WatchGuard ThreatSync+ NDR logo

    WatchGuard ThreatSync+ NDR

    WatchGuard ThreatSync+ NDR provides hybrid network defense security from the cloud. ThreatSync+ NDR uncovers risks and threats across network, cloud, user, VPN, and IoT threat surfaces. By combining AI, cross-event correlation, threat intelligence, and harmonized policy controls, ThreatSync+ NDR delivers a concise list of emerging risks and threats that pose the most significant risk and integrated remediation to mitigate them.

    Ratings and reviews

    4.3
    2 ratings
    3 star
    2 star
    1 star
    50%
    50%
    0%
    0%
    0%
    0 AWS reviews
    |
    2 external reviews
    External reviews are from PeerSpot .

    Filters

    Review type

    AWS Marketplace reviews
    External reviews
    Reviews (2)
    RickyMakkar

    Unified monitoring has improved hybrid visibility and automates threat detection across our network

    Reviewed on Aug 05, 2026
    Review provided by PeerSpot

    What is our primary use case?

    I use ThreatSync NDR for monitoring across our hybrid and cloud infrastructure. For monitoring in our hybrid and cloud infrastructure using ThreatSync NDR, we investigate indicators such as IP addresses, domains, users' devices, and file hashes based on historical network and activity. If there are any vulnerabilities or indicators of compromise, ThreatSync NDR gives us the signal.

    What is most valuable?

    I have ThreatSync NDR integrated with our firewall and endpoint security, which creates a more unified security platform that helps us detect and respond with coordination. We can rely on one product for our security needs.

    ThreatSync NDR offers strong MITRE ATT&CK mapping features that are up to date. If any specific attacks happen to the network or firewall, it detects them. It has advanced detection capabilities, which include signature-based monitoring that helps us identify the cause and attacks easily.

    Additionally, it has excellent behavioral analytics and they have introduced AI-assisted threat detection.

    ThreatSync NDR is a strong addition to our company's security architecture.

    Using ThreatSync NDR has significantly reduced incidents. We were receiving incidents from the cybersecurity team to block certain IPs or URLs, and that has been reduced because ThreatSync NDR automatically gives us the list of vulnerable or suspicious IPs, which significantly improves our organization's ability to detect and respond to cyber threats.

    What needs improvement?

    There are definitely areas for improvements in ThreatSync NDR, as no product is perfect. Its effectiveness depends on proper network visibility, so if important traffic segments are not mirrored or monitored, detection may be incomplete.

    Regarding improvements needed, ThreatSync NDR can definitely work on the user interface because it is currently a bit complex, and security teams sometimes find it unfamiliar with the behavioral analytics. If they can make it more user-friendly, that would help.

    Regarding ThreatSync NDR's AI capabilities, I think its governance and security are not fully enabled. While AI-assisted threat detections are there, it still requires significant improvements. However, the positive aspect is that it has significantly reduced the manual tasks and work of the security personnel.

    For how long have I used the solution?

    I have been using ThreatSync NDR for three years.

    What do I think about the stability of the solution?

    ThreatSync NDR is definitely stable. We have been using it for quite a while and have not faced any instability issues, such as it going down or providing inaccurate information, so we are quite satisfied with that stability.

    What do I think about the scalability of the solution?

    ThreatSync NDR's scalability is straightforward. Since we have already moved some parts of the firewalls to the cloud, the company provides us the option to scale and it is easy to do that.

    How are customer service and support?

    I would rate customer support as three out of five because it is sometimes difficult to connect with them.

    Which solution did I use previously and why did I switch?

    Currently, we are not considering switching from ThreatSync NDR because it fulfills our requirements.

    What's my experience with pricing, setup cost, and licensing?

    The pricing of ThreatSync NDR is comparatively less expensive than other global players in the market, making it suitable for medium to large enterprises and even for small enterprises. The setup cost is similar to the pricing compared to companies like Palo Alto or Cisco, which is also comparatively less expensive. Regarding licensing, it comes with multiple options such as yearly or five-year plans that you can choose based on affordability.

    What other advice do I have?

    If I am evaluating an NDR solution for medium to large enterprises, especially with our experience using it with our WatchGuard security products, ThreatSync NDR delivers strong visibility, intelligent detection, and practical investigation. I deducted two points because of the areas of improvement I have mentioned, but it has many good visibility and features that are up to standard.

    In terms of accuracy and reliability of output, we can rely on ThreatSync NDR because most of the time it gives us perfect analysis, so it is quite reliable.

    In our organization, ThreatSync NDR is deployed as a hybrid solution, with some firewalls moved to cloud infrastructure and others remaining on-premises. Gradually we are moving everything to the cloud, but as of now, we have a hybrid infrastructure.

    I would recommend using ThreatSync NDR as it is a strong addition to modern security architecture, complementing traditional firewalls and endpoint security by providing continuous visibility, especially firewall security visibility, along with AI-driven threat detection.

    Michael-Foster

    Has improved threat detection and reduced manual workload through real-time cloud insights

    Reviewed on Oct 23, 2025
    Review provided by PeerSpot

    What is our primary use case?

    We use ThreatSync+ NDR for both network monitoring and detection and response.

    What is most valuable?

    ThreatSync+ NDR's most valuable features include its easy setup process, and WatchGuard was available at all times to assist with setup if we encountered any issues.

    ThreatSync+ NDR's real-time cloud threat detection in our Azure workloads has been very effective. While we haven't encountered any major threats, it has detected and immediately stopped smaller security concerns.

    Implementing ThreatSync+ NDR has influenced our business significantly as it provides enhanced security and saves several hours daily by eliminating manual log reviews.

    What needs improvement?

    After using ThreatSync+ NDR for about a year, areas for improvement include the ability to pull logs from other vendors using an API.

    You can use Netflow which gets around this in some cases.

    For how long have I used the solution?

    I've been using ThreatSync+ NDR as part of a combined trial and purchase for approximately a year.

    What do I think about the stability of the solution?

    The stability deserves a perfect rating of 10, as we have experienced no issues thus far.

    What do I think about the scalability of the solution?

    The scalability merits a rating of 10.

    How are customer service and support?

    Our experience with our partner has been positive. We primarily used the partner to purchase the product, as most support comes directly from WatchGuard.

    The vendor support deserves a rating of nine.

    Which solution did I use previously and why did I switch?

    Prior to ThreatSync+ NDR, we relied entirely on manual work for our security operations.

    How was the initial setup?

    ThreatSync+ NDR implementation was straightforward, becoming operational within hours. The initial information collection and additional setup required only a few more hours.

    The easy setup process and vendor support are the most appreciated aspects.

    The solution is simple to maintain due to its cloud-based nature, with most maintenance handled by the vendor.

    What was our ROI?

    The return on investment is approximately 40% because we monitor more than just the UK office, given our global presence.

    Which other solutions did I evaluate?

    WatchGuard suits our needs better because we have WatchGuard firewalls. The initial integration was seamless compared to other vendors we considered, such as CrowdStrike, which cannot properly support our firewall logs.

    What other advice do I have?

    ThreatSync+ NDR has helped identify potential security gaps in my network, and we are currently working on resolving them.

    The impact on incident response time varies. During daytime operations, it reacts instantly with a notification delay of 10 to 20 minutes, while nighttime notifications can have up to eight hours delay.

    ThreatSync+ NDR has enhanced our ability to proactively manage network risks by enabling us to implement extra measures at a lower level based on its findings.

    The compliance reporting tools are comprehensive and meet our requirements. Though we haven't conducted official compliance reporting yet, we anticipate it will save approximately one day of work in report compilation.

    Regarding pricing, WatchGuard rates a nine out of ten.

    We maintain 1,001 licenses for ThreatSync+ NDR, serving approximately 1,000 users, with about 300 local users in the UK.

    ThreatSync+ NDR's effectiveness in identifying weaknesses before exploitation is excellent and very quick.

    I recommend ThreatSync+ NDR to other users based on its rapid deployment and immediate value delivery.

    I rate ThreatSync+ NDR 9 out of 10.