Vision One is the primary endpoint security product we use to protect our Macs and PCs. We also use the server product version, so it runs on my servers as well. We exclusively purchase Trend Micro's endpoint products. They have network and firewall products. We were using their email product until last month, and I ended up selecting a different provider. We stayed with them for the endpoint, but I moved off of them for the email product.
Systems and Security Manager at a educational organization with 5,001-10,000 employees
It improves the detection speed, but it could be more customizable
Pros and Cons
- "When we purchased Vision One, what set it apart was that it wasn't a traditional signature-based antivirus. It's a process-aware solution that provides real-time protection. That was a big differentiator three years ago, but now it's a given that every AV provider should be doing that. It combines signature-based telemetry with behavioral awareness and a detection-based solution, making it a good solution for us."
- "They need to stop changing Vision One once a week. They're in a hurry to change things so badly and so fast that I can't find where stuff is half the time, which is a challenge sometimes."
What is our primary use case?
How has it helped my organization?
Vision One was a big deal to us immediately because we did not have context-aware before. We saw everything we had no idea was happening. It was a big deal three years ago.
It certainly reduces time to detect because a lot of the time, I didn't have it before. I didn't have that information until it gave it to me. The speed of response helps me know much more about what's happening quicker. They have some improvement to do in terms of automated remediation. It probably makes investigations 30 percent faster because of what it puts together.
What is most valuable?
When we purchased Vision One, what set it apart was that it wasn't a traditional signature-based antivirus. It's a process-aware solution that provides real-time protection. That was a big differentiator three years ago, but now it's a given that every AV provider should be doing that. It combines signature-based telemetry with behavioral awareness and a detection-based solution, making it a good solution for us.
When we bought it three years ago, it was separate. Apex One handled cloud and web app security, and Vision One handled cloud and server workload protection. Now, they call it Vision One. The server stuff is still separate, but it is the same now. When we purchased it, they told us we'd have a single console, but that took about two and a half years. Finally, there is a single pane of glass.
One of the things that made me the craziest was that we had too many tools or one tool that I had to log into five different ways. One of the frustrations is you have both legacy and newer detection methods. Not being able to fully investigate it in a single portal was a huge pain.
What needs improvement?
They need to stop changing Vision One once a week. They're in a hurry to change things so badly and so fast that I can't find where stuff is half the time, which is a challenge sometimes.
I've given one piece of feedback to their product guys. One thing that they're trying to make is a SIEM. It's a product where you input all the logs from your tools, and it creates additional insights into how things look. They've been kind of playing the "me too" game on that, even though that's not what I bought the product for.
They have a new gateway where I can take my firewall of email logs and send it over there. In theory, it's supposed to do a more comprehensive evaluation of all my stuff to improve that risk index score. I'm not impressed with it, and I've told them as much. I feel if you're good at something, you should keep working on that and not try to be all the things to all the people.
I bought a different email solution even though it would have been 10 times easier to just stay with their email solution because they aren't great at it. They are great at other things, but they're playing the "me too" game with some of their products. Their competitors do this, so they should be doing this, too. They need to pick a product and keep being good at that. If they're going to roll new things out, they should do it but do it right.
They have a button to isolate an endpoint because it looks bad, but it doesn't usually work. I've had no chance to argue with the product guys to show them examples of how their button doesn't work. You think it does, but it doesn't work in a real environment. That can be a challenge sometimes.
I can see in the data showing what is a false positive. But it doesn't save me time helping them figure out how to fix the problem in their engine. It can help me identify it as a false positive, but it doesn't apply that consistently. It will ignore the false positive for that device, but if they start detecting a false positive on Apple devices, I have eight thousand Apple devices and get 8,000 alerts. I can tell that specific false positive, but it doesn't learn from that particularly well.
We use the executive dashboards, but I don't find them particularly useful. One is the ability to customize. That has gotten a little better, and it'll be better in the future. Most of what they have on there are data points that are generic and not particularly actionable. That's why it's called an executive dashboard. Executives want to see if we are secure, but it's hard for me to find out why our attack surface risk went down by x percentage. I don't know. It says that on the dashboard, but it doesn't give me specific details about why.
I find it confuses my executives, and it's not useful for me because it doesn't give me things to work on. It will give me generic things on the executive dashboard like you have a thousand accounts with an old password. Those are big generic things, but I also can't tell it that our password policy is different from what your automatic detection model means, and I don't have a problem with that, so quit lowering my risk score.
The risk score is useless. In theory, it's based on the random intelligence they're getting from their various customers. I'm in K-12 education, so they have a decent amount of K-12 customers, but it's a subset, and the baseline of what's common in K-12 education is not the same. There's not enough data to make that particularly clean or useful. Vision One is not custom, and that's part of my beef. That index score is based on whatever random report they're looking at from their data sources at any given moment in time. It's nice, but I'd rather have one that's based on your particular circumstances. Instead, it's saying that the number one attack threat surface for school districts is email phishing. It's too generic.
Buyer's Guide
TrendAI Vision One
May 2026
Learn what your peers think about TrendAI Vision One. Get advice and tips from experienced pros sharing their opinions. Updated: May 2026.
900,125 professionals have used our research since 2012.
For how long have I used the solution?
I have used Trend Vision One for three and a half years.
What do I think about the stability of the solution?
Vision One has been less impactful toward my endpoints when scanning than the previous solution.
What do I think about the scalability of the solution?
Vision One's resource usage is starting to creep up compared to three years ago. They used to focus on making their agent lightweight. I don't necessarily think all of this is their fault, but their agents are starting to suck more resources than they used to. Part of it is that the threat landscape has changed, and you need to look at it in additional ways, and it is a strain on the servers. They've gotten really bad about that on the servers.
How are customer service and support?
I rate Trend Micro support three out of 10. Their technical support is challenging. The support's good once you get to the second layer, but they don't read what you write. They auto-respond by telling us to give them the logs.
Every time, I need to send them a written statement with my product license ID and that I'm the contact authorized to do a support ticket. About 75 percent of the time when I open a support ticket, I immediately email my customer service satisfaction manager person with the ticket number so they can help move it along.
Which solution did I use previously and why did I switch?
I was using Sophos three years ago. I've looked at many of the feature sets out there, and they might be 80 percent of what Vision One has, and some might be better, but Vision One is price-competitive.
How was the initial setup?
Deploying Vision One was a pain because of the automated removal tool. In the antivirus world, they try to make it difficult to uninstall people's defenses because that's what an attacker would do. However, all the competitors are making tools to uninstall their competitors' tools when they win business. That's directly counterintuitive to the whole point of the antivirus.
We went through a process of trying to do this in an automated fashion to replace the old product, and Trend didn't quite do it right. Trend had a real struggle toget their own tool to fix it.
We use it as a SaaS, so we have a gateway integrator on the server on-site, but the product sits on all my endpoints. In that aspect, it's on-prem, but all the processing, reporting, and everything else happens in the cloud. We had it 75 percent deployed in 45 days. That last 25 percent took us another four months.
I work at an underfunded public school district. I need a whole team, but there is only me. I used to have a security analyst until that position moved around, and
my ability to use the product has been drastically reduced. I miss much of the value of what I'm paying for because I don't have enough staff to use it. I wouldn't need more than one if that was their whole job.
It's not a totally elegant solution that always feeds and cares for itself. We have to check if it's doing its updates properly. It doesn't tell us, for example, that 2,000 devices haven't been updated or checked in. I have to go proactively looking at it.
What's my experience with pricing, setup cost, and licensing?
Vision One's pricing is extremely competitive. They're probably the lowest-cost provider that has this feature set.
What other advice do I have?
I rate Vision One seven out of 10. Make sure you learn the 90 percent of stuff in there that you didn't know you bought and preestablish an escalation contact for support tickets.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Head of I T at Conquest Group
Transforms cybersecurity landscape with efficient and comprehensive protection
Pros and Cons
- "One of the best decisions we made was choosing Trend Vision One; it has transformed our entire security and cybersecurity landscape, providing a one-stop solution to manage everything efficiently and effectively."
- "The only disappointing aspect is that every time new features are adopted, additional credits are required, which could push the budget over. This practice should really be reconsidered by Trend."
What is our primary use case?
I use Trend Vision One for Total XDR and endpoint protection as an all-in-one security solution.
How has it helped my organization?
One of the best decisions we made was choosing Trend Vision One. It has transformed our entire security and cybersecurity landscape, providing a one-stop solution to manage everything efficiently and effectively.
What is most valuable?
One of the most valuable features is Cyber Risk Exposure Management.
What needs improvement?
There is room for improvement in leveraging AI technology to protect against emerging AI-based threats.
For how long have I used the solution?
I have been using the solution for two years.
Which solution did I use previously and why did I switch?
We previously used an outdated and inefficient Trend Micro system, which caused high security risks.
What's my experience with pricing, setup cost, and licensing?
This is not a competitive price — the costs are on the higher side. However, I don’t regret it, as it can help save significantly in other areas. The only disappointing aspect is that every time new features are adopted, additional credits are required, which could push the budget over. This practice should really be reconsidered by Trend.
Which other solutions did I evaluate?
I also evaluated CrowdStrike as an alternate solution.
What other advice do I have?
Trend Vision One is a five-star product.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Oct 5, 2025
Flag as inappropriateBuyer's Guide
TrendAI Vision One
May 2026
Learn what your peers think about TrendAI Vision One. Get advice and tips from experienced pros sharing their opinions. Updated: May 2026.
900,125 professionals have used our research since 2012.
Senior Technical Engineer at Safezone Secure Solutions Private Limited
Manages cyber risk across endpoints and email while simplifying detection and response workflows
Pros and Cons
- "ROI is absolutely achievable, especially with TrendAI Vision One and server TrendAI Vision One platform."
- "Compared to other vendors like SentinelOne or CrowdStrike, all of them are providing detection and response methodology. However, TrendAI Vision One provides more visibility but has limitations on the response part."
What is our primary use case?
I work with Trellix, Trend Micro, Fortinet, and Netrix for DLP solutions. For Netrix DLP, I use Forcepoint, and for email security, I use Barracuda.
I have been working with Trend Micro for the past six years. I started with Apex One and Worry-Free, which evolved to TrendAI Vision One. TrendAI Vision One is a collaborative XDR platform designed to bring all security solutions such as mail security, cloud security, endpoint security, and identity security together and manage them from a single console. That is the main goal of TrendAI Vision One.
From my end, I have deployed email security, endpoint security, XDR, and web security from TrendAI Vision One. We are using TrendAI Vision One with both business essentials and pro bundle.
TrendAI Vision One has two kinds of solutions for endpoint security: standard endpoint protection for desktop machines and server and workload protection for existing Linux servers, Windows servers, or even containers and workloads in the cloud where you can install agents for those containers as well. These are the deployments which we have done for endpoint security.
What is most valuable?
The detection part works well for me. The response part, including automatic containment, requires creating playbooks. Even though I create them, I have faced many threat attack scenarios where detection pops up, but the appropriate response action is not being taken.
Attack discovery and attack surface discovery are valuable features. Every organization has endpoints, and no organization will be willing to do a full discovery or testing on all those endpoints or devices. Attack discovery helps us know which endpoints we have with Trend Micro, what vulnerabilities and loopholes are available in the endpoints, and provides insights into our attack surface.
I have used the cyber risk exposure management product completely except for security awareness. I have used data security posture, identity security posture, and network security functionalities. I have not ensured cloud security yet, but we are yet to have hands-on experience with that. I have showcased these functionalities to customers and conducted many POCs for new clients covering cyber risk exposure management, XDR, email security, endpoint security, and network security. I have explained how well TrendAI Vision One captures the correct data.
The response time after detection is approximately three hours.
What needs improvement?
Visibility is good, but TrendAI Vision One can improve the response part. Compared to other vendors like SentinelOne or CrowdStrike, all of them are providing detection and response methodology. However, TrendAI Vision One provides more visibility but has limitations on the response part.
If TrendAI Vision One can improve the response time and playbooks, particularly with more customizable playbooks, it would be greatly helpful. We have raised feature requests to Trend Micro. If they have more predefined playbooks and more options for response management, it would be beneficial because that is what end users are expecting.
As a reseller, we are dealing with the pain because customers are asking why response is not being taken even though TrendAI Vision One detects suspicious files. In some cases, I follow best practices by updating playbooks at regular intervals, but that is a manual process. An automated process to take appropriate action for suspicious and malicious files would be necessary. The response part might be improved to provide better value.
For how long have I used the solution?
I have been working with Trend Micro for the past six years.
What do I think about the stability of the solution?
TrendAI Vision One is stable. Before TrendAI Vision One, Trend Micro had Apex One and Worry-Free products for endpoint security that were not stable. However, after TrendAI Vision One was introduced, I do not see any stability issues.
What do I think about the scalability of the solution?
Scalability is good. Previously, it was good because they were using a credit system where they would give credits and based on the credits we could allocate our own licenses. Right now they have removed this feature, so we are yet to do some testing on that. The credit system was effective because we had flexible licensing and scalability, and we were able to use the resources when and if it was necessary.
How are customer service and support?
Two factors are important: the time to give the first response and the technical ability of the engineers. I heard that they have laid off many old employees and senior employees.
The integration part is good. They also have an AI platform built into the console which provides more details in layman's terms. When explaining an attack to management, you can communicate it to a CIO in technical terms because they are from a technical background and will understand all the details. However, when taking this to a CEO or CFO who are not technical persons with backgrounds based on industry, you should explain it in simple terms. The AI integration with TrendAI Vision One gives the details in a much simpler way in layman's understanding. That feature is good.
How would you rate customer service and support?
Neutral
How was the initial setup?
The installation is easy. Even for Linux and Mac machines, it is just two or three commands.
What was our ROI?
ROI is absolutely achievable, especially with TrendAI Vision One and server TrendAI Vision One platform. Previously, they had MSVA, which was a virtual appliance that on-premises clients needed for mail security. After they came up with the cloud email security solution, many customers are feeling relief, and the latency is much better when compared to an on-premise solution.
For ROI in email security, they provide BEC, which is the best ROI for every customer. If there is an outage that occurs in Microsoft or AWS or any other cloud platform, there is an email continuity platform for emails. That is good ROI.
From a deployment perspective, it shows around fifty to sixty percent. The impact given to the business in terms of real impact is up to ten to twenty percent.
What's my experience with pricing, setup cost, and licensing?
This is quite affordable. It is not that expensive.
Which other solutions did I evaluate?
We buy from Trend Micro. TrendAI Vision One definitely falls in the leader quadrant in Gartner, and its capabilities are good. It can be in that leader quadrant. For an endpoint security solution, managing attacks is the key thing. It is not about daily activities like what policies and functionalities are provided. These matter, but at the end of the day, if an attack is going to happen, the end user will assess the support of TrendAI Vision One and the response part of TrendAI Vision One. These two parameters are going to be assessed, and based on these two parameters, any quadrant achievement from labs like Gartner or Forrester will be based on these two parameters only.
What other advice do I have?
For standard endpoint protection, if it is a detection, it is a detection. When compared to CrowdStrike, TrendAI Vision One creates much less false positives. There is no big noise on this, but that is one way to consider it. False positives do come, and it is completely based on the configuration which we do. On the initial phase of the deployment, after a month or two, we keep it in detection mode, and after that, we pursue the prevention mode so that blocking is enabled.
If the containment functionality gets automated, it would be on a better note. The response part, if improved, will be very helpful. From a deployment perspective, it shows around fifty to sixty percent.
TrendAI Vision One is fully on the cloud with no on-premise option. They tie up with multiple cloud vendors, but they provide a SaaS platform built by Trend Micro. Trend Micro itself is hosted on some AWS servers, which is what I have heard, but I do not want to comment on that.
I would rate this review an eight.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Last updated: Nov 24, 2025
Flag as inappropriateDeputy General Manager at Tata Communications Ltd
AI-driven visibility empowers risk management with faster detection
Pros and Cons
- "The most important features of Vision One include visibility, AI integration, attack pattern analysis, predictive analytics, and centralized visibility and management across protection layers."
- "There should be improvements in risk quantification, where the risk is displayed in a quantified manner, showing the dollar value loss."
What is our primary use case?
As a security architect, I design solutions for our end customers. In previous projects, we've successfully implemented Trend Vision One for customers with cloud-based assets and email servers, enabling them to extend security coverage to their remote clients.
The current market trend in email security solutions focuses on mitigating threats like phishing attacks. These widespread attacks occur across various points in the cyber kill chain process. Whether initiated from the perimeter or targeting cloud-based assets, monitoring all north-south and east-west traffic is challenging. Trend Vision One helps by providing a comprehensive analysis of these email phishing attacks, identifying the attack origin, parameters, and information extracted from attack patterns.
How has it helped my organization?
Trend Vision One offers centralized visibility and management across all protection layers. This comprehensive view provides valuable information for CISO/CIO presentations, including attack patterns, threat actors, and areas for predictive analysis. Such insights are crucial for informing policy changes and other security enhancements. The visibility also helps with efficiency.
We can summarize any technical information we receive using widgets and then present it to executives in a dashboard format.
Our customers adapt the risk index feature to align with the specific needs and conditions of their individual environments.
We have used Trend Vision One in several projects where our customers consolidated security across hybrid environments. The consolidation effort, particularly utilizing Vision One's AI-driven features, streamlined investigative analytics. Furthermore, merging multiple solutions into Vision One provided comprehensive insights, which proved invaluable for policy development.
The ability to manage risk and maintain visibility has improved by approximately 20 to 30 percent, significantly simplifying our tasks. Operationally, this has led to a 20 percent reduction in effort.
Trend Vision One has helped reduce detection and response times by 30 and 40 percent, respectively.
Trend Vision One has saved more than a week's worth of effort in investigating false positives.
Trend Vision One's automation capabilities have helped us save between 60 and 100 hours monthly.
What is most valuable?
The most important features of Vision One include visibility, AI integration, attack pattern analysis, predictive analytics, and centralized visibility and management across protection layers. These features are very important to us.
What needs improvement?
There should be improvements in risk quantification, where the risk is displayed in a quantified manner, showing the dollar value loss. The integration with third-party OEM solutions also needs enhancement, particularly in UEBA integration with Trend. Sometimes, there are blind spot discoveries that are not completely successful. Improving automation to avoid manual triaging and providing more insights on dashboards is desirable.
While Trend Vision One's attack surface risk management helped identify some vulnerabilities in our environment, the feature needs improvement. Specifically, the blind spot discovery is unreliable; for example, a missed blind spot in one environment led to an attack and subsequent investigation.
Automation should be improved to eliminate the need for manual effort in initial L1 triaging. Additionally, dashboards should provide more insightful analysis, including various mappings to the MITRE ATT&CK framework and Tactics, Techniques, and Procedures.
For how long have I used the solution?
I have been working with Vision One for almost almost two years.
How are customer service and support?
The support in Trend Micro is good.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I have worked on Exchange servers, and we are using Palo Alto to a certain extent. These were not from the XDR or EDR point of view.
What was our ROI?
The analysis shows that Trend Vision One has improved our ROI by 30 percent.
What's my experience with pricing, setup cost, and licensing?
Competitors offer comparable solutions at slightly lower prices, so Vision One has room to reduce its pricing by 15 percent, given that Trend Vision One charges approximately $10 per endpoint.
Which other solutions did I evaluate?
We evaluated other options but not to the same extent as Trend Micro because I was more familiar with Trend Micro solutions.
What other advice do I have?
I would rate Trend Vision One nine out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Platform Engineer Ii at a outsourcing company with 5,001-10,000 employees
Platform has improved ransomware detection and now supports faster automated incident response
Pros and Cons
- "TrendAI Vision One solves these problems by providing greater detection capabilities and automated response across all of these layers."
- "TrendAI Vision One could bring in more data loss prevention capabilities specifically on the endpoints, as the current offering lacks some important capabilities."
What is our primary use case?
TrendAI Vision One is our centralized platform for managing multiple security products, specifically on endpoint and workload security.
We have integrated TrendAI Vision One with Microsoft and AWS cloud accounts that we use. Our SOC team monitors TrendAI Vision One and the platform provides them with multiple views of data sets and detections that have occurred, helping them to quickly onboard with all the relevant data they should be aware of.
We are using TrendAI Vision One sensors across endpoint and workload security.
What is most valuable?
We were facing multiple cybersecurity incidents in our endpoint and workload security, including attacks such as ransomware and malware. TrendAI Vision One solves these problems by providing greater detection capabilities and automated response across all of these layers.
TrendAI Vision One helps with integration and correlation of multiple security solutions and provides us with better dashboard and reporting capabilities to showcase the data to our board.
We are seeing fewer threats and events across these security layers since we invested in TrendAI Vision One. The platform has been particularly useful in protecting against ransomware.
We are able to respond faster and quicker compared to earlier because of the automated response that TrendAI Vision One offers, which reduces our dependency on manual effort that was previously required.
What needs improvement?
TrendAI Vision One could bring in more data loss prevention capabilities specifically on the endpoints, as the current offering lacks some important capabilities.
They could also bring in data loss prevention capability and integrate with patch management solutions, which is overdue.
For how long have I used the solution?
We have been using TrendAI Vision One for the past three and a half years.
What other advice do I have?
It is extremely important to protect sensitive and critical data that resides on servers.
I would say TrendAI Vision One is a really good platform overall, and we found it fitting into our budget compared to competitive solutions. I would rate this product highly.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Dec 31, 2025
Flag as inappropriateSoc Analyst at Payatu
Centralized management enhances threat response with automation and comprehensive insights
Pros and Cons
- "The workbench alerts provide valuable insights into attack chains and relevant information, while Observer techniques give a comprehensive overview of ongoing activities."
- "Trend Vision One requires several enhancements for optimal performance."
What is our primary use case?
As a cybersecurity analyst at a managed security service provider, I use Trend Vision One for two of my clients. My primary use cases involve standard XDR functions, such as anomaly monitoring, alert analysis, and incident response. To streamline these processes, I've configured automated response playbooks within Trend Vision One. The insights provided by the platform, mainly through the Workbench and Observe Auto module, are invaluable for understanding my clients' environments and identifying vulnerabilities that need to be addressed.
I work with clients across various industries, including education and power. My education client utilizes Trend Vision One for specific security needs, while my power industry client, an electricity board, has a comprehensive Trend Micro solution in place, including Vision One, Apex One, and Deep Security Manager. With Vision One, I've successfully detected and addressed numerous web attacks, malware attacks, and unauthorized access attempts on production servers in the education sector. For the power client, the solution has effectively detected and blocked multiple ransomware attacks. These are common occurrences and demonstrate the value of Trend Micro's security solutions.
We use Trend Vision One on all endpoints in two scenarios. For one client with on-premises servers and endpoints, we use Trend Vision One as a comprehensive solution. For another client in the education sector, we use Trend Micro Deep Security Management alongside the Vision One XDR platform on their cloud-based Linux servers.
How has it helped my organization?
Trend Vision One provides centralized visibility and management across all protection layers. This is crucial for efficiently sharing data with management, both internally and client-side. The platform avoids technical jargon, offering executive summary dashboards and summarized incident reports that clearly communicate security status. This allows for concise and effective communication with non-technical stakeholders, assuring them of their security posture. Trend Vision One's automated dashboards streamline reporting, eliminating the need for extensive manual documentation, which is especially valuable for technical users.
I use executive dashboards to build on threat detection, check for vulnerabilities, and create appropriate responses for individuals or groups of endpoints.
We use the risk index to assess and enroll our risk score. We maintain a low-risk index, which helps both management and me understand our score in relation to global risk factors.
Although I inherited Vision One as a service provider from another team, I eventually began utilizing its full potential and reaping its benefits.
Trend Vision One offers a phishing simulation feature in its cyber risk assessment. I frequently use this tool with my clients to evaluate employee email awareness. It generates comprehensive reports and provides functionalities for easy management.
Attack surface risk management helps identify vulnerabilities and high-risk threats in an environment, but it may also generate some false positives.
Trend Vision One significantly reduces MTTD and MTTR by approximately 50 percent. Its automated playbooks enable an immediate response to detected threats, providing near-instantaneous protection. While manual analysis and reporting of critical errors typically take an analyst up to 15 minutes, Trend Vision One's configured playbooks can automatically complete the same task within two minutes.
I have configured some playbooks to take automated actions on Trend Vision One while detecting some specific alerts or while detecting some specific playbook alerts.
What is most valuable?
Trend Vision One offers several features that I appreciate. The workbench alerts provide valuable insights into attack chains and relevant information, while Observer techniques give a comprehensive overview of ongoing activities. The platform's automated playbooks streamline incident response, significantly reducing MTTD and MTTR. Additionally, the ability to integrate with various firewalls and data sources, including Trend Micro's suspicious object management, centralizes threat management and simplifies daily security operations and incident response tasks.
What needs improvement?
Trend Vision One requires several enhancements for optimal performance. The platform should allow users to create custom phishing templates directly within the console and improve logging capabilities to facilitate seamless integration with SIEM solutions. Additionally, it should provide a mechanism for configuring Office 365 Advanced Threat Protection alerts to be displayed within the Workbench for streamlined threat management.
For how long have I used the solution?
I have been using Trend Vision One for about a year and a half.
What do I think about the stability of the solution?
Trend Vision One is a stable platform with no significant issues like lagging or crashing.
What do I think about the scalability of the solution?
Trend Vision One is easy to scale up by adding new agents, although the credit system for feature usage is confusing and could be simplified.
Which solution did I use previously and why did I switch?
I have experience with solutions like Sophos Central XDR and Wazuh, and while they have their strengths, I find Trend Vision One to be a competitive option with a comprehensive range of capabilities.
What other advice do I have?
I would rate Trend Vision One nine out of ten.
The on-premises Trend Micro solutions may require updates.
After deploying Trend Vision One on pilot devices, I recommend exploring the entire portal to familiarize yourself with its features and capabilities.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company has a business relationship with this vendor other than being a customer. MSP
Systems Analyst at a manufacturing company with 201-500 employees
Provides full visibility and helps reduce our detection and remediation times
Pros and Cons
- "The most significant recent change has been the addition of the new AI companion."
- "The only downside to Trend Vision One is its complexity."
What is our primary use case?
We use Trend Vision One for the XDR and we absolutely love it, especially the full visibility into protected assets. It's incredibly easy to identify weaknesses across systems and manage any outdated software or areas needing attention directly within the user interface. Previously, we juggled multiple dashboards, but the new version has streamlined everything into a single, unified dashboard. This has significantly simplified our workflow and improved manageability. In essence, we can now manage multiple products seamlessly within the same Vision dashboard, which is a considerable improvement over the previous system. This year has brought significant and positive changes to our workflow.
We use XDR across Office 365 in the cloud and on-premises environments to safeguard our assets. This includes protecting our server environment, workstations, and Virtual Desktop Infrastructure, ensuring comprehensive endpoint security.
Our deployment utilizes a hybrid model, making agent deployment incredibly simple. We employ several different deployment methods: on-premise deployment through Active Directory and utilizing various tools. In case a system leaves the network for any reason, we have third-party solutions in place. We have multiple RMM solutions that can be rapidly deployed in these packages. For example, I've recently observed systems being spun up and sent home before antivirus protection was activated. We still have the opportunity to deploy these solutions in the cloud automatically. So, we have a few ways to work around this and deploy those agents, making it easy to deploy either on-premise or in the cloud. We can address several scenarios and push out to those endpoints.
How has it helped my organization?
Coverage is extremely important. We want to ensure visibility into all assets across the network, whether it's a workstation within the office or someone working remotely. This visibility is crucial even when they're outside the network or using cloud-based software, especially since we have no on-premise infrastructure. With the rise of remote work, having this extra visibility into devices, whether at home or abroad, is invaluable. We appreciate the ability to see what's happening on any asset, regardless of its location. This allows us to monitor running processes, identify vulnerabilities, and push necessary updates, ensuring we maintain connectivity and security no matter where devices are operating.
Trend Vision One offers us comprehensive visibility within a single dashboard, which is crucial since we manage numerous other products and security solutions with various dashboards. The simplicity and centralized visibility provided by Trend Vision One significantly streamline our operations. Managing a multitude of security products across our environment necessitates consolidated visibility to minimize back-and-forth navigation. Having all the necessary information in one place is essential for us.
We use executive dashboards to generate weekly or monthly reports that provide a risk score index. This index helps us identify areas needing attention and understand the teams' focus. We then share this information with IT senior management. In addition to our reporting, we receive a monthly report that allows us to compare our current status to the previous month's and highlight new challenges, team weaknesses, and ongoing efforts. This comprehensive view enables the executive team to monitor the team's continuous progress.
We utilize the risk index feature to monitor and mitigate potential environmental risks. One example of this is how we proactively worked to reduce the risk index score of a recently acquired company. Their antivirus product was expiring, so we opted to purchase additional licenses for our existing Trend Apex One product suite instead of renewing it. However, this integration significantly increased the risk index score due to numerous previously unmanaged devices on their network. To address this, we systematically worked through the risk index list, identifying outdated software and determining if it was still in use or could be safely removed. By leveraging the risk index in this way, we successfully lowered the score and ensured the secure integration of the newly acquired company into our environment.
It took some time to fine-tune Trend Vision One before realizing its benefits. A significant concern was integrating it into our virtual environment, a complex process. However, we gained significant visibility once set up in our VDI, leading to further adjustments. We fine-tuned the environment, removing unnecessary elements, which is especially crucial for our non-persistent VDI, where VMs reset if anything goes down. Through these tweaks, performance improved, and the extra visibility provided by Vision One highlighted areas needing attention, allowing us to optimize the environment gradually.
We use Trend Vision One within Azure, expanding its monitoring capabilities to both on-premises and cloud assets, including Active Directory, which is synchronized from our on-premises environment. This hybrid setup covers assets locally and in the cloud, including Office 365, and Trend Vision One effectively manages security across this environment. It has simplified the process, particularly for virtual environments, providing enhanced visibility and flexibility compared to previous products. The additional visibility has been invaluable, enabling us to address previously undetected vulnerabilities and mitigate risks.
During XDR and managed services pen testing exercises, we identified some weaknesses. They were able to automatically crack some accounts. As soon as one system was breached, the managed services team contacted us, escalating until they got a response. We could see their process in action - their steps and what they did in the backend. We provided them with details about the events and the ongoing pen test. It was an excellent test to see that the managed services worked as intended. There was a breach; they asked if we were aware and stated they would isolate the device if we weren't. We acknowledged we knew about the ongoing pen test. Throughout these exercises, they reached out immediately, demonstrating their focus on alerts, their process for triaging them, and their communication with clients.
The attack surface is directly related to exposure and risk. Any identified vulnerabilities, such as outdated software like older versions of Office or Google Chrome products, are flagged immediately. We use third-party solutions to address these issues across all workstations. Whenever we detect internal or internet-facing exposure, we prioritize remediation based on criticality. External-facing vulnerabilities are patched first, as they pose a greater risk than those affecting only internal assets. We rely heavily on exposure risk and risk index to determine priority and ensure the most critical vulnerabilities are addressed first. This helps us identify blind spots in our environment. Take the new acquisition as an example; many devices were unprotected and lacked crucial Windows updates. Numerous products and workstations required immediate attention. Security wasn't the initial priority, so we addressed that and ensured it became one. We implemented numerous changes with acquisitions to align them with our security standards.
Trend Vision One has significantly reduced our mean time to detect and respond to threats by 60 percent. It centralizes all information, enabling us to identify and address vulnerabilities quickly. For example, if we discover multiple devices running an outdated version of Office 2013 missing patches, we can easily compile a list of those devices and share it with the responsible team for remediation. This visibility allows us to proactively address weaknesses across the network, such as deploying updates or the latest release of third-party software to mitigate risks. Trend Vision One has been instrumental in enhancing our overall security posture.
The managed services significantly reduced the time we spent investigating false positive alerts. In uncertain scenarios, we consult the managed services team. If unsure about anything, we use the AI companion for questions. If we encounter an unfamiliar flag or event, we research it independently and involve the managed services team's professionals for deeper investigation.
We have implemented some automation but haven't fully explored its capabilities. We have a few playbooks for tasks like blocking user access based on IP addresses or email content. Since we use Office 365 in the cloud, there's also a lot of automation for handling incoming emails, such as blocking and sending alerts. While we've used playbooks to a limited extent, there's potential for further automation, and we plan to explore this further.
What is most valuable?
The most significant recent change has been the addition of the new AI companion. This feature has proven invaluable, especially when integrating with third-party products or resetting the dashboard, as it provides detailed step-by-step guidance. In fact, we were able to resolve all issues independently, without needing to contact support, thanks to the AI companion's comprehensive answers.
What needs improvement?
The only downside to Trend Vision One is its complexity. It's a comprehensive product covering a lot of ground, which can be a little intimidating initially. The user interface, in particular, can take some time to get used to, with menus that could be better organized and a dashboard that could be more user-friendly. Due to the sheer complexity of the product, navigating and familiarizing oneself with the environment requires some effort. While the initial learning curve might be steep, the product's vast capabilities justify the time investment.
For how long have I used the solution?
I have been using Trend Vision One for two and a half years.
What do I think about the stability of the solution?
I would rate the stability of Trend Vision One nine out of ten. I haven't experienced any crashes or issues in the last few years since we started using the product. While there are occasional upgrades and minor changes that require adjustments, the overall stability is excellent. We have no complaints, especially considering the VDI environment, our primary focus, has been running seamlessly. The lightweight agent minimizes resource usage, further contributing to smooth performance.
What do I think about the scalability of the solution?
I would rate the scalability of Trend Vision One nine out of ten. We successfully scaled it up by adding approximately 250 workstations and deployed the product within a week. We replaced their previous product, scripted everything, integrated it into their on-premise servers, and deployed the agents. The 250 additional assets were integrated within two or three days, providing complete visibility in the dashboard. The team then took over and identified any weaknesses. In summary, scaling up and adding 250 workstations was easy to implement.
How are customer service and support?
The technical support and service are excellent. After our new acquisition, we encountered a few issues that we hadn't seen in our environment compared to theirs. Through troubleshooting, we determined that the problems weren't caused by the product itself but rather by corruption in specific systems. We systematically worked through the other products, disabling them one by one. The troubleshooting experience was excellent, and we reached a resolution within a couple of days of contacting support. They were very professional and provided direct answers, resulting in the issues being resolved correctly and in a timely manner.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
In the past, we have used a few different products, including Sophos and Cylance, which we have used for the past couple of years. We also used Trend's older products, like OfficeScan, about eight or nine years ago. We eventually moved away from those products due to their lack of AI capabilities. After trying other products, we returned to Trend with Apex One and Vision One. We've been happy with the product, and its virtual environment capabilities were a major factor for us. Trend has consistently been the best performing product for us, so we decided to continue using their products with Trend Vision One.
How was the initial setup?
The initial deployment was straightforward. We leveraged our existing products to force and uninstall the previous product, opting for a custom scripting approach rather than standard GPOs or internal solutions. This allowed us to uninstall the old package and ensure the new installation was reflected in the dashboard, streamlining the process and enabling us to proceed seamlessly to the next phase. Overall, the deployment was straightforward from our perspective.
We deployed Trend Vision One during COVID, which took approximately one and a half weeks because the server side required additional fine-tuning for all the exclusions.
What about the implementation team?
We implemented the solution in-house. We repeatedly reached out to obtain basic information and guidelines on the VDI component and the virtual environment, specifically regarding steps for managing the virtual environment when closing a gold image and imaging numerous workstations with a single image. Due to the complexities involved, we requested documentation. However, our internal team completed the entire deployment with limited support from their support team, following the provided instructions.
What's my experience with pricing, setup cost, and licensing?
The pricing is fair compared to other solutions. It's within the price range we're looking at for a single endpoint, and fair pricing is important to us.
What other advice do I have?
I would rate Trend Vision One nine out of ten.
The Trend Vision team handles all maintenance on the SaaS backend. Internally, we only need to update the VDI environment occasionally because it's a non-persistent VDI, meaning it's locked down and reverts to its previous state upon reboot. We periodically open the gold images to perform maintenance, update signatures, and force program upgrades, but this is only a monthly task. So, we spend minimal time managing the solution.
Before implementing Trend Vision One, ensure you gather comprehensive documentation. Adhering to the guidelines will streamline setup, and any queries can be resolved using the efficient AI companion. Users can pose questions or access documentation directly from the Trend website. Initially, focus on familiarizing yourself with the dashboard, risk indexing, and the executive dashboard. Explore the product, ask questions, and continue experimenting and seeking assistance once deployed. The process is straightforward once you've had the opportunity to explore the system thoroughly. The primary challenge is becoming comfortable with the interface and navigating its features effectively.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
System Engineer at a computer software company with 5,001-10,000 employees
Ransomware playbooks have strengthened protection and improve threat detection and response
Pros and Cons
- "TrendAI Vision One has positively impacted my organization by specifically helping improve security posture and response time for threat handling, as well as improving our cyber risk score."
- "The area where I think TrendAI Vision One can improve is the technical support."
What is our primary use case?
My main use case for TrendAI Vision One is for ransomware protection, user behavior analysis, and protection. I use TrendAI Vision One for threat detection and response, which helps me with investigation and response. It helps to integrate with the existing infrastructure as my main use case for TrendAI Vision One. Data loss prevention has been a valuable use case with the endpoint security as a feature that stands out to me. The top security challenges in my industry include improving the cyber risk posture and ransomware protection, and TrendAI Vision One is helping me address them, especially for ransomware protection.
What is most valuable?
I find threat detection and response and remediation using playbooks the most useful features TrendAI Vision One offers me.
In a case of a ransomware incident, the playbook in TrendAI Vision One immediately contained the infection by isolating the endpoint, demonstrating how those playbooks and the detection and response features help me in my day-to-day work.
TrendAI Vision One has positively impacted my organization by specifically helping improve security posture and response time for threat handling, as well as improving our cyber risk score.
TrendAI Vision One has made managing security easier for me compared to earlier by providing centralized visibility and management across protection layers.
What needs improvement?
The area where I think TrendAI Vision One can improve is the technical support. TrendAI Vision One should speed up the response time for the support tickets that have been opened regarding needed improvements.
For how long have I used the solution?
I have been using TrendAI Vision One for almost one year now.
What other advice do I have?
TrendAI Vision One should speed up the response time for the support tickets that have been opened regarding needed improvements. I rate TrendAI Vision One a nine out of ten because TrendAI Vision One can improve the technical support. I am using TrendAI Vision One sensors on the endpoint, as well as on the endpoint and workloads. Covering the endpoint is very critical for my organization's network because the endpoint is one of the most important areas to be protected. TrendAI Vision One has helped reduce my time to detect and respond to threats; in my previous studies, I found the detection and response has come down from weeks to only days. My overall review rating for TrendAI Vision One is nine.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Dec 17, 2025
Flag as inappropriateBuyer's Guide
Download our free TrendAI Vision One Report and get advice and tips from experienced pros
sharing their opinions.
Updated: May 2026
Product Categories
Endpoint Detection and Response (EDR) Network Detection and Response (NDR) Extended Detection and Response (XDR) Attack Surface Management (ASM) AI-Powered Cybersecurity Platforms AI SecurityPopular Comparisons
CrowdStrike Falcon
Cortex XDR by Palo Alto Networks
Microsoft Defender for Endpoint
SentinelOne Singularity Endpoint
Darktrace
IBM Security QRadar
Microsoft Sentinel
Elastic Security
Huntress Managed EDR
Trellix Endpoint Security Platform
WatchGuard Firebox
Microsoft Defender XDR
TrendAI Vision One – Cloud Security
Buyer's Guide
Download our free TrendAI Vision One Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What is the biggest difference between EPP and EDR products?
- What is the difference between EDR and traditional antivirus?
- What is your recommendation for a 5-star EDR with low resource consumption for a financial services company?
- Which is the best EDR for a logistics company with 500-1000 employees?
- What is the best EDR or XDR product for a company with 9000 employees?
- What to choose: an endpoint antivirus, an EDR solution or both?
- Do we need to use both EDR and Antivirus (AV) solutions for better protection of IT assets?
- How does EternalBlue work?
- What are the best on-premise Endpoint Security solutions for a Tech Services company with 10,000 employees?
- Which is better for Endpoint Security: EDR or XDR solutions?

















