Overview

Product video
Trend Micro, a global cybersecurity leader, helps make the world safe for exchanging digital information. Fueled by decades of security expertise, global threat research, and continuous innovation, our cybersecurity platform protects 500,000+ organizations across cloud, networks, devices, and endpoints
Trend Micro Vision One is a purpose-built threat defense platform that provides added value and new benefits beyond XDR solutions, allowing you to see more and respond faster. Providing deep and broad extended detection and response.
Contact Trend Micro to put together a custom enterprise security solution for your organization! aws.marketplace@trendmicro.comÂ
Looking for our cloud security services platform for workloads, containers, network, serverless functions, storage and open source vulnerabilities? Check out our Trend Micro Cloud One offer.
Highlights
- Enterprise security solutions- including managed XDR. See more, respond faster.
- Increase risk visibility while decreasing response times.
- Greater Security Team Efficiency: one platform to respond faster with less resources and one source of truth
Details
Unlock automation with AI agent solutions

Features and programs
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Dimension | Description | Cost/month |
---|---|---|
Enterprise Solution | Custom Security solutions - contact for more info and pricing | $10,000.00 |
Dimensions summary
Top-of-mind questions for buyers like you
Vendor refund policy
Refunds are not available at this time.
Custom pricing options
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Resources
Support
Vendor support
Your purchase also includes 24x7 support from Trend Micro. If you experience any issues or have questions, please contact our AWS Cloud Security experts by email at aws.marketplace@trendmicro.com . aws.marketplace@trendmicro.comÂ
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Standard contract
Customer reviews
We've ease of configuration and customization and improvement in threat response
What is our primary use case?
We use Trend Vision One for our endpoint protection in our data center, mostly focused around our server assets, and we do anti-malware, intrusion prevention, as well as firewall, host-based firewall capabilities.
What is most valuable?
The ease of configuration, customization, and organization are what I appreciate the most about Trend Vision One .Â
What needs improvement?
It is a bit slow to implement kernel support on the Linux side. When doing patching and upgrades on our Linux servers, we often find that the Trend agent doesn't support the kernel version. It's usually not far behind, but we often are in a position where we may not be properly protected for a period.
For how long have I used the solution?
We started using Trend Deep Security , which was the product prior to Trend Vision One, seven or eight years ago, and then we transitioned to Trend Vision One two years ago. While we have been using Trend Vision One proper for two years, we had essentially the same product in an on-prem version for seven or eight years.
What do I think about the stability of the solution?
We've had performance issues with the agents of Trend Vision One at odd times, but I wouldn't say it's been a widespread issue or a common issue. Once in a while, there have been things that we've attributed to Trend.
What do I think about the scalability of the solution?
The scalability of Trend Vision One seems infinite. We're not a huge organization, so we haven't really run into any limitations, but it appears it can scale to accommodate and serve any of our purposes.
How are customer service and support?
The quality of support for Trend Vision One is generally very good. If we have any issues with support, we can leverage our sales engineer for support or escalation. I really haven't had any concerns. I have contacted the technical support or customer support via phone number or ticket.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We have used Microsoft Defender, Sophos, as well as McAfee as alternatives to Trend Vision One. I prefer Trend Vision One more compared to those alternatives.
How was the initial setup?
We transitioned from our on-premises Deep Security deployment to Vision One, and the process was relatively smooth. However, we encountered a few challenges related to legacy configurations and ensuring proper connectivity to our server assets. With an on-premises software application, we didn’t have to worry about internet accessibility for some of our server nodes. Consequently, we faced issues getting non-internet-connected server endpoints to communicate with the cloud. Luckily, there is a solution for that, but it took some time to get everything functioning properly.
Trend Vision One is a large product suite. There are many features that we don't have fully deployed, but the amount of time it took for us to go from on-prem to the cloud for similar services without onboarding anything new that Trend Vision One offered was two months for 400 assets, server nodes.
What was our ROI?
It has reduced our time to detect and respond to threats, but I don’t have a way to quantify that.
What's my experience with pricing, setup cost, and licensing?
I know the pricing for Trend Vision One. It's been a while, but it doesn't seem bad. They made some changes to their pricing in the past. It used to be a per-server node pricing structure, but now they do it by credits. I would say it's improved because we can, for the same investment, shift and adjust which capabilities we're leveraging within the platform. It's not super expensive. It's definitely an increased cost over leveraging Microsoft Defender, which we already have the licensing and capability for. We chose to spend money on this as opposed to leveraging a product that we already had, but the cost is fair.
What other advice do I have?
The sensors we're using include the anti-malware products, and we have the EDR sensors deployed on our server endpoints. They have network sensors and other features, but we're not leveraging any of those.
We started onboarding some of our services in the last three or four months to Trend Vision One to gain more visibility, so it's early in that adoption. We haven't taken any action based on alerts or notifications from Trend Vision One, as we're still in the early stages of getting our third-party services set up and monitored.
Trend Vision One hasn't helped us consolidate use of security vendors. This product is solely used for one purpose. We're not leveraging Trend Vision One for other areas within IT or at our company, so we haven't reduced silos. We had an opportunity to go with Defender, which would have reduced the number of products we use, but instead we decided to keep using Trend because we did appreciate it. I'm not sure if Trend Vision One has helped me to reduce the noise from false positives.
I would rate Trend Vision One a nine out of ten.
Worldwide Protection of the Entire IT Infrastructure with Just One Central Platform
What is our primary use case?
Our main goal with Trend Vision One is to ensure comprehensive security coverage for all our devices and clients worldwide. We're concerned with far more than just traditional antivirus protection. With this solution, I can now see in detail which software updates have already been installed and which security vulnerabilities still exist. The comprehensive reporting and intelligent protective measures give me significantly more control than before. We can now cover all servers uniformly and completely, which is something that wasn’t possible with our previous solution at this level of quality.
What is most valuable?
The dashboard is the heart of Trend Vision One for me. What I particularly appreciate is the flexibility: each colleague can create their own dashboard, and I still maintain an overview of the big picture. This granular way of working while maintaining a holistic view motivates me to engage with the tool.
The cloud-based architecture offers considerable advantages over local, individual solutions. Previously, I had to manage patching across various Trend Micro systems manually - now, that’s centrally handled. However, I need to be cautious that updates aren't rolled out too quickly, which could impact notebooks or servers.
The global overview has definitely helped me a lot. The only drawback is the usual subscription model - unfortunately, prices tend to move upward.
Since I've been working with Trend Micro for over 20 years, we’ve been able to consolidate our security landscape and source everything from one vendor, rather than juggling multiple providers.
Trend Vision One gives us better visibility to detect and respond to threats because we can now see more than ever before. We've always made every effort to receive notifications quickly so we could act immediately. Now, I have a much clearer, centralized platform where I can manage all incidents in a structured way.
Interestingly, Trend Vision One shows us more error messages than before, not because more problems are occurring, but because I can now see them for the first time and address them systematically.
Trend Vision One helps us reduce our overall cyber risk. I've always had good experiences with Trend Micro. It gives me the confidence to recognize well-protected areas and uncover vulnerabilities that need attention. Even though I've achieved a good security level, I can't afford to relax. For security audits, the solution helps us demonstrate compliance with certain standards.
Regarding AI integration, I can't make a final judgment yet. AI has both advantages and disadvantages, and attackers are increasingly using it too. However, I believe that AI will become indispensable in security platforms.
What needs improvement?
The expansion of Phish Insight would be desirable, especially for employee training. Also, in the MDM area for mobile devices, not all functions are available that I know from on-premise or other cloud variants. There's still development potential there.
For how long have I used the solution?
We began implementing the current Trend Vision One solution in June 2024. However, Trend Micro has been our vendor for about ten years.
What do I think about the stability of the solution?
I'm very satisfied with the stability. I haven't experienced any direct outages so far. Occasionally, there were connection problems with individual clients, but those were exceptions.
What do I think about the scalability of the solution?
I think Trend Vision One offers very good scalability.
How are customer service and support?
I would rate the service and technical support for Trend Vision One at nine to ten points. Of course, it depends on the specific situation, but overall, I'm very satisfied.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We didn't switch from another solution but rather implemented Trend Vision One as an evolution of our existing Trend Micro infrastructure. I had explored Microsoft solutions in recent years and attended related training, but ultimately, we stayed with Trend Micro.
How was the initial setup?
The initial setup has a certain complexity that varies by area. Some areas are relatively easy to configure; others definitely require expertise and practice. Without professional support, the start would have been difficult.
We had two German partners on board for several weeks and months. In short, intensive sessions of two to four hours, they developed a structured onboarding process with us. After about three two-hour sessions, we could work independently with the product.
Our implementation strategy for Trend Vision One was three-tiered: First, we migrated from our on-premise Apex One solution to Trend Vision One in the cloud. In the second step, we migrated the servers, and finally we checked all sensors.
What about the implementation team?
We worked with a Trend Micro partner for onboarding. With Trend Micro's recommendation, we also purchased the licenses through them. The partner guided us during the sessions, then we carried out the actual integration and migration ourselves.
For implementation, we needed two to three employees. A colleague and I carried the main responsibility, my colleague handled the cloud migration, agents, and clients. I brought in two additional colleagues for servers and local infrastructure, particularly for Mac systems.
From mid-June to mid-September, an average of two to three people were involved in the project.
What was our ROI?
I can't definitively evaluate the return on investment yet, since we've only been working productively for a few months. We had a very good onboarding process and worked intensively on it, but for a solid ROI evaluation, it's still too early. I plan to have meaningful numbers by year-end, particularly through patch management and sensor detections.
What's my experience with pricing, setup cost, and licensing?
As usual, we work with twelve-month or multi-year licenses on a subscription basis. The subscription model is ideal for the vendor and predictable for us, but still quite expensive.
I would like more flexibility - for example, the ability to purchase individual modules separately.
What other advice do I have?
For others evaluating Trend Vision One, I recommend checking whether the vendor is a pure security specialist or also active in other, non-security-related areas. That can be an important decision factor.
Overall, I rate the solution 9 out of 10 points.
Foreign language: (German)
Weltweiter Schutz der gesamten IT-Infrastruktur mit nur einer zentralen Plattform
Was ist unser primärer Anwendungsfall?
Unser Hauptziel mit Trend Vision One ist es, eine lückenlose Sicherheitsabdeckung für alle unsere Geräte und Clients weltweit zu gewährleisten. Dabei geht es uns um weit mehr als nur klassischen Antivirenschutz. Mit der Lösung kann ich nun detailliert einsehen, welche Software-Updates bereits installiert sind und welche Sicherheitslücken noch bestehen. Das umfassende Reporting und die intelligenten Schutzmaßnahmen geben mir deutlich mehr Kontrolle als früher. Wir können jetzt alle Server einheitlich und vollständig abdecken, was mit unserer vorherigen Lösung nicht in dieser Qualität möglich war.
Was ist am wertvollsten?
Das Dashboard ist für mich das Herzstück von Trend Vision One. Was ich besonders schätze, ist die Flexibilität: Jeder Kollege kann sich sein eigenes Dashboard erstellen, und trotzdem behalte ich den Überblick über das große Ganze. Diese granulare Arbeitsweise bei gleichzeitigem Gesamtüberblick motiviert mich mit dem Tool zu arbeiten.
Die Cloud-basierte Architektur bringt mir erhebliche Vorteile gegenüber lokalen Einzellösungen. Früher musste ich mich um das individuelle Patching verschiedener Trend Micro Systeme kümmern, das ist jetzt zentral verwaltet. Allerdings muss ich aufpassen, dass Updates nicht zu schnell ausgerollt werden und dabei Notebooks oder Server beeinträchtigen.
Der globale Ăśberblick hat mir definitiv sehr geholfen. Einziger Nachteil ist das ĂĽbliche Abonnementmodell, die Preise entwickeln sich leider nur in eine Richtung und das ist nach oben.
Da ich bereits seit ĂĽber 20 Jahren mit Trend Micro arbeite, konnten wir unsere Sicherheitslandschaft gut konsolidieren und alles aus einer Hand beziehen, anstatt verschiedene Anbieter zu jonglieren.
Trend Vision One verschafft uns deutlich bessere Sichtbarkeit, um Bedrohungen zu erkennen und darauf zu reagieren, weil wir jetzt noch mehr sehen können als zuvor. Wir haben immer alles darangesetzt, Informationen sehr schnell über Benachrichtigungen zu erhalten, damit wir sofort daran arbeiten können. Aber jetzt habe ich eine wesentlich klarere, zentrale Plattform, auf der ich alle Vorfälle strukturiert bearbeiten kann.
Interessant ist, dass Vision One uns mehr Fehlermeldungen anzeigt als frĂĽher, nicht weil mehr Probleme auftreten, sondern weil ich sie jetzt ĂĽberhaupt erst sehen und systematisch abarbeiten kann.
Trend Vision One hilft uns, unser gesamtes Cyber-Risiko zu reduzieren. Ich habe immer gute Erfahrungen mit Trend Micro gemacht. Es gibt mir das Sicherheitsgefühl, gut geschützte Bereiche zu erkennen, aber auch Schwachstellen aufzudecken, an denen wir arbeiten müssen. Auch wenn ich bereits ein gutes Sicherheitsniveau erreicht habe, darf ich mich nicht darauf ausruhen. Bei Sicherheits-Audits hilft uns die Lösung definitiv, bestimmte Standards nachzuweisen.
Zur KI-Integration kann ich noch nicht abschlieĂźend urteilen. KI hat Vor- und Nachteile, und auch Angreifer nutzen sie zunehmend. Ich gehe aber davon aus, dass KI in Sicherheitsplattformen unverzichtbar werden wird.
Was muss verbessert werden?
Der Ausbau von Phish Insight wäre wünschenswert, besonders für Mitarbeiterschulungen. Auch im MDM-Bereich für mobile Geräte sind nicht alle Funktionen verfügbar, die ich von On-Premise oder anderen Cloud-Varianten kenne. Da ist noch Entwicklungspotential vorhanden.
Wie lange nutze ich die Lösung schon?
Wir haben im Juni 2024 mit der Implementierung der aktuellen Vision One Lösung begonnen. Trend Micro als Anbieter begleitet uns aber bereits seit etwa zehn Jahren.
Was halte ich von der Stabilität der Lösung?
Ich bin mit der Stabilität sehr zufrieden. Direkte Ausfälle hatte ich bisher keine. Gelegentlich gab es Verbindungsprobleme bei einzelnen Clients, aber das waren eher Ausnahmen.
Was halte ich von der Skalierbarkeit der Lösung?
Ich denke, Trend Vision One bietet eine sehr gute Skalierbarkeit.
Wie sind Kundenservice und Support?
Ich würde den Service und technischen Support für Trend Vision One mit neun bis zehn Punkten bewerten. Es hängt natürlich immer von der konkreten Situation ab, aber grundsätzlich bin ich sehr zufrieden.
Welche Lösung habe ich zuvor verwendet und warum habe ich gewechselt?
Wir haben nicht von einer anderen Lösung gewechselt, sondern Vision One als Weiterentwicklung unserer bestehenden Trend Micro Infrastruktur implementiert. Ich hatte mir in den letzten Jahren zwar Microsoft-Lösungen angeschaut und entsprechende Schulungen besucht, aber letztendlich sind wir bei Trend Micro geblieben.
Wie war das initiale Setup?
Die Ersteinrichtung hat eine gewisse Komplexität, die je nach Bereich variiert. Einige Bereiche sind relativ einfach zu konfigurieren, andere erfordern definitiv Fachwissen und Übung. Ohne professionelle Unterstützung wäre der Start schwierig gewesen.
Wir hatten zwei deutsche Partner über mehrere Wochen und Monate im Boot. In kurzen, intensiven Sitzungen von zwei bis vier Stunden entwickelten sie mit uns einen strukturierten Onboarding-Prozess. Nach etwa drei zweistündigen Sitzungen konnten wir eigenständig mit dem Produkt arbeiten.
Unsere Implementierungsstrategie für Trend Vision One war dreistufig: Zunächst migrierten wir von unserer On-Premise Apex One Lösung zu Vision One in der Cloud. Im zweiten Schritt haben wir die Server migriert, und abschließend überprüften wir alle Sensoren.
Wie war das Implementierungsteam?
Wir arbeiteten mit einem Trend Micro Partner für das Onboarding zusammen. Auf Empfehlung von Trend Micro kauften wir auch die Lizenzen dort. Der Partner leitete uns während der Sitzungen an, die eigentliche Integration und Migration führten wir dann selbst durch.
Für die Implementierung benötigten wir zwei bis drei Mitarbeiter. Ein Kollege und ich trugen die Hauptverantwortung, wobei sich mein Kollege um den Cloud-Umzug, Agents und Clients kümmerte. Ich zog zwei weitere Kollegen für Server und lokale Infrastruktur, insbesondere für Mac-Systeme, hinzu.
Von Mitte Juni bis Mitte September waren durchschnittlich zwei bis drei Personen gleichzeitig am Projekt beteiligt.
Wie war unser ROI?
Den Return on Investment kann ich noch nicht definitiv bewerten, da wir erst seit wenigen Monaten produktiv arbeiten. Wir hatten einen sehr guten Onboarding-Prozess und haben intensiv daran gearbeitet, aber für eine fundierte ROI-Bewertung ist es derzeit noch zu früh. Ich plane, bis Jahresende aussagekräftige Zahlen zu haben, insbesondere durch das Patch-Management und die Sensor-Erkennungen.
Wie sind meine Erfahrungen mit Preisgestaltung, Einrichtungskosten und Lizenzierung?
Wie üblich arbeiten wir mit zwölfmonatigen oder mehrjährigen Lizenzen auf Abonnementbasis. Das Abonnementmodell ist für den Anbieter ideal und für uns kalkulierbar, auch wenn nicht ganz günstig.
Ich würde mir mehr Flexibilität wünschen – zum Beispiel die Möglichkeit, einzelne Module separat zu erwerben.
Welche weiteren Ratschläge habe ich?
Anderen, die Trend Vision One evaluieren, empfehle ich zu prüfen, ob der Anbieter ein reiner Sicherheitsspezialist ist oder ob er auch in anderen, sicherheitsfremden Bereichen tätig ist. Das kann ein wichtiger Entscheidungsfaktor sein.
Insgesamt bewerte ich die Lösung mit 9 von 10 Punkten.
Exceptional customer service streamlines onboarding and improves AWS security integration
What is our primary use case?
My main use case for Trend Vision One is XDR security in our AWS environment for our EC2 instances, and I'm hoping to accomplish effective security measures with it.
What is most valuable?
The best features Trend Vision One offers are the dashboard, reporting, and the customer service experience, specifically the customer service experience.
What makes the customer service experience stand out is that the onboarding process was exceptionally smooth. John, our account manager, was able to coordinate us with a technical resource to help with a white-glove onboarding process to ensure that our migration from Trend Micro Cloud One to Vision One was smooth and successful.
Trend Vision One has impacted my organization positively, and it's our XDRÂ solution, so it works as intended.
Having Trend Vision One as my XDR solution has helped my team significantly. The Sentinel integration is a huge help for allowing us to detect and respond to events in our AWS environment.
What needs improvement?
I cannot think of anything that Trend Vision One can be improved.
For how long have I used the solution?
I have been using Trend Vision One for about a week.
What do I think about the stability of the solution?
Trend Vision One is stable. I have experienced minimal issues with reliability or downtime.
What do I think about the scalability of the solution?
Trend Vision One's scalability is excellent. It can handle my organization's growth and changing needs.
How are customer service and support?
The customer support is exceptional. Working with their technical resource, Victor, was fantastic, and I am very happy with the customer service that we experienced from both Victor and John.
I would rate the customer support exceptionally high on a scale of one to ten.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
I did not previously use a different solution before Trend Vision One.
What was our ROI?
I have seen a return on investment. I have been a Trend Micro customer for years and I continue to see value in their platform and have used it at several jobs.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing was very easy. Our enterprise account manager, John, made all of that very easy, as he was able to send me the private offer, walk us through accepting it inside of the AWS Marketplace , and helped us cancel our existing subscription.
Which other solutions did I evaluate?
Before choosing Trend Vision One, I evaluated other options. I considered Microsoft Sentinel and Microsoft Defender.
What other advice do I have?
The advice I would give to others looking into using Trend Vision One is to try it.
I rate Trend Vision One an 8 out of 10.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Empowers teams to quickly identify and manage cyber risks through detailed insights and continuous support
What is our primary use case?
We use Trend Vision One as our primary security solution on all endpoints, servers, and clients in our environment. Through third-party integrations, we’ve also connected solutions from other vendors (including VMware and Fortinet).
How has it helped my organization?
Trend Vision One has increased our endpoint visibility and reduced attack vectors. We can now identify and respond to vulnerabilities and threats faster. This has reduced our response time by an estimated 25–30%. Vision One provides notifications about specific risks and helps us understand where the general risks lie, enabling proactive mitigation.
With other vendors, we’ve had to manually check for vulnerabilities in products and assess whether those vulnerabilities were relevant. Now, Vision One handles much of that process. It provides detailed information for each user and endpoint about existing risks and how to mitigate them.
I often compare patching vulnerabilities in Cyber Risk Exposure Management (CREM) to playing a game — the goal is to collect as few points as possible. The lower our score, the more secure our environment is. And like in real life, there are ups and downs because new risks arise daily. Vision One is an important tool for communicating risk assessments to management while also helping operational staff understand what risks mean and how to reduce them.
What is most valuable?
The feature I find most valuable in Vision One is CREM. CREM helps our company identify blind spots. It provides detailed information about the actions and improvements we should take to secure our environment, and gives concrete recommendations about how to resolve vulnerabilities.
As part of our Service One Complete service agreement, we have bi-weekly meetings with a Technical Account Manager (TAM) who advises us on improving security settings and informs us — even between meetings — about new attack scenarios and how to counter them.
What needs improvement?
It’s hard to pinpoint areas where Vision One could be improved or where additional features are needed. I’ve been working with the solution for three years, and Trend Micro is constantly developing. Sometimes, it’s hard to keep track of all the updates and added features.
I feel that Trend Micro is now better at identifying my needs than I am at recognizing them myself.
For how long have I used the solution?
Vision One has been in use at the company for three years.
What do I think about the stability of the solution?
The stability is excellent. In my opinion, performance and availability are both very good.
What do I think about the scalability of the solution?
The scalability of the solution is very good. We have not encountered any limitations as our environment has grown.
How are customer service and support?
I would rate customer service extremely positively. Support responds quickly, and together we’ve been able to solve all challenges in our day-to-day operations. On a scale from 1 to 10, I would rate customer service and technical support a 9 — there should always be room for improvement.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
Before Trend Vision One, we used a solution from Kaspersky. The switch was prompted by the German BSI ’s security warning regarding Kaspersky's antivirus products.
How was the initial setup?
I was heavily involved in the rollout and deployment of the solution. Implementation was relatively quick and smooth. We used a deployment script distributed to endpoints through our software distribution system.
Our rollout strategy started with a small number of endpoints being configured with antivirus and policies. After reviewing and refining the policies, Vision One was rolled out in phases to the remaining endpoints.
What about the implementation team?
We needed only one staff member for the implementation of Trend Vision One, and that was me.
What was our ROI?
The investment in Trend Micro Vision One has paid off, although ROI is difficult to calculate. A security solution is like a good insurance policy — ideally, you never need to use it. We haven’t had any incidents so far, and hope it stays that way.
I’ve noticed that the continuous visibility of potential risks has made our environment more secure and has enabled colleagues to respond faster, saving valuable working time.
Which other solutions did I evaluate?
Before we decided on Vision One, we also evaluated solutions from other vendors, including Microsoft and Fortinet. The differences between the products were not significant — they were more in the details. But since we had already been a Trend partner for 15 years (12 of them inactive), we ultimately decided to return to Trend Micro.
What other advice do I have?
Three years ago, we followed a different concept: two independent security solutions with separate management and reporting. Migrating to Vision One and consolidating everything into one interface gave us a 365° view of our IT infrastructure.
Central visibility of endpoints and vulnerabilities, as well asunified management, brought a new level of focus to IT security and boosted employee awareness.
If you're evaluating Trend Micro, don’t limit yourself to antivirus functionalities. Consider other features as well — especially the Managed Services, (strong technical support), and Cyber Risk Exposure Management capabilities, which I find highly valuable.
Create a centralized view of your IT infrastructure.
Define which features are important or necessary for you.
Get a comprehensive overview when evaluating different security vendors in terms of features and costs — so you’re not comparing apples to oranges.
Foreign Language: (German)
Ermöglicht Teams, Cyberrisiken schnell zu erkennen und zu managen – durch detaillierte Einblicke und kontinuierliche Unterstützung
Was ist unser primärer Anwendungsfall?
Trend Vision One kommt als primäre Sicherheitslösung auf allen Endpunkten (Server und Clients) in unserer Umgebung zum Einsatz. Darüber hinaus sind über die Third-Party Integration auch die von uns eingesetzten Lösungen weiterer Hersteller (u. a. VMware, Fortinet) eingebunden.
Wie hat es meiner Organisation geholfen?
Trend Vision One hat uns geholfen, die Sichtbarkeit der Endpunkte zu erhöhen und den Angriffsvektor zu verringern. Wir können schneller Schwachstellen/Bedrohungen identifizieren und darauf reagieren. Dadurch konnte unsere Reaktionszeit um schätzungsweise fünfundzwanzig bis dreißig Prozent gesenkt werden. Mit Vision One wird man über konkrete Risiken benachrichtigt und lernt, wo die Risiken im Allgemeinen liegen. So kann man aktiv daran arbeiten, diese zu beheben.
Früher mussten wir aus eigener Initiative heraus überprüfen, welche Schwachstellen bei bestimmten Herstellern bestehen und einschätzen, ob diese Schwachstellen für uns relevant sind. Das wird jetzt bereits zu einem großen Teil von Vision One erledigt. Herunter gebrochen bis auf jeden einzelnen Benutzer und Endpunkt wird dediziert angegeben, welche Risiken bestehen und wie diese verringert werden können.
Ich vergleiche die Behebung von Schwachstellen im Cyber Risk Exposure Management (CREM) mit einem umgekehrten Spiel. Es geht darum, so wenige Punkte wie möglich zu sammeln. Je niedriger unser Score ist, desto sicherer ist die Umgebung. Und wie im echten Leben gibt es Höhen und Tiefen, weil es täglich neue Risiken gibt.
Letztendlich ist Vision One ein wichtiges Tool, um einerseits eine allgemeine Risikobewertung für Führungskräfte/ Manager durchzuführen, und andererseits für operative Mitarbeiter, um zu wissen, was dieses Risiko tatsächlich beinhaltet und wie es sich reduzieren lässt.
Was ist am wertvollsten?
Die Funktion, die ich in Trend Vision One besonders wertvoll finde, ist Cyber Risk Exposure Management (CREM). CREM hilft unserem Unternehmen, blinde Flecken zu identifizieren. Diese wichtige Funktion zeigt sehr detailliert und umfassend auf, wo Handlungsbedarf oder Verbesserungspotenzial besteht. Gleichzeitig bietet es den Kollegen konkrete Handlungsempfehlungen, wie Schwachstellen geschlossen werden können.
Ein Bestandteil unseres Service One Complete Service-Vertrages sind zwei wöchentliche Meetings mit einem TAM (Technical Account Manager), der uns berät, wo Verbesserungspotenzial bei den Sicherheitseinstellungen besteht und uns regelmäßig – auch zwischen den Meetings – informiert, wenn es neue Angriffsszenarien gibt und wie diesen entgegengewirkt werden kann.
Was muss verbessert werden?
Bereiche, in denen Vision One verbessert werden könnte oder wo zusätzliche Funktionen erforderlich sind, sind schwer zu bestimmen. Ich arbeite jetzt seit drei Jahren mit der Lösung und Trend Micro arbeitet ständig an deren Weiterentwicklung. Stellenweise ist man gar nicht in der Lage, alle Änderungen zu erfassen oder welche zusätzlichen Funktionen eingebunden werden.
Ich glaube, Trend Micro ist derzeit schneller dabei, meine BedĂĽrfnisse zu identifizieren, als ich sie ĂĽberhaupt selbst erkenne.
Wie lange verwende ich die Lösung bereits?
Vision One ist seit drei Jahren im Unternehmen im Einsatz.
Was denke ich über die Stabilität der Lösung?
Die Stabilität der Lösung ist sehr gut. Meiner Meinung nach sind Leistung und Verfügbarkeit sehr gut.
Was denke ich über die Skalierbarkeit der Lösung?
Die Skalierbarkeit der Lösung ist sehr gut. Wir sind bisher auf keine Einschränkungen beim Wachstum unserer Umgebung gestoßen.
Wie sind Kundendienst und Support?
Ich würde die Erreichbarkeit und Kompetenz von Service und Support von Trend Micro als sehr hoch bewerten, ich bin sehr zufrieden. Antworten und Lösungen kommen prompt, das Personal ist professionell und auf einem sehr hohen Kommunikationsniveau.
Wie wĂĽrden Sie Kundendienst und Support bewerten?
Äußerst positiv. Kundendienst und Support reagieren zeitnah. Gemeinsam konnten bisher alle Herausforderungen unseres Tagesgeschäftes gelöst werden.Auf einer Skala von eins bis zehn würde ich den Kundendienst und den technischen Support für Trend Vision One mit einer Neun bewerten. Es muss ja noch Luft nach oben bleiben.
Welche Lösung habe ich vorher verwendet und warum bin ich gewechselt?
Vor Trendmicro Vision One war die Lösung von Kaspersky im Einsatz. Der Auslöser für den Wechsel war die vom BSI ausgesprochene Sicherheitswarnung vor den Virenschutzprodukten des Herstellers.
Wie war die anfängliche Einrichtung?
An der Einführung und Bereitstellung der Lösung war ich maßgeblich beteiligt. Die Implementierung erfolgte relativ schnell und problemlos mit einem Deployment-Skript, welches über das Software-Verteilungssystem auf die Endpunkte gebracht wurde.
Unsere Implementierungsstrategie sah vor, dass zunächst eine kleine Anzahl von Endpunkten mit Virenschutz und Richtlinien versorgt wurde. Dann wurden die Richtlinien noch einmal überprüft und verfeinert. Abschließend wurde Vision One in mehreren Etappen auf die restlichen Endpunkte ausgerollt.
Wie war unser ROI?
Die Investition in Trend Micro Vision One hat sich rentiert, aber der ROI ist schwer zu berechnen. Eine Sicherheitslösung ist wie eine gute Versicherung, die man hoffentlich nicht braucht. Wir hatten bisher keine Vorfälle und hoffen natürlich, dass wir auch in Zukunft keine haben werden.
Ich stelle fest, dass unsere Umgebung durch die permanente Sichtbarkeit von potentiellen Risiken sicherer geworden ist und dass die Kollegen schneller auf diese reagieren können. Das spart vor allem Arbeitszeit.
Welche anderen Lösungen habe ich evaluiert?
Bevor wir uns für Vision One entschieden haben, haben wir auch die Lösungen anderer Hersteller evaluiert, unter anderem die von Microsoft und Fortinet. Die Unterschiede bei den jeweiligen Produkten waren nicht so gravierend, sie lagen mehr im Detail. Aber da wir auch schon seit fünfzehn Jahren Trend Micro Partner sind (zwölf Jahre davon ruhend), sind wir schließlich wieder zu Trend Micro zurückgekehrt.
Welche anderen Ratschläge habe ich?
Wir hatten vor drei Jahren ein Konzept, das einen anderen Ansatz verfolgte. Zwei voneinander unabhängige Sicherheitslösungen, mit jeweils eigenem Management und Reporting . Die Migration zu Vision One mit der Konsolidierung in eine Oberfläche hat zu einer 365°-Sicht auf die IT-Infrastruktur geführt.
Die zentrale Sichtbarkeit von Endpunkten und Schwachstellen und das Management über alle Ebenen hinweg hat noch einmal einen ganz anderen Fokus auf das Thema IT-Sicherheit gelegt und das Bewusstsein der Mitarbeiter für dieses Thema gestärkt.
Wenn Sie Trend Micro evaluieren, beschränken Sie sich bitte nicht nur auf den reinen Virenschutz, sondern beziehen Sie auch die anderen Funktionen in die Betrachtung ein. Insbesondere die Managed Services, der Technical Account Manager und die Cyber Risk Exposure Management Funktionen haben für mich einen hohen Mehrwert.
Schaffen Sie eine zentralisierte Sicht auf Ihre IT-Infrastruktur.
Definieren Sie im Vorfeld, welche Funktionen für Sie wichtig sind bzw. Sie benötigen.
Verschaffen Sie sich einen umfassenden Überblick bei der Evaluierung verschiedener Sicherheitsanbieter hinsichtlich Funktionen und Kosten, damit Sie nicht Äpfel mit Birnen vergleichen.
Welches Bereitstellungsmodell verwenden Sie für diese Lösung?
Private Cloud
Falls öffentliche Cloud, private Cloud oder Hybrid-Cloud, welchen Cloud-Anbieter verwenden Sie?
Verschiedene.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Helps secure endpoints and quickly respond to incidents
What is our primary use case?
Our use cases for Trend Vision One are monitoring and alerts.
How has it helped my organization?
The biggest challenges we wanted to address with Trend Vision One were securing endpoints and enabling us to quickly respond to incidents or threats. This is the main goal for using this solution.
Trend Vision One has improved the way our organization functions by acting as both a monitoring tool and an antivirus, giving us insight on potential threats and enhancing our response time to security incidents. It is hard to measure the time savings but we save a significant amount of time in responding to potential threats. For example, we don't expect employees to respond to emails, chat, or calls outside of working hours. Trend Vision One has a feature where we can block all access to the laptop or endpoints. It allows us to take immediate action without waiting for the user to respond.
In terms of reducing noise from false positives, unfortunately, some behaviors can be mistaken for bad behaviors, but that isn't the fault of the software itself. It largely depends on how the developers of other applications implement their software and how it is run. We encountered an issue with another software called Rapid7, which periodically runs a command on MacBooks or Apple operating systems. This command, which is quite lengthy, searches for any unsecured credentials or API keys related to GitHub on the laptop. The way the application triggers is significant: it runs under root privileges, executing that command in the terminal for the user. Trend Vision One picks this up as a suspicious command, interpreting it as an attempt to find unsecured credentials. Despite having whitelisted the entire command in Rapid7, Trend Vision One still flagged it. We went back and forth on this issue, but ultimately we decided that it wasn't worth further troubleshooting to silence this alert due to the potential for actual malicious use of such commands. While we could whitelist it, we did not want to risk it being exploited maliciously. In the end, we chose to ignore the alert. They helped us reduce some other noise, but there was some noise that we weren't able to reduce.
Vision One AI has been very useful. All IT people stay up to date with security risks, exposures, alerts, or attacks. Vision One AI helps us explain or understand the alerts and what actions are recommended.
What is most valuable?
The workbench alerts are something we find very useful, as they help us stay informed about various activities. Not all alerts are positive, but they provide valuable insights into the detection methods and help us understand how certain issues arise. For example, if someone attempts to run a piece of software that encrypts a file, one of our tools, which is used for evidence gathering in surveillance systems, may encrypt the file too quickly. As a result, Trend Vision One may trigger an alert. Although this is a false positive, it still gives us insight into the behavior involved. This allows us to investigate the alert further and provide feedback to the user or development team, letting them know that similar triggers are likely to occur with other security systems or software.
Other useful features include intrusion and mailbox alerts, suspicious unauthorized access, tracing logs, website clicks, and email filtering for bad attachments.
What needs improvement?
The improvement I have been asking for is an easier way to create MDR requests. Not all alerts that come through Trend Vision One receive an investigation, and we would like the ability to easily request an investigation on lower-scored alerts without logging into the support portal to create a ticket.
I would like to see Trend Vision One and OfficeScan consolidated into one platform. Currently, it is the same space but two different layers. It would be nice to have both combined instead of having two clients.
There is room for improvement when it comes to support.
For how long have I used the solution?
I've been working with Trend Vision One for three years.
What do I think about the stability of the solution?
Trend Vision One is stable enough. We don't see many performance impacts on our endpoints, except for when our weekly scheduled scans happen. Our developers express that it limits how freely they can develop, but I personally appreciate the insight it gives us and the actions that allow us to take on our devices.
How are customer service and support?
I would rate their support a six out of ten. We encountered an issue with one of our tools—specifically, Visual Studio. One of our developers faced difficulties debugging code because Trend Vision One was blocking the debugging application or causing it to crash. This problem stemmed from a Windows update, and it took us a month and a half to identify the root cause. After we opened a ticket either at the end of March or early April, we waited several more weeks for a solution. Although the Windows update occurred back in February, we didn’t receive the fix until the end of May. The interaction between Windows and the application played a significant role in the issue, as the debugging application starts the code and injects itself into the running application, which Trend Micro flagged as problematic after the latest Windows update. Fortunately, this issue has now been resolved, but it was indeed a painful experience. Our developers were understandably frustrated that they couldn’t debug code for a month and a half, which impacted our project timelines.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
The company previously had SentinelOne before my time, and I can say that SentinelOne was not effective.Â
We currently use Rapid7 as our Managed Detection and Response (MDR) service. In my experience, both Rapid7 and Trend Vision One serve similar purposes, but they have distinct differences. There are times when Rapid7 provides us with more detailed information, while at other times, Trend Vision One offers greater insights. This is partly because Trend Vision One collects more data from the devices, allowing it to better identify the root causes of alerts compared to Rapid7.Â
Additionally, I find that the MDR team at Trend is generally more responsive than that of Rapid7. However, there are some disadvantages as well. For instance, we haven't yet set up cloud monitoring capabilities with Trend Vision One. Rapid7 currently handles our cloud infrastructure monitoring and manages services like Office and Okta. While Rapid7 is equipped to monitor these services, Trend Vision One is not yet at that level. We are exploring ways to enhance its capabilities, and if it can provide the same level of service as Rapid7, we might consider discontinuing our use of Rapid7 altogether.
How was the initial setup?
We use the SaaS solution. I was not involved in the initial setup and deployment process, which occurred prior to my time here, but I have readjusted some policies.
Previously, it was difficult to understand some alerts. However, as time goes by, we differentiate better between them, and the AI feature is an extremely good tool that explains things that are gibberish to the regular user. The learning curve is quite steep.
What was our ROI?
It has helped us understand some of the alerts that we did not comprehend.
What other advice do I have?
It is an all-around solution that includes various modules for comprehensive security monitoring and alerting. This solution is particularly effective when integrated with other hardware or on-premises solutions, such as Deep Discovery Inspector, which monitors your network.
The interface is adequate, but it is constantly changing. New features are being added, and items are being rearranged almost daily. We might have missed some announcements regarding these frequent updates. As it is an evolving solution, such changes are to be expected. However, there are still features that are buried within menus, which previously required extensive searching to locate. For instance, until last year, isolating endpoints was only possible through the search function. Now, they have added a feature within the endpoint inventory that allows you to select devices and isolate them immediately, rather than having to jump through multiple hoops to access that option.
The application has also become slightly more responsive. Regarding its functionality, the insights it provides are quite useful. The application displays various actions, and you can drill down into alerts to view the execution path associated with them. For example, if an application triggers an alert, you can right-click on that alert and select "Check Execution Profile." This feature shows you where the process started, what actions it took, and where it ended. This improvement is beneficial for understanding how tasks are executed.
I would rate Trend Vision One an eight out of ten.