Normally, we use the solution for day-to-day investigations. We get alerts when something is going on in the environment. Right now, we are using that tool for the asset management team to identify services or applications that are not allowed for governance and all of these purposes. In addition to that, we use it for isolating devices. We also have a service with them, an MDR service. They analyze information, and they do investigations for us as well.
Trend Enterprise Security Solutions
Trend MicroExternal reviews
External reviews are not included in the AWS star rating for the product.
Great support, easy to set up, and offers good visibility
What is our primary use case?
How has it helped my organization?
Mainly, we were concerned with the visibility of the environment. We didn't have a tool that was able to allow us to see or have visibility of what the endpoints were doing on the servers in the environment. That was the main reason to adopt this solution - to have visibility on the environment as, in the past, we didn't have that capability.
What is most valuable?
The isolation of devices has been really important. We like all the attack surface-managed NPEs. It's helping us to identify devices and protect us on the network. That's in combination with third-party integrations as well. We have integrations that are helping us to identify devices using our vulnerability management services. It's scanning the network and it's sending all that data to VisionOne. With that information, we identify devices that are protected on the network and the environment.
The reports are a really good feature for showing results to upper management levels.
The search features help us try to correlate information and identify any suspicious activity. That's another feature that has been really important.
We are using it everywhere except for the network, so we don't have the network discovery service from Trend Micro. However, we have it on endpoint servers and email and also the cloud as well. We use cloud conformity to connect that piece.
Trend Micro has a feature called Vision One, that provides us with centralized visibility management across all protection levels. That's helping us to have a centralized view of the console. That's the main reason why we still have that product.
Centralized visibility is important. When we are doing investigations, we can do everything in one console instead of moving to different screens or different windows. The centralized visibility and management across these protection levels helped with our efficiency. It helps us to identify quicker, any potential threat, or any special activity.
They have this feature called Risk Index which I use sometimes to validate the level of rates we have. We don’t use it often - maybe once every one or two weeks. We use it to rank our security operations overall. Mostly, we just check it out of curiosity.
We use the Managed XDR service that they have. It relieves a lot of workload especially during investigations or interim reports about any particular activity - especially with the coverage after hours. It is helping us with the capability there. Also, if something really bad is happening, we have eyes watching all the activity, which is nice.
Using this Managed XDR service enables our team to work on other tasks - especially when we, in certain ways, allocate some of the investigation pieces. We basically create a request for them to investigate things, and that allows us to focus on other things to optimize our security toolset. That's really helpful.
We use the attack surface risk management capability they have. We use that heavily right now. It was a big use case in the past few months. We use it to identify multiple devices without protection, the applications that have been used by our users, and which ones are risky. We are using that on a regular basis. It's helped us identify blind spots and more assets. It's positively affected our security posture by improving a lot of our visibility.
XDR helped us decrease our time to detect or respond to threats. In the past, we didn't have that visibility. When we enabled that tool, at the beginning, it was a little bit noisy. That's something to be expected coming from a new tool. However, after testing through these years, things are improving, and now we can see better results, especially during investigation alerts.
The solution has helped us to reduce the amount of time we spend investigating false positive alerts. In the beginning, there was a large amount of false positives. Right now, we are day to day trying to reduce them. At this point, they are lower compared with the beginning of the implementation. Things are improving. We are reducing false positives as we go which is great.
What needs improvement?
We do use the automation capability a little. However, we noticed some limitations, especially on the playbook side. The API we use. We are integrating that with another product, a SOAR product. The playbooks are a little bit limited in what they can do at this point. Let's say that we want to connect on a specific API. The templates we cannot modify very well. When we noticed that limitation, we decided to go and use Trend Micro VisionOne API and connect it to other tools to develop that activity using another product.
Under attack surface management, when you go to the specific sites or applications that the users are accessing, the capability of downloading that report could be better. Let's say, as an example, we want to identify users using chatGPT, for example. We want to download that data through an API or through the GUI. Right now, it's not available as an option. Maybe having the capability of extracting data from VisionOne for specific areas of the tool could work. That's something that could be useful, especially if we want to generate that report and send it to specific teams. Often, we don't want to provide DX to all the people. Sometimes it's easier to just have that file and share that file with the people who need to have that information.
For how long have I used the solution?
I've been using the solution for around three years now.
What do I think about the stability of the solution?
The stability is good. It's not very common to have any outages. Sometimes there may be a glitch, however, it's rare. Normally we have 95% stability.
What do I think about the scalability of the solution?
The scalability is good, especially when we are talking about third-party integrations. We can have visibility and control of all different assets. So we can have good scalability and visibility and know more about the environment in places where we didn't have any idea things were happening. It's a SaaS tool, and we don't have to do any maintenance, and it's easy to deploy. It's pretty straightforward.
How are customer service and support?
When we have specific issues or problems connecting some products we ask for support. They respond really fast. They always try to mitigate and resolve all the issues we have. If they cannot resolve the problem, they normally share some suggestions on how we can mitigate future problems.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We did not use other solutions, although we did use Apex One for a long time. We have also used an EDR product.
How was the initial setup?
I was involved in the deployment. I was the one leading the data during the implementation. The process is pretty straightforward. It was a little tricky to reduce the false positive alerts, however, the portion of deploying to the environment and connecting the pieces was simple.
From our side, we had three or four people involved in the implementation.
What about the implementation team?
We had some help with the deployment and we had some guidance in the beginning. We requested some support from our account manager.
What's my experience with pricing, setup cost, and licensing?
The pricing is good if you look at all the compatibilities and features offered by the product. There are features that can increase the pricing. We can put some credits to some features, however, if we want to enable them. With the amount of credit we have, we are covered for all of our needs.
What other advice do I have?
I'd rate the product eight out of ten.
It is a really good product and easy to deploy. They allow you to have more visibility on your environment, especially if you have any kind of XDR solution. It will increase the visibility of what's happening in the environment. Also, from the perspective of doing maintenance updates or patches, the cloud is the way to go. The product management team does a really good job of increasing the features, and they are listening really closely to what the customer needs via feedback.
Which deployment model are you using for this solution?
Great network protection, a centralized view, and user-friendly
What is our primary use case?
We use Trend Micro XDR to enhance our security framework.
One of our partners was the victim of a major attack, and we realized that our environment was susceptible to the same thing because we were only using an antivirus solution.
Trend Micro XDR is deployed on-premises, and we use it on our core business servers, clients, and the management portal to protect all of our network nodes from attacks.
How has it helped my organization?
Trend Micro Vision One provides centralized visibility and management across protection layers, which is important. It is part of our monitoring tool. The visibility gives us a centralized view of our network nodes, activities, and possible attacks.
The risk index feature plays an important role in our KPIs, which we report to the management team. Our business is dependent on our systems running 24/7.
Trend Micro XDR has helped decrease our time to detect and respond to threats.
Trend Micro XDR has reduced the time we spend investigating false positive alerts by 50 percent.
What is most valuable?
The most valuable feature is the network protection shield on every server, which isolates attacks and prevents our clients from being affected.
What needs improvement?
The deployment process could be more streamlined over the existing infrastructure, as it was not as easy as we thought. We are working with an expert from Trend Micro to improve the rollout process, but it has taken some time and we do not yet have a concrete understanding of the issue. There are some features that we have to install repeatedly before they start running.
For how long have I used the solution?
I have been using Trend Micro XDR for one year.
What do I think about the stability of the solution?
Trend Micro XDR is stable.
What do I think about the scalability of the solution?
Trend Micro XDR is scalable.
How are customer service and support?
The technical support is good.
How would you rate customer service and support?
Positive
How was the initial setup?
The deployment took six to eight weeks to complete. We had around five part-time people involved in the deployment.
What's my experience with pricing, setup cost, and licensing?
Trend Micro XDR is expensive but we got a good deal from Trend Micro. We pay for an annual license.
Which other solutions did I evaluate?
Currently, we are researching the question of whether to use Trend Micro XDR when we switch from our classic NPLS internal corporate lines to an SD-WAN solution. Or if we should use an integrated solution from the SD-WAN and firewall provider, such as Palo Alto or Fortinet.
What other advice do I have?
I would rate Trend Micro XDR eight out of ten.
We have 300 people in our organization that use the solution.
Maintenance is easy and done by two people, who update, patch, and install new servers; client-side, they also update user stations and analyze logs.
I recommend Trend Micro XDR. It is user-friendly.
Which deployment model are you using for this solution?
A comprehensive solution that is not overly complex to use or manage
What is our primary use case?
Trend Micro XDR is utilized for security management, and we apply it to our email, network, and endpoints.
Trend Micro XDR is based on its proprietary cloud.
How has it helped my organization?
Trend Micro provides us with centralized visibility and management across protection layers, which are important to our organization.
The centralized visibility and management across both layers improve our efficiency by offering central security without the need for extensive management or fine-tuning. Trend Micro is also comprehensive and user-friendly. We have confidence in the results.
The risk index provides us with insights into potentially vulnerable areas or aspects that we may need to double-check to ensure everything is working as expected. In other words, it's a useful tool to obtain a quick overview of parts that could be more exposed to risks and other potential issues.
Trend Micro helps reduce our MTTD and MTTR.
Trend Micro presents results in a comprehensive and easy-to-read manner, which helps reduce the time we spend investigating false positive alerts.
We utilize Trend Micro's automation capabilities for alerting and categorizing emails into specific categories based on their risk level.
What is most valuable?
Trend Micro XDR is a comprehensive solution that is not overly complex to use or manage. The security results have been quite good.
What needs improvement?
I would like to have more integration with mobile device management.
For how long have I used the solution?
I have been using Trend Micro XDR for three years.
What do I think about the stability of the solution?
Trend Micro XDR is stable.
What do I think about the scalability of the solution?
Trend Micro XDR is scalable. As a small company, the licenses we have are sufficient to meet our needs.
How are customer service and support?
The technical support team is excellent, and they were able to answer our questions to our satisfaction.
How would you rate customer service and support?
Positive
How was the initial setup?
The deployment did not appear to be complex, but it was managed by Pro-Axis, who utilized a large workforce to ensure the swift completion of the deployment.
What about the implementation team?
We engaged an external partner named Pro-Axis to assist us with migrating from Trend Micro on-premises to Trend Micro XDR. Their services were excellent, and we did not encounter any unexpected issues. We were fully satisfied with the migration process as Pro-Axis promptly restored our services.
What's my experience with pricing, setup cost, and licensing?
The pricing is competitive, and the cost aligns with the features we receive. The license fee covers all of our needs.
What other advice do I have?
I give Trend Micro XDR a nine out of ten.
We were initially using Trend Micro on-premises and then expanded our usage by implementing XDR. We were satisfied with the solution and its features, so we made the decision to stick with Trend Micro.
A small team is required for maintenance, which will not impose a significant burden on our IT team.
Our entire organization uses the solution.
I suggest trying out the trial of Trend Micro XDR to assess its suitability for their environment. It can be a good solution for small or medium-sized organizations, but keep in mind that everyone has their own specific requirements.