Try our new research platform with insights from 80,000+ expert users
Director at Eden Infosol Pvt Ltd
Real User
Top 10
Helps improve security posture, reduces overhead, and response times
Pros and Cons
  • "Apex One includes a built-in fine-grained DLP solution."
  • "The application and web controls have room for improvement."

What is our primary use case?

Our customer experienced a ransomware attack while using a different security solution. This prompted them to switch to Trend Micro Apex One, which they deployed for both their servers and endpoints. However, they only opted for the Endpoint Detection and Response version for their servers, not for their endpoints.

We have deployed Trend Micro Apex One to strengthen our defenses against viruses, enhance access control, and implement device control measures.

How has it helped my organization?

Apex One effectively defends endpoints against threats, including malware and malicious scripts.

The advanced protection capabilities adapt to safeguard against unknown and stealthy new threats, a critical advantage for our customers. We often observe that our customer's systems lack proper patching, making them more susceptible to infections. However, Apex One effectively mitigates the damage caused by these attacks.

It utilizes runtime machine learning capabilities to detect ransomware. This is crucial as ransomware poses a significant threat, and customers are increasingly moving beyond traditional antivirus solutions due to ransomware's heightened prevalence.

Apex One offers a unified console for cross-layer detection, threat hunting, and investigations, depending on the services we subscribe to. Utilizing a single console for these tasks is crucial as it eliminates the need to manage multiple solutions and their respective consoles. When a single OEM provides its solutions within a single console, it presents the most efficient approach, eliminating the need to toggle between different consoles, manage disparate systems, and correlate data across multiple platforms.

Apex One provides around 95 percent visibility into our IT security environment.

Improved visibility can help reduce response times and proactively address issues with our endpoints. This allows us to take a more proactive approach rather than a reactive one.

Apex One is easy to learn, but like any security product, it requires additional skills beyond simply navigating the solution. However, for those who need to explore the solution and figure things out, it is quite convenient. Technicians should not take long to adapt to a user's experience with any kind of endpoint security system.

It has improved our customers' security posture, enabling them to realize the benefits within the first three months.

Apex One proactively shields our customers from vulnerabilities by employing virtual patching, even before a patch is available for the underlying issue. This proactive approach proves invaluable in safeguarding against emerging threats.

Ideally, the reduction in risk stems from the implementation of multiple security measures. For instance, if an organization fails to implement device control, it might become susceptible to phishing attempts. These phishing emails, if clicked on or if attachments are downloaded, can lead to malware infections. However, endpoint security can block these threats before they reach the system, regardless of whether they arrive through a device, email, or web access. This is where detection becomes crucial. Endpoint security doesn't necessarily reduce the number of threats in the network environment, but it does prevent those threats from exploiting vulnerabilities on endpoints.

Apex One has helped reduce our customer's overhead by 30 to 40 percent.

What is most valuable?

Apex One includes a built-in fine-grained DLP solution. This is particularly beneficial for SMB customers, as they may not need to invest in a full-fledged DLP solution if Apex One meets their requirements.

What needs improvement?

The application and web controls have room for improvement. A fully integrated endpoint security system, encompassing EDR, should include application control, web control, device control, patch management, and encryption. This comprehensive solution would be highly appealing to customers, as they currently rely on multiple tools to address these security needs. Moreover, an EDR solution would provide visibility into endpoint vulnerabilities, such as unpatched systems, enabling proactive remediation. These features would undoubtedly enhance the value proposition of Trend Micro's security offerings.

Buyer's Guide
Trend Vision One Endpoint Security
August 2025
Learn what your peers think about Trend Vision One Endpoint Security. Get advice and tips from experienced pros sharing their opinions. Updated: August 2025.
867,349 professionals have used our research since 2012.

For how long have I used the solution?

I have been using Trend Micro Apex One for one year.

What do I think about the stability of the solution?

Trend Micro Apex One is stable. We have not encountered any issues.

What do I think about the scalability of the solution?

Trend Micro Apex One is highly scalable, meaning there are no significant challenges with increasing the solution's capacity to meet growing demands.

How are customer service and support?

The technical support is good.

How would you rate customer service and support?

Positive

How was the initial setup?

My team was part of the deployment and from my end, it was a smooth process. The deployment took three days to complete. 

We utilized Trend Micro's auto-deployment feature via Active Directory to seamlessly uninstall the existing antivirus software and deploy Trend Micro Apex One.

The deployment required two people from the customer's side and one person from our end.

What's my experience with pricing, setup cost, and licensing?

Apex One is expensive. On a scale of one to ten with ten being the most expensive, Apex One is an eight.

Initially, customers may be satisfied with the price of Apex One for the first year or two. However, as they become aware of other alternatives that meet their needs more effectively or at a lower cost, they start considering switching to a different option.

What other advice do I have?

I would rate Trend Micro Apex One nine out of ten.

For an organization with 500 to 700 employees, at least two dedicated personnel should be assigned to maintain Apex One if the customer operates multiple shifts. Otherwise, one dedicated personnel per shift is sufficient.

Trend Micro Apex One is a good option for organizations that don't have budget constraints. 

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company has a business relationship with this vendor other than being a customer. partner
PeerSpot user
Server Adminstrator at OPJU
Real User
Top 20
Offers advanced protection features, is easy to use, and saves us time
Pros and Cons
  • "The policies, protection, and ease of use are the most valuable features of Trend Micro Apex One."
  • "When I create and implement a new policy , it takes a couple of hours to apply to the devices."

What is our primary use case?

We use Trend Micro Apex One for our organization to provide security between departments.

It was implemented to help with all the policies regarding our migration.

How has it helped my organization?

Trend Micro Apex One does a good job defending endpoints against threats such as malware, ransomware, and malicious scripts.

Its advanced protection features can adapt to safeguard against unforeseen and cleverly disguised new threats. This is particularly crucial in the education sector, where our staff and students frequently visit research websites that may harbor potential security risks.

Apex One can detect ransomware with runtime machine-learning capabilities. This is useful for us.

Apex One provides us with a single console for cross-layered detection, threat hunting, and investigation.

The single console provides end-to-end visibility into the entire IT security environment.

A single console streamlines our response times, allowing us to save up to two hours. Previously, investigating issues required navigating multiple portals, which was time-consuming.

It is easy to learn and use.

The main benefit is the protection of our devices and systems.

We have not received any viruses or malware since implemention.

Apex One has helped reduce our administrative overhead.

What is most valuable?

The policies, protection, and ease of use are the most valuable features of Trend Micro Apex One.

What needs improvement?

When I create and implement a new policy, it takes a couple of hours to apply to the devices.

I would like the ability to customize the report notifications and who they are sent to.

For how long have I used the solution?

I have been using Trend Micro Apex One for almost three years.

What do I think about the stability of the solution?

Trend Micro Apex One is stable.

What do I think about the scalability of the solution?

It is easily scalable.

How are customer service and support?

The technical support is good.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We previously used Symantec. 

What other advice do I have?

I would rate Trend Micro Apex One 9 out of 10.

We have 2 administrators for Apex One with 600 endpoints deployed across multiple departments in one location.

Maintaining Apex One is easy.

Trend Micro Apex One is a user-friendly solution with great features and I recommend it to others.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Trend Vision One Endpoint Security
August 2025
Learn what your peers think about Trend Vision One Endpoint Security. Get advice and tips from experienced pros sharing their opinions. Updated: August 2025.
867,349 professionals have used our research since 2012.
reviewer2354775 - PeerSpot reviewer
CIO at a insurance company with 201-500 employees
Real User
Everything can be managed from one point
Pros and Cons
  • "Apex One offers a lot of bang for your buck. It includes an antivirus solution, DLP, app control, and all the other features found in endpoint protection solutions like Microsoft Defender. Many other solutions require additional licenses for different operating systems, but Trend Micro software bundles everything."
  • "We had issues with our system integrator who didn't have enough experience with Trend Micro. There aren't many enterprise customers in our country who use Trend Micro on the level that we are using it, so it might be a little too complex for them. Trend Micro is typically used in small companies that do not need all the advanced features that we are looking for. The integrators don't have experience deploying these features. The scope is broad, but Microsoft Defender is simpler."

What is our primary use case?

We use Apex One to protect our endpoints and servers against viruses. 

What is most valuable?

Apex One offers a lot of bang for your buck. It includes an antivirus solution, DLP, app control, and all the other features found in endpoint protection solutions like Microsoft Defender. Many other solutions require additional licenses for different operating systems, but Trend Micro software bundles everything.  Many other endpoint protection platforms are restricted by the operating system, but this is an all-in-one solution. The firewall and other aspects of endpoint protection can all be managed from one point.

We are pleased with the antivirus features and the overall experience. Trend Micro has enabled us to catch all the malware scripts and nasty things out there. We have a multilayered defense with different antivirus vendors and layers. It's easy to integrate Apex One with our other products. 

Once Apex One is set up, it isn't problematic to administer. The correct configuration and deployment is something that takes time. It isn't necessarily specific to Apex One. It's true of all vendors because you have guidelines and specific rules.

What needs improvement?

We had issues with our system integrator who didn't have enough experience with Trend Micro. There aren't many enterprise customers in our country who use Trend Micro on the level that we are using it, so it might be a little too complex for them. Trend Micro is typically used in small companies that do not need all the advanced features that we are looking for. The integrators don't have experience deploying these features. The scope is broad, but Microsoft Defender is simpler. 

Many vendors are pushing customers to the cloud for advanced XDR features. This drives costs up substantially and takes control out of the customer's hands. I would like Trend Micro and other vendors to make the advanced capabilities that are increasingly being deployed to the cloud also available on-premise.

For how long have I used the solution?

We have used Trend Micro endpoint protection products since 2010. We had OfficeScan and Deep Security at one point.

What do I think about the stability of the solution?

I rate Apex One nine out of ten for stability. 

What do I think about the scalability of the solution?

We haven't had any issues with scalability.

How are customer service and support?

I rate Trend Micro support seven out of ten. Like most vendors, Level 1 support is catastrophic. At Trend Micro, everything starts at Level 1, and the process of how quickly you get from Level 1 to Level 2 is something all vendors have issues with.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

We were using Sophos. Trend Micro Apex One is bundled with other enterprise protection products, so it covers more than just antivirus.

How was the initial setup?

We had some initial challenges configuring high availability on our server, but it wasn't difficult otherwise. 

What about the implementation team?

We had help from a systems integrator and Trend Micro support. I rate the integrator two out of ten and Trend Micro seven out of ten. 

What was our ROI?

We have seen a return on investment. When we initially switched to Trend Micro, we reduced the licensing costs by decreasing the number of products we use. In three years, we recovered the initial investment, and our costs have been more optimal since then. 

What's my experience with pricing, setup cost, and licensing?

Apex One's pricing is highly competitive. That's one advantage. We compared the pricing of solutions that do everything we want, and others are more expensive than what we have. There are no additional maintenance fees, but we have a support contract that we renew annually. 

What other advice do I have?

I rate Trend Micro Apex One eight out of ten. I would recommend Trend Micro to companies looking for more than basic antivirus protection. If you need firewalls, application control, device and USB control, Trend Micro bundles all of that. I would recommend Trend Micro to a company that needs to cover all those areas

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Farrukh Hussain - PeerSpot reviewer
Industry Advisory at 2M.ma
Real User
Top 10
Good security and endpoint protection with machine-learning capabilities
Pros and Cons
  • "It's reduced administrative overhead overall thanks to its centralized dashboard and single network administrator."
  • "The price is the main concern of the clients."

What is our primary use case?

Some customers require on-prem endpoint protection. When they need endpoint protection and DLP features with ransomware protection and firewall features, I use this product. And when they need multi-layer security, like application layers, network layers, IoT devices, and network switches, then I provide the XDR solution. 

How has it helped my organization?

As resellers, we benefit from the solution offering multiple events, seminars, and more, to gain knowledge and help clients. The solution offers a lot of updates and support to their partners. Solutions like Sophos don't have principals in our country (Pakistan) either. They are in the UAE. 

What is most valuable?

The core endpoint protection is the most valuable aspect. The DLP features are very good. The firewall security is also excellent. 

When a customer wants DLP features and endpoint protection, they can not get it from Sophos or Kaspersky. Only Trend Vision offers certain features.  

Trend Vision One Endpoint Security is great for defending endpoints against threats such as malware and malware and malicious scripts. Their AI feature is very attractive and very good as compared to the other malicious traffic detecting solutions. Trend Vision has excellent AI features and sensors are available when we use the XDR solution. 

They provide email sensors in the network devices. They provide the sensor in firewall traffic. The sensors are very good, and they're working well. 

Trend Vision offers virtual patching, which is a very good feature.

It has advanced protection capabilities that adapt to protect against unknown and known threats. They are connected with the global threat intelligence forum. They also have their own threat intelligence. They get data, use sensors, and have the capability to mitigate various attacks, including zero-day attacks. 

It detects ransomware with runtime machine-learning capabilities. Benchmark protection is necessary when customers have confidential data. They need the backup solution or they need two anti-ransomware detectors to make sure they are protected. That way, when attackers compromise any end users, they stay on the end user, and cannot spread. 

The product provides our customers with a single console for cross-layer detection, threat hunting, and investigation. They have a central dashboard for network administrators who can control everything from one window and analyze all of the end users and their activities. We can do single threat hunting from the console. Customers want the ability to see all events in their network and on their endpoints. It makes administration easy and more user-friendly. 

There's visibility into the entire IT security environment. This end-to-end visibility reduced our customer's response times by 30% to 40%.  

Trend Vision One Endpoint Security integrates with other security products. You can integrate with other Trend Vision products and third-party solutions like firewalls. The productivity with the integration goes from 70% to 80% up to 100% when you integrate with Trend Vision solutions. It's better to create a Trend Vision environment. 

Trend Vision One Endpoint Security deploys rapid updates to endpoints. Their sandbox is good. They have, as mentioned, very good threat intelligence. They're sharing details on global direct intelligence with Palo Alto, Kaspersky, and Sophos. They share all the events, and all the intelligence, and upgrade their sandbox accordingly. 

The updates to endpoints are very good and necessary to ensure protection from the latest threats. 

The learning curve is low. It's easy and user-friendly to learn. You need to be a bit technical to properly administer the product.

Trend Vision One Endpoint Security offers very good virtual patching. This is important for customer networks. The patching allows multiple authorities to double source patching of endpoints. This helps with audits, as it allows for regular patching to ensure endpoints are up to date and protected according to compliance requirements. 

We've seen reductions in viruses and malware since using the product. There are multiple levels of scanning, and AI helps to reduce threats and viruses. We've seen an overall reduction of 70% to 80%.

It's reduced administrative overhead overall thanks to its centralized dashboard and single network administrator. It reduced overhead by about 50%.

What needs improvement?

The main problem I faced with the solution was when customers were trying to buy the solution, they wanted a reasonable price, and when you compare this with Sophos or Kaspersky, Trend Vision is competitively more expensive. The price is the main concern of the clients. Otherwise, the solution is very good.

I'd like to see Trend Vision One Endpoint Security include role functionality and server protection. Users should have better email protection to ensure high results.

Customers would like DNS security improved in the product.

For how long have I used the solution?

I've used the solution for three years or more. 

What do I think about the stability of the solution?

The solution is stable. 

What do I think about the scalability of the solution?

Customers have been very happy with their ability to add endpoints. 

How are customer service and support?

We manage the SLA for one- to three-year periods, and if any policies need changing, etc., we are there to help customers. There are people who monitor the network and offer on-call support. When customers need field support, my team can assist.

When we do need the assistance of support, we've been satisfied with their response. They are quick and effective.

How would you rate customer service and support?

Positive

How was the initial setup?

I'm not a fully technical person, so I was not directly involved in the deployment. My pre-sales manager was largely involved in deploying and handling the dashboard as well as administering it to multiple end-users. If we run into any trouble, we can get help from Trend Vision sales. They can provide guidance. 

The solution is working okay. There is no maintenance needed. 

What's my experience with pricing, setup cost, and licensing?

The solution is quite expensive.

What other advice do I have?

I'm a reseller. We sell the product to clients. Some of my customers want DLP and firewall options, and some require endpoint protection. Trend Vision One Endpoint Security is powerful when a customer requires protection and not detection. I'm also working with Trend Vision's XDR solutions.

I'd rate the solution nine out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. reseller
PeerSpot user
Product Manager at a tech services company with 11-50 employees
Reseller
Top 5
Integrates well with other security products but has limited intelligence
Pros and Cons
  • "Its database is better than most of the endpoint protection solutions."
  • "It is weak in terms of intelligence. By implementing Trend Micro Apex One, I wanted to see real-life scenarios. I deployed it on 50 clients to check if I could do lateral moments and zero-day exploits. I wanted to check how the zero-day protection works with Trend Micro. It fails with most of them because it is signature-based. They are not looking at the MITRE ATT&CK framework, so with zero-day attacks, it mostly fails."

What is our primary use case?

I create real-life scenarios with products and work with products such as Trend Micro, CrowdStrike, SentinelOne, Palo Alto, etc. Trend Micro is not my focus item or brand. My focus is more on CrowdStrike, but I am using Trend Micro in my lab environments to check the real-life situation. I am not okay with what vendors share on their websites, so I give my customers and partners real-life scenarios.

How has it helped my organization?

I offer Trend Micro Apex One to our customers just because they want a secondary signature-based solution.

Apex One did not work as per my expectations. I am doing zero-day attacks by myself, and for fileless attacks, it does not work at all.

With the current architecture, Apex One does not have advanced protection capabilities that adapt to protect against unknown and stealthy new threats. It might have these capabilities in the future if they change the architecture. For instance, McAfee merged with FireEye and created a new brand Trellix. They changed the overall architecture. If Trend Micro considers shifting its architecture, it can get this kind of protection.

Apex One is okay for detecting ransomware with runtime machine-learning capabilities. It has some signature-based protection against ransomware, but it may miss the ransomware, which has been a huge threat at least for the last seven or eight years. It is the foundation of zero-day protection, and that is why I am looking for a more capable solution besides Trend Micro.

Apex One integrates with other security products. As part of this integration, when a threat is detected in the network sandbox, it deploys rapid updates to endpoints, which has huge importance because if you can respond to events in a short time, you get the least damage from attacks. It is of huge importance.

Apex One provides us with virtual patching to protect against vulnerabilities even before a patch is available for the source of the issue, but it is a problem in itself because it consumes too many resources on an endpoint. It is a good feature, but it is a problematic feature because it consumes lots of the system resources. If you use signature-less architecture, you do not have to deal with virtual patching because all attack types are already addressed with some framework, such as the MITRE ATT&CK framework. You do not have to deal with virtual patching at all.

There has been no reduction in viruses and malware since moving to Apex One because my customers are using it as a secondary solution. They have primary products, and there are not many things left for Apex One. My customers are using it as a secondary solution just because of their habits of using signature-based. Some of my customers could not understand the concept of signature-less protection. Antiviruses have been there for 40 years or so, and their habits are a little bit hard to change. That is the reason why I am offering this product.

What is most valuable?

I offer this solution only if a customer is looking for a signature-based protection solution. Its database is better than most of the endpoint protection solutions.

What needs improvement?

It is weak in terms of intelligence. By implementing Trend Micro Apex One, I wanted to see real-life scenarios. I deployed it on 50 clients to check if I could do lateral moments and zero-day exploits. I wanted to check how the zero-day protection works with Trend Micro. It fails with most of them because it is signature-based. They are not looking at the MITRE ATT&CK framework, so with zero-day attacks, it mostly fails. Instead of signature-based, Trend Micro may want to change the architecture to use more behavior analysis. Behavior analysis is included with Trend Micro, but it is not a complete set, so it needs enhancement.

Apex One does not provide a single console for cross-layer detection, threat hunting, and investigation. Managing it is a little bit hard. You have to use different consoles for Apex One, Deep Security, and Trend Micro endpoint protection, so managing it is a little bit tricky.

In terms of the learning curve, Apex One is easy for me, but regular users may have some issues. The management of Trend Micro products is a little bit tricky. Apex One does not include every protection in itself, so you have to use endpoint protection, and you have to use Deep Security. If three of them come together, at some point, it will be competitive with next-generation antiviruses or EPPs such as SentinelOne, Microsoft, CrowdStrike, etc.

Its implementation takes too much time. With CrowdStrike, I do not have to restart any operating system, but with Trend Micro, I have to.

Its administration is also a little bit tricky. It is easier when you have background knowledge.

For how long have I used the solution?

I have been using this product for a year.

What do I think about the stability of the solution?

Its stability is quite good. I cannot complain about the stability.

It sometimes also depends on luck. The product can sometimes conflict with other products, but to this day, I never encountered any issue like that.

What do I think about the scalability of the solution?

It is a little bit hard to scale as compared to CrowdStrike. I am using on-prem solutions most of the time. With on-prem solutions, it is a little bit hard to maintain, deploy, or scale a product, but cloud products are easier to scale.

I have a centralized customer, and I also have customers who have distributed locations all over Turkey, so I have both types of customers.

How are customer service and support?

It takes a little bit of time, and it can be improved. Sometimes, I get a response in two days, and at other times, I get a response in two hours. It depends. More consistency would be great, but I have already gotten used to this kind of issue, so I cannot complain at all. I would rate them a seven out of ten.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

I am using other server protections and intelligence products. I still have CrowdStrike in my portfolio. I have clients for that, and I am okay with CrowdStrike.

How was the initial setup?

Its deployment takes time. If I have to deploy it in a huge company with over 10,000 clients, it takes a little bit of time. If I am using CrowdStrike, it would take only two or three days, whereas Trend Micro takes more time. I have not measured the exact time difference, but it takes more time compared to other solutions or the next-gen antiviruses. It also depends on the environment because organizational units are not available all the time.

I deployed it on the cloud and on-premises. It depends on the end-user scenarios and topology. In Turkey, customers mostly prefer on-prem solutions, but this is changing day by day. Customers in Turkey tend to have their information on-premises. If a customer wants an on-prem solution, then I offer them the Trend Micro product or Trellix product. It also depends on their budget.

Its deployment is not too complex in my experience, but from the customer perspective, it is a little bit tricky. It takes a little bit of time. They have to have a little bit of background knowledge.

The implementation strategy varies. Sometimes, I use third-party solutions, and sometimes, I am just pushing from the central management console. It depends on the customer's topology.

In terms of maintenance, it does require maintenance. It depends on the company budget because some of my customers have a few locations in Turkey, and sometimes, they have only one IT specialist. They send that one person everywhere in Turkey or to multiple locations. If they have more than one IT guy and if they are also distributed, they do not have to send those guys to other places. It depends on the customer's budget.

What about the implementation team?

If I deploy the product, then one person is enough, but if I have to leave it to my customers, they need two or three people. They are usually IT specialists, but they are not so knowledgeable.

What was our ROI?

It takes time, but it is better than some of the other products such as Symantec. Symantec takes more time compared to Trend Micro.

What's my experience with pricing, setup cost, and licensing?

It is okay. Compared to Sophos, it is a little bit expensive, but it is a good product and it is better than Sophos, for instance. It is equivalent to Trellix.

Its cost depends on the country. I am in Turkey, and Trend Micro is not so affordable in Turkey. SMB companies are looking for cheaper products. In Turkey, enterprise customers tend to use Trend Micro, and if they have more money, then they use next-generation antivirus or EPP products such as SentinelOne, CrowdStrike, or Microsoft E5 package.

Which other solutions did I evaluate?

I evaluate most of the popular brands such as Trellix, Sophos, and Kaspersky.

What other advice do I have?

Trend Micro Apex One has some good benefits, and CrowdStrike also has some benefits. I would recommend Apex One depending on the scenario. I have to check it with my customer first. I have to identify their basic needs and what they want to do. Sometimes, it just matches the requirements, and sometimes, it does not, so it depends.

If you are looking for the productivity of employees, go for a signatureless solution.

For an SMB, I would rate it an eight out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Meleria Mangaring - PeerSpot reviewer
Solutions Engineer at Trends and Technologies, Inc
Real User
Offers great integration, has valuable ransomware protection, and behavior monitoring
Pros and Cons
  • "The ransomware protection and behavior monitoring features of Trend Micro Apex One are actually good."
  • "One of Trend Micro's weaknesses is its high resource utilization."

What is our primary use case?

Many clients come to us after they have been attacked by ransomware. They often ask us to immediately remediate the situation, but this is not possible once a system has been compromised. However, we can usually install Trend Micro Apex One or a Cloud One product right away. This is our standard response to these situations.

Most of the clients I work with are hospitals. They have been using a different endpoint security solution, but they were attacked by ransomware and reached out to us for a different solution.

In one of the use cases we worked on, we simply installed an endpoint security solution. During the proof of concept, the hospital actually encountered a ransomware attack. There were two systems that were attacked: our test PC running Apex One and the other that was using the existing endpoint security solution. The Trend Micro-installed PC was able to navigate the attack, but the files on the other PC were corrupted.

We also simulate other attacks, such as ransomware or simple malware, using the Intelligent Content Analysis and Response tool. We then check the Device Control feature. Apex One also has data loss prevention and application control features. The DLP feature is not as comprehensive as a full-blown DLP solution, but it can be used to leverage regular expressions, specific keywords, and specific attributes. We also test the application control feature.

Our most recent testing has been with the new Vision One product. This is an extended detection and response platform that can be integrated with not only Trend Micro's other solutions, but also with other security solutions from different vendors, such as SIEM, firewalls, NDR, and vulnerability management systems.

When we test the integration of Apex One and Vision One, we focus on automation, remediation, and cost analysis. We can see how an attack was carried out, down to the file level, hostname, and user. If Vision One is integrated with Active Directory, we can also see who the user was at the time of the attack.

This is the scope of the usual use cases we perform during proof of concepts for Trend Micro Apex One.

How has it helped my organization?

I would rate Apex One nine out of ten for its ability to defend endpoints against malware, ransomware, and malicious scripts.

Apex One can defend against zero-day attacks and stealthy attacks. This is important because in-house applications can have many vulnerabilities, such as coding errors and misconfigurations, which attackers can exploit. Having Apex One as an advantage would give clients a head start in defending against unknown threats.

It uses runtime machine learning to detect ransomware. Machine learning allows us to monitor activities and suspicious behaviors running in our system, not only at the file transfer level but also at the library and registry level. This is important because it allows us to identify potential threats. Runtime machine learning can see any entry points that ransomware might use to infect a system.

Trend Micro has announced that they will be migrating the Apex One platform to Vision One, which can be integrated with an XDR.

Our clients have integrated Apex One with a vulnerability management firewall, SIEM, MFA solutions integrated with Azure AD, and the native security of Microsoft 365.

Apex One is user-friendly. For those familiar with an endpoint security solution, it will not be difficult to learn Trend Micro Apex One. However, for those who are new to the solution, they will need to take some time to learn the ropes.

Administering Apex One is straightforward, especially for the SaaS solution compared to the on-premises solution. This is because we only need to download the installer. The installer is large, around 400 MB. Once we install it on the system, we can communicate with the management console, which is the same for both solutions. We just need to make sure that all required communication ports, FQDNs, IP addresses, and ports are allowed on the firewall. We usually take into consideration the clients when we are doing POCs, and we need to work with the infrastructure team to check on this.

Apex One provides our clients with virtual patching to protect against vulnerabilities. From the perspective of an impending threat, if a client is able to patch the vulnerability in the meantime, Apex One can see the potential threat and take action to protect the client. This is done by identifying the signatures of the vulnerability and creating a virtual patch. It is important to make sure that clients understand that this is not an official patch, but rather a temporary measure that can be used while the official patch is being developed and applied.

Before using Trend Micro, many of our larger clients, which are hospitals, were constantly attacked by malware. However, after adopting Apex One, the viruses and malware have been significantly reduced or eliminated altogether. This is why they continue to renew their subscriptions to Trend Micro.

Most of the time, we recommend the SaaS version of Apex One because the on-premises solution from Trend Micro requires significant resources from the client. If they do not have the necessary monetary resources, they will need to take this into account. This is because when we build an on-premises Apex One, we need two servers: one for Apex One on-premises and one for Apex in Cloud. Additionally, if we leverage the entire SPE package, we will also need a server for mobile security and file and drive encryption.

The endpoint deployment in the cloud has helped our clients reduce their staff workload, especially on the maintenance side.

Apex One has helped reduce our client's administrative overhead.

Some of our clients use Trend Micro's managed XDR service and they love it because the automation makes things easier for them. 

What is most valuable?

The ransomware protection and behavior monitoring features of Trend Micro Apex One are actually good. All endpoint security solutions are in the market to defend against and remediate threats. However, Trend Micro is particularly quick to identify suspicious activities. Any malicious virus or malware that can be extracted from the system is something that they can leverage and work on. One way they do this is through virtual patching. Most of the time, vulnerabilities come from legacy operating systems. These operating systems cannot always be updated, such as Windows 7. If Microsoft announces that it will no longer update a specific operating system, there is nothing that can be done about it. However, Trend Micro can anticipate specific vulnerabilities that can be exploited due to the lack of updates. They can then leverage these vulnerabilities to create a virtual patch that can be applied to the specific system. I believe this is one of the many highlights of Trend Micro Apex One.

What needs improvement?

One of Trend Micro's weaknesses is its high resource utilization. Many of our clients have complained about this, and it is a valid concern. However, we assure our clients that the level of security that Trend Micro provides is worth the high resource utilization. Trend Micro is very fast at detecting and protecting against threats. For example, they were able to identify suspicious signatures for a ransomware attack that was happening worldwide months before the attack actually occurred. We believe that this level of threat intelligence is a major strength of Trend Micro. Of course, no security solution is perfect. There are always ups and downs. However, we believe that Trend Micro's strengths outweigh its weaknesses. However, we do not only offer Trend Micro for this reason.

For how long have I used the solution?

I have been using Trend Micro Apex One for four years.

What do I think about the stability of the solution?

Trend Micro has consistently been in Gartner's Leaders Program year after year. Apex One is stable.

What do I think about the scalability of the solution?

Apex One is scalable.

How was the initial setup?

The initial setup is straightforward. We usually plan and gather data before implementing. We ensure that there are no residual old endpoints installed in the system. We then set expectations with the client and proceed with setting up the management console. We install the system step-by-step and then work on the policies. We also integrate with other systems and transfer knowledge and troubleshooting skills. 

I usually complete the deployments on my own, but for our larger clients with over 2,000 endpoints in different locations, we need to be on-site. For a three-month deployment of those 2,000 endpoints, we allocated three engineers. There was also one time when we had to allocate a lot of engineers for a government agency with eight thousand employees.

What's my experience with pricing, setup cost, and licensing?

The pricing for Apex One is midrange, and worth the costs.

What other advice do I have?

I would rate Trend Micro Apex One an eight out of ten.

All security solutions require maintenance. But with SaaS deployment and SaaS security solutions, most of the maintenance is actually covered by the principal itself.

Apex One can be resource-intensive and have high utilization, but it does a great job protecting our clients' endpoints.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company has a business relationship with this vendor other than being a customer. reseller
PeerSpot user
Information security specialist at a energy/utilities company with 10,001+ employees
Real User
Top 10
It's a good solution for large companies that need to monitor and mitigate external threats
Pros and Cons
  • "I like Apex One's USB port blocking. We implement different policies for each client. For example, a client might ask us to block certain USB devices or require us to restart a desktop on the network."
  • "Apex One's account security could be improved."

What is our primary use case?

I work with Trend Micro Apex One and Vision One. The solutions are also integrated with ServiceNow ITSM. When we detect issues with Apex One, we can open up tickets in ServiceNow to address them. We customize the solution for our clients. The types of policies we implement in ApexOne depend on the customer's situation. 

How has it helped my organization?

Apex One has helped us mitigate a lot of threats like phishing and malware. We've seen a reduction of about 30 percent. 

What is most valuable?

I like Apex One's USB port blocking. We implement different policies for each client. For example, a client might ask us to block certain USB devices or require us to restart a desktop on the network. We can track threats across the network and delete viruses on the endpoint level from a desktop or a laptop. Apex One offers cloud security for large companies that need to monitor and mitigate external threats. It's crucial to have end-to-end visibility from a central console. 

What needs improvement?

Apex One's account security could be improved. 

For how long have I used the solution?

I have used Trend Micro Apex One for about six months.

What do I think about the stability of the solution?

Apex One is stable. 

What do I think about the scalability of the solution?

Apex One is scalable. 

How are customer service and support?

I rate Trend Micro support eight out of 10. I have had no problems with Trend Micro support. 

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We previously used McAfee EDR. I like Apex One much better. 

How was the initial setup?

Apex One isn't complex to set up. The deployment time depends on the size of the company. It could take a few weeks in some cases. A five-person team deployed the solution. 

What's my experience with pricing, setup cost, and licensing?

Apex One is relatively inexpensive. 

What other advice do I have?

I rate Trend Micro Apex One eight out of 10. It's an excellent solution that helps companies mitigate attacks from the internet.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Senior Manager at Gsfc Ltd
Real User
Top 20
A user-friendly solution that provides virtual patching to protect systems with old operating systems from attacks
Pros and Cons
  • "The most valuable feature of Trend Vision One Endpoint Security is the virtual patching it provides."
  • "The solution can be improved to utilize fewer system resources, like memory and hard disk, during scanning."

What is our primary use case?

We use Trend Vision One Endpoint Security for securing end-user systems, desktops, and laptops. We also use it to secure the data in the user system, which we officially provide to employees. It also supports backward compatibility by providing virtual patching to operating systems like Windows 8, whose end-of-life was declared by Microsoft.

How has it helped my organization?

Normally, all organizations have their own domain services. Employees who log in to the local LAN network are given unique login credentials to log in to the system and access applications. Without the solution, DDoS attacks could happen in the network, and unknown traffic could be generated from the endpoints. Sometimes, the malware uses up all the resources, generates traffic, and destabilizes the server or network connectivity.

Services like Trend Vision One Endpoint Security and endpoints security identify malware or viruses infecting the systems. We can disconnect them from the network and limit unknown traffic. The official work which needs to be done gets faster. Otherwise, it slows the network and affects the other systems by overloading the services and applications.

Since we have installed the solution in the system, malware attacks get quarantined, and we get notifications on our dashboard. We get a notification on the solution's centralized dashboard, and then we take the needful action on that.

Trend Vision One Endpoint SecurityOne has advanced protection capabilities that adapt to protect against unknown and new threats.

The solution detects ransomware with run-time machine learning capabilities.

The solution's ransomware detection ability is very important to us.

The dashboard provides us with a single console for cross-layer detection, threat hunting, and investigation. It is very important to have a single console for cross-layer detection.

The solution does not provide end-to-end visibility into the entire IT security environment. It only provides visibility for the desktop part. There is a separate solution for the server part. However, the solution provides complete visibility for the end user part.

The solution integrates with other security products. As part of integrating with other security products, when a threat is detected in the network sandbox, the solution deploys rapid updates to the endpoint. We have scheduled updates. On the server, it gets automatically updated, but on the end user part, we have defined the schedule for when it should get updated.

Trend Vision One Endpoint Security is easy to learn because it's a web-based application. It gives a dashboard on the web, making it easy to identify the affected endpoint or port. So it's easy, and any technical person can use it in a simple way.

Administering it is just a one-time setup; if you have done it, you won't face any issues.

Trend Vision One Endpoint Security has reduced administrative overhead for us. Earlier, we used a different endpoint solution. So the administrative people involved with the old solution are also involved in the new solution.

We are using Trend Micro's managed XDR services in conjunction with Trend Vision One Endpoint Security, which has been quite useful for our Trend Vision One Endpoint Security deployment. It's an additional benefit to the Trend Vision Service.

Users can evaluate the product, and they can use it. We have been using it for the last six to seven years, and it's a stable solution. We haven't faced many issues. The functions we set are normal, and if the end-user faces any issue, we can easily rectify it.Trend Vision One Endpoint Security is a user-friendly solution that can be used by all organizations.

What is most valuable?

The most valuable feature of Trend Vision One Endpoint Security is the virtual patching it provides. If no patches are available for any operating system we use, the system becomes vulnerable to attacks. Trend Vision One Endpoint Security provides virtual patching services, which protect the system from any attack.

The virtual patching feature of Trend Vision One Endpoint Security is quite significant. While Microsoft has released new operating systems like Windows 10 and Windows 11, older operating systems like Windows 8 and Windows 7 are being used for specific purposes. It's not possible to immediately upgrade to a new operating system once it is released. In such a case, we can use the virtual patching feature, which helps limit any attacks on that system, and we can use it till we go for any replacement or upgrade of that machine.

What needs improvement?

The resources used by Trend Vision One Endpoint Security during scanning could be improved. Once the endpoint scanning starts, it may run up to two to three hours; and other applications slow down during that time. The solution can be improved to utilize fewer system resources, like memory and hard disk, during scanning.

For how long have I used the solution?

I have been using Trend Vision One Endpoint Security for the last six years.

What do I think about the stability of the solution?

Trend Vision One Endpoint Security is a stable solution.

I rate it a nine out of ten for stability.

What do I think about the scalability of the solution?

Trend Vision One Endpoint Security is a scalable solution.

I rate it an eight out of ten for scalability.

Which solution did I use previously and why did I switch?

We previously used McAfee. McAfee had some business changes as some other company took over, and there was no future roadmap for the next releases. I was unclear if I would get any updates or if the solution would introduce new versions or releases in the coming years.

How was the initial setup?

The solution's initial setup is straightforward. We have installed the solution on two virtual servers with high availability mode.

What about the implementation team?

We had support from Trend Micro, and a partner was also involved in the solution's deployment. So around four people were involved during the solution's one-time installation.

All the departments use Trend Vision One Endpoint Security in our organization. We have a separate contract for the maintenance of the solution on an on-call basis. If we face any maintenance issues, we open a ticket.

What was our ROI?

We have seen a return on investment with Trend Vision One Endpoint Security. We have seen a significant reduction of around 60 to 70% in viruses and malware since we started using Trend Vision One Endpoint Security.

What's my experience with pricing, setup cost, and licensing?

The subscription model is definitely on the expensive side. Earlier, we used to pay a one-time license fee and yearly support charges. However, with the subscription model, we have to pay more for the complete cost every year.

What other advice do I have?

Overall, I rate Trend Trend Vision One Endpoint Security an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Trend Vision One Endpoint Security Report and get advice and tips from experienced pros sharing their opinions.
Updated: August 2025
Buyer's Guide
Download our free Trend Vision One Endpoint Security Report and get advice and tips from experienced pros sharing their opinions.