We use Trend Vision One as our primary security solution on all endpoints, servers, and clients in our environment. Through third-party integrations, we’ve also connected solutions from other vendors (including VMware and Fortinet).
Head of Organization at ZEUS Informationstechnologie GmbH
Empowers teams to quickly identify and manage cyber risks through detailed insights and continuous support
Pros and Cons
- "Trend Vision One has increased our endpoint visibility and reduced attack vectors, enabling us to identify and respond to vulnerabilities and threats faster, which has reduced our response time by an estimated 25–30%."
What is our primary use case?
How has it helped my organization?
Trend Vision One has increased our endpoint visibility and reduced attack vectors. We can now identify and respond to vulnerabilities and threats faster. This has reduced our response time by an estimated 25–30%. Vision One provides notifications about specific risks and helps us understand where the general risks lie, enabling proactive mitigation.
With other vendors, we’ve had to manually check for vulnerabilities in products and assess whether those vulnerabilities were relevant. Now, Vision One handles much of that process. It provides detailed information for each user and endpoint about existing risks and how to mitigate them.
I often compare patching vulnerabilities in Cyber Risk Exposure Management (CREM) to playing a game — the goal is to collect as few points as possible. The lower our score, the more secure our environment is. And like in real life, there are ups and downs because new risks arise daily. Vision One is an important tool for communicating risk assessments to management while also helping operational staff understand what risks mean and how to reduce them.
What is most valuable?
The feature I find most valuable in Vision One is CREM. CREM helps our company identify blind spots. It provides detailed information about the actions and improvements we should take to secure our environment, and gives concrete recommendations about how to resolve vulnerabilities.
As part of our Service One Complete service agreement, we have bi-weekly meetings with a Technical Account Manager (TAM) who advises us on improving security settings and informs us — even between meetings — about new attack scenarios and how to counter them.
What needs improvement?
It’s hard to pinpoint areas where Vision One could be improved or where additional features are needed. I’ve been working with the solution for three years, and Trend Micro is constantly developing. Sometimes, it’s hard to keep track of all the updates and added features.
I feel that Trend Micro is now better at identifying my needs than I am at recognizing them myself.
Buyer's Guide
TrendAI Vision One
February 2026
Learn what your peers think about TrendAI Vision One. Get advice and tips from experienced pros sharing their opinions. Updated: February 2026.
884,656 professionals have used our research since 2012.
For how long have I used the solution?
Vision One has been in use at the company for three years.
What do I think about the stability of the solution?
The stability is excellent. In my opinion, performance and availability are both very good.
What do I think about the scalability of the solution?
The scalability of the solution is very good. We have not encountered any limitations as our environment has grown.
How are customer service and support?
I would rate customer service extremely positively. Support responds quickly, and together we’ve been able to solve all challenges in our day-to-day operations. On a scale from 1 to 10, I would rate customer service and technical support a 9 — there should always be room for improvement.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Before Trend Vision One, we used a solution from Kaspersky. The switch was prompted by the German BSI’s security warning regarding Kaspersky's antivirus products.
How was the initial setup?
I was heavily involved in the rollout and deployment of the solution. Implementation was relatively quick and smooth. We used a deployment script distributed to endpoints through our software distribution system.
Our rollout strategy started with a small number of endpoints being configured with antivirus and policies. After reviewing and refining the policies, Vision One was rolled out in phases to the remaining endpoints.
What about the implementation team?
We needed only one staff member for the implementation of Trend Vision One, and that was me.
What was our ROI?
The investment in Trend Micro Vision One has paid off, although ROI is difficult to calculate. A security solution is like a good insurance policy — ideally, you never need to use it. We haven’t had any incidents so far, and hope it stays that way.
I’ve noticed that the continuous visibility of potential risks has made our environment more secure and has enabled colleagues to respond faster, saving valuable working time.
Which other solutions did I evaluate?
Before we decided on Vision One, we also evaluated solutions from other vendors, including Microsoft and Fortinet. The differences between the products were not significant — they were more in the details. But since we had already been a Trend partner for 15 years (12 of them inactive), we ultimately decided to return to Trend Micro.
What other advice do I have?
Three years ago, we followed a different concept: two independent security solutions with separate management and reporting. Migrating to Vision One and consolidating everything into one interface gave us a 365° view of our IT infrastructure.
Central visibility of endpoints and vulnerabilities, as well asunified management, brought a new level of focus to IT security and boosted employee awareness.
If you're evaluating Trend Micro, don’t limit yourself to antivirus functionalities. Consider other features as well — especially the Managed Services, (strong technical support), and Cyber Risk Exposure Management capabilities, which I find highly valuable.
Create a centralized view of your IT infrastructure.
Define which features are important or necessary for you.
Get a comprehensive overview when evaluating different security vendors in terms of features and costs — so you’re not comparing apples to oranges.
Foreign Language: (German)
Ermöglicht Teams, Cyberrisiken schnell zu erkennen und zu managen – durch detaillierte Einblicke und kontinuierliche Unterstützung
Was ist unser primärer Anwendungsfall?
Trend Vision One kommt als primäre Sicherheitslösung auf allen Endpunkten (Server und Clients) in unserer Umgebung zum Einsatz. Darüber hinaus sind über die Third-Party Integration auch die von uns eingesetzten Lösungen weiterer Hersteller (u. a. VMware, Fortinet) eingebunden.
Wie hat es meiner Organisation geholfen?
Trend Vision One hat uns geholfen, die Sichtbarkeit der Endpunkte zu erhöhen und den Angriffsvektor zu verringern. Wir können schneller Schwachstellen/Bedrohungen identifizieren und darauf reagieren. Dadurch konnte unsere Reaktionszeit um schätzungsweise fünfundzwanzig bis dreißig Prozent gesenkt werden. Mit Vision One wird man über konkrete Risiken benachrichtigt und lernt, wo die Risiken im Allgemeinen liegen. So kann man aktiv daran arbeiten, diese zu beheben.
Früher mussten wir aus eigener Initiative heraus überprüfen, welche Schwachstellen bei bestimmten Herstellern bestehen und einschätzen, ob diese Schwachstellen für uns relevant sind. Das wird jetzt bereits zu einem großen Teil von Vision One erledigt. Herunter gebrochen bis auf jeden einzelnen Benutzer und Endpunkt wird dediziert angegeben, welche Risiken bestehen und wie diese verringert werden können.
Ich vergleiche die Behebung von Schwachstellen im Cyber Risk Exposure Management (CREM) mit einem umgekehrten Spiel. Es geht darum, so wenige Punkte wie möglich zu sammeln. Je niedriger unser Score ist, desto sicherer ist die Umgebung. Und wie im echten Leben gibt es Höhen und Tiefen, weil es täglich neue Risiken gibt.
Letztendlich ist Vision One ein wichtiges Tool, um einerseits eine allgemeine Risikobewertung für Führungskräfte/ Manager durchzuführen, und andererseits für operative Mitarbeiter, um zu wissen, was dieses Risiko tatsächlich beinhaltet und wie es sich reduzieren lässt.
Was ist am wertvollsten?
Die Funktion, die ich in Trend Vision One besonders wertvoll finde, ist Cyber Risk Exposure Management (CREM). CREM hilft unserem Unternehmen, blinde Flecken zu identifizieren. Diese wichtige Funktion zeigt sehr detailliert und umfassend auf, wo Handlungsbedarf oder Verbesserungspotenzial besteht. Gleichzeitig bietet es den Kollegen konkrete Handlungsempfehlungen, wie Schwachstellen geschlossen werden können.
Ein Bestandteil unseres Service One Complete Service-Vertrages sind zwei wöchentliche Meetings mit einem TAM (Technical Account Manager), der uns berät, wo Verbesserungspotenzial bei den Sicherheitseinstellungen besteht und uns regelmäßig – auch zwischen den Meetings – informiert, wenn es neue Angriffsszenarien gibt und wie diesen entgegengewirkt werden kann.
Was muss verbessert werden?
Bereiche, in denen Vision One verbessert werden könnte oder wo zusätzliche Funktionen erforderlich sind, sind schwer zu bestimmen. Ich arbeite jetzt seit drei Jahren mit der Lösung und Trend Micro arbeitet ständig an deren Weiterentwicklung. Stellenweise ist man gar nicht in der Lage, alle Änderungen zu erfassen oder welche zusätzlichen Funktionen eingebunden werden.
Ich glaube, Trend Micro ist derzeit schneller dabei, meine Bedürfnisse zu identifizieren, als ich sie überhaupt selbst erkenne.
Wie lange verwende ich die Lösung bereits?
Vision One ist seit drei Jahren im Unternehmen im Einsatz.
Was denke ich über die Stabilität der Lösung?
Die Stabilität der Lösung ist sehr gut. Meiner Meinung nach sind Leistung und Verfügbarkeit sehr gut.
Was denke ich über die Skalierbarkeit der Lösung?
Die Skalierbarkeit der Lösung ist sehr gut. Wir sind bisher auf keine Einschränkungen beim Wachstum unserer Umgebung gestoßen.
Wie sind Kundendienst und Support?
Ich würde die Erreichbarkeit und Kompetenz von Service und Support von Trend Micro als sehr hoch bewerten, ich bin sehr zufrieden. Antworten und Lösungen kommen prompt, das Personal ist professionell und auf einem sehr hohen Kommunikationsniveau.
Wie würden Sie Kundendienst und Support bewerten?
Äußerst positiv. Kundendienst und Support reagieren zeitnah. Gemeinsam konnten bisher alle Herausforderungen unseres Tagesgeschäftes gelöst werden.Auf einer Skala von eins bis zehn würde ich den Kundendienst und den technischen Support für Trend Vision One mit einer Neun bewerten. Es muss ja noch Luft nach oben bleiben.
Welche Lösung habe ich vorher verwendet und warum bin ich gewechselt?
Vor Trendmicro Vision One war die Lösung von Kaspersky im Einsatz. Der Auslöser für den Wechsel war die vom BSI ausgesprochene Sicherheitswarnung vor den Virenschutzprodukten des Herstellers.
Wie war die anfängliche Einrichtung?
An der Einführung und Bereitstellung der Lösung war ich maßgeblich beteiligt. Die Implementierung erfolgte relativ schnell und problemlos mit einem Deployment-Skript, welches über das Software-Verteilungssystem auf die Endpunkte gebracht wurde.
Unsere Implementierungsstrategie sah vor, dass zunächst eine kleine Anzahl von Endpunkten mit Virenschutz und Richtlinien versorgt wurde. Dann wurden die Richtlinien noch einmal überprüft und verfeinert. Abschließend wurde Vision One in mehreren Etappen auf die restlichen Endpunkte ausgerollt.
Wie war unser ROI?
Die Investition in Trend Micro Vision One hat sich rentiert, aber der ROI ist schwer zu berechnen. Eine Sicherheitslösung ist wie eine gute Versicherung, die man hoffentlich nicht braucht. Wir hatten bisher keine Vorfälle und hoffen natürlich, dass wir auch in Zukunft keine haben werden.
Ich stelle fest, dass unsere Umgebung durch die permanente Sichtbarkeit von potentiellen Risiken sicherer geworden ist und dass die Kollegen schneller auf diese reagieren können. Das spart vor allem Arbeitszeit.
Welche anderen Lösungen habe ich evaluiert?
Bevor wir uns für Vision One entschieden haben, haben wir auch die Lösungen anderer Hersteller evaluiert, unter anderem die von Microsoft und Fortinet. Die Unterschiede bei den jeweiligen Produkten waren nicht so gravierend, sie lagen mehr im Detail. Aber da wir auch schon seit fünfzehn Jahren Trend Micro Partner sind (zwölf Jahre davon ruhend), sind wir schließlich wieder zu Trend Micro zurückgekehrt.
Welche anderen Ratschläge habe ich?
Wir hatten vor drei Jahren ein Konzept, das einen anderen Ansatz verfolgte. Zwei voneinander unabhängige Sicherheitslösungen, mit jeweils eigenem Management und Reporting. Die Migration zu Vision One mit der Konsolidierung in eine Oberfläche hat zu einer 365°-Sicht auf die IT-Infrastruktur geführt.
Die zentrale Sichtbarkeit von Endpunkten und Schwachstellen und das Management über alle Ebenen hinweg hat noch einmal einen ganz anderen Fokus auf das Thema IT-Sicherheit gelegt und das Bewusstsein der Mitarbeiter für dieses Thema gestärkt.
Wenn Sie Trend Micro evaluieren, beschränken Sie sich bitte nicht nur auf den reinen Virenschutz, sondern beziehen Sie auch die anderen Funktionen in die Betrachtung ein. Insbesondere die Managed Services, der Technical Account Manager und die Cyber Risk Exposure Management Funktionen haben für mich einen hohen Mehrwert.
Schaffen Sie eine zentralisierte Sicht auf Ihre IT-Infrastruktur.
Definieren Sie im Vorfeld, welche Funktionen für Sie wichtig sind bzw. Sie benötigen.
Verschaffen Sie sich einen umfassenden Überblick bei der Evaluierung verschiedener Sicherheitsanbieter hinsichtlich Funktionen und Kosten, damit Sie nicht Äpfel mit Birnen vergleichen.
Welches Bereitstellungsmodell verwenden Sie für diese Lösung?
Private Cloud
Falls öffentliche Cloud, private Cloud oder Hybrid-Cloud, welchen Cloud-Anbieter verwenden Sie?
Verschiedene.
Which deployment model are you using for this solution?
Private Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Jul 27, 2025
Flag as inappropriateSystems and Security Manager at a educational organization with 5,001-10,000 employees
It improves the detection speed, but it could be more customizable
Pros and Cons
- "When we purchased Vision One, what set it apart was that it wasn't a traditional signature-based antivirus. It's a process-aware solution that provides real-time protection. That was a big differentiator three years ago, but now it's a given that every AV provider should be doing that. It combines signature-based telemetry with behavioral awareness and a detection-based solution, making it a good solution for us."
- "They need to stop changing Vision One once a week. They're in a hurry to change things so badly and so fast that I can't find where stuff is half the time, which is a challenge sometimes."
What is our primary use case?
Vision One is the primary endpoint security product we use to protect our Macs and PCs. We also use the server product version, so it runs on my servers as well. We exclusively purchase Trend Micro's endpoint products. They have network and firewall products. We were using their email product until last month, and I ended up selecting a different provider. We stayed with them for the endpoint, but I moved off of them for the email product.
How has it helped my organization?
Vision One was a big deal to us immediately because we did not have context-aware before. We saw everything we had no idea was happening. It was a big deal three years ago.
It certainly reduces time to detect because a lot of the time, I didn't have it before. I didn't have that information until it gave it to me. The speed of response helps me know much more about what's happening quicker. They have some improvement to do in terms of automated remediation. It probably makes investigations 30 percent faster because of what it puts together.
What is most valuable?
When we purchased Vision One, what set it apart was that it wasn't a traditional signature-based antivirus. It's a process-aware solution that provides real-time protection. That was a big differentiator three years ago, but now it's a given that every AV provider should be doing that. It combines signature-based telemetry with behavioral awareness and a detection-based solution, making it a good solution for us.
When we bought it three years ago, it was separate. Apex One handled cloud and web app security, and Vision One handled cloud and server workload protection. Now, they call it Vision One. The server stuff is still separate, but it is the same now. When we purchased it, they told us we'd have a single console, but that took about two and a half years. Finally, there is a single pane of glass.
One of the things that made me the craziest was that we had too many tools or one tool that I had to log into five different ways. One of the frustrations is you have both legacy and newer detection methods. Not being able to fully investigate it in a single portal was a huge pain.
What needs improvement?
They need to stop changing Vision One once a week. They're in a hurry to change things so badly and so fast that I can't find where stuff is half the time, which is a challenge sometimes.
I've given one piece of feedback to their product guys. One thing that they're trying to make is a SIEM. It's a product where you input all the logs from your tools, and it creates additional insights into how things look. They've been kind of playing the "me too" game on that, even though that's not what I bought the product for.
They have a new gateway where I can take my firewall of email logs and send it over there. In theory, it's supposed to do a more comprehensive evaluation of all my stuff to improve that risk index score. I'm not impressed with it, and I've told them as much. I feel if you're good at something, you should keep working on that and not try to be all the things to all the people.
I bought a different email solution even though it would have been 10 times easier to just stay with their email solution because they aren't great at it. They are great at other things, but they're playing the "me too" game with some of their products. Their competitors do this, so they should be doing this, too. They need to pick a product and keep being good at that. If they're going to roll new things out, they should do it but do it right.
They have a button to isolate an endpoint because it looks bad, but it doesn't usually work. I've had no chance to argue with the product guys to show them examples of how their button doesn't work. You think it does, but it doesn't work in a real environment. That can be a challenge sometimes.
I can see in the data showing what is a false positive. But it doesn't save me time helping them figure out how to fix the problem in their engine. It can help me identify it as a false positive, but it doesn't apply that consistently. It will ignore the false positive for that device, but if they start detecting a false positive on Apple devices, I have eight thousand Apple devices and get 8,000 alerts. I can tell that specific false positive, but it doesn't learn from that particularly well.
We use the executive dashboards, but I don't find them particularly useful. One is the ability to customize. That has gotten a little better, and it'll be better in the future. Most of what they have on there are data points that are generic and not particularly actionable. That's why it's called an executive dashboard. Executives want to see if we are secure, but it's hard for me to find out why our attack surface risk went down by x percentage. I don't know. It says that on the dashboard, but it doesn't give me specific details about why.
I find it confuses my executives, and it's not useful for me because it doesn't give me things to work on. It will give me generic things on the executive dashboard like you have a thousand accounts with an old password. Those are big generic things, but I also can't tell it that our password policy is different from what your automatic detection model means, and I don't have a problem with that, so quit lowering my risk score.
The risk score is useless. In theory, it's based on the random intelligence they're getting from their various customers. I'm in K-12 education, so they have a decent amount of K-12 customers, but it's a subset, and the baseline of what's common in K-12 education is not the same. There's not enough data to make that particularly clean or useful. Vision One is not custom, and that's part of my beef. That index score is based on whatever random report they're looking at from their data sources at any given moment in time. It's nice, but I'd rather have one that's based on your particular circumstances. Instead, it's saying that the number one attack threat surface for school districts is email phishing. It's too generic.
For how long have I used the solution?
I have used Trend Vision One for three and a half years.
What do I think about the stability of the solution?
Vision One has been less impactful toward my endpoints when scanning than the previous solution.
What do I think about the scalability of the solution?
Vision One's resource usage is starting to creep up compared to three years ago. They used to focus on making their agent lightweight. I don't necessarily think all of this is their fault, but their agents are starting to suck more resources than they used to. Part of it is that the threat landscape has changed, and you need to look at it in additional ways, and it is a strain on the servers. They've gotten really bad about that on the servers.
How are customer service and support?
I rate Trend Micro support three out of 10. Their technical support is challenging. The support's good once you get to the second layer, but they don't read what you write. They auto-respond by telling us to give them the logs.
Every time, I need to send them a written statement with my product license ID and that I'm the contact authorized to do a support ticket. About 75 percent of the time when I open a support ticket, I immediately email my customer service satisfaction manager person with the ticket number so they can help move it along.
How would you rate customer service and support?
Negative
Which solution did I use previously and why did I switch?
I was using Sophos three years ago. I've looked at many of the feature sets out there, and they might be 80 percent of what Vision One has, and some might be better, but Vision One is price-competitive.
How was the initial setup?
Deploying Vision One was a pain because of the automated removal tool. In the antivirus world, they try to make it difficult to uninstall people's defenses because that's what an attacker would do. However, all the competitors are making tools to uninstall their competitors' tools when they win business. That's directly counterintuitive to the whole point of the antivirus.
We went through a process of trying to do this in an automated fashion to replace the old product, and Trend didn't quite do it right. Trend had a real struggle toget their own tool to fix it.
We use it as a SaaS, so we have a gateway integrator on the server on-site, but the product sits on all my endpoints. In that aspect, it's on-prem, but all the processing, reporting, and everything else happens in the cloud. We had it 75 percent deployed in 45 days. That last 25 percent took us another four months.
I work at an underfunded public school district. I need a whole team, but there is only me. I used to have a security analyst until that position moved around, and
my ability to use the product has been drastically reduced. I miss much of the value of what I'm paying for because I don't have enough staff to use it. I wouldn't need more than one if that was their whole job.
It's not a totally elegant solution that always feeds and cares for itself. We have to check if it's doing its updates properly. It doesn't tell us, for example, that 2,000 devices haven't been updated or checked in. I have to go proactively looking at it.
What's my experience with pricing, setup cost, and licensing?
Vision One's pricing is extremely competitive. They're probably the lowest-cost provider that has this feature set.
What other advice do I have?
I rate Vision One seven out of 10. Make sure you learn the 90 percent of stuff in there that you didn't know you bought and preestablish an escalation contact for support tickets.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Buyer's Guide
TrendAI Vision One
February 2026
Learn what your peers think about TrendAI Vision One. Get advice and tips from experienced pros sharing their opinions. Updated: February 2026.
884,656 professionals have used our research since 2012.
Head of I T at Conquest Group
Transforms cybersecurity landscape with efficient and comprehensive protection
Pros and Cons
- "One of the best decisions we made was choosing Trend Vision One; it has transformed our entire security and cybersecurity landscape, providing a one-stop solution to manage everything efficiently and effectively."
- "The only disappointing aspect is that every time new features are adopted, additional credits are required, which could push the budget over. This practice should really be reconsidered by Trend."
- "The only disappointing aspect is that every time new features are adopted, additional credits are required, which could push the budget over."
What is our primary use case?
I use Trend Vision One for Total XDR and endpoint protection as an all-in-one security solution.
How has it helped my organization?
One of the best decisions we made was choosing Trend Vision One. It has transformed our entire security and cybersecurity landscape, providing a one-stop solution to manage everything efficiently and effectively.
What is most valuable?
One of the most valuable features is Cyber Risk Exposure Management.
What needs improvement?
There is room for improvement in leveraging AI technology to protect against emerging AI-based threats.
For how long have I used the solution?
I have been using the solution for two years.
Which solution did I use previously and why did I switch?
We previously used an outdated and inefficient Trend Micro system, which caused high security risks.
What's my experience with pricing, setup cost, and licensing?
This is not a competitive price — the costs are on the higher side. However, I don’t regret it, as it can help save significantly in other areas. The only disappointing aspect is that every time new features are adopted, additional credits are required, which could push the budget over. This practice should really be reconsidered by Trend.
Which other solutions did I evaluate?
I also evaluated CrowdStrike as an alternate solution.
What other advice do I have?
Trend Vision One is a five-star product.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Oct 5, 2025
Flag as inappropriateDeputy General Manager at Tata Communications Ltd
AI-driven visibility empowers risk management with faster detection
Pros and Cons
- "The most important features of Vision One include visibility, AI integration, attack pattern analysis, predictive analytics, and centralized visibility and management across protection layers."
- "There should be improvements in risk quantification, where the risk is displayed in a quantified manner, showing the dollar value loss."
What is our primary use case?
As a security architect, I design solutions for our end customers. In previous projects, we've successfully implemented Trend Vision One for customers with cloud-based assets and email servers, enabling them to extend security coverage to their remote clients.
The current market trend in email security solutions focuses on mitigating threats like phishing attacks. These widespread attacks occur across various points in the cyber kill chain process. Whether initiated from the perimeter or targeting cloud-based assets, monitoring all north-south and east-west traffic is challenging. Trend Vision One helps by providing a comprehensive analysis of these email phishing attacks, identifying the attack origin, parameters, and information extracted from attack patterns.
How has it helped my organization?
Trend Vision One offers centralized visibility and management across all protection layers. This comprehensive view provides valuable information for CISO/CIO presentations, including attack patterns, threat actors, and areas for predictive analysis. Such insights are crucial for informing policy changes and other security enhancements. The visibility also helps with efficiency.
We can summarize any technical information we receive using widgets and then present it to executives in a dashboard format.
Our customers adapt the risk index feature to align with the specific needs and conditions of their individual environments.
We have used Trend Vision One in several projects where our customers consolidated security across hybrid environments. The consolidation effort, particularly utilizing Vision One's AI-driven features, streamlined investigative analytics. Furthermore, merging multiple solutions into Vision One provided comprehensive insights, which proved invaluable for policy development.
The ability to manage risk and maintain visibility has improved by approximately 20 to 30 percent, significantly simplifying our tasks. Operationally, this has led to a 20 percent reduction in effort.
Trend Vision One has helped reduce detection and response times by 30 and 40 percent, respectively.
Trend Vision One has saved more than a week's worth of effort in investigating false positives.
Trend Vision One's automation capabilities have helped us save between 60 and 100 hours monthly.
What is most valuable?
The most important features of Vision One include visibility, AI integration, attack pattern analysis, predictive analytics, and centralized visibility and management across protection layers. These features are very important to us.
What needs improvement?
There should be improvements in risk quantification, where the risk is displayed in a quantified manner, showing the dollar value loss. The integration with third-party OEM solutions also needs enhancement, particularly in UEBA integration with Trend. Sometimes, there are blind spot discoveries that are not completely successful. Improving automation to avoid manual triaging and providing more insights on dashboards is desirable.
While Trend Vision One's attack surface risk management helped identify some vulnerabilities in our environment, the feature needs improvement. Specifically, the blind spot discovery is unreliable; for example, a missed blind spot in one environment led to an attack and subsequent investigation.
Automation should be improved to eliminate the need for manual effort in initial L1 triaging. Additionally, dashboards should provide more insightful analysis, including various mappings to the MITRE ATT&CK framework and Tactics, Techniques, and Procedures.
For how long have I used the solution?
I have been working with Vision One for almost almost two years.
How are customer service and support?
The support in Trend Micro is good.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I have worked on Exchange servers, and we are using Palo Alto to a certain extent. These were not from the XDR or EDR point of view.
What was our ROI?
The analysis shows that Trend Vision One has improved our ROI by 30 percent.
What's my experience with pricing, setup cost, and licensing?
Competitors offer comparable solutions at slightly lower prices, so Vision One has room to reduce its pricing by 15 percent, given that Trend Vision One charges approximately $10 per endpoint.
Which other solutions did I evaluate?
We evaluated other options but not to the same extent as Trend Micro because I was more familiar with Trend Micro solutions.
What other advice do I have?
I would rate Trend Vision One nine out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Platform Engineer Ii at a outsourcing company with 5,001-10,000 employees
Platform has improved ransomware detection and now supports faster automated incident response
Pros and Cons
- "TrendAI Vision One solves these problems by providing greater detection capabilities and automated response across all of these layers."
- "TrendAI Vision One could bring in more data loss prevention capabilities specifically on the endpoints, as the current offering lacks some important capabilities."
What is our primary use case?
TrendAI Vision One is our centralized platform for managing multiple security products, specifically on endpoint and workload security.
We have integrated TrendAI Vision One with Microsoft and AWS cloud accounts that we use. Our SOC team monitors TrendAI Vision One and the platform provides them with multiple views of data sets and detections that have occurred, helping them to quickly onboard with all the relevant data they should be aware of.
We are using TrendAI Vision One sensors across endpoint and workload security.
What is most valuable?
We were facing multiple cybersecurity incidents in our endpoint and workload security, including attacks such as ransomware and malware. TrendAI Vision One solves these problems by providing greater detection capabilities and automated response across all of these layers.
TrendAI Vision One helps with integration and correlation of multiple security solutions and provides us with better dashboard and reporting capabilities to showcase the data to our board.
We are seeing fewer threats and events across these security layers since we invested in TrendAI Vision One. The platform has been particularly useful in protecting against ransomware.
We are able to respond faster and quicker compared to earlier because of the automated response that TrendAI Vision One offers, which reduces our dependency on manual effort that was previously required.
What needs improvement?
TrendAI Vision One could bring in more data loss prevention capabilities specifically on the endpoints, as the current offering lacks some important capabilities.
They could also bring in data loss prevention capability and integrate with patch management solutions, which is overdue.
For how long have I used the solution?
We have been using TrendAI Vision One for the past three and a half years.
What other advice do I have?
It is extremely important to protect sensitive and critical data that resides on servers.
I would say TrendAI Vision One is a really good platform overall, and we found it fitting into our budget compared to competitive solutions. I would rate this product highly.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Dec 31, 2025
Flag as inappropriateSenior Technical Engineer at Safezone Secure Solutions Private Limited
Manages cyber risk across endpoints and email while simplifying detection and response workflows
What is our primary use case?
I work with Trellix, Trend Micro, Fortinet, and Netrix for DLP solutions. For Netrix DLP, I use Forcepoint, and for email security, I use Barracuda.
I have been working with Trend Micro for the past six years. I started with Apex One and Worry-Free, which evolved to TrendAI Vision One. TrendAI Vision One is a collaborative XDR platform designed to bring all security solutions such as mail security, cloud security, endpoint security, and identity security together and manage them from a single console. That is the main goal of TrendAI Vision One.
From my end, I have deployed email security, endpoint security, XDR, and web security from TrendAI Vision One. We are using TrendAI Vision One with both business essentials and pro bundle.
TrendAI Vision One has two kinds of solutions for endpoint security: standard endpoint protection for desktop machines and server and workload protection for existing Linux servers, Windows servers, or even containers and workloads in the cloud where you can install agents for those containers as well. These are the deployments which we have done for endpoint security.
What is most valuable?
The detection part works well for me. The response part, including automatic containment, requires creating playbooks. Even though I create them, I have faced many threat attack scenarios where detection pops up, but the appropriate response action is not being taken.
Attack discovery and attack surface discovery are valuable features. Every organization has endpoints, and no organization will be willing to do a full discovery or testing on all those endpoints or devices. Attack discovery helps us know which endpoints we have with Trend Micro, what vulnerabilities and loopholes are available in the endpoints, and provides insights into our attack surface.
I have used the cyber risk exposure management product completely except for security awareness. I have used data security posture, identity security posture, and network security functionalities. I have not ensured cloud security yet, but we are yet to have hands-on experience with that. I have showcased these functionalities to customers and conducted many POCs for new clients covering cyber risk exposure management, XDR, email security, endpoint security, and network security. I have explained how well TrendAI Vision One captures the correct data.
The response time after detection is approximately three hours.
What needs improvement?
Visibility is good, but TrendAI Vision One can improve the response part. Compared to other vendors like SentinelOne or CrowdStrike, all of them are providing detection and response methodology. However, TrendAI Vision One provides more visibility but has limitations on the response part.
If TrendAI Vision One can improve the response time and playbooks, particularly with more customizable playbooks, it would be greatly helpful. We have raised feature requests to Trend Micro. If they have more predefined playbooks and more options for response management, it would be beneficial because that is what end users are expecting.
As a reseller, we are dealing with the pain because customers are asking why response is not being taken even though TrendAI Vision One detects suspicious files. In some cases, I follow best practices by updating playbooks at regular intervals, but that is a manual process. An automated process to take appropriate action for suspicious and malicious files would be necessary. The response part might be improved to provide better value.
For how long have I used the solution?
I have been working with Trend Micro for the past six years.
What do I think about the stability of the solution?
TrendAI Vision One is stable. Before TrendAI Vision One, Trend Micro had Apex One and Worry-Free products for endpoint security that were not stable. However, after TrendAI Vision One was introduced, I do not see any stability issues.
What do I think about the scalability of the solution?
Scalability is good. Previously, it was good because they were using a credit system where they would give credits and based on the credits we could allocate our own licenses. Right now they have removed this feature, so we are yet to do some testing on that. The credit system was effective because we had flexible licensing and scalability, and we were able to use the resources when and if it was necessary.
How are customer service and support?
Two factors are important: the time to give the first response and the technical ability of the engineers. I heard that they have laid off many old employees and senior employees.
The integration part is good. They also have an AI platform built into the console which provides more details in layman's terms. When explaining an attack to management, you can communicate it to a CIO in technical terms because they are from a technical background and will understand all the details. However, when taking this to a CEO or CFO who are not technical persons with backgrounds based on industry, you should explain it in simple terms. The AI integration with TrendAI Vision One gives the details in a much simpler way in layman's understanding. That feature is good.
How would you rate customer service and support?
Neutral
How was the initial setup?
The installation is easy. Even for Linux and Mac machines, it is just two or three commands.
What was our ROI?
ROI is absolutely achievable, especially with TrendAI Vision One and server TrendAI Vision One platform. Previously, they had MSVA, which was a virtual appliance that on-premises clients needed for mail security. After they came up with the cloud email security solution, many customers are feeling relief, and the latency is much better when compared to an on-premise solution.
For ROI in email security, they provide BEC, which is the best ROI for every customer. If there is an outage that occurs in Microsoft or AWS or any other cloud platform, there is an email continuity platform for emails. That is good ROI.
From a deployment perspective, it shows around fifty to sixty percent. The impact given to the business in terms of real impact is up to ten to twenty percent.
What's my experience with pricing, setup cost, and licensing?
This is quite affordable. It is not that expensive.
Which other solutions did I evaluate?
We buy from Trend Micro. TrendAI Vision One definitely falls in the leader quadrant in Gartner, and its capabilities are good. It can be in that leader quadrant. For an endpoint security solution, managing attacks is the key thing. It is not about daily activities like what policies and functionalities are provided. These matter, but at the end of the day, if an attack is going to happen, the end user will assess the support of TrendAI Vision One and the response part of TrendAI Vision One. These two parameters are going to be assessed, and based on these two parameters, any quadrant achievement from labs like Gartner or Forrester will be based on these two parameters only.
What other advice do I have?
For standard endpoint protection, if it is a detection, it is a detection. When compared to CrowdStrike, TrendAI Vision One creates much less false positives. There is no big noise on this, but that is one way to consider it. False positives do come, and it is completely based on the configuration which we do. On the initial phase of the deployment, after a month or two, we keep it in detection mode, and after that, we pursue the prevention mode so that blocking is enabled.
If the containment functionality gets automated, it would be on a better note. The response part, if improved, will be very helpful. From a deployment perspective, it shows around fifty to sixty percent.
TrendAI Vision One is fully on the cloud with no on-premise option. They tie up with multiple cloud vendors, but they provide a SaaS platform built by Trend Micro. Trend Micro itself is hosted on some AWS servers, which is what I have heard, but I do not want to comment on that.
I would rate this review an eight.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Last updated: Nov 24, 2025
Flag as inappropriateSoc Analyst at Payatu
Centralized management enhances threat response with automation and comprehensive insights
Pros and Cons
- "The workbench alerts provide valuable insights into attack chains and relevant information, while Observer techniques give a comprehensive overview of ongoing activities."
- "Trend Vision One requires several enhancements for optimal performance."
What is our primary use case?
As a cybersecurity analyst at a managed security service provider, I use Trend Vision One for two of my clients. My primary use cases involve standard XDR functions, such as anomaly monitoring, alert analysis, and incident response. To streamline these processes, I've configured automated response playbooks within Trend Vision One. The insights provided by the platform, mainly through the Workbench and Observe Auto module, are invaluable for understanding my clients' environments and identifying vulnerabilities that need to be addressed.
I work with clients across various industries, including education and power. My education client utilizes Trend Vision One for specific security needs, while my power industry client, an electricity board, has a comprehensive Trend Micro solution in place, including Vision One, Apex One, and Deep Security Manager. With Vision One, I've successfully detected and addressed numerous web attacks, malware attacks, and unauthorized access attempts on production servers in the education sector. For the power client, the solution has effectively detected and blocked multiple ransomware attacks. These are common occurrences and demonstrate the value of Trend Micro's security solutions.
We use Trend Vision One on all endpoints in two scenarios. For one client with on-premises servers and endpoints, we use Trend Vision One as a comprehensive solution. For another client in the education sector, we use Trend Micro Deep Security Management alongside the Vision One XDR platform on their cloud-based Linux servers.
How has it helped my organization?
Trend Vision One provides centralized visibility and management across all protection layers. This is crucial for efficiently sharing data with management, both internally and client-side. The platform avoids technical jargon, offering executive summary dashboards and summarized incident reports that clearly communicate security status. This allows for concise and effective communication with non-technical stakeholders, assuring them of their security posture. Trend Vision One's automated dashboards streamline reporting, eliminating the need for extensive manual documentation, which is especially valuable for technical users.
I use executive dashboards to build on threat detection, check for vulnerabilities, and create appropriate responses for individuals or groups of endpoints.
We use the risk index to assess and enroll our risk score. We maintain a low-risk index, which helps both management and me understand our score in relation to global risk factors.
Although I inherited Vision One as a service provider from another team, I eventually began utilizing its full potential and reaping its benefits.
Trend Vision One offers a phishing simulation feature in its cyber risk assessment. I frequently use this tool with my clients to evaluate employee email awareness. It generates comprehensive reports and provides functionalities for easy management.
Attack surface risk management helps identify vulnerabilities and high-risk threats in an environment, but it may also generate some false positives.
Trend Vision One significantly reduces MTTD and MTTR by approximately 50 percent. Its automated playbooks enable an immediate response to detected threats, providing near-instantaneous protection. While manual analysis and reporting of critical errors typically take an analyst up to 15 minutes, Trend Vision One's configured playbooks can automatically complete the same task within two minutes.
I have configured some playbooks to take automated actions on Trend Vision One while detecting some specific alerts or while detecting some specific playbook alerts.
What is most valuable?
Trend Vision One offers several features that I appreciate. The workbench alerts provide valuable insights into attack chains and relevant information, while Observer techniques give a comprehensive overview of ongoing activities. The platform's automated playbooks streamline incident response, significantly reducing MTTD and MTTR. Additionally, the ability to integrate with various firewalls and data sources, including Trend Micro's suspicious object management, centralizes threat management and simplifies daily security operations and incident response tasks.
What needs improvement?
Trend Vision One requires several enhancements for optimal performance. The platform should allow users to create custom phishing templates directly within the console and improve logging capabilities to facilitate seamless integration with SIEM solutions. Additionally, it should provide a mechanism for configuring Office 365 Advanced Threat Protection alerts to be displayed within the Workbench for streamlined threat management.
For how long have I used the solution?
I have been using Trend Vision One for about a year and a half.
What do I think about the stability of the solution?
Trend Vision One is a stable platform with no significant issues like lagging or crashing.
What do I think about the scalability of the solution?
Trend Vision One is easy to scale up by adding new agents, although the credit system for feature usage is confusing and could be simplified.
Which solution did I use previously and why did I switch?
I have experience with solutions like Sophos Central XDR and Wazuh, and while they have their strengths, I find Trend Vision One to be a competitive option with a comprehensive range of capabilities.
What other advice do I have?
I would rate Trend Vision One nine out of ten.
The on-premises Trend Micro solutions may require updates.
After deploying Trend Vision One on pilot devices, I recommend exploring the entire portal to familiarize yourself with its features and capabilities.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company has a business relationship with this vendor other than being a customer. MSP
Systems Analyst at a manufacturing company with 201-500 employees
Provides full visibility and helps reduce our detection and remediation times
Pros and Cons
- "The most significant recent change has been the addition of the new AI companion."
- "The only downside to Trend Vision One is its complexity."
What is our primary use case?
We use Trend Vision One for the XDR and we absolutely love it, especially the full visibility into protected assets. It's incredibly easy to identify weaknesses across systems and manage any outdated software or areas needing attention directly within the user interface. Previously, we juggled multiple dashboards, but the new version has streamlined everything into a single, unified dashboard. This has significantly simplified our workflow and improved manageability. In essence, we can now manage multiple products seamlessly within the same Vision dashboard, which is a considerable improvement over the previous system. This year has brought significant and positive changes to our workflow.
We use XDR across Office 365 in the cloud and on-premises environments to safeguard our assets. This includes protecting our server environment, workstations, and Virtual Desktop Infrastructure, ensuring comprehensive endpoint security.
Our deployment utilizes a hybrid model, making agent deployment incredibly simple. We employ several different deployment methods: on-premise deployment through Active Directory and utilizing various tools. In case a system leaves the network for any reason, we have third-party solutions in place. We have multiple RMM solutions that can be rapidly deployed in these packages. For example, I've recently observed systems being spun up and sent home before antivirus protection was activated. We still have the opportunity to deploy these solutions in the cloud automatically. So, we have a few ways to work around this and deploy those agents, making it easy to deploy either on-premise or in the cloud. We can address several scenarios and push out to those endpoints.
How has it helped my organization?
Coverage is extremely important. We want to ensure visibility into all assets across the network, whether it's a workstation within the office or someone working remotely. This visibility is crucial even when they're outside the network or using cloud-based software, especially since we have no on-premise infrastructure. With the rise of remote work, having this extra visibility into devices, whether at home or abroad, is invaluable. We appreciate the ability to see what's happening on any asset, regardless of its location. This allows us to monitor running processes, identify vulnerabilities, and push necessary updates, ensuring we maintain connectivity and security no matter where devices are operating.
Trend Vision One offers us comprehensive visibility within a single dashboard, which is crucial since we manage numerous other products and security solutions with various dashboards. The simplicity and centralized visibility provided by Trend Vision One significantly streamline our operations. Managing a multitude of security products across our environment necessitates consolidated visibility to minimize back-and-forth navigation. Having all the necessary information in one place is essential for us.
We use executive dashboards to generate weekly or monthly reports that provide a risk score index. This index helps us identify areas needing attention and understand the teams' focus. We then share this information with IT senior management. In addition to our reporting, we receive a monthly report that allows us to compare our current status to the previous month's and highlight new challenges, team weaknesses, and ongoing efforts. This comprehensive view enables the executive team to monitor the team's continuous progress.
We utilize the risk index feature to monitor and mitigate potential environmental risks. One example of this is how we proactively worked to reduce the risk index score of a recently acquired company. Their antivirus product was expiring, so we opted to purchase additional licenses for our existing Trend Apex One product suite instead of renewing it. However, this integration significantly increased the risk index score due to numerous previously unmanaged devices on their network. To address this, we systematically worked through the risk index list, identifying outdated software and determining if it was still in use or could be safely removed. By leveraging the risk index in this way, we successfully lowered the score and ensured the secure integration of the newly acquired company into our environment.
It took some time to fine-tune Trend Vision One before realizing its benefits. A significant concern was integrating it into our virtual environment, a complex process. However, we gained significant visibility once set up in our VDI, leading to further adjustments. We fine-tuned the environment, removing unnecessary elements, which is especially crucial for our non-persistent VDI, where VMs reset if anything goes down. Through these tweaks, performance improved, and the extra visibility provided by Vision One highlighted areas needing attention, allowing us to optimize the environment gradually.
We use Trend Vision One within Azure, expanding its monitoring capabilities to both on-premises and cloud assets, including Active Directory, which is synchronized from our on-premises environment. This hybrid setup covers assets locally and in the cloud, including Office 365, and Trend Vision One effectively manages security across this environment. It has simplified the process, particularly for virtual environments, providing enhanced visibility and flexibility compared to previous products. The additional visibility has been invaluable, enabling us to address previously undetected vulnerabilities and mitigate risks.
During XDR and managed services pen testing exercises, we identified some weaknesses. They were able to automatically crack some accounts. As soon as one system was breached, the managed services team contacted us, escalating until they got a response. We could see their process in action - their steps and what they did in the backend. We provided them with details about the events and the ongoing pen test. It was an excellent test to see that the managed services worked as intended. There was a breach; they asked if we were aware and stated they would isolate the device if we weren't. We acknowledged we knew about the ongoing pen test. Throughout these exercises, they reached out immediately, demonstrating their focus on alerts, their process for triaging them, and their communication with clients.
The attack surface is directly related to exposure and risk. Any identified vulnerabilities, such as outdated software like older versions of Office or Google Chrome products, are flagged immediately. We use third-party solutions to address these issues across all workstations. Whenever we detect internal or internet-facing exposure, we prioritize remediation based on criticality. External-facing vulnerabilities are patched first, as they pose a greater risk than those affecting only internal assets. We rely heavily on exposure risk and risk index to determine priority and ensure the most critical vulnerabilities are addressed first. This helps us identify blind spots in our environment. Take the new acquisition as an example; many devices were unprotected and lacked crucial Windows updates. Numerous products and workstations required immediate attention. Security wasn't the initial priority, so we addressed that and ensured it became one. We implemented numerous changes with acquisitions to align them with our security standards.
Trend Vision One has significantly reduced our mean time to detect and respond to threats by 60 percent. It centralizes all information, enabling us to identify and address vulnerabilities quickly. For example, if we discover multiple devices running an outdated version of Office 2013 missing patches, we can easily compile a list of those devices and share it with the responsible team for remediation. This visibility allows us to proactively address weaknesses across the network, such as deploying updates or the latest release of third-party software to mitigate risks. Trend Vision One has been instrumental in enhancing our overall security posture.
The managed services significantly reduced the time we spent investigating false positive alerts. In uncertain scenarios, we consult the managed services team. If unsure about anything, we use the AI companion for questions. If we encounter an unfamiliar flag or event, we research it independently and involve the managed services team's professionals for deeper investigation.
We have implemented some automation but haven't fully explored its capabilities. We have a few playbooks for tasks like blocking user access based on IP addresses or email content. Since we use Office 365 in the cloud, there's also a lot of automation for handling incoming emails, such as blocking and sending alerts. While we've used playbooks to a limited extent, there's potential for further automation, and we plan to explore this further.
What is most valuable?
The most significant recent change has been the addition of the new AI companion. This feature has proven invaluable, especially when integrating with third-party products or resetting the dashboard, as it provides detailed step-by-step guidance. In fact, we were able to resolve all issues independently, without needing to contact support, thanks to the AI companion's comprehensive answers.
What needs improvement?
The only downside to Trend Vision One is its complexity. It's a comprehensive product covering a lot of ground, which can be a little intimidating initially. The user interface, in particular, can take some time to get used to, with menus that could be better organized and a dashboard that could be more user-friendly. Due to the sheer complexity of the product, navigating and familiarizing oneself with the environment requires some effort. While the initial learning curve might be steep, the product's vast capabilities justify the time investment.
For how long have I used the solution?
I have been using Trend Vision One for two and a half years.
What do I think about the stability of the solution?
I would rate the stability of Trend Vision One nine out of ten. I haven't experienced any crashes or issues in the last few years since we started using the product. While there are occasional upgrades and minor changes that require adjustments, the overall stability is excellent. We have no complaints, especially considering the VDI environment, our primary focus, has been running seamlessly. The lightweight agent minimizes resource usage, further contributing to smooth performance.
What do I think about the scalability of the solution?
I would rate the scalability of Trend Vision One nine out of ten. We successfully scaled it up by adding approximately 250 workstations and deployed the product within a week. We replaced their previous product, scripted everything, integrated it into their on-premise servers, and deployed the agents. The 250 additional assets were integrated within two or three days, providing complete visibility in the dashboard. The team then took over and identified any weaknesses. In summary, scaling up and adding 250 workstations was easy to implement.
How are customer service and support?
The technical support and service are excellent. After our new acquisition, we encountered a few issues that we hadn't seen in our environment compared to theirs. Through troubleshooting, we determined that the problems weren't caused by the product itself but rather by corruption in specific systems. We systematically worked through the other products, disabling them one by one. The troubleshooting experience was excellent, and we reached a resolution within a couple of days of contacting support. They were very professional and provided direct answers, resulting in the issues being resolved correctly and in a timely manner.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
In the past, we have used a few different products, including Sophos and Cylance, which we have used for the past couple of years. We also used Trend's older products, like OfficeScan, about eight or nine years ago. We eventually moved away from those products due to their lack of AI capabilities. After trying other products, we returned to Trend with Apex One and Vision One. We've been happy with the product, and its virtual environment capabilities were a major factor for us. Trend has consistently been the best performing product for us, so we decided to continue using their products with Trend Vision One.
How was the initial setup?
The initial deployment was straightforward. We leveraged our existing products to force and uninstall the previous product, opting for a custom scripting approach rather than standard GPOs or internal solutions. This allowed us to uninstall the old package and ensure the new installation was reflected in the dashboard, streamlining the process and enabling us to proceed seamlessly to the next phase. Overall, the deployment was straightforward from our perspective.
We deployed Trend Vision One during COVID, which took approximately one and a half weeks because the server side required additional fine-tuning for all the exclusions.
What about the implementation team?
We implemented the solution in-house. We repeatedly reached out to obtain basic information and guidelines on the VDI component and the virtual environment, specifically regarding steps for managing the virtual environment when closing a gold image and imaging numerous workstations with a single image. Due to the complexities involved, we requested documentation. However, our internal team completed the entire deployment with limited support from their support team, following the provided instructions.
What's my experience with pricing, setup cost, and licensing?
The pricing is fair compared to other solutions. It's within the price range we're looking at for a single endpoint, and fair pricing is important to us.
What other advice do I have?
I would rate Trend Vision One nine out of ten.
The Trend Vision team handles all maintenance on the SaaS backend. Internally, we only need to update the VDI environment occasionally because it's a non-persistent VDI, meaning it's locked down and reverts to its previous state upon reboot. We periodically open the gold images to perform maintenance, update signatures, and force program upgrades, but this is only a monthly task. So, we spend minimal time managing the solution.
Before implementing Trend Vision One, ensure you gather comprehensive documentation. Adhering to the guidelines will streamline setup, and any queries can be resolved using the efficient AI companion. Users can pose questions or access documentation directly from the Trend website. Initially, focus on familiarizing yourself with the dashboard, risk indexing, and the executive dashboard. Explore the product, ask questions, and continue experimenting and seeking assistance once deployed. The process is straightforward once you've had the opportunity to explore the system thoroughly. The primary challenge is becoming comfortable with the interface and navigating its features effectively.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Buyer's Guide
Download our free TrendAI Vision One Report and get advice and tips from experienced pros
sharing their opinions.
Updated: February 2026
Product Categories
Endpoint Detection and Response (EDR) Network Detection and Response (NDR) Extended Detection and Response (XDR) Attack Surface Management (ASM) AI-Powered Cybersecurity Platforms AI SecurityPopular Comparisons
CrowdStrike Falcon
Microsoft Defender for Endpoint
Darktrace
SentinelOne Singularity Complete
Cortex XDR by Palo Alto Networks
Microsoft Sentinel
IBM Security QRadar
Fortinet FortiEDR
Microsoft Defender XDR
Elastic Security
WatchGuard Firebox
Trellix Endpoint Security Platform
Check Point Harmony Endpoint
Buyer's Guide
Download our free TrendAI Vision One Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What is the biggest difference between EPP and EDR products?
- What is the difference between EDR and traditional antivirus?
- What is your recommendation for a 5-star EDR with low resource consumption for a financial services company?
- Which is the best EDR for a logistics company with 500-1000 employees?
- What is the best EDR or XDR product for a company with 9000 employees?
- What to choose: an endpoint antivirus, an EDR solution or both?
- Do we need to use both EDR and Antivirus (AV) solutions for better protection of IT assets?
- How does EternalBlue work?
- What are the best on-premise Endpoint Security solutions for a Tech Services company with 10,000 employees?
- Which is better for Endpoint Security: EDR or XDR solutions?


















