES acts as a second layer on top of the Microsoft mail relay we use. It scans every email coming into our organization and automatically checks the validity. We also check manually in some cases.  

While we mainly use it for the mail relay, IRONSCALES can also act as a phishing campaign simulator. We can send simulated phishing emails to our colleagues to test their readiness. 

Our entire organization uses IRONSCALES across many locations worldwide in South America, Asia, Europe, and North America. All sites use the system to protect the mailboxes and just act as a mail relay. We have about 8,000 users.

How has it helped my organization?

The biggest benefit is that we get fewer phishing and spam emails, so using IRONSCALES has made our environment much safer. While I wasn't here when they deployed the system, I believe they saw benefits right away.

What is most valuable?

The feature I use the most is the main relay. IRONSCALES was designed around that, but phishing simulation management is also a handy tool that I don't see often. Combining these features enables a user to be more comfortable with the simulations. 

For example, one of IRONSCALES' features is an Outlook extension that lets you report phishing emails and other stuff that looks malicious. In our training, we encourage our colleagues to click this button to report as many emails as possible. Reporting suspicious emails should become part of our employees' everyday routine. The training campaign usually helps us catch our colleagues outside their comfort zone to see if they're paying attention to all these suspicious emails they receive.

AI and machine learning are essential components of the product. It automatically can identify phishing emails and classify them according to several factors. I'm not sure how it works, but there's a ranking system that ports onto every sender and email we receive. This artificial intelligence can conduct a thorough search that's sometimes better than humans. 

The automated detection and response feature handles most of the job. I only need to classify a few emails manually each day. Artificial intelligence does everything else automatically for me. Without this technology, we would have to sort 1,000 emails each day manually. IRONSCALES cuts that down to maybe 50.

The IRONSCALES mobile app is convenient to use outside working hours. It's not my primary tool, but it's nice not to need to open your laptop whenever you would like to classify something. You can use the app to check up on the system. 

What needs improvement?

There's room for improvement in the campaign management. IRONSCALES has many built-in templates that I use, but I can also build templates from scratch. However, the interface for creating custom templates needs to be updated. 

I've already contacted IRONSCALES with some features I'd like to see, and they've promised to implement them. For example, let's say I send campaigns using customized tags assigned to each user. If I would like to send a campaign to my colleagues in China, I would send the campaign using a tag that says China. In many cases, new users don't have tags. 

I asked IRONSCALES to add the ability to send campaigns to colleagues that don't have any tags. They promised this feature would be available during the next update.

For how long have I used the solution?

I've been using IRONSCALES since I started working here at my current company about a year ago. 

What do I think about the stability of the solution?

IRONSCALES is stable. I can't think of any outages. 

What do I think about the scalability of the solution?

We can grow as much as we want. We are growing right now and adding new sites to our company.

How are customer service and support?

I rate IRONSCALES support 10 out of 10. They provide support in less than 24 hours. I have never had a problem with them, and they always solve my issues. 

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

The company previously used Microsoft ATP, which required a lot of manual work. I was told that they used to spend a lot of time manually sorting the emails by phishing, spam, etc. The company switched to IRONSCALES because they wanted something to help automatically sort stuff and get faster results.

How was the initial setup?

Though I wasn't here when IRONSCALES was deployed, I saw the system requirements and a basic guide to implementing the system. It was straightforward. 

After deployment, it doesn't require much maintenance. It does everything automatically as well. IRONSCALES supports older versions of Exchange and local Exchange servers that require manual updates of the add-ons they use to protect the mailboxes, but we don't use those services.

What other advice do I have?

I rate IRONSCALES nine out of ten. Some improvements to the campaign management might bring it up to ten. It's a great system. I would recommend it if you only need a mail relay. On top of that, there are additional advantages of using the system, like the campaign manager that complements the mail relay. 

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Buyer's Guide
IRONSCALES
March 2024
Learn what your peers think about IRONSCALES. Get advice and tips from experienced pros sharing their opinions. Updated: March 2024.
768,740 professionals have used our research since 2012.
Digital Risk Intelligence Partner at a comms service provider with 1-10 employees
Real User
Easy to set up with great AI and very good threat-sharing capabilities
Pros and Cons
  • "The stability is good."
  • "The integration with Google Suite needs to be better. it's something they can work on."

What is our primary use case?

We help customers use this to help them to secure against business email compromises, phishing, and impersonation.

What is most valuable?

They're outstanding as a solution. They have a threat-sharing capability so that you get information from all the customers regarding any phishing attack. That's a great feature for us due to the fact that we get information very fast if someone else in the world has seen that email. 

The artificial intelligence is excellent. They are able to use it to recognize phishing emails due to the language used.

The initial setup is very easy.

The solution can scale.

The stability is good.

We've been satisfied with technical support.

What needs improvement?

The integration with Google Suite needs to be better. it's something they can work on.

The pricing is a bit high.

In the future, I'd like to see digital exposure of the users, such as credential exposure, or this kind of feature.

For how long have I used the solution?

We've been working with the solution over the past year.

What do I think about the stability of the solution?

The solution has been very stable. It's reliable. We haven't found bugs or glitches and it doesn't crash or freeze. 

What do I think about the scalability of the solution?

We don't have any issues with scaling - even when dealing with many different customers. 

Our clients range in size. We help companies with anywhere from 50 users to thousands of users. 

How are customer service and technical support?

We have been satisfied with the solution's technical support. They have been helpful and responsive. 

Which solution did I use previously and why did I switch?

We have used Darktrace in the past. The reason we are looking into Darktrace is to have another option. However, for us, Darktrace is not so good as IRONSCALES. IRONSCALES is easier to use, easier to implement, and more accurate when it comes to false positives.

We've also worked with Proofpoint and some Microsoft-owned options, however, we haven't worked with anything else. 

How was the initial setup?

The initial setup is amazing. it's not overly complex or difficult at all. 

It was fast, easy, and straightforward to implement and deploy. On average, with the customers, it takes us around 10 minutes to one hour to set everything up, depending on the size of the customer.

What about the implementation team?

We can assist our clients with the initial setup.

What's my experience with pricing, setup cost, and licensing?

We have a yearly licensing contract. The pricing is a bit expensive, and we'd, of course, like it to be lower, however, we really like the product.

What other advice do I have?

We are a customer as well as an integrator. In some cases we sell the solution, in some cases, we provide the customer with the service. We are a security service provider.

We are working with the latest version. IRONSCALES is a universal service cloud for service. So you always have the latest one.

I would recommend the solution to other users and companies. I couldn't believe that it could filter out 35% of the email. We've very satisfied.

I'd rate the solution at a nine out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: System provider, Partner
PeerSpot user
Buyer's Guide
Download our free IRONSCALES Report and get advice and tips from experienced pros sharing their opinions.
Updated: March 2024
Buyer's Guide
Download our free IRONSCALES Report and get advice and tips from experienced pros sharing their opinions.