No more typing reviews! Try our Samantha, our new voice AI agent.
Matthew Guzzi - PeerSpot reviewer
Information Systems Administrator at a government with 10,001+ employees
Real User
Nov 20, 2023
Provides great visibility, saves us time, and integrates well
Pros and Cons
  • "Drilling down further, we can analyze how our users are utilizing their workstations, including the websites they visit."
  • "While the continuous addition of features is commendable, the sheer volume of changes makes it difficult to stay abreast of the latest developments."

What is our primary use case?

We utilize Trend Vision One to identify and neutralize malicious activities on our network. This comprehensive security solution extends beyond traditional antivirus software, which relies on pattern matching, by actively monitoring endpoint behavior for anomalies and deviations from established norms.

In 2020, we transitioned to remote work like many other companies. During this transition, we conducted an internal Trend Micro office scan, which revealed that many of our users' devices were out of date due to their inability to connect to the VPN for extended periods. This prompted us to switch to Apex One later that year. As part of the Apex One implementation, we were given a complimentary trial of Vision One. During this trial, we received an alert that demonstrated the product's effectiveness, leading us to purchase a subscription. Vision One has been an excellent addition to our security arsenal. Trend Micro continuously adds new features and updates, making it an ever-evolving and valuable tool. The product's capabilities, functionality, and incident response capabilities have improved significantly over the past several years. We can set up playbooks to automate our response to specific incidents, which is a tremendous asset. Vision One is an outstanding security solution.

How has it helped my organization?

We are a state government agency that is subject to oversight by the state. Vision One has detected attempted attacks that the state SOC has missed, enabling us to swiftly halt these attacks and address the vulnerabilities before they escalate into more widespread problems.

The integrations have been great. There have been a couple of issues, but overall they've been very helpful. Vision One recently added the ability to connect to our on-premises AD. This was a sticking point for us for a year or so because we didn't have Azure. So we were stuck in a situation where we couldn't tie Vision One to our AD. But since they added the on-premises integration, it's been easy to set up.

Trend Vision One has saved us ten percent of our time. It has eliminated the need for us to rebuild machines. It has helped us even more than that because the few times we have had a threat, it has stopped it in its tracks. This has prevented the threat from spreading and compromising multiple machines. Without Trend Vision One, we would have had to investigate the threat, which would have taken time and resources. Additionally, we would have had to rebuild the compromised machines, which would have taken them offline and impacted our users. In some cases, a widespread outbreak could have occurred, causing even more disruption.

What is most valuable?

The dashboard provides great visibility into our risk profile. We receive a daily email report that outlines our risk score and identifies the machines with the highest risk. This information is based on usage patterns, vulnerabilities, and non-compliance issues. This helps us prioritize which machines require patching or further investigation.

Drilling down further, we can analyze how our users are utilizing their workstations, including the websites they visit. While we don't track specific website URLs, we can categorize website types and identify any potentially risky or inappropriate usage patterns. This allows us to proactively address any potential security concerns.

For instance, we identified a user who was using ChatGPT for work-related tasks. This flagged our system, and we were able to discuss the user's usage of ChatGPT to gain a better understanding of how our users are working and identify any areas that require additional attention.

What needs improvement?

Trend Vision One offers training sessions every few weeks or every month to showcase new features. However, the product's rapid development and the introduction of numerous new features make it challenging to keep track of the evolving interface and maintain a consistent understanding of its usability. While the continuous addition of features is commendable, the sheer volume of changes makes it difficult to stay abreast of the latest developments.

Buyer's Guide
TrendAI Vision One
August 2026
Learn what your peers think about TrendAI Vision One. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
913,630 professionals have used our research since 2012.

For how long have I used the solution?

I have been using Trend Vision One for two years.

What do I think about the stability of the solution?

Trend Vision One has proven to be extremely stable in our environment. We have deployed the Trend Micro client across all workstations. Additionally, we utilize a tool for vulnerability scanning, one for application whitelisting, and FireEye, as mandated by state regulations. These security solutions coexist harmoniously, causing no compatibility issues. We have also implemented laptop encryption and other security measures to further enhance protection. Throughout our experience, Trend Micro has not caused any conflicts with Microsoft or our other security tools.

What do I think about the scalability of the solution?

Trend Vision One is scalable. We can add another 150 machines with no problems.

How are customer service and support?

The technical support is excellent. We experienced what we initially thought was a technical issue, but it turned out to be a state update that triggered alerts across all of our machines. I contacted the support team and our sales representative. Within an hour, the incident response team was on the phone with me, examining the file hashes of the updated DLL to determine the cause of the issue. They quickly identified that the update was not malicious. Their promptness and thoroughness were outstanding. The incident was resolved within three hours of receiving the alerts.

Which solution did I use previously and why did I switch?

We lacked an XDR tool. Instead, we relied on FireEye, which offers similar capabilities, but it doesn't provide us with the same level of visibility as Vision One. Vision One has consistently detected threats that FireEye missed. While we were mandated to use FireEye by state regulations, we sought a more robust solution that could effectively identify anomalies and patterns. Vision One's utilization of the MITRE ATT&CK framework has been particularly advantageous. We've found great value in Vision One's comprehensive feature set, particularly its well-designed playbooks.

How was the initial setup?

The initial deployment was straightforward. I was able to deploy Trend Vision One with the vendor's assistance within one week.

What about the implementation team?

The vendor guided us through the implementation process and continues to conduct periodic check-ins to verify that everything continues to function effectively in accordance with industry best practices.

What was our ROI?

Our return on investment does not stem from direct cost savings but from the fact that Vision One has mitigated issues before they escalated into larger problems. This has saved us time, which is a valuable asset.

What's my experience with pricing, setup cost, and licensing?

The pricing for Trend Vision One is reasonable. I am not sure of the exact amount we pay, but it is not excessively expensive.

What other advice do I have?

I would give Trend Vision One a perfect score of ten out of ten. It is undoubtedly the best product in the market today. While I appreciate CrowdStrike and its offerings, I believe Trend Vision One stands out as the leader. In my opinion, these two products are the clear frontrunners in the XDR space at this moment.

Trend Vision One is deployed at a single location. We have approximately 50 endpoints. Most of our devices are laptops because we have a large number of employees who travel frequently.

Trend Vision One is maintenance-free, which is convenient because patching is handled seamlessly from the backend in the cloud. Trend Micro proactively notifies users about upcoming patching schedules and provides detailed information about the patches, new features, and updates. The patching process is managed entirely by Trend Micro, eliminating the need for user intervention. A client installed on the machines receives updates from the cloud server, ensuring that all devices remain protected and up-to-date without any manual effort.

I highly recommend Trend Vision One. Contact Trend Micro and they'll be happy to schedule a demo. I suggest installing the demo, testing it out, and seeing if it's a good fit for the organization's needs before purchasing. Trend Vision One is worthwhile.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Meako-Anna Marlow - PeerSpot reviewer
Security Operations Analyst at Compugen
MSP
Jul 28, 2024
Offers centralized oversight, improved efficiency, and is user-friendly
Pros and Cons
  • "It is so helpful to have something that pulls all the data into one visual representation of the events."
  • "Vision One generates numerous false positives, forcing unnecessary investigations and highlighting a need for improved filtering options."

What is our primary use case?

Trend Vision One functions as our XDR solution. I spend considerable time within it conducting reconnaissance on any security incidents requiring investigation. This tool allows me to quickly search for information that might be difficult to locate using our other tools.

We implemented Trend Vision One to improve our security posture by creating multiple layers of protection. This tool addresses security gaps our existing solutions, like Defender, may miss, providing deeper insights into potential threats.

How has it helped my organization?

We have implemented the product on both our cloud environment and endpoints. While we utilize a different Trend product for email, we also leverage Trend for this purpose. Trend's complete coverage is invaluable, as it centralizes data that would otherwise be difficult to locate, and its robust search function has been instrumental in our decision to continue using the platform. Although our organization is always exploring alternatives, the all-in-one nature of this solution has proven highly effective for our needs.

Vision One offers centralized oversight and control across our protective layers. It provides valuable insights into our various Trend applications, though its visibility into other layers is understandably limited. This limitation isn't a concern at this time.

Vision One has significantly improved our efficiency. For example, we recently faced a critical situation where a rule change on a client-server posed a potential security breach. Using Vision One, we quickly identified the employee responsible for the shift and resolved the incident without an extensive investigation. This would have been highly challenging without the tool, as determining the culprit would have been much more difficult.

We've been using the risk index feature to try to chip away at the risks within the environment and identify the vulnerabilities that need to be prioritized because that's been one area that has been more invisible to us with the other tools.

Vision One offers a valuable new perspective on our risk profile. While we receive reports from other tools like Nexus IQ, Vision One's unique risk classification and ranking system allows us to prioritize issues differently. This enables more informed decision-making as we can identify risks that other tools might underestimate. We've fully leveraged Vision One's benefits since our team's formation over two years ago. Though the tool existed previously, its impact was limited due to the absence of a dedicated team focused on its utilization.

It's able to detect things that other tools don't detect. We use a layered approach, so those tools have found stuff it hasn't detected. But that's to be expected. That's the goal of using the layered approach to it. But it's helpful because it catches things we might have been unaware of. Additionally, it might rank things differently than the other tools, and that's the same for this piece. And that can be very helpful for us to catch things we might have otherwise missed because it gives us that extra detail.

Trend Micro XDR has significantly reduced the time needed to detect and respond to threats. It offers capabilities that other security solutions lack, enabling us to address challenges innovatively. Additionally, built-in features such as insights and endpoint protection provide valuable tools that enhance our security posture compared to other systems.

Despite having a fifteen-year career in cybersecurity, I joined this role with limited hands-on experience. However, I quickly became proficient with Trend Vision One through self-directed learning, and my team soon recognized my expertise in the tool, making it a positive experience overall.

What is most valuable?

The Workbench feature is fantastic. It is so helpful to have something that pulls all the data into one visual representation of the events.

What needs improvement?

Vision One generates numerous false positives, forcing unnecessary investigations and highlighting a need for improved filtering options. A recurring false positive in our environment cannot be safely filtered, preventing us from ignoring it without risking overlooking genuine threats. This issue arises from a script that renames computers, which behaves suspiciously like malware but lacks a unique identifier within Trend for precise filtering. We cannot exclude the entire script due to potential exploitation by attackers who could embed malicious code within it, bypassing our security measures. While this scenario requires a targeted attack, the sensitive nature of our client's data, including threats from nation-state actors, necessitates a cautious approach to avoid compromising our security posture.

We want the ability to download and inspect emails from clients' mailboxes. Microsoft's platform supports this functionality, and we possess the necessary license. However, some clients lack the required license, prompting us to recommend Trend. If we could directly access and inspect client emails, it would eliminate the need to sell additional licenses to those clients, streamlining the process.

For how long have I used the solution?

I have been using Trend Vision One for over two years.

What do I think about the stability of the solution?

Trend Vision One is stable.

What do I think about the scalability of the solution?

As we've added employees and removed employees and added servers and removed servers, I haven't had to think about the scalability of Vision One. It has been very smooth.

How are customer service and support?

We had a script that was not right and kept triggering false positives. I had reached out for help with that. The help I got took a lot of time to get responses. And in the end, they closed out the ticket I had opened without resolving it. I also found the communication experience to be rather frustrating. My biggest complaint about my experience with Trend has been the support. There's a lot of good to be said, but there's room for improvement in the support. The people were very polite, so I'm not giving them a five because that goes a long way for me. Having support that is snippy makes the experience significantly worse. So, I am grateful for that part.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

We used a Microsoft XDR in conjunction with Trend Vision One. The main pros for Vision One are that the interface is typically a lot easier and a lot less confusing. 

The overall experience of the interface is a lot more positive. The details I can pull out of Trend are much better than I can typically pull out from Microsoft. I'm able to get results that Microsoft doesn't seem to gather. The cons are that it's in such flux right now because they're moving all their other products into the Vision One console, which can sometimes make it a bit confusing. 

It can also mean that we're unable to access the tools we previously did as rapidly. For example, many of the Apex One stuff is now within Vision One. So we had to relearn how to do that, which cost us time during security incidents. And Microsoft does change things, but they typically change things by adding extra bloat. So that ends up being a con for Trend compared to Microsoft.

What was our ROI?

While I cannot confirm the specific return on investment for Vision One without firsthand data, I expect it to be positive, given our organization's tendency to quickly discontinue partnerships that fail to deliver value.

What other advice do I have?

I would rate Trend Vision One eight out of ten. There is room for improvement, but with the tools I've used, Vision One is one of the better.

I don't do much regarding the maintenance of Trend Vision One, but I also know that because I get emails about stuff that goes down, it's relatively low maintenance compared to other tools.

We have Trend Vision One deployed across multiple locations internationally. Because the number fluctuates, we have roughly 1,500 to 2,000 users at any given time. Three people on our network team use Vision One. We have also used Trend products, other than Vision One, for a couple of our clients, which would expand those numbers significantly.

My experience with Trend Vision One has taught me many valuable details, and I strongly recommend that new users carefully review the provided documentation.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Buyer's Guide
TrendAI Vision One
August 2026
Learn what your peers think about TrendAI Vision One. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
913,630 professionals have used our research since 2012.
Julio Velasco - PeerSpot reviewer
Information Security Coordinator at a maritime company with 10,001+ employees
Real User
Feb 7, 2024
Its real-time analysis has impacted our security incident response time
Pros and Cons
  • "I can prevent my environment from different types of attacks based on what I see in the Vision One console."
  • "It is very expensive."

How has it helped my organization?

Its real-time analysis has impacted our security incident response time. We use the Workbench console and dashboards. We are normally able to analyze an incident in a few hours, understand what is going on, and provide a specific solution for any type of incident.

A few days ago, a user opened something with malware on their machine. In a few seconds, I received an email, and I received a pop-up in the console. To mitigate this, we removed the machine from the network and checked it.

In terms of integration, we intend to integrate more solutions with Trend Micro, but so far, we have just integrated the firewall.

What is most valuable?

Telemetry is very useful. They provide all the information. I can see specific details about any malware and various types of attacks. I can prevent my environment from different types of attacks based on what I see in the Vision One console.

Log inspection is also very useful for me. We check the logs all the time. In certain cases, it is necessary to analyze with more detail. It is very useful to understand what is going on in my environment with log inspection.

What needs improvement?

It is very expensive. 

For how long have I used the solution?

I have been using this solution for ten years.

What do I think about the stability of the solution?

We do not have any problems with the stability of this solution.

What do I think about the scalability of the solution?

It scales well. We do not have any problems with scalability.

At the moment, we do not have any plans to increase its usage.

How are customer service and support?

Their technical support is good. They take some time to give me the answers, but in the end, they fix and solve all my problems. I would rate their support a nine out of ten.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We were not using any other solution previously. We have been using Trend Micro's solutions from the beginning of our operations in Brazil.

How was the initial setup?

It is a SaaS solution. Its initial setup is not complex. It is very easy to deploy. It is not complicated. It is very user-friendly. It took around 15 days.

In terms of implementation strategy, we prepared some test machines and servers. After that, we deployed it for the entire company.

They do the maintenance, but we do not have any downtime in this maintenance mode.

What about the implementation team?

We had a Brazilian reseller.

What was our ROI?

We have not seen an ROI.

What's my experience with pricing, setup cost, and licensing?

Trend Micro's cost is higher than other solutions. That is the main reason why we need to switch to another solution.

We are using a full license that provides different types of features, but CrowdStrike does not provide some of the features such as MDM or anti-spam. We do not have these options or features with CrowdStrike. If we switch to CrowdStrike, we would have to buy other solutions to have a complete solution.

In addition to the license, there are no extra costs.

Which other solutions did I evaluate?

Its cost is high for us, so we are checking other options and other companies to provide the same solution. We are evaluating CrowdStrike, Trellix, McAfee, and Sophos. We have not yet received the quotation, but their cost is lower than Trend Micro.

What other advice do I have?

Trend Vision One is very useful. It has many functionalities and integrations. Its integration with other products is growing. In the future, it will probably be the biggest console in the world.

Trend Micro is making some changes to the console. At the moment, it is a little bit confusing for our use case because we are using three or four consoles from Trend Micro. We intend to migrate to just one, which is the Vision One console, but at the moment, we are using the Apex One console for the workstations and the Cloud One console for the servers. I do not know if the integration is complicated for Trend Micro, but at this moment, it is not so easy for me to manage all devices.

I would rate Trend Vision One an eight out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1656681 - PeerSpot reviewer
Chief Technology Officer at a healthcare company with 10,001+ employees
Real User
Jan 8, 2024
Provides centralized visibility, eliminates blind spots, and saves us a significant amount of time
Pros and Cons
  • "The automatic EDR system that notifies us when something is wrong is valuable."
  • "The information captured by Trend Vision One needs to be more detailed."

What is our primary use case?

We use Trend Vision One for our endpoint detection and antivirus solution.

The endpoint agents are deployed locally on our computers and the centralized controller is in the cloud.

How has it helped my organization?

Trend Vision One's centralized view boosts our visibility into harmful malware, viruses, and ransomware. Before Trend Vision One it was impossible to protect against attacks but the centralized management now makes it easy for us to focus on one platform.

The centralized visibility and management across protection layers have improved our efficiency. Now we have multiple tools to monitor our computers across our enterprise.

The executive dashboard is important because it allows us to dive into advanced functions.

I use the risk index feature daily and report the information weekly. This helps us address the risk factors.

Ransomware and intrusion attacks are common these days and Trend Vision One has helped us protect our devices and prevent these types of attacks.

The attack surface risk management eliminates blind spots.

Trend Micro XDR helps decrease our time to detect and respond because everything is available in one dashboard eliminating the need to use multiple dashboards and look at multiple locations.

Trend Vision One has saved us 80 percent of our time by constantly monitoring our environment and reducing our investigation time.

What is most valuable?

The automatic EDR system that notifies us when something is wrong is valuable.

What needs improvement?

The information captured by Trend Vision One needs to be more detailed.

For how long have I used the solution?

I have been using Trend Vision One for two years.

What do I think about the stability of the solution?

Trend Vision One is stable and I would rate it ten out of ten.

What do I think about the scalability of the solution?

Trend Vision One is scalable.

How are customer service and support?

The technical support is good but 20 percent of the time the response is slow or they assume our issue is solved so they stop communicating with me.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial deployment is straightforward. We run the program and it deploys automatically.

What about the implementation team?

We used a reseller for the implementation.

What was our ROI?

We have seen a return on investment.

What's my experience with pricing, setup cost, and licensing?

The price for Trend Vision One is reasonable compared to Microsoft and Symantec.

What other advice do I have?

I would rate Trend Vision One a nine out of ten.

We have Trend Vision One deployed across 250 endpoints.

Minimal maintenance is required.

I recommend Trend Vision One because it is easy to deploy and includes rich content. 

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer2295564 - PeerSpot reviewer
Security Consultant at a tech services company with 10,001+ employees
Real User
Oct 24, 2023
Has a good workbench feature and observed attack technique
Pros and Cons
  • "I like XDR's workbench feature and observed attack technique. It generates an alert once certain conditions are met. For example, let's say there's a threat called malicious.exe being deployed on your system. It will generate an alert with information like the file path, location, hash, etc. You also see a relational matrix showing how that file was executed and which processes were installed."
  • "Also, XDR should improve its coverage of the latest IOCs. Their suspicious object management works, but the coverage should be improved. It will take one or two months to get those things covered. XDR will detect on a behavioral basis, but these databases will not get updated daily like some other solutions. If you're dealing with new ransomware or malware, it may take around a month before it's covered by Trend Micro."

What is our primary use case?

We had a SIEM in place, but we wanted to do some behavioral analysis of the files that are getting deployed. We wanted to check to ensure that it was nothing with the external registration side. We needed an EDR solution for checking and monitoring everything deployed on this target machine or our host machine site. It will check and detect if any malicious files are there or not. We are getting alerts related to that kind of thing. So we used to check those alerts on the XDR, and we used to, like, do the incident and response to that kind of thing there.

How has it helped my organization?

If you have a SIEM in place, you will only get the network logs. XDR gives you more control over what files are getting deployed, how they are being executed, and how they can potentially harm your system. XDR doesn't work like a normal antivirus solution, which uses signatures to detect and block threats. XDR detects based on behavioral analysis and blocks most things.

It reduces the investigation time because it gives you everything, including how the file was executed, which processes it called, the file name, the stemming, and the time. When we have the endpoint name, we can reach out directly to the endpoint owners and communicate with them regarding those alerts.

What is most valuable?

I like XDR's workbench feature and observed attack technique. It generates an alert once certain conditions are met. For example, let's say there's a threat called malicious.exe being deployed on your system. It will generate an alert with information like the file path, location, hash, etc. You also see a relational matrix showing how that file was executed and which processes were installed.

It's a SaaS solution that covers endpoints, email, and cloud. We have agents installed wherever data is being pushed, so it used to give us a payload. Cloud functionality is one of the most critical things because we don't generally have visibility for cloud applications. Once we install the agents, we gain visibility into all the things integrated on the cloud or any SSH attempts.

XDR offers visibility across layers. This is critical when you want to implement some policies and apply exclusions for particular parts of the system that should not get scanned. It's easy to implement those things. Let's say you want to deploy policies for multiple systems. Using Apex Central, you can directly push the policy to various systems and cover the logs of several systems at a time. 

What needs improvement?

Sometimes, there are some false positives. For example, once a user had a file in their system named recovery.txt. The solution was flagging that as a ransom note, so we were confused. It isn't that serious, but it should be improved. 

Also, XDR should improve its coverage of the latest IOCs. Their suspicious object management works, but the coverage should be improved. It will take one or two months to get those things covered. XDR will detect on a behavioral basis, but these databases will not get updated daily like some other solutions. If you're dealing with new ransomware or malware, it may take around a month before it's covered by Trend Micro. 

For how long have I used the solution?

I have used XDR for two years.

What do I think about the stability of the solution?

Trend Micro XDR is stable. We've never had downtime. 

What do I think about the scalability of the solution?

Trend Micro XDR is scalable if you can pay more for licenses. 

How are customer service and support?

I rate Trend Micro support seven out of 10. Their technical support is good. They reply regarding your cases. However, if you don't reply to them properly, they may close your case if you are not reviewing that kind of thing. 

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

 I previously used Crowdstrike, which is an MDR, so it was totally managed by the Crowdstrike team. They were monitoring every alert that was generated, so it's hard to compare it to Trend Micro XDR. It was somewhat similar, but CrowdStrike is more proactive than Trend Micro, and it has greater coverage of IOCs. I have also used SentinelOne.

How was the initial setup?

It's a SaaS solution deployed across multiple locations covering 20,000 endpoints. It doesn't require any maintenance aside from updates. 

What other advice do I have?

I rate Trend Micro XDR seven out of 10. If you plan to implement XDR you should be aware of the IOC coverage and follow up with the Trend Micro team. Most things are covered, but it takes time to add and deploy all that stuff. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
IT Architect at a outsourcing company with 11-50 employees
Real User
Oct 15, 2023
Great network protection, a centralized view, and user-friendly
Pros and Cons
  • "The most valuable feature is the network protection shield on every server, which isolates attacks and prevents our clients from being affected."
  • "The deployment process could be more streamlined over the existing infrastructure, as it was not as easy as we thought."

What is our primary use case?

We use Trend Micro XDR to enhance our security framework.

One of our partners was the victim of a major attack, and we realized that our environment was susceptible to the same thing because we were only using an antivirus solution. 

Trend Micro XDR is deployed on-premises, and we use it on our core business servers, clients, and the management portal to protect all of our network nodes from attacks.

How has it helped my organization?

Trend Micro Vision One provides centralized visibility and management across protection layers, which is important. It is part of our monitoring tool. The visibility gives us a centralized view of our network nodes, activities, and possible attacks.

The risk index feature plays an important role in our KPIs, which we report to the management team. Our business is dependent on our systems running 24/7.

Trend Micro XDR has helped decrease our time to detect and respond to threats.

Trend Micro XDR has reduced the time we spend investigating false positive alerts by 50 percent.

What is most valuable?

The most valuable feature is the network protection shield on every server, which isolates attacks and prevents our clients from being affected.

What needs improvement?

The deployment process could be more streamlined over the existing infrastructure, as it was not as easy as we thought. We are working with an expert from Trend Micro to improve the rollout process, but it has taken some time and we do not yet have a concrete understanding of the issue. There are some features that we have to install repeatedly before they start running.

For how long have I used the solution?

I have been using Trend Micro XDR for one year.

What do I think about the stability of the solution?

Trend Micro XDR is stable.

What do I think about the scalability of the solution?

Trend Micro XDR is scalable.

How are customer service and support?

The technical support is good.

How would you rate customer service and support?

Positive

How was the initial setup?

The deployment took six to eight weeks to complete. We had around five part-time people involved in the deployment.

What's my experience with pricing, setup cost, and licensing?

Trend Micro XDR is expensive but we got a good deal from Trend Micro. We pay for an annual license.

Which other solutions did I evaluate?

Currently, we are researching the question of whether to use Trend Micro XDR when we switch from our classic NPLS internal corporate lines to an SD-WAN solution. Or if we should use an integrated solution from the SD-WAN and firewall provider, such as Palo Alto or Fortinet.

What other advice do I have?

I would rate Trend Micro XDR eight out of ten.

We have 300 people in our organization that use the solution.

Maintenance is easy and done by two people, who update, patch, and install new servers; client-side, they also update user stations and analyze logs.

I recommend Trend Micro XDR. It is user-friendly.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
PeerSpot user
IT Securiy Administrator at a transportation company with 1,001-5,000 employees
Real User
Top 20
Aug 21, 2024
Easy to set up with good support and great threat intelligence
Pros and Cons
  • "The most valuable feature is how the stack fully integrates all components of a solution."
  • "The SOAR features (Security Playbooks) are quite limited."

What is our primary use case?

We use Vision One to detect to detect and respond to malware incidents. With endpoints (Apex One/Cloud One Workload Security), network (Deep Discovery Inspector) and Office365 (Cloud Email and Collaboration Security).

The environment is complex, distributed in more than +100 locations. Some locations are just offices, some others are industrial facilities with ICS and SCADA. Besides Windows, we deal with a lot of operating systems, including Solaris on SPARC. And our users are diverse, with lots of employees roaming around the country.

With CREM, we tackle important use cases around identity protection and risk management in general. Identification, prioritization, and remediation.

How has it helped my organization?

The full stack of Vision One has delivered what "SIEM 2.0" couldn't deliver. The capability to monitor threats and discover attack vectors before they are exploited and across all our workspace (on-prem, IaaS, PaaS and SaaS). We have invested well over a million into SIEM during the last decade. A full ArcSight upgrade and then a Splunk migration assisted with a large MSSP. Vision One is still ahead at a fraction of the cost.

Going through a capable, single-vendor solution was necessary, given our small team. Choosing the best solutions for every task and building all the integrations was not an option.

Vision One is much more than just EDR for us; it is a threat intelligence platform and a SOAR too. And even with the limited capabilities in this area, we find ways to tackle challenges our MSSP and SOC haven't been able to accomplish on a very large budget.

What is most valuable?

I like everything. The most valuable feature is how the stack fully integrates all components of a solution. Then, integrations with third parties will be provided.

As an example, I am capable of sending a suspicious file directly to my Deep Discovery Analyzer appliance (a sandbox) while investigating a suspicious download/file interaction, and I can then quickly push the IOCs in the suspicious object lists to protect both managed endpoints, and the rest of the network too! Yes, you can push domains and IP addresses to Palo Alto through a Trend Micro Service Gateway, ensuring you can protect even what cannot receive an endpoint. And all this without writing a single line of code. The ease of use and ease of deployment for use cases like this are my favourite features.

What needs improvement?

The SOAR features (Security Playbooks) are quite limited. At the moment, it is impossible to execute a simple piece of Python code that would pull or push something to an API, for example. While you can tackle some use cases, a SOAR from another vendor is still a must-have.

To assist with complex use case integrations, having all the data from the SIEM inside XDR would be great, too. That's where the market is moving with solutions like Falcon Logscale and Cortex XSIAM. Pivoting from XDR to Splunk or vice-versa can be time-consuming during incidents.

For how long have I used the solution?

I was actually an early beta tester of the Apex One Endpoint Sensor before Vision One appeared in 2021. That would be three solid years of using it.

What do I think about the stability of the solution?

Quite reliable. In the last three years, only one incident created memory leaks on Windows Servers. We didn't see too much impact (fortunately) as a workaround could be quickly provided.

Support is quite responsive when something does work well. However, we do pay for Premium support.

What do I think about the scalability of the solution?

The scalability is really good.

How are customer service and support?

My experience is generally good, but I have had the chance to deal with premium support. I'd say I get the support I expect for the price that I pay.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Although we have been dealing with other security vendors (McAfee, Symantec, Proofpoint, and more), Vision One was really our first EDR.

How was the initial setup?

The initial setup was a breeze. It is realistically one of the strong points of the solution.

What about the implementation team?

We implemented the solution in-house. Although with premium support, you do get a lot of help from Trend Micro if you ask for it. You'll be able to talk to actual experts.

What was our ROI?

It is very hard to quantify an ROI on a security product. It doesn't generate revenues, and you can't quantify the cost of incidents that didn't happen.

What's my experience with pricing, setup cost, and licensing?

Product names are changing all the time. Lots of changes in the last three years. They introduced the concept of credits, too, which did not make anything easier.

It's also easy to underestimate the credits required with Cloud Email and Collaboration Security: people invited from third-party tenants will count.

The credit usage and allocation tool has been improving, at least.

Which other solutions did I evaluate?

We had a look at Carbon Black and CrowdStrike Falcon.

What other advice do I have?

It's probably the best solution for a small team that cannot absorb the complexity of a multivendor solution. The ability to execute VS the cost is surprisingly good.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Information Technology Security Manager at Mewah International Inc
Real User
Jul 14, 2024
What would previously take us two to three hours to fix, we can do in one hour or even half an hour
Pros and Cons
  • "The user interface is very good."
  • "We'd like to see more use of AI around analytics and controls."

What is our primary use case?

I primarily use the solution to prevent attacks. 

How has it helped my organization?

It's good for detecting malware and anomalies. We use it on our endpoints. 

What is most valuable?

The user interface is very good. Everything is all on one single platform.

With this product, we get centralized visibility and management across all of our protection layers. With a central platform, we don't have to look around across different websites or platforms. We can go right on the portal and manage things. It also helps us reduce the learning curve. We can manage and monitor products from the same place instead of learning different platforms. It's also helped us increase efficiency.

We have made use of the executive dashboard. It greatly increased visibility. We get a risk management view and metrics that help us narrow down and find issues. It helps us reduce risks. The risk index feature gives us a score to help us in our security goals. With it, we know what's the baseline or standard, so now we know what we need to do in order to meet the standards out there in the industry. We can see everything we need to in one glance. 

It's kept up to date and is consistently improving. This helps us protect our environment. 

The patch management has been very useful. They help recommend what needs to be installed.

We leverage the attack surface risk management capabilities. It shows the entire incident, including how it happened. We can use the information when we're doing forensics.

We've been able to reduce our mean time to detect and mean time to respond. What would previously take us two to three hours to fix, we can do in one hour or even half an hour. We've also been able to reduce the amount of time we spend investigating false positives. 

What needs improvement?

We'd like to see more use of AI around analytics and controls. 

For how long have I used the solution?

I've been using the solution for five years. 

What do I think about the stability of the solution?

The stability is good; I'd rate it eight out of ten.

What do I think about the scalability of the solution?

We're a small-to-medium-sized company. We have it deployed to less than 5,000 users. 

I'm not sure of the scalability. It works for us and our company size.

How are customer service and support?

Support is okay. They could be more responsive and could provide more communication channels. 

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We did not previously use a different solution. 

How was the initial setup?

I'm more of an end-user. I do not handle the installation aspect. The deployment was done a long time ago. 

The tool does not require much maintenance. 

What's my experience with pricing, setup cost, and licensing?

I'm not familiar with the exact pricing of the solution. My understanding is the licensing is reasonable. 

What other advice do I have?

I'm an end-user and customer. 

I'd rate the solution eight out of ten. It has very good management and monitoring benefits. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Fernanda Sampaio - PeerSpot reviewer
Information Security Analyst at Protega – Managed Cybersecurity
Real User
May 12, 2024
Has made our detection and response time much faster
Pros and Cons
  • "I like Vision One's workbench. It provides helpful logs that I can search, and the telemetry is excellent because I can see what's happening during an attack or potential attack."
  • "Vision One's search could be improved. While the platform is very user-friendly, the search feature uses terms that aren't as intuitive."

What is our primary use case?

We use Vision One together with the other products in the Trend Micro security stack, such as XDR, Site Management, and Apex One. 

How has it helped my organization?

Vision One has made our detection and response time much faster. We have 30-plus integrations, helping us to identify the most critical threats. The more connections, the better. We can also identify and resolve false positives faster. 

What is most valuable?

I like Vision One's workbench. It provides helpful logs that I can search, and the telemetry is excellent because I can see what's happening during an attack or potential attack.

Another one of my favorite features is attack surface risk management. It shows me faults and blind spots in my security. I also like the attack phase management. The model shows the risks in the corporation and provides considerable information about what is happening on the platform and the network, offering more visibility. There's also a risk index that shows me where I can improve my security. 

Vision One provides centralized visibility and management across multiple layers. This is critical because I need to see what's happening. It also allows me to set separate rules and policies for some security areas. 

What needs improvement?

Vision One's search could be improved. While the platform is very user-friendly, the search feature uses terms that aren't as intuitive. The automation is excellent, but I wish there were more templates to help me optimize more things. 

For how long have I used the solution?

I have used Vision One for nearly a year.

What do I think about the stability of the solution?

I rate Vision One nine out of 10 for stability. It has only crashed once. 

How are customer service and support?

I rate Trend Micro support six out of 10. They respond quickly but the answers aren't clear sometimes. They don't always understand the issue, so I need to explain a lot.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

I previously used the Microsoft 365 security stack, but I found Microsoft's XDR lacking. We also used Microsoft CASB and Defender for Endpoint. Vision One's threat intelligence and modeling are better. It has all the features like attack surface and risk management as well as the workbench. I also find Vision One easier to navigate. 

How was the initial setup?

Vision One is easy to deploy. It's mostly automatic, but we needed to deploy some of the agents manually. If you can deploy all of the agents to the endpoints automatically, it takes only about five minutes. 

What's my experience with pricing, setup cost, and licensing?

Vision One is expensive, but I think it's a typical market price. 

What other advice do I have?

I rate Visione One nine out of 10. I recommend fully exploring Vision One's features. It has many features that you don't need to pay extra for. There are so many things to explore. For example, they have free playbooks for third-party integration.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
reviewer2296710 - PeerSpot reviewer
Security Specialist at a transportation company with 1,001-5,000 employees
Real User
Oct 27, 2023
Simple monitoring with centralized dashboards and great visibility into vulnerabilities
Pros and Cons
  • "The most important thing for us as a customer is that we can spend more time in other places as it's simpler to have that overview. We have much more time for other tasks."
  • "They should increase their potential for third-party integrations."

What is our primary use case?

The reason we invested in Trend Micro XDR was to consolidate security operations and monitoring. On top of that, we invested in their managed detection and response service, which they can provide on top of the ETA service, which makes our lives easier. You can say that with it, we need fewer hands.

How has it helped my organization?

We're able to gather a more simple view of what was going on in our infrastructure. Before this solution, we used a SIEM system. Trend Micro XDR made monitoring more simple, and we trusted them as a security partner.

It definitely has improved our visibility of all of our ongoing items in the infrastructure. We can get a good overview of what's going on across our network and what our security looks like.  

What is most valuable?

Having everything under one management console and having them monitored from one place is the most beneficial.

It saves time and we do not have to invest in a lot of products to meet all of our use case needs.

It's quite simple to monitor everything under one console. It makes life simpler for our operations team. 

We have the solution everywhere, including email, network, endpoints, and cloud. This is important to have this coverage. As a former incident response analyst, having visibility everywhere is really important. Having everything correlated into one place increases visibility.

We have centralized visibility and management across our production layers. They are also improving that from month to month. It's important for us. In security operations, the fewer places you need to go to have a look around, the easier it is. Back in the day, we had to open ten different consoles. Now we just open one. 

The most important thing for us as a customer is that we can spend more time in other places as it's simpler to have that overview. We have much more time for other tasks. 

We use the solution's executive dashboards. We like that we can drill down from the dashboards into XDR detections. It helps the C-suite understand. However, it also helps us drill down by allowing us to choose which views we want. 

We have a trial version of the Risk Index. We have a daily look at it and it gives a nice overview of our vulnerability management and what the attack surface looks like. It helps us prioritize our daily tasks. 

The Managed XDR service was great. It helped quite a lot. We had to get used to working with them and they with us, however, now it's quite an easy task and the advisory and alerts we get from them have been helpful. The availability to work on other tasks has helped us improve in other areas. It's positively affected our business. Having this product means that we are improving in a lot of different areas that we also need to focus on. They can do the monitoring better than we can do it ourselves. We don't have the manpower to do it on our own so it helps a lot to have them help with management.

We use the Attack Surface Risk Management capabilities, which are also in the trial period. It's absolutely helped us to identify blind spots in our environment. It made us realize that, for example, users were using their work email for private services such as Netflix or other services that, if they had a data breach, would be an issue. With this, we can reach out to those users and explain to them how to act on the Internet, not to use your work email for private services, et cetera.

It's helped decrease our time to detect and respond to threats. It's likely 80% faster now. It's also helped us reduce the time we spend investigating false positive alerts. They do a lot of the initial work for us and come back with the actions we need to do on our part (if any). It's helped us reduce false positive investigations by 50%.

We're using some of the automation capabilities of XDR. It's helped us save time. At the moment, it's likely helped us save 20% of the time we'd normally spend on manual processes. 

What needs improvement?

They should increase their potential for third-party integrations. We'd like to see integrations with other IT security vendors that are not currently there. 

I'd like to see central management of all products.

For how long have I used the solution?

I've been using the solution since it came out, essentially. I've been working with it for eight or nine years.

What do I think about the stability of the solution?

The solution is quite stable. 

What do I think about the scalability of the solution?

We don't have branch offices, however we have 2200 clients and 800 servers. 

It is easy to scale if you are a bigger organization. We do plan to scale further in the future. 

How are customer service and support?

We have Service One, which includes three-year support. It is 24/7/365 support and they are quite good. 

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Before Trend Micro, we used Splunk. The use case and monitoring were easier with Trend Micro. We found it easier to fulfill our needs using Trend Micro. 

How was the initial setup?

I was involved in the deployment process. Some of it was quite complex. Unfortunately, we had an on-prem environment that wasn't well taken care of. The migration was hard, however, that was more our fault. It could be easier to migrate, however. 

It took us about nine months to fully deploy. 

We already had some products in the cloud, however, we needed to migrate all of our endpoints. The on-premise agent needed to be placed in the cloud and we had some problems as some clients did not have an opening to the internet, et cera. There was some preparation we needed to do. We needed to do some upgrading before migrating. 

There were two to four people performing the implementation. 

The solution requires maintenance and we have a person that manages that. 

What about the implementation team?

We had help from Trend Micro professional services. 

What was our ROI?

We have noted an ROI. Having them monitor our IT solutions allowed us to have fewer people on the team. It's saved us in man hours. 

What's my experience with pricing, setup cost, and licensing?

The solution is affordable. You do need to pay additional fees for some of the functionalities.

Which other solutions did I evaluate?

We also evaluated Microsoft's solutions. 

What other advice do I have?

I'm a customer and end-user.

We realized the benefits of the solution pretty fast - within a couple of weeks. We knew the benefits beforehand which is why we chose Trend Micro. The possibility of having the solution monitored by the vendor itself was quite helpful. 

I'd rate the solution nine out of ten. 

I would advise others to prepare your needs beforehand. If you know those, you will know Trend Micros is the right fit for you. It's great. If there's a problem with central management or monitoring, Trend Micros is quite useful. 

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Buyer's Guide
Download our free TrendAI Vision One Report and get advice and tips from experienced pros sharing their opinions.
Updated: August 2026
Buyer's Guide
Download our free TrendAI Vision One Report and get advice and tips from experienced pros sharing their opinions.