No more typing reviews! Try our Samantha, our new voice AI agent.
Chief Digital Officer at Samson Systems Group, Inc.
User
Top 20
Dec 4, 2024
Has significantly improved our company because we can now track and see how many attacks we have
Pros and Cons
  • "Trend Vision One has significantly improved our company because we can now track and see how many attacks we have. Since we’ve implemented it, we haven’t had any major attacks that have successfully entered the company. So, we know the defense mechanism is working."
  • "It would be great if there were Trend Micro products that could enhance the security of these devices, either as part of our product or in some other way integrated into our offering."

What is our primary use case?

Our use cases are essentially all the classic defense mechanisms that are used to protect devices, secure emails, and ensure that we don’t pull in anything harmful. We also monitor Internet and Intranet traffic to detect abnormal behavior and address it. This has helped us in many situations where we’ve faced external attacks, which then usually try to go back out. I always say that they try to drill through the wall and get back out, and in that way, we’ve been able to recognize when someone has gained access to our devices.

We operate in 60 countries with 4,000 to 4,500 employees, of which nearly 2,000 are based in Frankfurt. All of the end devices of our colleagues are under IT security monitoring. The Deep Discovery Inspector is implemented at three global locations: one in Europe, one in Asia, and one in the USA. This allows us to detect any issues early on, and with network segmentation, we can minimize potential damage in case of an incident.

The biggest security concerns in our industry are not really industry-specific but are intrusions. Identity theft is a challenge and then there are issues where people are manipulated into making money transfers to what seem like customer accounts that don’t actually exist.

Another is the classic attack, where ransomware is used to infiltrate systems and gain access through encryption and similar methods.

Additionally, we also have the issue of IP protection.

How has it helped my organization?

Trend Vision One has significantly improved our company because we can now track and see how many attacks we have. Since we’ve implemented it, we haven’t had any major attacks that have successfully entered the company. So, we know the defense mechanism is working.

In terms of our ability to manage risks, we already had the stances for risk management in place, from our side, from a purely conceptual standpoint. Through a solution like this, we always want to get a more concrete approach for the operational side. We aim to identify and assess risks and then determine the measures we can take to mitigate those risks. That’s where Trend Micro is very helpful.

Trend Vision One has significantly helped reduce our time to detect and respond to threats.

In terms of whether or not Trend Vision One has helped my organization reduce noise from false positives, it’s always a matter of perspective in terms of whether or not the number of alarms has truly been reduced or if they were false alarms. We rolled out the solution across the company, and as a result, we now monitor more devices and have a more comprehensive view of security. Therefore, the number of alarms and false alarms has certainly increased, because we are now looking at all devices. Previously, we didn’t monitor them, so we didn’t notice them.

We have always seen alarms and false alarms. However, we have incorporated mechanisms to identify where the false alarms are coming from, and we continuously refine the system. Sometimes, activities in the internal IT administrative area trigger alarms that are not actual threats, and we continuously adjust and refine those rules to reduce false alarms. We didn’t have a solution in place before to compare whether or not it has reduced false positives. The mechanisms we have now allow us to assess both alarms and false alarms in detail and, in the case of false alarms, to trace where they come from and implement rules to prevent them from happening again.

Trend Vision One has definitely reduced my organization's cyber risk. We took a holistic view of all devices, became more aware of IT security risks from the outset, and then integrated all devices into that view. In the incidents we encountered at the beginning, as we increasingly implemented and observed this solution, a clear path was outlined on how to address and resolve these issues.

What is most valuable?

We implement the sensors globally from the angle that we are, in fact, global and operate worldwide. The importance lies in the fact that we know attacks can happen from anywhere, and therefore we decided to implement this as a standard solution within our company, The Samson Group. The Samson Group itself has 60 legal entities worldwide, and from our side, this is more of a governance requirement, meaning it must be used to protect the entire organization.

We have found the Deep Discovery Inspector that is in place exceptionally valuable. It has consistently helped us identify areas where issues are happening and where there have been small vulnerabilities in the network that could lead to issues. This happens when, at some point, an unauthorized device—one that shouldn’t be in the network—somehow gains access. This is certainly one of Trend Micro's standout features, as it has provided us with insight into what is happening in our network, which has prevented us from facing significant damage.

We have a positive impression of Trend Vision One's ability to provide us with centralized visibility and management across protection layers. The impression is definitely positive for us. That’s also why we decided to extend the contracts. It’s a very mature solution that is well-understood and user-friendly for people working in this field.

Trend Micro helps us consolidate security vendors because we are now establishing this as standard software for the company. We only work with one solution provider, which is part of the consolidation. When selecting the solutions, we carefully considered what was important to us and where issues occurred. For example, we were particularly pleased that the base and system come from a Japanese company, meaning we don’t have to put ourselves in the hands of Russian or American companies to make this happen.

We use the CREM features and from our perspective, it is very helpful because it provides a supportive function. In situations where we notice something, we also have a very direct line to the team.

When it comes to having AI, from a high-level perspective, I don’t really care how it’s done in terms of the solution. It's great if AI is used because we measure based on the results we achieve. It must meet the requirements for performance and speed. Today, AI is the tool of choice to achieve the necessary speed and performance. But it’s not about the fact that AI is involved; it’s about the fact that, at the end of the day, a fast and reliable solution has been created.

What needs improvement?

We still have devices that are not traditional IT equipment but rather fall under the category of Operational Technology (OT) devices. There is increasingly a blending of the traditional OT world, which requires a specific focus, as OT devices often don't use standard Ethernet protocols and similar technologies. These are areas where I believe more can be done by Trend Vision One.

Taking it a step further, we also produce items that include IT elements, which are then used by customers. It would be great if there were Trend Micro products that could enhance the security of these devices, either as part of our product or in some other way integrated into our offering. But that's a different approach. At the moment, we use Trend Micro to protect our own company and our internal networks, but expanding this to our customer-facing products is an idea for the future.

Buyer's Guide
TrendAI Vision One
April 2026
Learn what your peers think about TrendAI Vision One. Get advice and tips from experienced pros sharing their opinions. Updated: April 2026.
892,776 professionals have used our research since 2012.

For how long have I used the solution?

We have been using Trend Micro for a long time, since 2020. We started in 2019 and signed our first Trend Vision One contract in 2020.

What do I think about the stability of the solution?

The stability is very high. We rarely encounter stability issues. When we do have issues, we typically find that they originate from our side, usually because certain information couldn't be provided by the server.

What do I think about the scalability of the solution?

Compared to other companies, we're not huge, but during the rollout and expansion, we found that it scales easily. We haven't encountered any issues with scaling effects or anything like that.

How are customer service and support?

Their technical support is excellent because we continuously see that when an issue arises, direct communication is sought. The ability to act quickly and be in direct communication is very important to us. It's not just about high-level support with the chatbot; rather, when an issue occurs, we have the experts on-site and ready to respond swiftly, which is crucial. In such situations, you need to act quickly without wasting time on what should happen next.

Which solution did I use previously and why did I switch?

We have used a lot of products. Over the past few years, we have been consolidating into a single corporation and replacing other solutions with the corporate mandate of Trend Micro. The reason is for efficiency reasons, among others. By using the same solution across the entire company, we can manage and maintain it centrally, ensuring uniform behavior without having to deal with individual solutions for each part of the organization.

How was the initial setup?

I was involved in the setup in terms of managing the role and function, but not from a technical standpoint.

My colleagues reported that it is a very well-designed software. We’ve experienced other solutions where we’ve worked on software for a long time, and it didn’t go as smoothly. I haven’t heard any complaints, so the setup must have been good.

We took a risk-based approach to implement this. We started rolling it out in some large manufacturing companies, where the potential damage in case of an incident would be the greatest. From there, we moved to the smaller legal entities, such as just sales offices or similar, so from large to small.

We have a relatively small team in the global function with three people who worked on it. We also have a packaging team and similar resources when it comes to creating installation scripts for end devices.

In terms of maintenance, we have purchased Trend Vision One as part of a SaaS solution. This includes updates and ongoing support, such as the provision of virus signatures, so we don't have dedicated staff specifically for maintenance. We do have designated contacts around the world dedicated to handling alarms and events. This is an additional responsibility for the IT team members after their training, so I can't give you a precise number of people involved. These activities are integrated into the existing IT staff who manage them alongside their regular tasks.

What was our ROI?

We have seen a return on investment fundamentally more qualitatively, proportionally, and quantitatively. We haven't done a strict ROI calculation. We know it's in place to counter potential damage, but it's hard to quantify potential damage in an ROI calculation. On the other hand, we had two incidents during the rollout for the global company. Thankfully, we also had cyber security insurance, and the insurance covered the incidents because, through Trend Micro and the implementation of the solution, along with the data it provided, we were able to demonstrate what had happened. Without this, we certainly wouldn’t have received the insurance payout.

What's my experience with pricing, setup cost, and licensing?

Of course, we'd prefer for it to be free. Security has its price. Regarding the prices we've experienced, we consider Trend Micro to be competitive. However, we sometimes wish for a higher discount based on more usage as the company grows.

Which other solutions did I evaluate?

We looked around at other solutions. When we started evaluating options in 2019, we explored the typical solution portfolios available at the time. We considered several options, and then, based on different factors, we decided on a company operating out of Japan, rather than an extension of an American company. I don't quite remember all the details, but at the time, there was also a Russian solution that was quite popular in the European market, which we decided not to pursue further.

The main differences between these products and Trend Vision One were the functionality and the overall environment. We wanted a truly independent solution. From the perspective of German and European data protection laws, it was a matter of weighing where we could place the most trust and where we would see those principles reflected in the implementation.

What other advice do I have?

My advice would be that one should really take the time to think carefully about what they want and need, and particularly engage in conversations with colleagues to find the right solution. One could say that to perform Deep Discovery Inspector on network traffic, more nodes could be added but at some point, the cost-benefit effect becomes minimal.

We always felt that Trend Micro provided us with very good advice, suggesting that more than three nodes in a global context weren't necessary. Any additional nodes would only slightly improve performance, making it not worthwhile. It's important to listen to the Trend Micro team and communicate openly. What's key is that you have to think about your scenarios and risks in advance—this is something they can't take off your hands. For example, network segmentation, which isn't part of Trend Micro's offering, is a mechanism we also bring in. It's important to work hand in hand, and there needs to be a lot of dialogue at this stage.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Zhaffi Ibrahim - PeerSpot reviewer
Assistant Vice President at NETS
Real User
Top 20
Jan 31, 2026
Centralized threat visibility has streamlined investigations and now reduces risk significantly
Pros and Cons
  • "By switching to TrendAI Vision One, I have reduced my risk by approximately eighty percent."
  • "In TrendAI Vision One, an area that has room for improvement is the DLP policy governance, particularly around data leakage protection."

What is our primary use case?

My use case for TrendAI Vision One is more focused on the XDR.

What is most valuable?

In my opinion, the best features of TrendAI Vision One are the UI itself, which is very user-friendly. I consider that to be the most intricate part about TrendAI Vision One compared to other XDR platforms.

I use the sensors in TrendAI Vision One, and they are critical for our network coverage. They help us considerably because we are using TrendAI Vision One in the corporate environment, where people come and go. The sensors are very helpful because when you want to release the sensor on a laptop that is not used, you can simply release it.

My impressions of TrendAI Vision One's ability to provide centralized visibility and management across protection layers are very interesting because other solutions do not actually provide a centralized platform to view everything. Trend Micro introduced TrendAI Vision One, which allows all that to be in one central console, enabling you to have all features enabled or disabled based on credits.

TrendAI Vision One helps consolidate my use of security vendors and reduces silos. Currently, we are mainly using the XDR function, but we are also looking at the sandboxing feature. It is a good platform because in our environment, the engineering team uses the XDR function while the Digital Forensic & Incident Response team uses the sandboxing analysis functions, allowing two cross-entities to use one platform for their own tools.

What needs improvement?

In TrendAI Vision One, an area that has room for improvement is the DLP policy governance, particularly around data leakage protection. I believe the main focus is currently on thumb drives and external drives, but in older environments, we also use CDs and DVDs for read and write functions.

For how long have I used the solution?

I have been using TrendAI Vision One for approximately eight months in totality.

What do I think about the stability of the solution?

I would rate the stability of TrendAI Vision One as very stable, giving it a nine out of ten.

What do I think about the scalability of the solution?

In terms of scalability, I would say TrendAI Vision One is a ten out of ten because it is based on credits.

How are customer service and support?

From one to ten, I would rate the technical support that TrendAI Vision One provides as a nine because we are subscribed to premium support.

How would you rate customer service and support?

Positive

How was the initial setup?

I found the deployment of TrendAI Vision One to be very easy; I was very surprised because we had a seamless migration from Apex One.

It took less than a day to implement TrendAI Vision One; in fact, it was completed in just one day.

What about the implementation team?

In my organization, we have a team of five engineers and close to three hundred endpoints using TrendAI Vision One.

What was our ROI?

I estimate that I have seen approximately fifteen to twenty percent return on investment from using TrendAI Vision One.

What's my experience with pricing, setup cost, and licensing?

Regarding the pricing of TrendAI Vision One, I think it is on the costlier side compared to other solutions due to the functions they offer, but in totality, it is cost-efficient.

Which other solutions did I evaluate?

I have tested other vendors for endpoint solutions, including Kaspersky and Symantec.

What other advice do I have?

The top security challenges in my industry include finding people who can operate TrendAI Vision One as an operator, and actually, TrendAI Vision One's user interface is so user-friendly that it takes maybe an experienced cybersecurity engineer about two to three weeks to get used to it.

The solution does not require any maintenance in terms of patching because we are on SaaS; we have a proxy, so there is no maintenance for it.

TrendAI Vision One has reduced my time to detect and respond to threats by approximately forty to fifty percent.

It has reduced noise from false positives by approximately twenty percent, which has saved me a significant amount of time.

By switching to TrendAI Vision One, I have reduced my risk by approximately eighty percent.

I would recommend TrendAI Vision One to other users because it is user-friendly and offers good support. I would rate this review a nine out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Jan 31, 2026
Flag as inappropriate
PeerSpot user
Buyer's Guide
TrendAI Vision One
April 2026
Learn what your peers think about TrendAI Vision One. Get advice and tips from experienced pros sharing their opinions. Updated: April 2026.
892,776 professionals have used our research since 2012.
Torsten Lang - PeerSpot reviewer
Head of Organization at ZEUS Informationstechnologie GmbH
Real User
Top 10
Jul 27, 2025
Empowers teams to quickly identify and manage cyber risks through detailed insights and continuous support
Pros and Cons
  • "Trend Vision One has increased our endpoint visibility and reduced attack vectors, enabling us to identify and respond to vulnerabilities and threats faster, which has reduced our response time by an estimated 25–30%."

    What is our primary use case?

    We use Trend Vision One as our primary security solution on all endpoints, servers, and clients in our environment. Through third-party integrations, we’ve also connected solutions from other vendors (including VMware and Fortinet).


    How has it helped my organization?

    Trend Vision One has increased our endpoint visibility and reduced attack vectors. We can now identify and respond to vulnerabilities and threats faster. This has reduced our response time by an estimated 25–30%. Vision One provides notifications about specific risks and helps us understand where the general risks lie, enabling proactive mitigation.

    With other vendors, we’ve had to manually check for vulnerabilities in products and assess whether those vulnerabilities were relevant. Now, Vision One handles much of that process. It provides detailed information for each user and endpoint about existing risks and how to mitigate them.

    I often compare patching vulnerabilities in Cyber Risk Exposure Management (CREM) to playing a game — the goal is to collect as few points as possible. The lower our score, the more secure our environment is. And like in real life, there are ups and downs because new risks arise daily. Vision One is an important tool for communicating risk assessments to management while also helping operational staff understand what risks mean and how to reduce them.



    What is most valuable?

    The feature I find most valuable in Vision One is CREM. CREM helps our company identify blind spots. It provides detailed information about the actions and improvements we should take to secure our environment, and gives concrete recommendations about how to resolve vulnerabilities.

    As part of our Service One Complete service agreement, we have bi-weekly meetings with a Technical Account Manager (TAM) who advises us on improving security settings and informs us — even between meetings — about new attack scenarios and how to counter them.



    What needs improvement?

    It’s hard to pinpoint areas where Vision One could be improved or where additional features are needed. I’ve been working with the solution for three years, and Trend Micro is constantly developing. Sometimes, it’s hard to keep track of all the updates and added features.

    I feel that Trend Micro is now better at identifying my needs than I am at recognizing them myself.


    For how long have I used the solution?

    Vision One has been in use at the company for three years.

    What do I think about the stability of the solution?

    The stability is excellent. In my opinion, performance and availability are both very good.

    What do I think about the scalability of the solution?

    The scalability of the solution is very good. We have not encountered any limitations as our environment has grown.

    How are customer service and support?


    I would rate customer service extremely positively. Support responds quickly, and together we’ve been able to solve all challenges in our day-to-day operations. On a scale from 1 to 10, I would rate customer service and technical support a 9 — there should always be room for improvement.


    Which solution did I use previously and why did I switch?

    Before Trend Vision One, we used a solution from Kaspersky. The switch was prompted by the German BSI’s security warning regarding Kaspersky's antivirus products.

    How was the initial setup?

    I was heavily involved in the rollout and deployment of the solution. Implementation was relatively quick and smooth. We used a deployment script distributed to endpoints through our software distribution system.

    Our rollout strategy started with a small number of endpoints being configured with antivirus and policies. After reviewing and refining the policies, Vision One was rolled out in phases to the remaining endpoints.



    What about the implementation team?

    We needed only one staff member for the implementation of Trend Vision One, and that was me.

    What was our ROI?

    The investment in Trend Micro Vision One has paid off, although ROI is difficult to calculate. A security solution is like a good insurance policy — ideally, you never need to use it. We haven’t had any incidents so far, and hope it stays that way.

    I’ve noticed that the continuous visibility of potential risks has made our environment more secure and has enabled colleagues to respond faster, saving valuable working time.



    Which other solutions did I evaluate?

    Before we decided on Vision One, we also evaluated solutions from other vendors, including Microsoft and Fortinet. The differences between the products were not significant — they were more in the details. But since we had already been a Trend partner for 15 years (12 of them inactive), we ultimately decided to return to Trend Micro.

    What other advice do I have?

    Three years ago, we followed a different concept: two independent security solutions with separate management and reporting. Migrating to Vision One and consolidating everything into one interface gave us a 365° view of our IT infrastructure.

    Central visibility of endpoints and vulnerabilities, as well asunified management, brought a new level of focus to IT security and boosted employee awareness.

    If you're evaluating Trend Micro, don’t limit yourself to antivirus functionalities. Consider other features as well — especially the Managed Services, (strong technical support), and Cyber Risk Exposure Management capabilities, which I find highly valuable.

    Create a centralized view of your IT infrastructure.

    Define which features are important or necessary for you.

    Get a comprehensive overview when evaluating different security vendors in terms of features and costs — so you’re not comparing apples to oranges.



    Which deployment model are you using for this solution?

    Private Cloud
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Endpoint Solutions Support at Compass Group
    Real User
    Top 5
    Apr 16, 2025
    An integrated platform that simplifies threat and response management
    Pros and Cons
    • "The most valuable feature of Trend Vision One is response management; when there is a malware issue, we need to isolate the endpoint, which I can do through response management. I"
    • "Trend Vision One is an integrated platform where I can get all the information about all the endpoints, whether it be a server, laptop, or desktop."
    • "In future releases of Trend Vision One, I would like to see improvements regarding role-based access control, as it is important to ensure that when granting admin access to a person, their visibility is limited to only their respective markets. For example, while creating roles for countries like France, Germany, and Italy, they should only manage their own endpoints to maintain privacy and security."
    • "In future releases of Trend Vision One, I would like to see improvements regarding role-based access control, as it is important to ensure that when granting admin access to a person, their visibility is limited to only their respective markets."

    What is our primary use case?

    Our usual use cases for Trend Vision One involve the detection of any kind of threat. We are getting alerts from the workbench on Trend Vision One and we perform threat hunting. If there are false positives, we close them, and in the case of true positives, we take action toward remediation and closure. Predominantly, we use it for threat management.

    How has it helped my organization?

    Trend Vision One is an integrated platform where I can get all the information about all the endpoints, whether it be a server, laptop, or desktop. Everything is integrated, allowing me to see everything within one console; that is one of the greatest advantages of Trend Vision One.

    In terms of centralized visibility and management across protection layers, Trend Vision One provides protection across all attack vectors. It allows us to manage threats in all phases. We can even perform forensics where we can collect suspicious files remotely to submit to Trend Micro.

    Trend Vision One helps reduce the time to detect and respond to threats. We get alerts in real-time. We receive notifications as email alerts, as well as alerts in the console. Through the workbench, we can monitor the console 24/7 with real-time information; there is not much delay.

    Trend Vision One has helped us reduce noise from false positives, thanks to the SOAR functionality. We are able to configure automatic responses, and in case any false positives are identified, the Vision One console takes care of them automatically. This helps us reduce a lot of false positives.

    Trend Vision One has indeed helped consolidate our use of security vendors and reduce silos. We sometimes get threat notifications from other vendor products, such as Microsoft Cloud App Security, which identifies threats, and we can trace similar traffic from the endpoints in Vision One. This correlation adds more value for our clients.

    What is most valuable?

    The most valuable feature of Trend Vision One is response management; when there is a malware issue, we need to isolate the endpoint, which I can do through response management. I can isolate an endpoint, restore the endpoint, and run manual malware scans, which will be very useful when performing malware remediation actions.

    What needs improvement?

    In future releases of Trend Vision One, I would like to see improvements regarding role-based access control, as it is important to ensure that when granting admin access to a person, their visibility is limited to only their respective markets. For example, while creating roles for countries like France, Germany, and Italy, they should only manage their own endpoints to maintain privacy and security.

    For how long have I used the solution?

    I have been working with Trend Vision One for more than 2 years.

    What do I think about the stability of the solution?

    I have not encountered any issues with the stability of Trend Vision One. There have been no problems at all.

    Stability is critically important for us with Trend Vision One; it is very stable, providing continuous 24/7 support, and we do not face challenges in accessing services from Trend Micro.

    What do I think about the scalability of the solution?

    Regarding scalability, Trend Vision One accommodates many endpoints without any challenges, allowing easy expansion of our portfolio.

    How are customer service and support?

    I would rate the technical support for Trend Vision One a perfect 10 out of 10, as Trend Micro supported us throughout the transition from on-prem servers or other vendors, providing top-notch service at all times.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    Before using Trend Vision One, we were utilizing McAfee, and some of our clients were using Symantec. Currently, most clients have transitioned to Trend Micro.

    The decision to switch from McAfee was driven by factors such as high costs and the global presence of organizations. Trend Micro has a more robust global reach and its pricing is very competitive compared to McAfee.

    How was the initial setup?

    The initial setup of Trend Vision One is not complex; it is straightforward. We had the options in the Trend Vision One console, and we received training from Trend Micro-certified administrators. We had knowledge transfer sessions, and later, we successfully migrated our products from on-prem servers to the cloud. 

    We have been using the product for more than 7 to 8 years, and we did not face any challenges during this migration.

    What was our ROI?

    We have seen a return on investment with Trend Vision One, primarily in terms of having more confidence in addressing any kind of suspicious activities. Any such activities will be notified to us, allowing us to take action. The return on investment is apparent in managing the endpoints and addressing suspicious activity that might otherwise go unnoticed.

    It has saved about 25% to 30% of our time. The risk has been reduced by more than 25% after switching to Trend Vision One.

    What's my experience with pricing, setup cost, and licensing?

    Its price is very decent. It suits our requirements.

    Which other solutions did I evaluate?

    I did evaluate other options, including Microsoft Sentinel, but ultimately, most vendors choose Trend Vision One.

    The factors that led us to choose Trend Vision One over Microsoft or other options include costs, and since we already have Microsoft for other protections (like M365 security protection), we opted for protection with a different vendor, rather than the same vendor.

    What other advice do I have?

    I would rate Trend Vision One a nine out of ten.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Other
    Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
    PeerSpot user
    DavidBowman - PeerSpot reviewer
    Systems and Security Manager at a educational organization with 5,001-10,000 employees
    Real User
    Top 20
    Jul 22, 2024
    It improves the detection speed, but it could be more customizable
    Pros and Cons
    • "When we purchased Vision One, what set it apart was that it wasn't a traditional signature-based antivirus. It's a process-aware solution that provides real-time protection. That was a big differentiator three years ago, but now it's a given that every AV provider should be doing that. It combines signature-based telemetry with behavioral awareness and a detection-based solution, making it a good solution for us."
    • "They need to stop changing Vision One once a week. They're in a hurry to change things so badly and so fast that I can't find where stuff is half the time, which is a challenge sometimes."

    What is our primary use case?

    Vision One is the primary endpoint security product we use to protect our Macs and PCs. We also use the server product version, so it runs on my servers as well. We exclusively purchase Trend Micro's endpoint products. They have network and firewall products. We were using their email product until last month, and I ended up selecting a different provider. We stayed with them for the endpoint, but I moved off of them for the email product.

    How has it helped my organization?

    Vision One was a big deal to us immediately because we did not have context-aware before. We saw everything we had no idea was happening. It was a big deal three years ago. 

    It certainly reduces time to detect because a lot of the time, I didn't have it before. I didn't have that information until it gave it to me. The speed of response helps me know much more about what's happening quicker. They have some improvement to do in terms of automated remediation. It probably makes investigations 30 percent faster because of what it puts together. 

    What is most valuable?

    When we purchased Vision One, what set it apart was that it wasn't a traditional signature-based antivirus. It's a process-aware solution that provides real-time protection. That was a big differentiator three years ago, but now it's a given that every AV provider should be doing that. It combines signature-based telemetry with behavioral awareness and a detection-based solution, making it a good solution for us.

    When we bought it three years ago, it was separate. Apex One handled cloud and web app security, and Vision One handled cloud and server workload protection. Now, they call it Vision One. The server stuff is still separate, but it is the same now. When we purchased it, they told us we'd have a single console, but that took about two and a half years. Finally, there is a single pane of glass. 

    One of the things that made me the craziest was that we had too many tools or one tool that I had to log into five different ways. One of the frustrations is you have both legacy and newer detection methods. Not being able to fully investigate it in a single portal was a huge pain.

    What needs improvement?

    They need to stop changing Vision One once a week. They're in a hurry to change things so badly and so fast that I can't find where stuff is half the time, which is a challenge sometimes.

    I've given one piece of feedback to their product guys. One thing that they're trying to make is a SIEM. It's a product where you input all the logs from your tools, and it creates additional insights into how things look. They've been kind of playing the "me too" game on that, even though that's not what I bought the product for.

    They have a new gateway where I can take my firewall of email logs and send it over there. In theory, it's supposed to do a more comprehensive evaluation of all my stuff to improve that risk index score. I'm not impressed with it, and I've told them as much. I feel if you're good at something, you should keep working on that and not try to be all the things to all the people. 

    I bought a different email solution even though it would have been 10 times easier to just stay with their email solution because they aren't great at it. They are great at other things, but they're playing the "me too" game with some of their products. Their competitors do this, so they should be doing this, too. They need to pick a product and keep being good at that. If they're going to roll new things out, they should do it but do it right. 

    They have a button to isolate an endpoint because it looks bad, but it doesn't usually work. I've had no chance to argue with the product guys to show them examples of how their button doesn't work. You think it does, but it doesn't work in a real environment. That can be a challenge sometimes.

    I can see in the data showing what is a false positive. But it doesn't save me time helping them figure out how to fix the problem in their engine. It can help me identify it as a false positive, but it doesn't apply that consistently. It will ignore the false positive for that device, but if they start detecting a false positive on Apple devices, I have eight thousand Apple devices and get 8,000 alerts. I can tell that specific false positive, but it doesn't learn from that particularly well.

    We use the executive dashboards, but I don't find them particularly useful. One is the ability to customize. That has gotten a little better, and it'll be better in the future. Most of what they have on there are data points that are generic and not particularly actionable. That's why it's called an executive dashboard. Executives want to see if we are secure, but it's hard for me to find out why our attack surface risk went down by x percentage. I don't know. It says that on the dashboard, but it doesn't give me specific details about why.

    I find it confuses my executives, and it's not useful for me because it doesn't give me things to work on. It will give me generic things on the executive dashboard like you have a thousand accounts with an old password. Those are big generic things, but I also can't tell it that our password policy is different from what your automatic detection model means, and I don't have a problem with that, so quit lowering my risk score. 

    The risk score is useless. In theory, it's based on the random intelligence they're getting from their various customers. I'm in K-12 education, so they have a decent amount of K-12 customers, but it's a subset, and the baseline of what's common in K-12 education is not the same. There's not enough data to make that particularly clean or useful. Vision One is not custom, and that's part of my beef. That index score is based on whatever random report they're looking at from their data sources at any given moment in time. It's nice, but I'd rather have one that's based on your particular circumstances. Instead, it's saying that the number one attack threat surface for school districts is email phishing. It's too generic.

    For how long have I used the solution?

    I have used Trend Vision One for three and a half years.

    What do I think about the stability of the solution?

    Vision One has been less impactful toward my endpoints when scanning than the previous solution. 

    What do I think about the scalability of the solution?

    Vision One's resource usage is starting to creep up compared to three years ago. They used to focus on making their agent lightweight. I don't necessarily think all of this is their fault, but their agents are starting to suck more resources than they used to. Part of it is that the threat landscape has changed, and you need to look at it in additional ways, and it is a strain on the servers. They've gotten really bad about that on the servers.

    How are customer service and support?

    I rate Trend Micro support three out of 10. Their technical support is challenging. The support's good once you get to the second layer, but they don't read what you write. They auto-respond by telling us to give them the logs. 

    Every time, I need to send them a written statement with my product license ID and that I'm the contact authorized to do a support ticket. About 75 percent of the time when I open a support ticket, I immediately email my customer service satisfaction manager person with the ticket number so they can help move it along.

    How would you rate customer service and support?

    Negative

    Which solution did I use previously and why did I switch?

    I was using Sophos three years ago. I've looked at many of the feature sets out there, and they might be 80 percent of what Vision One has, and some might be better, but Vision One is price-competitive.

    How was the initial setup?

    Deploying Vision One was a pain because of the automated removal tool. In the antivirus world, they try to make it difficult to uninstall people's defenses because that's what an attacker would do. However, all the competitors are making tools to uninstall their competitors' tools when they win business. That's directly counterintuitive to the whole point of the antivirus. 

    We went through a process of trying to do this in an automated fashion to replace the old product, and Trend didn't quite do it right. Trend had a real struggle toget their own tool to fix it. 

    We use it as a SaaS, so we have a gateway integrator on the server on-site, but the product sits on all my endpoints. In that aspect, it's on-prem, but all the processing, reporting, and everything else happens in the cloud. We had it 75 percent deployed in 45 days. That last 25 percent took us another four months.

    I work at an underfunded public school district. I need a whole team, but there is only me. I used to have a security analyst until that position moved around, and
    my ability to use the product has been drastically reduced. I miss much of the value of what I'm paying for because I don't have enough staff to use it. I wouldn't need more than one if that was their whole job. 

    It's not a totally elegant solution that always feeds and cares for itself. We have to check if it's doing its updates properly. It doesn't tell us, for example, that 2,000 devices haven't been updated or checked in. I have to go proactively looking at it.

    What's my experience with pricing, setup cost, and licensing?

    Vision One's pricing is extremely competitive. They're probably the lowest-cost provider that has this feature set. 

    What other advice do I have?

    I rate Vision One seven out of 10. Make sure you learn the 90 percent of stuff in there that you didn't know you bought and preestablish an escalation contact for support tickets. 

    Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
    PeerSpot user
    reviewer2741328 - PeerSpot reviewer
    Head of I T at Conquest Group
    User
    Top 20
    Oct 5, 2025
    Transforms cybersecurity landscape with efficient and comprehensive protection
    Pros and Cons
    • "One of the best decisions we made was choosing Trend Vision One; it has transformed our entire security and cybersecurity landscape, providing a one-stop solution to manage everything efficiently and effectively."
    • "The only disappointing aspect is that every time new features are adopted, additional credits are required, which could push the budget over. This practice should really be reconsidered by Trend."
    • "The only disappointing aspect is that every time new features are adopted, additional credits are required, which could push the budget over."

    What is our primary use case?

    I use Trend Vision One for Total XDR and endpoint protection as an all-in-one security solution.

    How has it helped my organization?

    One of the best decisions we made was choosing Trend Vision One. It has transformed our entire security and cybersecurity landscape, providing a one-stop solution to manage everything efficiently and effectively.

    What is most valuable?

    One of the most valuable features is Cyber Risk Exposure Management.

    What needs improvement?

    There is room for improvement in leveraging AI technology to protect against emerging AI-based threats.

    For how long have I used the solution?

    I have been using the solution for two years.

    Which solution did I use previously and why did I switch?

    We previously used an outdated and inefficient Trend Micro system, which caused high security risks.

    What's my experience with pricing, setup cost, and licensing?

    This is not a competitive price — the costs are on the higher side. However, I don’t regret it, as it can help save significantly in other areas. The only disappointing aspect is that every time new features are adopted, additional credits are required, which could push the budget over. This practice should really be reconsidered by Trend.

    Which other solutions did I evaluate?

    I also evaluated CrowdStrike as an alternate solution.

    What other advice do I have?

    Trend Vision One is a five-star product.

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    Last updated: Oct 5, 2025
    Flag as inappropriate
    PeerSpot user
    GANESAN K - PeerSpot reviewer
    Senior Technical Engineer at Safezone Secure Solutions Private Limited
    Reseller
    Top 5Leaderboard
    Nov 24, 2025
    Manages cyber risk across endpoints and email while simplifying detection and response workflows
    Pros and Cons
    • "ROI is absolutely achievable, especially with TrendAI Vision One and server TrendAI Vision One platform."
    • "Compared to other vendors like SentinelOne or CrowdStrike, all of them are providing detection and response methodology. However, TrendAI Vision One provides more visibility but has limitations on the response part."

    What is our primary use case?

    I work with Trellix, Trend Micro, Fortinet, and Netrix for DLP solutions. For Netrix DLP, I use Forcepoint, and for email security, I use Barracuda.

    I have been working with Trend Micro for the past six years. I started with Apex One and Worry-Free, which evolved to TrendAI Vision One. TrendAI Vision One is a collaborative XDR platform designed to bring all security solutions such as mail security, cloud security, endpoint security, and identity security together and manage them from a single console. That is the main goal of TrendAI Vision One.

    From my end, I have deployed email security, endpoint security, XDR, and web security from TrendAI Vision One. We are using TrendAI Vision One with both business essentials and pro bundle.

    TrendAI Vision One has two kinds of solutions for endpoint security: standard endpoint protection for desktop machines and server and workload protection for existing Linux servers, Windows servers, or even containers and workloads in the cloud where you can install agents for those containers as well. These are the deployments which we have done for endpoint security.

    What is most valuable?

    The detection part works well for me. The response part, including automatic containment, requires creating playbooks. Even though I create them, I have faced many threat attack scenarios where detection pops up, but the appropriate response action is not being taken.

    Attack discovery and attack surface discovery are valuable features. Every organization has endpoints, and no organization will be willing to do a full discovery or testing on all those endpoints or devices. Attack discovery helps us know which endpoints we have with Trend Micro, what vulnerabilities and loopholes are available in the endpoints, and provides insights into our attack surface.

    I have used the cyber risk exposure management product completely except for security awareness. I have used data security posture, identity security posture, and network security functionalities. I have not ensured cloud security yet, but we are yet to have hands-on experience with that. I have showcased these functionalities to customers and conducted many POCs for new clients covering cyber risk exposure management, XDR, email security, endpoint security, and network security. I have explained how well TrendAI Vision One captures the correct data.

    The response time after detection is approximately three hours.

    What needs improvement?

    Visibility is good, but TrendAI Vision One can improve the response part. Compared to other vendors like SentinelOne or CrowdStrike, all of them are providing detection and response methodology. However, TrendAI Vision One provides more visibility but has limitations on the response part.

    If TrendAI Vision One can improve the response time and playbooks, particularly with more customizable playbooks, it would be greatly helpful. We have raised feature requests to Trend Micro. If they have more predefined playbooks and more options for response management, it would be beneficial because that is what end users are expecting.

    As a reseller, we are dealing with the pain because customers are asking why response is not being taken even though TrendAI Vision One detects suspicious files. In some cases, I follow best practices by updating playbooks at regular intervals, but that is a manual process. An automated process to take appropriate action for suspicious and malicious files would be necessary. The response part might be improved to provide better value.

    For how long have I used the solution?

    I have been working with Trend Micro for the past six years.

    What do I think about the stability of the solution?

    TrendAI Vision One is stable. Before TrendAI Vision One, Trend Micro had Apex One and Worry-Free products for endpoint security that were not stable. However, after TrendAI Vision One was introduced, I do not see any stability issues.

    What do I think about the scalability of the solution?

    Scalability is good. Previously, it was good because they were using a credit system where they would give credits and based on the credits we could allocate our own licenses. Right now they have removed this feature, so we are yet to do some testing on that. The credit system was effective because we had flexible licensing and scalability, and we were able to use the resources when and if it was necessary.

    How are customer service and support?

    Two factors are important: the time to give the first response and the technical ability of the engineers. I heard that they have laid off many old employees and senior employees.

    The integration part is good. They also have an AI platform built into the console which provides more details in layman's terms. When explaining an attack to management, you can communicate it to a CIO in technical terms because they are from a technical background and will understand all the details. However, when taking this to a CEO or CFO who are not technical persons with backgrounds based on industry, you should explain it in simple terms. The AI integration with TrendAI Vision One gives the details in a much simpler way in layman's understanding. That feature is good.

    How would you rate customer service and support?

    Neutral

    How was the initial setup?

    The installation is easy. Even for Linux and Mac machines, it is just two or three commands.

    What was our ROI?

    ROI is absolutely achievable, especially with TrendAI Vision One and server TrendAI Vision One platform. Previously, they had MSVA, which was a virtual appliance that on-premises clients needed for mail security. After they came up with the cloud email security solution, many customers are feeling relief, and the latency is much better when compared to an on-premise solution.

    For ROI in email security, they provide BEC, which is the best ROI for every customer. If there is an outage that occurs in Microsoft or AWS or any other cloud platform, there is an email continuity platform for emails. That is good ROI.

    From a deployment perspective, it shows around fifty to sixty percent. The impact given to the business in terms of real impact is up to ten to twenty percent.

    What's my experience with pricing, setup cost, and licensing?

    This is quite affordable. It is not that expensive.

    Which other solutions did I evaluate?

    We buy from Trend Micro. TrendAI Vision One definitely falls in the leader quadrant in Gartner, and its capabilities are good. It can be in that leader quadrant. For an endpoint security solution, managing attacks is the key thing. It is not about daily activities like what policies and functionalities are provided. These matter, but at the end of the day, if an attack is going to happen, the end user will assess the support of TrendAI Vision One and the response part of TrendAI Vision One. These two parameters are going to be assessed, and based on these two parameters, any quadrant achievement from labs like Gartner or Forrester will be based on these two parameters only.

    What other advice do I have?

    For standard endpoint protection, if it is a detection, it is a detection. When compared to CrowdStrike, TrendAI Vision One creates much less false positives. There is no big noise on this, but that is one way to consider it. False positives do come, and it is completely based on the configuration which we do. On the initial phase of the deployment, after a month or two, we keep it in detection mode, and after that, we pursue the prevention mode so that blocking is enabled.

    If the containment functionality gets automated, it would be on a better note. The response part, if improved, will be very helpful. From a deployment perspective, it shows around fifty to sixty percent.

    TrendAI Vision One is fully on the cloud with no on-premise option. They tie up with multiple cloud vendors, but they provide a SaaS platform built by Trend Micro. Trend Micro itself is hosted on some AWS servers, which is what I have heard, but I do not want to comment on that.

    I would rate this review an eight.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
    Last updated: Nov 24, 2025
    Flag as inappropriate
    PeerSpot user
    Deputy General Manager at Tata Communications Ltd
    Real User
    Top 5
    Nov 24, 2024
    AI-driven visibility empowers risk management with faster detection
    Pros and Cons
    • "The most important features of Vision One include visibility, AI integration, attack pattern analysis, predictive analytics, and centralized visibility and management across protection layers."
    • "There should be improvements in risk quantification, where the risk is displayed in a quantified manner, showing the dollar value loss."

    What is our primary use case?

    As a security architect, I design solutions for our end customers. In previous projects, we've successfully implemented Trend Vision One for customers with cloud-based assets and email servers, enabling them to extend security coverage to their remote clients.

    The current market trend in email security solutions focuses on mitigating threats like phishing attacks. These widespread attacks occur across various points in the cyber kill chain process. Whether initiated from the perimeter or targeting cloud-based assets, monitoring all north-south and east-west traffic is challenging. Trend Vision One helps by providing a comprehensive analysis of these email phishing attacks, identifying the attack origin, parameters, and information extracted from attack patterns.

    How has it helped my organization?

    Trend Vision One offers centralized visibility and management across all protection layers. This comprehensive view provides valuable information for CISO/CIO presentations, including attack patterns, threat actors, and areas for predictive analysis. Such insights are crucial for informing policy changes and other security enhancements. The visibility also helps with efficiency.

    We can summarize any technical information we receive using widgets and then present it to executives in a dashboard format.

    Our customers adapt the risk index feature to align with the specific needs and conditions of their individual environments.

    We have used Trend Vision One in several projects where our customers consolidated security across hybrid environments. The consolidation effort, particularly utilizing Vision One's AI-driven features, streamlined investigative analytics. Furthermore, merging multiple solutions into Vision One provided comprehensive insights, which proved invaluable for policy development.

    The ability to manage risk and maintain visibility has improved by approximately 20 to 30 percent, significantly simplifying our tasks. Operationally, this has led to a 20 percent reduction in effort.

    Trend Vision One has helped reduce detection and response times by 30 and 40 percent, respectively.

    Trend Vision One has saved more than a week's worth of effort in investigating false positives.

    Trend Vision One's automation capabilities have helped us save between 60 and 100 hours monthly. 

    What is most valuable?

    The most important features of Vision One include visibility, AI integration, attack pattern analysis, predictive analytics, and centralized visibility and management across protection layers. These features are very important to us. 

    What needs improvement?

    There should be improvements in risk quantification, where the risk is displayed in a quantified manner, showing the dollar value loss. The integration with third-party OEM solutions also needs enhancement, particularly in UEBA integration with Trend. Sometimes, there are blind spot discoveries that are not completely successful. Improving automation to avoid manual triaging and providing more insights on dashboards is desirable.

    While Trend Vision One's attack surface risk management helped identify some vulnerabilities in our environment, the feature needs improvement. Specifically, the blind spot discovery is unreliable; for example, a missed blind spot in one environment led to an attack and subsequent investigation.

    Automation should be improved to eliminate the need for manual effort in initial L1 triaging. Additionally, dashboards should provide more insightful analysis, including various mappings to the MITRE ATT&CK framework and Tactics, Techniques, and Procedures.

    For how long have I used the solution?

    I have been working with Vision One for almost almost two years.

    How are customer service and support?

    The support in Trend Micro is good.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    I have worked on Exchange servers, and we are using Palo Alto to a certain extent. These were not from the XDR or EDR point of view.

    What was our ROI?

    The analysis shows that Trend Vision One has improved our ROI by 30 percent.

    What's my experience with pricing, setup cost, and licensing?

    Competitors offer comparable solutions at slightly lower prices, so Vision One has room to reduce its pricing by 15 percent, given that Trend Vision One charges approximately $10 per endpoint.

    Which other solutions did I evaluate?

    We evaluated other options but not to the same extent as Trend Micro because I was more familiar with Trend Micro solutions.

    What other advice do I have?

    I would rate Trend Vision One nine out of ten.

    Which deployment model are you using for this solution?

    Hybrid Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Other
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Buyer's Guide
    Download our free TrendAI Vision One Report and get advice and tips from experienced pros sharing their opinions.
    Updated: April 2026
    Buyer's Guide
    Download our free TrendAI Vision One Report and get advice and tips from experienced pros sharing their opinions.