No more typing reviews! Try our Samantha, our new voice AI agent.
reviewer2787369 - PeerSpot reviewer
Security Engineer at a consultancy with 11-50 employees
Real User
Top 20
Dec 15, 2025
Consolidated security tools into one console and manage endpoints, servers, and emails efficiently
Pros and Cons
  • "TrendAI Vision One has helped me to consolidate my use of security vendors quite a lot."
  • "Sometimes the CPU utilization is so high that the computer crashes or lags behind."

What is our primary use case?

I have experience with TrendAI Vision One, specifically using endpoint security, email security, and all of the modules that are used most commonly.

We mostly install TrendAI Vision One endpoint security in all client organizations, configure everything covering endpoints, servers, emails, and then work on the alerts for them as the need arises.

We are using the sensors that are included in TrendAI Vision One.

What is most valuable?

TrendAI Vision One has helped me to consolidate my use of security vendors quite a lot. Many of my clients were using different brands of antivirus for the server security and endpoint security, and another product for email security. Because of TrendAI Vision One, they were able to combine all of them in the same console. This reduced a lot of siloed tools.

I am quite impressed by the speed with which the server policy gets deployed. While the endpoint policy takes about 15 minutes to get assigned to the system, server policy is quite quick in that regard.

The coverage of these sensors is quite vast. When compared to other antiviruses, we found that TrendAI Vision One does cover quite a lot of ground.

What needs improvement?

The endpoint security policy for standard endpoints with TrendAI Vision One takes a lot of time. It would be beneficial if there were DLP features in it, as many customers require that. While TrendAI Vision One's full suite is quite impressive, customers have to find another product for DLP and file monitoring. TrendAI Vision One does have a not fully-fledged DLP in the endpoint security part, and it sometimes hangs up the PC when we apply it.

The alerts could be better because when an alert comes for an email that has been compromised and found on the dark web, we cannot quite find where it got compromised from.

The network part is something that needs to be worked on because most of the time we have to look at the firewall to get the full scenario or coverage.

What do I think about the stability of the solution?

We have found a lot of performance issues with TrendAI Vision One agents. They are not lightweight. The first time I used TrendAI Vision One, the agent was 500 MB. Now that I am using them, the initial size is 800 MB. Sometimes the CPU utilization is so high that the computer crashes or lags behind. This is a really big concern for everyone using TrendAI Vision One.

Buyer's Guide
TrendAI Vision One
April 2026
Learn what your peers think about TrendAI Vision One. Get advice and tips from experienced pros sharing their opinions. Updated: April 2026.
892,776 professionals have used our research since 2012.

What do I think about the scalability of the solution?

TrendAI Vision One is quite a good tool because there are not any issues in scalability. We can easily add more licenses to it and increase our organization security. Scalability-wise, it is good.

How are customer service and support?

I have contacted the technical support or customer support of TrendAI Vision One quite a lot.

The engineers are quite helpful when they respond, but I have found that sometimes the assigned engineer responds to the first query a bit too late. I can see in the portal that the engineer has been assigned to my case, but we have to prompt them to give us a reply because nobody is answering. We have to call TrendAI Vision One support sometimes. Once we start the case, the responses are quite helpful, though we have had to escalate some of the cases quite a lot when customers need it.

Which solution did I use previously and why did I switch?

I have not basically used any alternatives to TrendAI Vision One. I have tried CrowdStrike and Symantec. Symantec is so far out of TrendAI Vision One's reach and CrowdStrike, I have not used it much, but it is a bit harder to configure than TrendAI Vision One. I find TrendAI Vision One's UI much easier.

How was the initial setup?

The initial deployment of TrendAI Vision One is quite easy since it is basically a cloud-based app, and you just have to deploy the agent.

What about the implementation team?

If integrating AD with TrendAI Vision One, I am sure only one person would be needed. If you have to deploy and install the agents directly into the systems, at least four to five people are needed if the size of the organization is for 1,000 to 2,000 employees.

What was our ROI?

It would take one or two months to deploy TrendAI Vision One for a client, but mostly because sometimes things get delayed on the client side.

What's my experience with pricing, setup cost, and licensing?

No maintenance is required on our side for TrendAI Vision One.

Which other solutions did I evaluate?

I am not into sales, but we have lost a few customers because of the pricing of TrendAI Vision One. They seem to gravitate to Symantec and others because their pricing range is quite less than TrendAI Vision One, and we have lost them because of that.

What other advice do I have?

My review rating for TrendAI Vision One is 9 out of 10.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Last updated: Dec 15, 2025
Flag as inappropriate
PeerSpot user
reviewer2706279 - PeerSpot reviewer
Beheerder ICT-Services at a government with 201-500 employees
Real User
Top 20
May 17, 2025
Centralized visibility improves threat detection and response
Pros and Cons
  • "I like how easy it is, and there is a single pane of glass. We have one console for everything."
  • "Trend Vision One helped reduce the time to detect and respond to threats by 70% to 80%."
  • "Vulnerability scanning could be improved. They need to see more CVEs and scan products for known vulnerabilities, allowing for better display and review of potentially exploitable servers by hackers or through configuration settings."
  • "Vulnerability scanning could be improved. They need to see more CVEs and scan products for known vulnerabilities, allowing for better display and review of potentially exploitable servers by hackers or through configuration settings."

What is our primary use case?

Our use case for Trend Vision One is for our security platform. We use it for antivirus, XDR, and network telemetry purposes.

How has it helped my organization?

Trend Vision One helped us to consolidate our use of security vendors and reduce silos. We had three or four consoles from different products, and we consolidated them into one console with this product. 

Trend Vision One helped reduce the time to detect and respond to threats by 70% to 80%.

Trend Vision One has helped us reduce noise from false positives.

We have been using cyber risk exposure management for 2 months since upgrading in April. It helps us identify blind spots by providing more visibility and insights into our environment, making it a valuable feature. 

We use the network sensor, and its coverage is critical. With SIEM, we gain substantial insights into our environment, and having a complete 360 view is necessary in today's security world. It reduces the risk by 50%.

Having AI built into the Trend Vision One platform is important for our organization. It reduces many manual steps, resulting in more and quicker detections and advanced automation for remediation, improving efficiency by 60% to 70%. The solution aims to reduce risks and enhance detection.

What is most valuable?

I like how easy it is, and there is a single pane of glass. We have one console for everything. 

Trend Vision One provides centralized visibility and management across protection layers. It has the functionality of different products and management of a single pane of glass. We have one console for everything. As a security engineer, it's easier to check the alerts and find everything. It consolidates a lot of consoles into one, and that's what we like most about it.

What needs improvement?

Vulnerability scanning could be improved. They need to see more CVEs and scan products for known vulnerabilities, allowing for better display and review of potentially exploitable servers by hackers or through configuration settings.

For how long have I used the solution?

We have been using Trend Vision One for approximately 18 months.

What do I think about the stability of the solution?

We haven't experienced any stability issues. It has proven to be stable.

What do I think about the scalability of the solution?

The scalability of Trend Vision One is good.

How are customer service and support?

I have contacted technical support from Trend Micro. The quality and speed of support are good.

How would you rate customer service and support?

Positive

How was the initial setup?

It was easy. It took us one day to fully deploy Trend Vision One.

Some maintenance is required for updating agents on the servers.

What about the implementation team?

The deployment involved just one person working with the vendor in one day.

What was our ROI?

Trend Vision One has reduced risks by 50%. We have reduced the response time by approximately 70%-80%.

What's my experience with pricing, setup cost, and licensing?

When we have a good product such as Trend Vision One, the price is fine.

Which other solutions did I evaluate?

We have used Trend Micro products for many years, and we upgraded to Trend Vision One. We didn't test any alternatives, staying with what we've used for years.

What other advice do I have?

I would rate Trend Vision One an eight out of ten.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Buyer's Guide
TrendAI Vision One
April 2026
Learn what your peers think about TrendAI Vision One. Get advice and tips from experienced pros sharing their opinions. Updated: April 2026.
892,776 professionals have used our research since 2012.
reviewer2813907 - PeerSpot reviewer
Managed Detection And Response Delivery Analyst at a tech vendor with 10,001+ employees
Real User
Top 5
Apr 3, 2026
Incident analysis has become faster and clearer but event interfaces still need improvement
Pros and Cons
  • "The solution saves time approximately by 80 to 90 percent; it is very simple."
  • "The scalability of TrendAI Vision One would be around a six; it is appropriate for smaller companies, but for bigger ones such as Nike, I would say it would not fit as well."

What is our primary use case?

TrendAI Vision One is used for XDR.

What is most valuable?

TrendAI Vision One is more limited, but the strong part is its minimalist design, allowing you to know the most important information about the incident. This is the strong point.

TrendAI Vision One helps consolidate security software across hybrid environments, and I think it is useful, especially when integrated with another tool for some clients. It is so useful to get a first analysis or to get some CUs with TrendAI Vision One, so it helps.

The solution saves time approximately by 80 to 90 percent; it is very simple.

What needs improvement?

To provide centralized visibility and management across various protection layers could be better. I would add different interfaces as I really appreciate how CrowdStrike manages the datasets. An interface where you can select the different events that happened in the incident would be beneficial because in TrendAI Vision One the information is very basic; you get all the information raw in a column, which I would improve by adding an advanced search feature similar to CrowdStrike where events can be filtered. This would make the analysis better for the client who is receiving the information.

TrendAI Vision One has room for improvement regarding different interfaces, specifically similar to the Event Simple part of CrowdStrike where you can identify what happened. It would be helpful to have an integrated identity module, because sometimes I want to see who executed an incident, such as a PowerShell command, to know if it was an admin or the local user of the machine. If I cannot see that, I do not know anything. Integrating the identity module would be beneficial.

For how long have I used the solution?

I have been working with TrendAI Vision One for one year and a half.

What do I think about the stability of the solution?

I rate the stability of TrendAI Vision One as a ten because I did not have any problems with it.

What do I think about the scalability of the solution?

The scalability of TrendAI Vision One would be around a six; it is appropriate for smaller companies, but for bigger ones such as Nike, I would say it would not fit as well.

What was our ROI?

Using TrendAI Vision One has reduced the time to detect and respond by approximately 20 percent up to 80 percent; the strong point is that it is simple, making it fast and easy to learn.

What other advice do I have?

When an incident appears in TrendAI Vision One, I open it and on the first page, you get to see the timeline of where all the different assets appear, including the host and other information. It is helpful because you get directly all the information by taking a look at the host involved. For example, if it is a server and you see SSH commands, it may fit with your conclusion. After that, I open the XDR part where you see in raw form all the different information. Finally, I can use the XDR view where you can filter using their raw SQL language to filter all the different incidents, for example, by endpoint GUID, something I usually use.

The risk reduction from using TrendAI Vision One depends on various factors. If I only get to use TrendAI Vision One and not any other tools, I think it would be approximately 80 percent, because if you have normal incidents, it is helpful, making it easier for the team of the final client to read the information. However, for real incidents requiring forensics, if you have to activate forensics, I think you would have difficulties, so I would say around 80 percent.

The importance of AI built into TrendAI Vision One is relatively recent for me; it is helpful to have a direct verdict, but I prefer to make my manual verdict. I would say it is important at a level of five for me, but for some inexperienced analysts, it might be at a level of five or seven because they will rely on that.

TrendAI Vision One is more simple compared to other solutions, but it could be useful for controlled cases if you have a small enterprise where the same software is used, making it interesting for situations where you are familiar with specific CUs. In my opinion, it would be more interesting than Cortex for smaller incidents, while I would prefer Cortex for larger cases than false positives which will be better managed by TrendAI Vision One.

My clients may be less than average because TrendAI Vision One is not that widely used. I think it is getting used less, but perhaps with the AI update it will be used more. I would estimate around 5 to 10 clients, approximately half of my client base.

Learning TrendAI Vision One can take anywhere from two weeks to one month.

In my opinion, TrendAI Vision One gets the information easily, but it does not really help reduce false positives by itself; you have to do the final work. I would say it helps with false positives around 80 percent because in TrendAI Vision One, you can see the verdict, plus AI is assisting with it.

I would recommend TrendAI Vision One, telling potential users that it is very easy to use, but it would be useful to learn how to use SQL for deeper analysis of different modules, which is important. Knowing how to use the different modules that your client has integrated will make a significant difference.

Which deployment model are you using for this solution?

On-premises

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company has a business relationship with this vendor other than being a customer. partner
Last updated: Apr 3, 2026
Flag as inappropriate
PeerSpot user
Soufiane Hammoutou - PeerSpot reviewer
Consultant at HAUTS-DE-SEINE HABITAT
Consultant
Top 20
Jan 14, 2026
Centralized protection has improved threat response and simplified endpoint security management
Pros and Cons
  • "TrendAI Vision One helps with centralized visibility and protection across multiple layers."
  • "To improve TrendAI Vision One to a perfect score, I believe better pricing and more support would be ideal."

What is our primary use case?

My use case for TrendAI Vision One is deploying it for an entity within a company. I deployed TrendAI Vision One to protect all kinds of endpoints, including mobiles, machines, mailboxes, and servers.

What is most valuable?

The best features of TrendAI Vision One that I appreciate include its centralized nature, the Copilot AI agent, its simplicity of use, and the quality of their API.

TrendAI Vision One has helped reduce my time to detect and time to respond to threats by approximately 10%.

What needs improvement?

To improve TrendAI Vision One to a perfect score, I believe better pricing and more support would be ideal.

For how long have I used the solution?

I have been using TrendAI Vision One for one year.

What do I think about the stability of the solution?

I would rate the stability of TrendAI Vision One highly, as there were no bugs. I would give it a 10.

What do I think about the scalability of the solution?

Regarding scalability, TrendAI Vision One is scalable. I would give it an eight.

How are customer service and support?

I rate the technical support an eight.

The coverage for my organization's network is critical. When we have questions, we return to them. When we need something, we return to them, and they were always available.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

The risk reduced by switching to TrendAI Vision One is similar to other EDR or XDR solutions. It can detect malicious operations and threats, but the exact percentage is difficult to quantify. For the company I was deploying it for, we detected many threats. I would rate the risk reduction as a 10 because the company in question did not have an XDR or EDR solution in place before.

How was the initial setup?

The deployment of TrendAI Vision One is easy; it is just an executable.

It takes almost one day for TrendAI Vision One to appear in the console.

What about the implementation team?

In my organization, we had four specialists working with TrendAI Vision One: myself and three security engineers. I was the project manager.

What was our ROI?

I can estimate the ROI seen from TrendAI Vision One to be approximately 15%.

What's my experience with pricing, setup cost, and licensing?

When it comes to pricing, I find TrendAI Vision One not expensive compared to other products.

Which other solutions did I evaluate?

I compare TrendAI Vision One with other solutions and vendors on the market, and we can see that it is well-placed in Gartner, so it is one of the best products.

What other advice do I have?

TrendAI Vision One helps with centralized visibility and protection across multiple layers.

The visibility and protection provided by TrendAI Vision One allow us to see all the assets in one console, which is beneficial. We can also see all the features in one console, which is equally advantageous.

I did not use the cyber risk exposure management capabilities with TrendAI Vision One, nor did my clients use that for identifying blind spots.

The top security challenges in the industry include handling the decommissioning of old products, specifically a Microsoft product. Additionally, not all features are centralized in one console, which is not ideal for the correlation of investigations.

TrendAI Vision One is deployed as a cloud solution and a SaaS solution.

I used TrendAI Vision One sensors.

I would recommend TrendAI Vision One to other users because it is easy to use and easy to deploy, as these are the most important factors. The importance of having AI built into TrendAI Vision One is significant; I use the AI aspects. When I want to look for a feature, I go to AI. When I want to create, for example, an IOC, I go to AI, and it assists with this.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company has a business relationship with this vendor other than being a customer. partner
Last updated: Jan 14, 2026
Flag as inappropriate
PeerSpot user
Monish Kumar V - PeerSpot reviewer
Senior Associate Cyber Security Defense at kyndryl
Real User
Top 20
Feb 12, 2026
Improved incident investigations have reduced analyst effort with enriched high-fidelity alerts
Pros and Cons
  • "Since the alerts are high fidelity and TrendAI Vision One requires less overall from the security analyst perspective, it reduces cyber risk effectively."
  • "Compared to CrowdStrike sensor, TrendAI Vision One consumes more compute power."

What is our primary use case?

We use TrendAI Vision One for endpoint security.

For example, we use XSIAM, which is Palo Alto's XDR plus SIEM solution. When we get an incident, we need to do some hunting in that system. It takes approximately 45 minutes. However, with TrendAI Vision One, because most of the information is already enriched, we get only high fidelity incidents. This saves us around 25% of time compared to other solutions.

TrendAI Vision One mostly delivers high-fidelity incidents. We receive nearly 60% of incidents as true positives, with the remaining 40% being false positives. Comparatively, with XSIAM we have around 40% true positives and 60% false positives.

We are an MSSP with nearly 60 people working in SCI, which is Shared Commercial Infrastructure. We have approximately 60 people dedicated to TrendAI Vision One.

What is most valuable?

One feature I appreciate about TrendAI Vision One is that compared to other solutions, the alerts we receive are already enriched. We use it in a shared commercial infrastructure which was inherited from IBM. During investigation, it is much easier to work with TrendAI Vision One compared to other solutions.

What needs improvement?

Compared to CrowdStrike sensor, TrendAI Vision One consumes more compute power. CrowdStrike is more optimized than this solution.

TrendAI Vision One is a niche product because XSIAM is a combination of SIEM plus XDR, while this is an XDR solution. If I need to do deep hunting, for example, we had an incident in Microsoft Defender yesterday which required advanced hunting capabilities. This is not possible in TrendAI Vision One, which I see as a drawback. TrendAI Vision One is a very good product, but it has a specific use case. If you want less customization, you can use TrendAI Vision One. If you need more customization, you need to use a SIEM plus XDR solution. Nowadays, they are integrating SIEM with XDR solutions. For example, we have XSIAM and Microsoft Defender is going to integrate SIEM as well going forward. In that case, TrendAI Vision One is a niche product. As a product with its specific use case, it is good.

Specifically regarding sensors, they consume comparatively more compute capacity, so we need to plan our workloads accordingly. Additionally, the user interface could be improved. When I investigate one alert, all the indicators appear jumbled together in one area. If they improve the user interface, it would be better.

For how long have I used the solution?

We have been using TrendAI Vision One for the last one and a half years.

How are customer service and support?

I would rate the technical support an eight.

How would you rate customer service and support?

Positive

What other advice do I have?

Since the alerts are high fidelity and TrendAI Vision One requires less overall from the security analyst perspective, it reduces cyber risk effectively. Regarding downtime compared to XSIAM, I would rate this a nine because its downtime is considerably less. In terms of scalability, it is pretty scalable, though somewhat complex, so I would rate it an eight point five. I would recommend TrendAI Vision One if the organization is less mature in terms of SOC. However, if you want to do advanced SOC hunting, this is not the right product in my opinion. The overall review rating for this product is eight point five.

Which deployment model are you using for this solution?

On-premises

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

IBM
Disclosure: My company has a business relationship with this vendor other than being a customer. MSP
Last updated: Feb 12, 2026
Flag as inappropriate
PeerSpot user
MalayKumar Das - PeerSpot reviewer
SOC Consultant SOC Consultant at IBM
Real User
Top 20
Dec 15, 2025
Centralized threat hunting has improved endpoint visibility and allows silent remote remediation
Pros and Cons
  • "TrendAI Vision One allows mitigation of threats without interrupting branch users' regular work, which is its unique selling point."
  • "The area for improvement is to provide more clarity on the query part, including examples for creating reference sets and documenting capabilities thoroughly so future users can benefit without needing to experiment."

What is our primary use case?

TrendAI Vision One use cases are mostly related to endpoints, such as detecting registry modifications or new software being added, as well as monitoring for malicious activities including PowerShell scripts, double extension files, ransomware, and crypto miners. Since I work for the financial sector, it is crucial to ensure there are no remote software programs running, especially regarding banking security.

What is most valuable?

TrendAI Vision One has two types of alerts that help reduce the time to detect and respond to threats. The first is based on alerts and workbench ID, while the second is host-based detections, allowing me to see all different threats on particular endpoints over a selected time frame. I can check for various endpoints affected by different alerts and customize this for specific time frames. Monitoring critical assets, threat hunting, and running queries are feasible tasks, providing a comprehensive overview of endpoint security and the ability to remove malicious files quickly.

One of the best features of TrendAI Vision One is its ability to let me remediate endpoints without disturbing branch users, as long as the endpoint is online and connected. I can delete files or take control through the console by informing the bank's security team to get approval. Another great feature is viewing alerts, segregating them by type and host, which makes it easier to fine-tune security and monitor critical resources. Additionally, the ability to create reference sets for known malicious hashes enhances detection capabilities across endpoints.

TrendAI Vision One saves resources and time. It provides better visibility of endpoints compared to other security management tools, which makes it invaluable. For smaller organizations that may not afford multiple tools, an XDR solution can handle their security needs effectively.

TrendAI Vision One allows mitigation of threats without interrupting branch users' regular work, which is its unique selling point.

What needs improvement?

The area for improvement is to provide more clarity on the query part, including examples for creating reference sets and documenting capabilities thoroughly so future users can benefit without needing to experiment.

Documenting the capabilities of endpoint consoles would also be beneficial for new users understanding what can be done effectively.

For how long have I used the solution?

I initially used the first EDR approximately two years ago, and now I have been using TrendAI Vision One for eight to nine months.

What do I think about the stability of the solution?

The stability of TrendAI Vision One is good; I would rate it an eight.

What do I think about the scalability of the solution?

I would rate the scalability at eight and a half.

How are customer service and support?

I have not worked with technical support yet, so I cannot rate it.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

I have not worked with other solutions yet, so I can only speak to my experience with TrendAI Vision One XDR, which I find to be good for handling threats across endpoints.

How was the initial setup?

I am not aware of the deployment process since I have not been involved with it.

What about the implementation team?

Only a few of us are using the solution currently—my manager and I. Due to my background in threat hunting, I have admin access to monitor various alerts and create reference sets for potential threats effectively.

Only three or four users have access to TrendAI Vision One, including my manager and me from the vendor side, and two from the bank end.

I am a vendor hired for SOC security and threat hunting, working for IBM clients.

What was our ROI?

I cannot estimate the return on investment accurately, as I do not have insight into the financials. However, I can say that the tool is good, particularly the basic subscription which provides me with necessary tools and knowledge to protect security.

What's my experience with pricing, setup cost, and licensing?

I do not have any information regarding the pricing, so I cannot comment on that.

Which other solutions did I evaluate?

Every organization typically installs antivirus agents on their endpoints and servers.

What other advice do I have?

My false positives have decreased, but reducing them requires thorough investigation. For example, each endpoint has its own scanning device, such as Windows Defender.

Apex Central is attempting to stop the services of Windows Defender, leading to alerts when malicious behavior is detected. Through thorough investigation, I have identified that while Apex Central might not directly stop processes, it does so using CMDlets. Hence, I decided to whitelist that.

TrendAI Vision One reduces endpoint risk by approximately 60 to 70 percent; the remaining 30 percent can be due to other factors such as phishing and web interactions.

For small organizations, implementing TrendAI Vision One is a wise choice because it delivers great visibility and clarity on endpoint threats, enabling effective monitoring and quarantining regardless of the environment.

TrendAI Vision One sensors are being used on the endpoints.

I do not know if Cyber Risk Exposure Management comes under the basic subscription, as I mostly focus on threat hunting and do not recall using it.

If the suggested improvements are implemented, it will be even more flexible and feasible.

I give this review an overall rating of 9 out of 10, and I definitely recommend TrendAI Vision One to other users because it provides solid security for endpoint protection.

Which deployment model are you using for this solution?

On-premises

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

IBM
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Dec 15, 2025
Flag as inappropriate
PeerSpot user
reviewer1072692 - PeerSpot reviewer
Head of IT at a financial services firm with 11-50 employees
Real User
Top 5Leaderboard
Nov 3, 2025
Provides centralized visibility and improves threat response across hybrid environments
Pros and Cons
  • "The comprehensive overview of the security status is the most valuable feature of TrendAI Vision One, and its ability to provide centralized visibility and management is quite good because all the relevant data are present, providing everything needed."
  • "Some improvements could be made, but all the possibilities of the platform are not being fully utilized, so some features that could be discussed may not have been explored yet, though they may already be available."

What is our primary use case?

TrendAI Vision One sensors are used at the endpoint to gather information from endpoints, which has proven to be very useful. The coverage provided by TrendAI Vision One is critical for our organization's network because it's a comprehensive way to get all the relevant data from the endpoints regarding antivirus security and similar security settings.

Some basic features of the Cyber Risk Exposure Management capabilities in TrendAI Vision One are being used. Plans exist to expand the usage, but currently the overview of the cyber risk settings is checked, though it hasn't been used much in the last few months.

TrendAI Vision One has helped consolidate the use of security vendors and reduce silos, but other vendors have not been replaced. TrendAI Vision One alone is sufficient for current needs, so other vendors for such solutions do not need to be used, at least not for now.

TrendAI Vision One is used for consolidated security across hybrid environments.

What is most valuable?

The comprehensive overview of the security status is the most valuable feature of TrendAI Vision One. TrendAI Vision One platform's ability to provide centralized visibility and management is quite good because all the relevant data are present, providing everything needed. The interface is quite simple to use and all the relevant data can be seen there.

TrendAI Vision One has helped reduce the time to detect and respond to threats because information is gathered more quickly and all the relevant points are visible. If there's any problem, it can be seen much easier and quicker.

TrendAI Vision One has also helped reduce cyber risks because it decreases cyber risks as there is more control over the environment.

What needs improvement?

There are currently no particular suggestions on how TrendAI Vision One can be improved because improvements have been seen in nearly every version, and satisfaction with what can be seen and used is high.

Additional features are not desired to be seen in the next release of TrendAI Vision One because not all the features that are available now are being used. For current needs, everything is already there. Perhaps in the future something else will be needed, but everything that is currently needed is already included.

TrendAI Vision One has improved its integration with other products, with other vendors, or with mobile device management. The mobile device management solution has improved over the years and was pretty basic when it started, but now it has much more options. Some improvements could be made, but all the possibilities of the platform are not being fully utilized, so some features that could be discussed may not have been explored yet, though they may already be available.

For how long have I used the solution?

TrendAI Vision One has been used for a couple of years.

What do I think about the scalability of the solution?

There have been no problems with scaling TrendAI Vision One. The organization is not large, so there were no problems in scaling. TrendAI Vision One appears to be tailored for much bigger organizations, so no scaling problems were encountered.

How are customer service and support?

There has not been much contact with technical support, though some checks and presentations were conducted, which were quite good. The response was very quick and all the information needed was received, resulting in high satisfaction.

Technical support would be rated nine out of ten. Regarding local technical support, it is also quite good through the partner network and directly. If something is escalated directly to Trend Micro, responses are received. There is high satisfaction with the current support level.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup of TrendAI Vision One was seamless because it was a migration from an on-premises Trend Micro service to a cloud-based one, so there were no particular problems.

What about the implementation team?

External partners were used for the implementation of TrendAI Vision One, though the process was overseen. There was a transfer of knowledge during the implementation.

What was our ROI?

Return on investment from TrendAI Vision One has not been calculated in the traditional sense, but price-wise, it's a better solution than some others that have been looked at or researched. TrendAI Vision One is quite convenient for the organization.

Which other solutions did I evaluate?

Before TrendAI Vision One, a broader marketplace was evaluated. A granular possibility to purchase only needed options without purchasing unnecessary components was not observed in other solutions. The licensing model of TrendAI Vision One is the best among other solutions that have been seen.

What other advice do I have?

For integrations with third-party solutions, integration was done for log management. Logs are downloaded or shipped from Trend Micro solutions to internal log management solutions, and there were no particular problems in integrations. Many other integrations specifically with Trend Micro were not conducted.

TrendAI Vision One is considered the best option on the market at the moment for this organization. TrendAI Vision One appears to be quite popular in the region, with many companies using it, both bigger and smaller organizations. A community provides information and support, making TrendAI Vision One popular in the area.

TrendAI Vision One has been using AI technologies already for some time, which shows awareness of the landscape. It is believed that TrendAI Vision One will tailor the solution accordingly, as AI is already being used in some solutions within the platform, indicating good direction for the product.

TrendAI Vision One provides learning courses, and events from partners sometimes offer opportunities to gather new information on the products. Additionally, a community is available, creating a good landscape for learning and support in the region.

The partnership program is not well known because collaboration is through partners, but it is believed that partner satisfaction is high.

TrendAI Vision One received an overall rating of eight out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Nov 3, 2025
Flag as inappropriate
PeerSpot user
Manish Kumar Twinkle - PeerSpot reviewer
Security Engineer at Eventus Aecurity
Real User
Top 5Leaderboard
Feb 18, 2026
Integrated XDR has strengthened endpoint protection and reduces false positives in daily incident response
Pros and Cons
  • "TrendAI Vision One has positively impacted our organization by giving us fewer false positive alerts, and with its support, we are securing our environment against upcoming vulnerabilities such as zero-day attacks."

    What is our primary use case?

    My main use case for TrendAI Vision One is for endpoint security and XDR, as we need to handle incidents effectively.

    What is most valuable?

    TrendAI Vision One provides all the details for incident handling in our bank security operations, such as identifying where a threat is coming from, its impact, and a workbench to manage responses, making it easy to mitigate issues. In my daily work, TrendAI Vision One helps us first on the endpoint by preventing threats, allowing us not to worry about the types of daily updates, which we schedule based on preferences. Additionally, with XDR, we receive all threat events and their impacts, which helps us mitigate cyber risks and create playbooks.

    The best features of TrendAI Vision One are its integration capabilities with third-party intelligence such as STIX and MISP, along with collaboration and integration with tools such as Splunk, IBM QRadar, and DSPM and SASE products. The integrations with third-party tools such as Splunk and QRadar help our team significantly; we utilize syslog to gather all endpoint logs and QRadar logs. We simply generate an API and API key to facilitate integration with Splunk or QRadar.

    TrendAI Vision One has in-depth analysis and recognition features that provide a diagram of a workbench if a preventive attack is happening or has occurred, allowing me to access all logs and additional information regarding the threat's origin, impact, and mitigation strategies.

    TrendAI Vision One has positively impacted our organization by giving us fewer false positive alerts, and with its support, we are securing our environment against upcoming vulnerabilities such as zero-day attacks. Reducing false positives and handling zero-day attacks has streamlined our team's daily workflow and improved our overall security posture. For example, we integrated with Netskope and IBM QRadar, which reduced our workload by decreasing alerts, as QRadar detects genuine files that may have been previously flagged.

    What needs improvement?

    I do not have any specific suggestions for improving TrendAI Vision One.

    For how long have I used the solution?

    I have been using TrendAI Vision One for three years.

    What do I think about the stability of the solution?

    In my experience, TrendAI Vision One is stable.

    What do I think about the scalability of the solution?

    The scalability of TrendAI Vision One is notably low maintenance, and their support for the agent is long-term. We update the agent quarterly, and their Basecamp services share a data lake, making information gathering effortless.

    How are customer service and support?

    The customer support for TrendAI Vision One is very good. We create a case, and Trend support connects remotely, typically within twenty-four hours.

    Which solution did I use previously and why did I switch?

    Previously, we used Sophos, which was very bulky and caused slowness issues, prompting us to switch to TrendAI Vision One.

    How was the initial setup?

    The setup cost is reasonable, and the licensing is relatively low.

    What about the implementation team?

    We have directly purchased TrendAI Vision One from Trend Micro and did not acquire it through the AWS marketplace.

    What was our ROI?

    We have seen a return on investment because it is easy to use. One agent installed on the endpoint saves both money and time, as we only need L1 engineers to support the endpoints, reducing the number of employees needed to manage them.

    What's my experience with pricing, setup cost, and licensing?

    In my opinion, the pricing for TrendAI Vision One is somewhat high.

    Which other solutions did I evaluate?

    Before choosing TrendAI Vision One, we evaluated other options such as SentinelOne and CrowdStrike.

    What other advice do I have?

    I rate TrendAI Vision One a ten out of ten. Most importantly, I chose ten out of ten because it is easy to control and install the product, and the support from Trend engineers is exceptional along with the help we receive from salespersons. I advise those looking into using TrendAI Vision One to consider it seriously, as it offers XDR features, endpoint security features, and ZTNA features, eliminating the need for multiple agents or plugins. TrendAI Vision One is a very good solution that is easy to use. Their knowledge-based articles are extremely helpful, allowing us as techies to troubleshoot issues independently without always relying on senior staff or support.

    Which deployment model are you using for this solution?

    Hybrid Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Disclosure: My company has a business relationship with this vendor other than being a customer. Partner, Reseller
    Last updated: Feb 18, 2026
    Flag as inappropriate
    PeerSpot user
    Buyer's Guide
    Download our free TrendAI Vision One Report and get advice and tips from experienced pros sharing their opinions.
    Updated: April 2026
    Buyer's Guide
    Download our free TrendAI Vision One Report and get advice and tips from experienced pros sharing their opinions.