Ransomware playbooks have strengthened protection and improve threat detection and response
What is our primary use case?
My main use case for Trend Vision One is for ransomware protection, user behavior analysis, and protection. I use Trend Vision One for threat detection and response, which helps me with investigation and response. It helps to integrate with the existing infrastructure as my main use case for Trend Vision One. Data loss prevention has been a valuable use case with the endpoint security as a feature that stands out to me. The top security challenges in my industry include improving the cyber risk posture and ransomware protection, and Trend Vision One is helping me address them, especially for ransomware protection.
What is most valuable?
I find threat detection and response and remediation using playbooks the most useful features Trend Vision One offers me.
In a case of a ransomware incident, the playbook in Trend Vision One immediately contained the infection by isolating the endpoint, demonstrating how those playbooks and the detection and response features help me in my day-to-day work.
Trend Vision One has positively impacted my organization by specifically helping improve security posture and response time for threat handling, as well as improving our cyber risk score.
Trend Vision One has made managing security easier for me compared to earlier by providing centralized visibility and management across protection layers.
What needs improvement?
The area where I think Trend Vision One can improve is the technical support. Trend Vision One should speed up the response time for the support tickets that have been opened regarding needed improvements.
For how long have I used the solution?
I have been using Trend Vision One for almost one year now.
What other advice do I have?
Trend Vision One should speed up the response time for the support tickets that have been opened regarding needed improvements. I rate Trend Vision One a nine out of ten because Trend Vision One can improve the technical support. I am using Trend Vision One sensors on the endpoint, as well as on the endpoint and workloads. Covering the endpoint is very critical for my organization's network because the endpoint is one of the most important areas to be protected. Trend Vision One has helped reduce my time to detect and respond to threats; in my previous studies, I found the detection and response has come down from weeks to only days. My overall review rating for Trend Vision One is nine.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Centralized threat investigations have improved visibility across hybrid environments while complex deployment and lagging dashboards still require attention
What is our primary use case?
Trend Vision One provides a platform where everything is consolidated. I started with the proxy and then moved on to the
XDR, which
Trend Vision One provided. We collaborated with them, had POCs for the customer, and they liked it, going ahead with it. The main scenario was to integrate with the cloud security platform since the customer had a hybrid platform and needed one-point access to view the whole infrastructure in one place rather than having different solutions for each cloud and device.
What is most valuable?
The best feature of Trend Vision One that I like the most is the investigation graph, which was the main point demonstrated during the POC. If an attack happens and data is exfiltrated or an attacker finds a backdoor into the system, I need a graph of it rather than going to third-party sources. Trend Vision One
XDR provides this graph, which helps visualize and make RCA and incident understanding easier, especially when presenting the findings to management.
Trend Vision One has greatly reduced my time to detect and respond to threats. After the implementation, I see how it integrates with the SOC team, and the XDR is so consolidated, making it easier for the SOC team to analyze tickets since it does not export logs from different components. The logs from Trend Vision One are easy to understand, which has helped me reduce false positives and determine whether they are true or not without checking each system individually, which made my job much easier.
The ability of Trend Vision One to provide centralized visibility and management across various protection layers is the best part for me. Many may not appreciate everything under one roof because it creates confusion, but once you get familiar with the dashboard, it becomes easy to navigate. However, it can create confusion because everything is under one roof, showcasing both pros and cons.
What needs improvement?
Aside from the investigation graph, I find that sometimes when we collect data, the UI seems a bit laggish and is not that interactive during that process. When we extract logs, it can be a bit slow, but everything else is acceptable.
The UI does lag a bit.
The implementation of Trend Vision One was not easy; it is not a one-click process. I prefer it for larger organizations that can allocate team resources because the implementation can be complex. Resource utilization is quite high, and there is a scarcity of resources focused on Trend Vision One. The availability of troubleshooting guides is not as high as with some other vendors, creating some difficulties, but it is manageable because their support is good. When I open a ticket, they respond quickly.
For how long have I used the solution?
I have been using Trend Vision One for two years in my previous organization, and right now, I am implementing it as a system integrator at our customer location.
What do I think about the stability of the solution?
Stability-wise, I feel there are times when it is not a stable solution, but I also had another client where it worked smoothly, and I did not have to revisit it often. However, in hybrid setups, I do face multiple issues, but the on-premises platform works quite well.
What do I think about the scalability of the solution?
Trend Vision One is scalable. We have deployed it for the maximum users, around two hundred to two hundred fifty, and it handles that well.
How are customer service and support?
For Trend Vision One's technical support, I would rate it around seven point five to eight, so let us give it an eight.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
I have worked with SentinelOne and multiple other solutions, and from a user experience perspective, I find SentinelOne to be more convenient compared to Trend Vision One. However, for consolidation, the fact that I can find everything under one roof is a plus for Trend Vision One, despite my preference for ease of user experience in other products such as SentinelOne.
How was the initial setup?
The implementation of Trend Vision One was not easy; it is not a one-click process. I prefer it for larger organizations that can allocate team resources because the implementation can be complex.
What about the implementation team?
In my organization, there are only four Trend Vision One specialists, including me.
What was our ROI?
I would estimate that overall, I have seen approximately a twenty percent return on investment.
What's my experience with pricing, setup cost, and licensing?
I would not say Trend Vision One is cheap; I always recommend it for mid-size to large-sized enterprises, not for SMBs, as I have other solutions suited for them. I have never pitched Trend Vision One to SMBs because I believe it fits mid-sized to large-sized businesses better.
Which other solutions did I evaluate?
I have worked with SentinelOne and multiple other solutions, and from a user experience perspective, I find SentinelOne to be more convenient compared to Trend Vision One.
What other advice do I have?
I actually believe that it has reduced false positives by more than fifteen to twenty percent.
The switch to Trend Vision One did reduce risks significantly. Deploying XDR created a spiderweb effect, monitoring every endpoint and node, which mitigated many attacks and helped prevent some.
The built-in AI is important, and I am currently working on certifications from Trend Vision One to better pitch it to AI development companies to demonstrate its benefits. I need hands-on experience with it before I pitch to those companies.
Overall, from implementation to operations, I would rate it a seven.
I do recommend this product; it depends on the case-to-case scenario. If a customer wants everything in a single platform, I recommend Trend Vision One without hesitation. Its good support and lack of major issues influence my decision to pitch it to customers looking for a consolidated platform. My overall review rating for Trend Vision One is seven.
Manages cyber risk across endpoints and email while simplifying detection and response workflows
What is our primary use case?
I work with Trellix, Trend Micro, Fortinet, and Netrix for
DLP solutions. For Netrix
DLP, I use Forcepoint, and for email security, I use Barracuda.
I have been working with Trend Micro for the past six years. I started with Apex One and Worry-Free, which evolved to Trend Vision One. Trend Vision One is a collaborative XDR platform designed to bring all security solutions such as mail security, cloud security, endpoint security, and identity security together and manage them from a single console. That is the main goal of Trend Vision One.
From my end, I have deployed email security, endpoint security, XDR, and web security from Trend Vision One. We are using Trend Vision One with both business essentials and pro bundle.
Trend Vision One has two kinds of solutions for endpoint security: standard endpoint protection for desktop machines and server and workload protection for existing Linux servers, Windows servers, or even containers and workloads in the cloud where you can install agents for those containers as well. These are the deployments which we have done for endpoint security.
What is most valuable?
The detection part works well for me. The response part, including automatic containment, requires creating playbooks. Even though I create them, I have faced many threat attack scenarios where detection pops up, but the appropriate response action is not being taken.
Attack discovery and attack surface discovery are valuable features. Every organization has endpoints, and no organization will be willing to do a full discovery or testing on all those endpoints or devices. Attack discovery helps us know which endpoints we have with Trend Micro, what vulnerabilities and loopholes are available in the endpoints, and provides insights into our attack surface.
I have used the cyber risk exposure management product completely except for security awareness. I have used data security posture, identity security posture, and network security functionalities. I have not ensured cloud security yet, but we are yet to have hands-on experience with that. I have showcased these functionalities to customers and conducted many POCs for new clients covering cyber risk exposure management, XDR, email security, endpoint security, and network security. I have explained how well Trend Vision One captures the correct data.
The response time after detection is approximately three hours.
What needs improvement?
Visibility is good, but Trend Vision One can improve the response part. Compared to other vendors like SentinelOne or CrowdStrike, all of them are providing detection and response methodology. However, Trend Vision One provides more visibility but has limitations on the response part.
If Trend Vision One can improve the response time and playbooks, particularly with more customizable playbooks, it would be greatly helpful. We have raised feature requests to Trend Micro. If they have more predefined playbooks and more options for response management, it would be beneficial because that is what end users are expecting.
As a reseller, we are dealing with the pain because customers are asking why response is not being taken even though Trend Vision One detects suspicious files. In some cases, I follow best practices by updating playbooks at regular intervals, but that is a manual process. An automated process to take appropriate action for suspicious and malicious files would be necessary. The response part might be improved to provide better value.
For how long have I used the solution?
I have been working with Trend Micro for the past six years.
What do I think about the stability of the solution?
Trend Vision One is stable. Before Trend Vision One, Trend Micro had Apex One and Worry-Free products for endpoint security that were not stable. However, after Trend Vision One was introduced, I do not see any stability issues.
What do I think about the scalability of the solution?
Scalability is good. Previously, it was good because they were using a credit system where they would give credits and based on the credits we could allocate our own licenses. Right now they have removed this feature, so we are yet to do some testing on that. The credit system was effective because we had flexible licensing and scalability, and we were able to use the resources when and if it was necessary.
How are customer service and support?
Two factors are important: the time to give the first response and the technical ability of the engineers. I heard that they have laid off many old employees and senior employees.
The integration part is good. They also have an AI platform built into the console which provides more details in layman's terms. When explaining an attack to management, you can communicate it to a CIO in technical terms because they are from a technical background and will understand all the details. However, when taking this to a CEO or CFO who are not technical persons with backgrounds based on industry, you should explain it in simple terms. The AI integration with Trend Vision One gives the details in a much simpler way in layman's understanding. That feature is good.
How would you rate customer service and support?
How was the initial setup?
The installation is easy. Even for Linux and Mac machines, it is just two or three commands.
What was our ROI?
ROI is absolutely achievable, especially with Trend Vision One and server Trend Vision One platform. Previously, they had MSVA, which was a virtual appliance that on-premises clients needed for mail security. After they came up with the cloud email security solution, many customers are feeling relief, and the latency is much better when compared to an on-premise solution.
For ROI in email security, they provide BEC, which is the best ROI for every customer. If there is an outage that occurs in Microsoft or AWS or any other cloud platform, there is an email continuity platform for emails. That is good ROI.
From a deployment perspective, it shows around fifty to sixty percent. The impact given to the business in terms of real impact is up to ten to twenty percent.
What's my experience with pricing, setup cost, and licensing?
This is quite affordable. It is not that expensive.
Which other solutions did I evaluate?
We buy from Trend Micro. Trend Vision One definitely falls in the leader quadrant in Gartner, and its capabilities are good. It can be in that leader quadrant. For an endpoint security solution, managing attacks is the key thing. It is not about daily activities like what policies and functionalities are provided. These matter, but at the end of the day, if an attack is going to happen, the end user will assess the support of Trend Vision One and the response part of Trend Vision One. These two parameters are going to be assessed, and based on these two parameters, any quadrant achievement from labs like Gartner or Forrester will be based on these two parameters only.
What other advice do I have?
For standard endpoint protection, if it is a detection, it is a detection. When compared to CrowdStrike, Trend Vision One creates much less false positives. There is no big noise on this, but that is one way to consider it. False positives do come, and it is completely based on the configuration which we do. On the initial phase of the deployment, after a month or two, we keep it in detection mode, and after that, we pursue the prevention mode so that blocking is enabled.
If the containment functionality gets automated, it would be on a better note. The response part, if improved, will be very helpful. From a deployment perspective, it shows around fifty to sixty percent.
Trend Vision One is fully on the cloud with no on-premise option. They tie up with multiple cloud vendors, but they provide a SaaS platform built by Trend Micro. Trend Micro itself is hosted on some AWS servers, which is what I have heard, but I do not want to comment on that.
I would rate this review an eight.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)