My main use case for TrendAI Vision One is for ransomware protection, user behavior analysis, and protection. I use TrendAI Vision One for threat detection and response, which helps me with investigation and response. It helps to integrate with the existing infrastructure as my main use case for TrendAI Vision One. Data loss prevention has been a valuable use case with the endpoint security as a feature that stands out to me. The top security challenges in my industry include improving the cyber risk posture and ransomware protection, and TrendAI Vision One is helping me address them, especially for ransomware protection.
System Engineer at a computer software company with 5,001-10,000 employees
Ransomware playbooks have strengthened protection and improve threat detection and response
Pros and Cons
- "TrendAI Vision One has positively impacted my organization by specifically helping improve security posture and response time for threat handling, as well as improving our cyber risk score."
- "The area where I think TrendAI Vision One can improve is the technical support."
What is our primary use case?
What is most valuable?
I find threat detection and response and remediation using playbooks the most useful features TrendAI Vision One offers me.
In a case of a ransomware incident, the playbook in TrendAI Vision One immediately contained the infection by isolating the endpoint, demonstrating how those playbooks and the detection and response features help me in my day-to-day work.
TrendAI Vision One has positively impacted my organization by specifically helping improve security posture and response time for threat handling, as well as improving our cyber risk score.
TrendAI Vision One has made managing security easier for me compared to earlier by providing centralized visibility and management across protection layers.
What needs improvement?
The area where I think TrendAI Vision One can improve is the technical support. TrendAI Vision One should speed up the response time for the support tickets that have been opened regarding needed improvements.
For how long have I used the solution?
I have been using TrendAI Vision One for almost one year now.
Buyer's Guide
TrendAI Vision One
July 2026
Learn what your peers think about TrendAI Vision One. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
908,344 professionals have used our research since 2012.
What other advice do I have?
TrendAI Vision One should speed up the response time for the support tickets that have been opened regarding needed improvements. I rate TrendAI Vision One a nine out of ten because TrendAI Vision One can improve the technical support. I am using TrendAI Vision One sensors on the endpoint, as well as on the endpoint and workloads. Covering the endpoint is very critical for my organization's network because the endpoint is one of the most important areas to be protected. TrendAI Vision One has helped reduce my time to detect and respond to threats; in my previous studies, I found the detection and response has come down from weeks to only days. My overall review rating for TrendAI Vision One is nine.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Dec 17, 2025
Flag as inappropriateData Protection Officer at eComm
Centralized visibility enhances security posture with robust features
Pros and Cons
- "The Trend hunting feature is beneficial, providing the opportunity to investigate and see what's happening, using frameworks such as MITRE ATT&CK to analyze logs."
- "Trend Vision One provides centralized visibility and management across protection layers, which is crucial for compliance."
- "An easier way to understand the credit structure would be helpful."
What is our primary use case?
Our infrastructure utilizes Trend Vision One for endpoint and cloud-based security. While all our endpoints are cloud-based, allowing us to deploy Trend Vision One in the cloud, we also maintain endpoint-specific protection. Currently, our network infrastructure is not fully integrated with Trend Vision One. The platform primarily monitors our backend infrastructure and provides initial response capabilities.
I implemented Trend Vision One to consolidate log inspection, integrity monitoring, intrusion prevention, and application control into a single platform, eliminating the need to switch between multiple applications.
How has it helped my organization?
Trend Vision One provides centralized visibility and management across protection layers, which is crucial for compliance. It allows us to show audits of what’s going on and keep all evidence in one place. This centralized visibility has improved our efficiency, as it means just one login is needed to complete all necessary tasks, maintaining focus and reducing distractions resulting from multiple sources.
The Vision One executive dashboards effectively communicate our company's overall security posture by providing a clear risk overview. Executives appreciate the simple visual cues, with green indicating low risk and yellow signaling high risk, allowing for quick and easy understanding of our current security status.
I immediately recognized the benefits of Trend Vision One because, unlike our other security applications, it provides comprehensive visibility.
I utilize Vision One's risk index feature to assess our organization's risk level and benchmark it against our peers. This comprehensive evaluation allows us to understand our current risk profile, identify areas for mitigation, and determine acceptable risk thresholds. The risk index feature is essential to our business operations.
Attack surface risk management helped us identify blind spots in our environment and provided detailed remediation strategies. This works as a second pair of eyes that helps look for vulnerabilities, which in turn improves our security posture.
Trend Vision One improves our detection and response times by identifying vulnerabilities and summarizing mitigation strategies.
Trend Vision One helps reduce the amount of time we spend investigating false positive alerts by 80 percent.
What is most valuable?
I love Trend Vision One for its robustness, allowing us to deep dive into a lot of information. The Trend hunting feature is beneficial, providing the opportunity to investigate and see what's happening, using frameworks such as MITRE ATT&CK to analyze logs. Its risk index feature allows us to see risk status quickly and provides valuable insights into our security posture.
What needs improvement?
The only issue I have with Trend Vision One is the credit structure, which is confusing. An easier way to understand the credit structure would be helpful.
For how long have I used the solution?
I have been using Trend Vision One for over five years.
What do I think about the stability of the solution?
Trend Vision One is stable and does not crash. In my experience, it has not shown any instability issues.
What do I think about the scalability of the solution?
Trend Vision One is scalable. We can increase or decrease according to needs, although pricing changes when scaling.
How are customer service and support?
Trend Micro's support response time can be slow. The quality of assistance varies depending on the issue. However, reaching qualified technical engineers can be challenging due to lengthy escalation processes.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
I've used many alternatives before, like Avast, SonicWall, and Mimecast. These alternatives don't have all the integrated features of Trend Vision One, particularly the server and workload capabilities.
How was the initial setup?
The initial setup required deep diving and using resources such as help centers. Despite not being straightforward, it was manageable.
The deployment took three days.
What about the implementation team?
I implemented Trend Vision One in-house with the support of team members, using resources like software guides and videos.
What's my experience with pricing, setup cost, and licensing?
Trend Vision One is an expensive product.
What other advice do I have?
I would rate Trend Vision One eight out of ten.
The most significant security challenge we face is zero-day attacks, which exploit vulnerabilities unknown to us. While Trend Vision One provides some protection, it cannot catch all zero-day threats, leaving us potentially exposed. This inherent vulnerability in our security poses the greatest risk.
Trend Micro handles most maintenance, but we are responsible for installing agent patches on our servers.
New users should understand that Trend Vision One is different from other solutions they might have used. Reading and fact-finding are crucial. They must ask the right questions.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
TrendAI Vision One
July 2026
Learn what your peers think about TrendAI Vision One. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
908,344 professionals have used our research since 2012.
Co-founder & CTO, Director (Special Advisory Services) at ORNA Inc.
Consolidated security operations enhance threat management
Pros and Cons
- "Trend Vision One's most valuable feature is its centralized console, which provides comprehensive security features, including attack surface risk management."
- "Overall, I rate Trend Vision One a ten out of ten as I am extremely happy with Trend Micro's capabilities and their platform's strength."
- "Expanding compatibility to include currently unsupported security tools, such as firewalls, would be beneficial."
- "To improve support, the company should streamline communication and reduce response times."
What is our primary use case?
We primarily use Trend Vision One for its XDR capabilities, email security features, and MDR services offered through ServiceOne. Leveraging these Trend Vision One products allows us to provide robust security solutions to our customers.
My customers range from small non-profits with 40 endpoints to large enterprises with over 2,000 endpoints across diverse sectors, including energy, manufacturing, finance, and software.
How has it helped my organization?
Vision One possesses machine learning predictive capabilities that have already proven effective. In the past week alone, it detected and blocked two scans for unknown threats. This capability is crucial, especially since our predominantly Canadian customer base faces an elevated risk of cyberattacks from China due to the recent government-level ban on TikTok. Consequently, we anticipate an increase in attacks. Trend Vision One boasts the largest zero-day initiative, renowned for its proficiency in detecting such threats.
The single console in Vision One streamlines cross-layer detection, threat hunting, and investigation, incorporating sandbox analysis and log search capabilities. It allows for endpoint isolation, remote shell establishment, and integration with tools like Active Directory and Microsoft Entra ID. Automated playbooks enable actions such as endpoint isolation, custom script execution, forensic investigations, user lockouts, and password resets, all of which are customizable. This automation is crucial for containing threats outside of working hours, as playbooks can be configured to automatically execute actions based on specific criteria, mitigating damage before staff return.
The single console provides comprehensive visibility across the entire IT security environment, including endpoints, cloud activity, workflow protection, email protection, and mobile device management, all within a single, unified platform.
Trend Vision One integrates with a range of security products, including various SIEM solutions, vulnerability management tools, and select firewalls. A comprehensive list of compatible products is available on Trend Micro's website.
Trend Vision One is relatively easy to learn for those with some security background. While first-time users may find it initially confusing, abundant learning resources such as YouTube videos and comprehensive documentation are available to help users quickly familiarize themselves with the platform.
Some of my customers maintain hybrid environments, and Trend Vision One enhances visibility by consolidating all systems into a single platform.
Trend Vision One has malware scanning capabilities, allowing it to detect, quarantine, and block malware effectively.
Trend's Managed Detection and Response service provides continuous 24/7 monitoring, effectively reducing staff workloads by eliminating the need for in-house security monitoring.
Trend Vision One improves my organization's visibility by consolidating security functions into a single console. These capabilities enhance our security operations, making it easier to manage threats.
What is most valuable?
Trend Vision One's most valuable feature is its centralized console, which provides comprehensive security features, including attack surface risk management. This allows for benchmarking our risk score against similar organizations based on size, industry, and location. Additionally, it offers endpoint vulnerability assessment, user behavior analytics, and standard XDR detection capabilities.
What needs improvement?
An area for improvement is integrating more tools with Trend Micro's SIEM. Expanding compatibility to include currently unsupported security tools, such as firewalls, would be beneficial.
For how long have I used the solution?
I have been using Trend Vision One for approximately four months.
What do I think about the scalability of the solution?
Trend Vision One is scalable.
How are customer service and support?
To improve support, the company should streamline communication and reduce response times. Specifically, support tickets often require customers to provide redundant information, creating unnecessary extra steps in the process.
How would you rate customer service and support?
Positive
What other advice do I have?
Overall, I rate Trend Vision One a ten out of ten as I am extremely happy with Trend Micro's capabilities and their platform's strength.
Trend Vision One is easy to maintain.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Sr. Manager (Technology) at Contessabd
Improved firewall management and centralized visibility
Pros and Cons
- "Trend Vision One's most valuable feature is its endpoint firewall rules."
- "Integration with other tools and deploying in hybrid environments need improvement."
What is our primary use case?
The primary use of Trend Vision One is for its Endpoint Detection and Response and Extended Detection and Response solutions.
To address challenges with our attack surface management, we implemented Trend Vision One.
What is most valuable?
Trend Vision One's most valuable feature is its endpoint firewall rules.
The centralized visibility and management have been very important to us, as it allows for an effective EDR or XDR solution with central management. Without such solutions, I cannot imagine dealing with problems efficiently. The executive dashboards are used for main reporting and central management, improving readability.
Trend Vision One's attack surface management capabilities are a critical feature that we utilize.
What needs improvement?
Integration with other tools and deploying in hybrid environments need improvement. The deployment can be complex, and we'd like an easier process, especially when integrating with on-prem and cloud environments.
The high number of false positives in Trend Vision One presents a challenge. Reducing these requires extensive exclusion and allow lists, which are difficult to manage effectively.
For how long have I used the solution?
I have been using Trend Micro Vision One for one year.
What do I think about the scalability of the solution?
Trend Vision One is scalable.
How are customer service and support?
The technical support is not good. We have to purchase support separately and the engineers are not readily available.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
We previously used Sophos and Microsoft Defender. For hybrid, we switched to Microsoft Defender due to easier integration with on-prem and cloud. I would recommend Trend Micro for Linux and mixed environments.
How was the initial setup?
The standard deployment of Trend Vision One was straightforward and took approximately 24 hours to complete with two people involved.
What's my experience with pricing, setup cost, and licensing?
Trend Vision One offers a competitive price-to-value ratio.
Which other solutions did I evaluate?
We evaluated Microsoft Defender and Sophos before switching. Microsoft offers more options for attack surface reduction rules compared to Trend Vision One.
What other advice do I have?
I would rate Trend Vision One eight out of ten.
We have 400 users of Trend Vision One in our organization.
Two administrators are required to manage Vision One.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Deputy General Manager at Tata Communications Ltd
AI-driven visibility empowers risk management with faster detection
Pros and Cons
- "The most important features of Vision One include visibility, AI integration, attack pattern analysis, predictive analytics, and centralized visibility and management across protection layers."
- "There should be improvements in risk quantification, where the risk is displayed in a quantified manner, showing the dollar value loss."
What is our primary use case?
As a security architect, I design solutions for our end customers. In previous projects, we've successfully implemented Trend Vision One for customers with cloud-based assets and email servers, enabling them to extend security coverage to their remote clients.
The current market trend in email security solutions focuses on mitigating threats like phishing attacks. These widespread attacks occur across various points in the cyber kill chain process. Whether initiated from the perimeter or targeting cloud-based assets, monitoring all north-south and east-west traffic is challenging. Trend Vision One helps by providing a comprehensive analysis of these email phishing attacks, identifying the attack origin, parameters, and information extracted from attack patterns.
How has it helped my organization?
Trend Vision One offers centralized visibility and management across all protection layers. This comprehensive view provides valuable information for CISO/CIO presentations, including attack patterns, threat actors, and areas for predictive analysis. Such insights are crucial for informing policy changes and other security enhancements. The visibility also helps with efficiency.
We can summarize any technical information we receive using widgets and then present it to executives in a dashboard format.
Our customers adapt the risk index feature to align with the specific needs and conditions of their individual environments.
We have used Trend Vision One in several projects where our customers consolidated security across hybrid environments. The consolidation effort, particularly utilizing Vision One's AI-driven features, streamlined investigative analytics. Furthermore, merging multiple solutions into Vision One provided comprehensive insights, which proved invaluable for policy development.
The ability to manage risk and maintain visibility has improved by approximately 20 to 30 percent, significantly simplifying our tasks. Operationally, this has led to a 20 percent reduction in effort.
Trend Vision One has helped reduce detection and response times by 30 and 40 percent, respectively.
Trend Vision One has saved more than a week's worth of effort in investigating false positives.
Trend Vision One's automation capabilities have helped us save between 60 and 100 hours monthly.
What is most valuable?
The most important features of Vision One include visibility, AI integration, attack pattern analysis, predictive analytics, and centralized visibility and management across protection layers. These features are very important to us.
What needs improvement?
There should be improvements in risk quantification, where the risk is displayed in a quantified manner, showing the dollar value loss. The integration with third-party OEM solutions also needs enhancement, particularly in UEBA integration with Trend. Sometimes, there are blind spot discoveries that are not completely successful. Improving automation to avoid manual triaging and providing more insights on dashboards is desirable.
While Trend Vision One's attack surface risk management helped identify some vulnerabilities in our environment, the feature needs improvement. Specifically, the blind spot discovery is unreliable; for example, a missed blind spot in one environment led to an attack and subsequent investigation.
Automation should be improved to eliminate the need for manual effort in initial L1 triaging. Additionally, dashboards should provide more insightful analysis, including various mappings to the MITRE ATT&CK framework and Tactics, Techniques, and Procedures.
For how long have I used the solution?
I have been working with Vision One for almost almost two years.
How are customer service and support?
The support in Trend Micro is good.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I have worked on Exchange servers, and we are using Palo Alto to a certain extent. These were not from the XDR or EDR point of view.
What was our ROI?
The analysis shows that Trend Vision One has improved our ROI by 30 percent.
What's my experience with pricing, setup cost, and licensing?
Competitors offer comparable solutions at slightly lower prices, so Vision One has room to reduce its pricing by 15 percent, given that Trend Vision One charges approximately $10 per endpoint.
Which other solutions did I evaluate?
We evaluated other options but not to the same extent as Trend Micro because I was more familiar with Trend Micro solutions.
What other advice do I have?
I would rate Trend Vision One nine out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Cloud Cyber Security Tech Lead at Vodafone
Enables efficient threat detection and investigation through seamless cross-border capabilities
Pros and Cons
- "Trend Vision One's greatest assets are its cloud-based platform and credit-based purchasing system, which eliminate the need for traditional licensing and procurement processes, enabling quick product acquisition within one or two days."
- "One area that requires improvement is the installation process of the agents, as it is not seamless."
What is our primary use case?
Vision One access supports multiple modules, including endpoint protection, the XDR module, and the Cloud One module, which are the ones that particularly caught our interest.
We have been doing a proof of concept for Trend Vision One to assess its capabilities as a cybersecurity solution. Vodafone is partnering with Trend Micro to offer security services and products to our customers to secure their environments, similar to a SaaS solution. We are exploring it as a partnership opportunity to provide enhanced security solutions to our customers.
How has it helped my organization?
We conducted a POC and tested multiple use cases by downloading malicious files and observing their behavior. Trend Vision One successfully detected and blocked all threats, including malicious files, scripts, and even dormant scripts that later became active. All these threats were stopped at the endpoint level, demonstrating that Trend Vision One effectively defends against malware, ransomware, and malicious scripts.
Trend Vision One incorporates a machine learning agent designed to defend against advanced threats, such as zero-day attacks. This agent monitors endpoints for malicious activity and, if detected, automatically quarantines the affected machine to conduct further analysis.
It employs machine learning to quarantine devices during ransomware attacks, however, this functionality has not yet been tested.
Trend Vision One provides a single console with a unified dashboard that consolidates information from our entire environment.
The single console provides end-to-end visibility into our IT security environment. We tested the endpoint security, and the SDR performed exceptionally well, providing a clear topology and metrics of our environment. This allows us to monitor the status of each node within our network.
The Trend Vision One platform was integrated with a Linux-based Service Engine to facilitate integration with third-party IT security solutions.
Learning to use Trend Vision One was straightforward, thanks to the helpful courses available on their portal and the excellent support provided during product introduction.
Administering Vision One endpoint security is easy through the single console.
We successfully tested Trend Vision One in a hybrid environment, with components deployed both on-premises and in the cloud.
Trend Vision One offers virtual patching to protect against vulnerabilities while vendors develop permanent patches. This is crucial because vendor patches can be delayed, leaving systems exposed. Virtual patching provides immediate protection, acting as a temporary shield until the official fix is released.
Since we are still in the testing phase, we have not yet seen a reduction in viruses or malware. However, we anticipate potential improvements in security operations across hybrid environments if implemented fully.
What is most valuable?
Trend Vision One's greatest assets are its cloud-based platform and credit-based purchasing system, which eliminate the need for traditional licensing and procurement processes, enabling quick product acquisition within one or two days. Trend Micro's strong reputation and excellent threat intelligence further enhance the platform's value. The analytics are also good, particularly the XDR and cloud assessment tools, which correlate logs and information to consolidate alerts for the SOC team.
What needs improvement?
One area that requires improvement is the installation process of the agents, as it is not seamless. The installation sometimes requires multiple troubleshooting steps and is not straightforward.
For how long have I used the solution?
We have been conducting the POC of Trend Vision One for approximately three to four months.
What do I think about the stability of the solution?
There were no major issues with stability, no bugs, glitches, or errors, except for the challenges faced with agent installation. I rate the stability of Trend Vision One eight out of ten.
What do I think about the scalability of the solution?
I rate the scalability of Trend Vision One ten out of ten.
How are customer service and support?
We did not engage with customer support during the POC phase, so we cannot provide feedback on that aspect at this time.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
For endpoint protection, we have used Microsoft Defender and Cortex XDR. We encountered issues with those solutions, but Trend Vision One seemed to address these concerns effectively.
How was the initial setup?
The initial setup was not complex. The prerequisites were set first, allowing integration to be completed in about a week.
What's my experience with pricing, setup cost, and licensing?
The pricing is mid-range, neither cheap nor overly expensive. The cost is considered fairly priced.
What other advice do I have?
I would rate Trend Vision One nine out of ten.
Our team from our organization includes three members involved in the POC testing.
I recommend Trend Vision One to other users based on our experience during the POC phase.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Head of ICT at Sumac Microfinance Bank Ltd
A unified platform for simplified operations and automation
Pros and Cons
- "From an automation point of view, I find the ability to curate and deploy playbooks very helpful. I find that very convenient for us."
- "There should be a bit more dynamism when it comes to their playbooks in terms of the action triggers. That is the only thing that I would want to see a bit more."
What is our primary use case?
Its main purpose is orchestration where I have full visibility into all the different Trend Micro products I use, and it is all centralized in a single dashboard. There is ease of use with this centralized dashboard. With this centralized management, I can dive into technicalities, and I am able to do all my workbench investigations. It is quite clear, and I do not have to sift through different logs. It makes our work so easy when we need to respond to or remediate a particular issue.
The main problem that we wanted to solve by implementing Trend Vision One was the blindspots. We tend to focus on endpoints, but we forget IoT devices such as printers and CCTV cameras. This is where we had serious blind spots simply because these devices do not have an operating system. For us, it was just about eliminating these blind spots. That was our number one focus.
How has it helped my organization?
It has been exceptional. If you look at the evolution of the Trend Micro products up until Vision One, you can see that they do what they say they do. It has worked for me so well. That is why I have had it all these years.
We have protection against zero-day threats. One of the things that pushed me towards Trend Micro was the fact that they have the R&D for the zero-day initiative. They are a pioneer in terms of classifying CVEs. It gives me comfort. When you go and check the workbench or the report, you can see the type of exploits that it was able to detect, which have even been classified as CVEs.
Apart from the things that I do in IT, my responsibility is to protect my company's assets. I am able to safeguard my data against ransomware. The company does not have to worry that they can be held at ransom. The assurance that they do not have to pay just to get their data back makes it easy to sleep at night.
We have a single console for cross-layer detection, threat hunting, and investigation. We have what we call the executive dashboard. This is what I share with the C-suite. It is quite easy for me to break down cybersecurity in a business way, and then, of course, we have the operational dashboard and the security dashboard where I centralize all the products into one single pane. From an orchestration point of view, I love Trend Vision One. We are able to orchestrate all of our different products from one single dashboard.
Trend Vision One provides visibility into different products. I have a 360-degree view of my entire IT infrastructure, which helps me understand my threat landscape and the way it looks. The beauty of it is that it has metrics. I can see how I am performing as compared to 30 days or 7 days ago in terms of the risk indicator. Is it going up or is it going down? This is important for me because I am able to forecast and anticipate behaviors or patterns from the people perspective and the process perspective. I know what I need to do and train people on, and in terms of processes, I know what I need to do to clean up my policies. In terms of technology, I can assess if there is any other thing of Trend Micro that I need to supplement to make sure I am fully protected.
Our response is instantaneous. I do not have an exact percentile in mind when it comes to the reduction in the response time, but our response is instantaneous.
I have integrated it with my NUC, my firewall, and my database monitoring tool. Trend Micro has a feature for virtual patching through Trend Micro TippingPoint. It instantaneously does the patching and cascades them across. Apart from what we call scheduled patching, on-demand patching is a part of their product features.
Trend Vision One is very easy to learn. This is the second organization where I am using this Trend Micro solution. When I introduced it, my team did not know about Trend Vision One, but within a month, simply with the help of the business portal where we have the e-learning, they were fully skilled and even certified at the entry-level of Trend Micro. Their feedback was that it was quite easy for them to adopt.
Trend Vision One is not at all difficult to administer.
We have seen a reduction in viruses and malware since implementing this solution. They provide you with the metrics for risk posture. You can see the reduction in your threat landscape. It goes granular to the point of telling you which type of malware or threat you are exposed to and the reduction. It is very definitive from a percentile marking. In my previous organization, we saw about a 75% reduction when we rolled it out. We were previously using something else there.
It reduces administrative overhead. I stopped adding additional headcounts from a security analyst and a security officer's point of view. It helps me reduce the overhead. On average, considering the annual wage of a security analyst, there is a reduction of about 7,000 dollars per annum.
I use Trend Micro's managed XDR services in conjunction with Vision One Endpoint Security. It reduces overhead. It is a fully-fledged managed service, so I do not need to have the business invest in an in-house SOC. It is a whole lot cheaper.
What is most valuable?
From an automation point of view, I find the ability to curate and deploy playbooks very helpful. I find that very convenient for us. It gives away the manual process. There is the ease of use.
I love what they have done with their Trend Companion AI, where it becomes so easy to have it do something for you instead of sifting through different tabs. So, the automation element and their new AI feature are top-notch for me.
I find the virtual patching that they offer superb.
What needs improvement?
There should be a bit more dynamism when it comes to their playbooks in terms of the action triggers. That is the only thing that I would want to see a bit more. There should be a bit more dynamism, especially when you are creating your own playbook. This is something I have also discussed with Trend Micro.
For how long have I used the solution?
I have been using Trend Vision One since 2020 when it was rolled out. I have been using Trend Micro products since 2015.
What do I think about the stability of the solution?
It is stable. I would rate it a ten out of ten for stability.
What do I think about the scalability of the solution?
It is scalable. I would rate it a ten out of ten for scalability.
How are customer service and support?
I would rate their support a ten out of ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I have used a plethora of other solutions. I moved to Trend Vision One for multiple reasons:
- The ability to do what the solution says it does
- The ability to orchestrate all different solutions into one single pane
- The ability to have automation when it comes to detecting and responding to threats
How was the initial setup?
It is deployed on the cloud. For me, the deployment was easy. For the endpoints, we just did a GPO push through Active Directory. For the cloud, we used just simple tenancy APIs and we were good to go.
It took us a week simply by virtue of how big the organization was.
In the IT team, there are 10 people working with this solution. We also have other departments such as risk and audit that use it. Overall, there are about 20 people directly working with it. The remaining are users for whom it just works silently in the background.
The maintenance is not done in-house. It is handled 100% by the OEM. They do share notifications, but we as users do not feel it, so whatever maintenance is required is handled 100% by the OEM. That is the beauty of a cloud service. You are not overly bothered by it.
What was our ROI?
In my previous company, over the four years, I believe we had seen about 81% ROI.
There are cost reductions because of the simple fact that I have automation. It means that I do not need to spend a whole lot on headcount for security analysts. From a commercial point of view, it has helped me reduce my operational costs, and then there are also security cost reductions because of the fact that it is automated and it responds in real time.
What's my experience with pricing, setup cost, and licensing?
When I compare it to its peers that can do the same, it is cost-effective.
What other advice do I have?
The evolution has been great. When I started using Trend Micro Vision One, the product feature was what they used to call business worry-free. It has evolved from an EDR to a fully-fledged XDR. You can see that the R&D is putting in work, and there is evolution. In terms of product coverage, they do not look at only endpoint protection. Right now, we have bespoke server protection. We have cloud asset protection and email security. You can see the growth of Trend Micro when it comes to its cybersecurity offering.
Based on my experience, I would recommend this solution. The ease of use, elimination of overhead, and return on investment are the reasons why you should have this solution.
I would rate Trend Vision One a ten out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Engineering leader at a tech services company with 11-50 employees
Gives detailed maps and correlated information at one place
Pros and Cons
- "I find the maps particularly helpful. The object list, specifically the suspicious object list, is also quite valuable. You can simply add one object to that list to manage it from another solution."
- "Trend Vision One has helped reduce our time to detect and respond to threats by 30% to 40%."
- "I believe that the interface could be more user-friendly. At times, it is challenging to locate certain features, and they need to reorganize the user interfaces."
- "I would rate their customer support a five out of ten. They sometimes do not give enough attention to the tickets."
What is our primary use case?
We use it for analytics. We check all the maps and communications when there is an incident or an issue. It is very helpful for analytics.
How has it helped my organization?
Trend Vision gives a lot of visibility. If you have a big environment, you can use it to see logs or events. It gives more visibility into what is going on in your infrastructure.
Last year, we experienced an attack attempt, and it gave us a lot of visibility. We were able to track the source and all the processes that were involved during the attack. For security, it is very good.
Trend Vision One has helped reduce our time to detect and respond to threats by 30% to 40%.
What is most valuable?
I find the maps particularly helpful. The object list, specifically the suspicious object list, is also quite valuable. You can simply add one object to that list to manage it from another solution.
It gives comprehensive visibility. It is very good. It gives a lot of visibility into all layers such as layer three or layer seven. It helps with monitoring the endpoints, including all the desktops and processes or communication between servers.
What needs improvement?
I believe that the interface could be more user-friendly. At times, it is challenging to locate certain features, and they need to reorganize the user interfaces.
For how long have I used the solution?
I have been using the solution for one year.
How are customer service and support?
I would rate their customer support a five out of ten. They sometimes do not give enough attention to the tickets. Even when I update a ticket or a case, they ask the same questions that I have already answered. I explain my problem, and they respond as if not paying enough attention.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
Previously, we used another solution. We observed that Trend is trying to move all the solutions to Vision One. That is why we decided to transition, and it is working very well.
It gives more visibility. The other solution was focused only on the server or endpoint protection. It did not provide any tracks, just the basics. With Vision One, we can see all the information correlated in one place, which I find very helpful.
How was the initial setup?
The initial setup is very easy. It is not very complicated. Sometimes, the documentation is not updated, but the processes are very intuitive, so it is not that hard.
In terms of the implementation strategy, we first focus on non-critical servers or appliances, and then we move on to critical ones.
It is being used in an enterprise environment at a data center.
What about the implementation team?
The implementation may require two people, depending on the infrastructure and scale. You might need an engineer or an administrator.
For maintenance, there are two people. One person scans and reviews all the information and the other one is from the backup. It requires minimal maintenance.
What was our ROI?
Overall, the visibility and security that it provides are our returns on the investments.
What's my experience with pricing, setup cost, and licensing?
I feel that Vision One is a bit expensive. As for the pricing or licensing, I would rate it a seven out of ten.
What other advice do I have?
I would rate Vision One an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Associate Manager - Information Security at a tech vendor with 10,001+ employees
Reliable threat intelligence with customizable reporting improvements
Pros and Cons
- "Its threat intelligence sources enable it to automatically block domains known for command-and-control callbacks, effectively preventing attacks from those sources."
- "The reports lack detail and customization options, particularly for XDR, which hinders our ability to provide tailored reports to clients."
What is our primary use case?
We use Vision One XDR to provide managed security services to our clients by correlating logs from various Trend Micro products like Apex One, Cloud One, and Deep Security. Vision One acts as a central monitoring platform, providing a single pane of glass view of our clients' security posture. This simplifies monitoring and allows us to easily create playbooks and analyze alerts. While our EDR solutions, Apex One, Cloud One, and Deep Security provide robust security features like anti-malware, web reputation, and intrusion prevention, Vision One enhances this by correlating logs and leveraging threat intelligence to identify incidents missed by these individual products. Essentially, Vision One functions like a level three SOC analyst, providing an additional layer of protection and ensuring comprehensive security coverage.
How has it helped my organization?
Trend Vision One's centralized visibility and management are crucial for our managed security services because they reduce the overhead required for monitoring. As an XDR solution, it performs many of the tasks an analyst would typically handle, streamlining our workflow and allowing us to focus on in-depth analysis when needed. This reduction in workload is a significant benefit, enabling us to efficiently provide comprehensive security services to our clients.
The executive dashboard is a valuable tool for analyzing the threat level of specific assets, particularly for generating end-of-month reports that detail threat and alert volumes, and highlight high-security risks. This comprehensive analysis helps customers understand their security posture and take appropriate action to strengthen their defenses. However, it's important to note that the dashboard's usefulness may vary depending on the individual customer's needs and priorities.
The risk index is a useful tool that provides benefits, but its value depends on the specific needs of the customer. Some customers may utilize the risk index to identify assets with high-security risks, allowing them to address vulnerabilities and implement necessary patching. However, other customers may rely on alternative sources for vulnerability visibility and, therefore, may not prioritize the risk index. While not always a primary focus, the risk index remains a valuable resource.
Trend Vision One provides immediate benefits upon deployment. Its built-in XDR, which includes EDR functionality and integrates with existing security models like Apex One, Cloud One, or Workload Security, allows for seamless provisioning of endpoints and workloads. Rigorous testing confirms that Vision One effectively identifies and correlates alerts, including those missed by other EDR solutions. This enhanced detection capability is evident during post-deployment testing, as Vision One Workbench alerts are generated immediately.
We use Trend Vision One to consolidate security across hybrid environments.
We use attack surface risk management and often customize it in our reports to meet client needs. This service helps identify vulnerabilities and blind spots in their environments. For instance, we assisted a customer experiencing recurring attacks due to unknown vulnerabilities. Our attack surface management analysis provided the data to identify and patch these critical vulnerabilities, ultimately enhancing their security posture.
Vision One XDR significantly reduces threat detection and response time by automating the analysis typically done by a level two or three analyst. It provides a comprehensive view of the environment, incorporating behavioral analysis and intelligence sources to quickly identify unusual activity. This eliminates the need for manual investigation of logs and data, allowing analysts to focus on addressing actual threats. The XDR's automated workbench triggers alerts with a high degree of accuracy, minimizing false positives and further streamlining the security process.
We use security playbooks for certain low-level security alerts because many of these alerts, despite the large volume of data they represent, do not require significant time or attention. Playbooks are particularly useful in these situations as they automate the process of blocking the source or IP address associated with the alert.
What is most valuable?
Vision One offers several features I value.
The threat intelligence sources enable it to automatically block domains known for command-and-control callbacks, effectively preventing attacks from those sources.
Additionally, the security playbooks provide templates to block URLs or scripts, enhancing endpoint protection.
Finally, the console allows for remote connection to endpoints, enabling direct investigation and remediation within the customer's environment. This flexibility and comprehensive functionality make Vision One a valuable tool.
What needs improvement?
Trend Micro is making many improvements, including addressing some of our feature requests. However, their reporting functionality needs improvement. The reports lack detail and customization options, particularly for XDR, which hinders our ability to provide tailored reports to clients. For example, we cannot generate reports on threat intelligence data from XDR, making it difficult to assess the protection received from external sources. This limitation also prevents clients from seeing the total value of XDR, including external factors contributing to their security posture. Threat intelligence is crucial, and clients want to understand its impact. Therefore, enhancing report customization, especially for XDR, would be a significant improvement.
For how long have I used the solution?
I have been using Trend Vision One XDR for one and a half years.
What do I think about the stability of the solution?
Lagging does happen in Trend Vision One but it is infrequent and does not significantly disrupt operations. This is typical for many SaaS platforms and not a major issue.
What do I think about the scalability of the solution?
Trend Vision One is scalable, allowing for flexibility from four licenses to a hundred or more, depending on how much or how fast scaling is needed.
How are customer service and support?
The experience with customer service can vary depending on the case. Simple issues might involve referring to KB articles for resolution, while more complex issues might need backend support, which can take time. Overall, my experience has been positive.
How would you rate customer service and support?
Neutral
How was the initial setup?
Trend Vision One is easy to set up and can potentially be handled by one person. However, teamwork is preferred to ensure accuracy, catch potential errors, and maintain a high standard of service.
What's my experience with pricing, setup cost, and licensing?
Trend Micro's licensing is outsourced to third-party vendors, resulting in price variations depending on the vendor. Since Trend Micro doesn't directly handle pricing, I cannot provide specific cost details.
What other advice do I have?
Trend Vision One XDR is an excellent security product that deserves a ten out of ten rating. It's surprising that more companies haven't adopted XDR, given its advantages over traditional SIEM solutions. XDR automates tasks like configuration, signature creation, and rule implementation, significantly reducing the manual workload required with SIEM. While I expect a shift towards XDR, many companies still rely on SIEM, which seems inefficient in comparison.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. MSP
Systems and Security Manager at a educational organization with 5,001-10,000 employees
It improves the detection speed, but it could be more customizable
Pros and Cons
- "When we purchased Vision One, what set it apart was that it wasn't a traditional signature-based antivirus. It's a process-aware solution that provides real-time protection. That was a big differentiator three years ago, but now it's a given that every AV provider should be doing that. It combines signature-based telemetry with behavioral awareness and a detection-based solution, making it a good solution for us."
- "They need to stop changing Vision One once a week. They're in a hurry to change things so badly and so fast that I can't find where stuff is half the time, which is a challenge sometimes."
What is our primary use case?
Vision One is the primary endpoint security product we use to protect our Macs and PCs. We also use the server product version, so it runs on my servers as well. We exclusively purchase Trend Micro's endpoint products. They have network and firewall products. We were using their email product until last month, and I ended up selecting a different provider. We stayed with them for the endpoint, but I moved off of them for the email product.
How has it helped my organization?
Vision One was a big deal to us immediately because we did not have context-aware before. We saw everything we had no idea was happening. It was a big deal three years ago.
It certainly reduces time to detect because a lot of the time, I didn't have it before. I didn't have that information until it gave it to me. The speed of response helps me know much more about what's happening quicker. They have some improvement to do in terms of automated remediation. It probably makes investigations 30 percent faster because of what it puts together.
What is most valuable?
When we purchased Vision One, what set it apart was that it wasn't a traditional signature-based antivirus. It's a process-aware solution that provides real-time protection. That was a big differentiator three years ago, but now it's a given that every AV provider should be doing that. It combines signature-based telemetry with behavioral awareness and a detection-based solution, making it a good solution for us.
When we bought it three years ago, it was separate. Apex One handled cloud and web app security, and Vision One handled cloud and server workload protection. Now, they call it Vision One. The server stuff is still separate, but it is the same now. When we purchased it, they told us we'd have a single console, but that took about two and a half years. Finally, there is a single pane of glass.
One of the things that made me the craziest was that we had too many tools or one tool that I had to log into five different ways. One of the frustrations is you have both legacy and newer detection methods. Not being able to fully investigate it in a single portal was a huge pain.
What needs improvement?
They need to stop changing Vision One once a week. They're in a hurry to change things so badly and so fast that I can't find where stuff is half the time, which is a challenge sometimes.
I've given one piece of feedback to their product guys. One thing that they're trying to make is a SIEM. It's a product where you input all the logs from your tools, and it creates additional insights into how things look. They've been kind of playing the "me too" game on that, even though that's not what I bought the product for.
They have a new gateway where I can take my firewall of email logs and send it over there. In theory, it's supposed to do a more comprehensive evaluation of all my stuff to improve that risk index score. I'm not impressed with it, and I've told them as much. I feel if you're good at something, you should keep working on that and not try to be all the things to all the people.
I bought a different email solution even though it would have been 10 times easier to just stay with their email solution because they aren't great at it. They are great at other things, but they're playing the "me too" game with some of their products. Their competitors do this, so they should be doing this, too. They need to pick a product and keep being good at that. If they're going to roll new things out, they should do it but do it right.
They have a button to isolate an endpoint because it looks bad, but it doesn't usually work. I've had no chance to argue with the product guys to show them examples of how their button doesn't work. You think it does, but it doesn't work in a real environment. That can be a challenge sometimes.
I can see in the data showing what is a false positive. But it doesn't save me time helping them figure out how to fix the problem in their engine. It can help me identify it as a false positive, but it doesn't apply that consistently. It will ignore the false positive for that device, but if they start detecting a false positive on Apple devices, I have eight thousand Apple devices and get 8,000 alerts. I can tell that specific false positive, but it doesn't learn from that particularly well.
We use the executive dashboards, but I don't find them particularly useful. One is the ability to customize. That has gotten a little better, and it'll be better in the future. Most of what they have on there are data points that are generic and not particularly actionable. That's why it's called an executive dashboard. Executives want to see if we are secure, but it's hard for me to find out why our attack surface risk went down by x percentage. I don't know. It says that on the dashboard, but it doesn't give me specific details about why.
I find it confuses my executives, and it's not useful for me because it doesn't give me things to work on. It will give me generic things on the executive dashboard like you have a thousand accounts with an old password. Those are big generic things, but I also can't tell it that our password policy is different from what your automatic detection model means, and I don't have a problem with that, so quit lowering my risk score.
The risk score is useless. In theory, it's based on the random intelligence they're getting from their various customers. I'm in K-12 education, so they have a decent amount of K-12 customers, but it's a subset, and the baseline of what's common in K-12 education is not the same. There's not enough data to make that particularly clean or useful. Vision One is not custom, and that's part of my beef. That index score is based on whatever random report they're looking at from their data sources at any given moment in time. It's nice, but I'd rather have one that's based on your particular circumstances. Instead, it's saying that the number one attack threat surface for school districts is email phishing. It's too generic.
For how long have I used the solution?
I have used Trend Vision One for three and a half years.
What do I think about the stability of the solution?
Vision One has been less impactful toward my endpoints when scanning than the previous solution.
What do I think about the scalability of the solution?
Vision One's resource usage is starting to creep up compared to three years ago. They used to focus on making their agent lightweight. I don't necessarily think all of this is their fault, but their agents are starting to suck more resources than they used to. Part of it is that the threat landscape has changed, and you need to look at it in additional ways, and it is a strain on the servers. They've gotten really bad about that on the servers.
How are customer service and support?
I rate Trend Micro support three out of 10. Their technical support is challenging. The support's good once you get to the second layer, but they don't read what you write. They auto-respond by telling us to give them the logs.
Every time, I need to send them a written statement with my product license ID and that I'm the contact authorized to do a support ticket. About 75 percent of the time when I open a support ticket, I immediately email my customer service satisfaction manager person with the ticket number so they can help move it along.
How would you rate customer service and support?
Negative
Which solution did I use previously and why did I switch?
I was using Sophos three years ago. I've looked at many of the feature sets out there, and they might be 80 percent of what Vision One has, and some might be better, but Vision One is price-competitive.
How was the initial setup?
Deploying Vision One was a pain because of the automated removal tool. In the antivirus world, they try to make it difficult to uninstall people's defenses because that's what an attacker would do. However, all the competitors are making tools to uninstall their competitors' tools when they win business. That's directly counterintuitive to the whole point of the antivirus.
We went through a process of trying to do this in an automated fashion to replace the old product, and Trend didn't quite do it right. Trend had a real struggle toget their own tool to fix it.
We use it as a SaaS, so we have a gateway integrator on the server on-site, but the product sits on all my endpoints. In that aspect, it's on-prem, but all the processing, reporting, and everything else happens in the cloud. We had it 75 percent deployed in 45 days. That last 25 percent took us another four months.
I work at an underfunded public school district. I need a whole team, but there is only me. I used to have a security analyst until that position moved around, and
my ability to use the product has been drastically reduced. I miss much of the value of what I'm paying for because I don't have enough staff to use it. I wouldn't need more than one if that was their whole job.
It's not a totally elegant solution that always feeds and cares for itself. We have to check if it's doing its updates properly. It doesn't tell us, for example, that 2,000 devices haven't been updated or checked in. I have to go proactively looking at it.
What's my experience with pricing, setup cost, and licensing?
Vision One's pricing is extremely competitive. They're probably the lowest-cost provider that has this feature set.
What other advice do I have?
I rate Vision One seven out of 10. Make sure you learn the 90 percent of stuff in there that you didn't know you bought and preestablish an escalation contact for support tickets.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Buyer's Guide
Download our free TrendAI Vision One Report and get advice and tips from experienced pros
sharing their opinions.
Updated: July 2026
Product Categories
Endpoint Detection and Response (EDR) Network Detection and Response (NDR) Extended Detection and Response (XDR) Attack Surface Management (ASM) AI-Powered Cybersecurity Platforms AI SecurityPopular Comparisons
CrowdStrike Falcon
Cortex XDR by Palo Alto Networks
Microsoft Defender for Endpoint
SentinelOne Singularity Endpoint
Darktrace
IBM Security QRadar
Microsoft Sentinel
Elastic Security
Huntress Managed EDR
Trellix Endpoint Security Platform
WatchGuard Firebox
TrendAI Vision One – Cloud Security
Buyer's Guide
Download our free TrendAI Vision One Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What is the biggest difference between EPP and EDR products?
- What is the difference between EDR and traditional antivirus?
- What is your recommendation for a 5-star EDR with low resource consumption for a financial services company?
- Which is the best EDR for a logistics company with 500-1000 employees?
- What is the best EDR or XDR product for a company with 9000 employees?
- What to choose: an endpoint antivirus, an EDR solution or both?
- Do we need to use both EDR and Antivirus (AV) solutions for better protection of IT assets?
- How does EternalBlue work?
- What are the best on-premise Endpoint Security solutions for a Tech Services company with 10,000 employees?
- Which is better for Endpoint Security: EDR or XDR solutions?























