I use Vision One for security monitoring. We monitor any alerts triggered in the console and detections based on the rules we've set. We analyze those and raise tickets when we find something suspicious that needs to be escalated.
We deploy and configure the solution based on the client's needs. Some clients are multinational companies with many locations we monitor throughout various regions. It might require different frameworks for privacy laws and regulatory compliance.
Trend Cloud One
Trend MicroExternal reviews
External reviews are not included in the AWS star rating for the product.
Trend micro a great way for malware protection
Trend Micro Hybrid Advanced Cloud Security
Cloud Security on a role
Review of Trend Micro Hybrid Cloud security
Customer support is a plus
It is very easy to use
It very easy to implement and bring our server under this umbrealla i.e easy intergration
Update frequency is pain area
Trend Micro Hybrid Cloud Security Advantages
Robust tool with good cloud protections
It's flexible, customizable, and easy to integrate via API, but the licensing model may limit scalability
What is our primary use case?
How has it helped my organization?
Vision One is versatile and can be integrated with many SIEMs. You're not limited to only one SIEM, such as Microsoft Sentinel. The API integrations are seamless, and we have all the documentation needed to integrate Vision One via API.
It takes a few months to realize the solution's full benefits. To get complete visibility and control of your cloud environment, you need to configure it correctly and have the right policies in place for response.
What is most valuable?
I like the degree to which you can fine-tune Vision One's policies. It takes some time to get them how you want them, but it has helped us. Vision One's detection capabilities stand out because they work at every level, from the network to the endpoint and application levels.
It monitors in real-time. There's no lag in the live detection and response. The multi-cloud protection is excellent, but you need to have a specialized understanding of the cloud framework, the policies you want in place, and what you are monitoring. Once you set that up, it becomes easier in terms of analyzing the logs and alerts. All the information is well structured on the console, giving you detailed visibility.
Vision One protects workloads on all the major cloud providers. You can use it with AWS, GCP, or Azure. It's highly useful with AWS. The integrations mostly primarily benefit AWS if I'm not mistaken.
What needs improvement?
The licensing model could be improved. To gain full coverage, you need to spend more to buy subscriptions for each kind of service they offer. It will start to be pricey if you want full coverage.
For how long have I used the solution?
I have used Vision One for about two years.
What do I think about the stability of the solution?
I have had no issues with the console regarding stability that required me to escalate to support or ask for technical assistance.
What do I think about the scalability of the solution?
Scalability could be an issue in terms of cost, but integration is effortless, so it's easy to scale when deploying but not cost-effective.
Which solution did I use previously and why did I switch?
I've used many tools, and many of them offer the same coverage or features. They have the same capabilities, but every console is different. Vision One ranks highly among EDR or XDR systems on Gartner's rankings. It has so many possibilities. I would compare it to Sentinel because it works on so many levels. However, I can't say that it's beating everyone. It ranks up there, but it still isn't surpassing the leaders.
How was the initial setup?
Deploying Vision One can be straightforward if you have the expertise and understand the architecture. API is the easiest way to connect. It's a little more complicated if you're connecting it through another SIEM or forwarding the logs. That's a more archaic method, but everyone uses API integration. It took a couple of weeks from the initial installation to go live.
There are many deployment phases. The first is the information-gathering stage. We provide clients with questionnaires asking what they need. We only needed two staff members to deploy it. Vision One requires some maintenance. We need to perform health checks to ensure that everything is working properly.
What other advice do I have?
I rate Trend Micro Vision One Cloud Security 7 out of 10. It's one of the top three EDR/XDR solutions I've used.
Services
Powerful tool for ensuring compliance and security across multi cloud platform
Great approach
Adaptive protection and
Integrated compliance