What is our primary use case?
In terms of the VDR, we are doing the Sophos entire solutions. We are doing the firewall, as well as endpoint, as well as email security.
When it comes to SophosLabs Intelix or Sophos Cloud Optix, basically, we are working with Sophos XDR and MDR right now.
As a partner, we have so many clients who are serving the Extended Detection and Response, and some users are just selling the Sophos Managed Detection and Response services. Basically, it's XDR, it's a tool, and MDR is managed by the Sophos security team 24/7. So, we are selling the Sophos MDR.
On the firewall side, we are doing the Sophos firewall, SonicWall firewall, and FortiGate.
We are dealing with Trend Micro for EDR and XDR.
We have been doing this product for the last 10 years, actually. Ten plus years we have been doing this product—Sophos entire solution and Trend Micro entire solution. Trend Micro has so many products, including anti-APT and IDS, IPS device.
For TrendAI Vision One, I have many corporate users who are using it for their servers' security, as well as the IDS, IPS device and TippingPoint, SMS gateway, and so on.
TrendAI Vision One has core features, such as endpoint, email, identity, servers, cloud workloads, and networks. When we talk about endpoint security, it includes anti-malware, anti-ransomware, behavioral analysis, exploit protections, device control, application control, post firewall, and EDR capabilities for the threat investigation and response. These are the TrendAI Vision One features.
Regarding TrendAI CReM capabilities, the threat hunting includes searching across telemetry data, IOC sweeping, root cause analysis, and advanced investigation tools. When we talk about the CReM features, they provide visibility into endpoints, server, cloud workloads, and identities. They help to identify unknown or exposed assets in the environment, then asset discovery, vulnerability management, and attack surface management.
My impressions of TrendAI Vision One include risk prioritization analysis, security posture, and assessment. Right now, I am working with Sophos in Sophos XDR.
I just appreciate the Sophos server protection and its lockdown features. When I whitelisted some applications, other executable files or any files do not run in the environment. I compare Sophos EDR with Sophos XDR, Endpoint Detection and Response, and Extended Detection and Response. When we're going with Sophos XDR, they have email, identity, firewall, cloud, and any third-party integrations.
I am focusing on the Sophos product, but as per the client requirement, I recommend Sophos because the clients are using a parameter gateway with a Sophos firewall. I pitch Sophos because they enable Heartbeat security, so the firewall and endpoint communicate effectively. It's a good bundle when combining Sophos firewall with Sophos endpoint.
Some users using Sophos require on-premises solutions and do not move to the cloud. So many reasons exist for this, which is why we pitch server solutions. Trend Micro server protection is a really good product, but my query always relates to support; I cannot get immediate support from Trend Micro.
What is most valuable?
For TrendAI Vision One, I have many corporate users who are using it for their servers' security, as well as the IDS, IPS device and TippingPoint, SMS gateway, and so on.
TrendAI Vision One has core features, such as endpoint, email, identity, servers, cloud workloads, and networks. When we talk about endpoint security, it includes anti-malware, anti-ransomware, behavioral analysis, exploit protections, device control, application control, post firewall, and EDR capabilities for the threat investigation and response. These are the TrendAI Vision One features.
Regarding TrendAI CReM capabilities, the threat hunting includes searching across telemetry data, IOC sweeping, root cause analysis, and advanced investigation tools. When we talk about the CReM features, they provide visibility into endpoints, server, cloud workloads, and identities. They help to identify unknown or exposed assets in the environment, then asset discovery, vulnerability management, and attack surface management.
I appreciate the Sophos server protection and its lockdown features. When I whitelisted some applications, other executable files or any files do not run in the environment. I compare Sophos EDR with Sophos XDR, Endpoint Detection and Response, and Extended Detection and Response. When we're going with Sophos XDR, they have email, identity, firewall, cloud, and any third-party integrations.
I am focusing on the Sophos product, but as per the client requirement, I recommend Sophos because the clients are using a parameter gateway with a Sophos firewall. I pitch Sophos because they enable Heartbeat security, so the firewall and endpoint communicate effectively. It's a good bundle when combining Sophos firewall with Sophos endpoint.
What needs improvement?
From my perspective, the only disadvantage in TrendAI Vision One is the support size.
The support takes too much time. When I email, I have to collect logs and submit them to the engineer, then wait for their reply. It takes too much time. The product is really good, but the support is not good in my perspective since it takes too long to receive help, especially when all the devices are in production.
The price is high when compared to the features. After installing the product, support is always required. Whenever we deploy any product, we need support, especially if an issue arises, support is a must.
We face lots of challenges, but the product itself is good. The main issues arise from support.
Some users using Sophos require on-premises solutions and do not move to the cloud. So many reasons exist for this, which is why we pitch server solutions. Trend Micro server protection is a really good product, but my query always relates to support; I cannot get immediate support from Trend Micro.
Trend Micro is a really good product, but I face challenges when not getting proper support; hence I feel helpless at times. The product itself is really good; I have no doubts about that.
For how long have I used the solution?
We have been doing this product for the last 10 years. Ten plus years we have been doing this product—Sophos entire solution and Trend Micro entire solution.
How are customer service and support?
The support takes too much time. When I email, I have to collect logs and submit them to the engineer, then wait for their reply. It takes too much time. The product is really good, but the support is not good in my perspective since it takes too long to receive help, especially when all the devices are in production.
From my perspective, the only disadvantage in TrendAI Vision One is the support size. Sophos support is really good, but when I require immediate support from Trend Micro, it is a challenge.
How was the initial setup?
TrendAI Vision One is easy; deployment is not a problem.
What other advice do I have?
We are dealing with Trend Micro for EDR and XDR.
My impressions of TrendAI Vision One include risk prioritization analysis, security posture, and assessment. Right now, I am working with Sophos in Sophos XDR.
When we talk about the CReM features, they provide visibility into endpoints.
I would rate Trend Micro support a six to seven, possibly seven to eight.
The interface and everything are good; my only query is on the support, which is not good from my perspective.
Some limited corporate users and some government users choose Trend Micro instead of Sophos.
Trend Micro is a really good product, but I face challenges when not getting proper support; hence I feel helpless at times. The product itself is really good; I have no doubts about that.
I would rate this review an eight overall.
Which deployment model are you using for this solution?
On-premises
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner