TrendAI Vision One™ (PAYG)
Automated remediation has transformed incident triage and now streamlines threat hunting
What is our primary use case?
My main use case for TrendAI Vision One is for incident triage and response management.
A specific example of how I use it for incident triage and response management is the elimination of collateral display and low log management from emails. This is how it helped.
The automated remediation triggers automated commitment actions, isolating infection of the endpoint. This is beneficial and helps significantly.
What is most valuable?
The best features TrendAI Vision One offers include the powerful threat hunting and AI security capabilities, among the top features mentioned. The AI security analysis allows input of plain language requests for effective endpoint command analysis. Threat hunting assists in identifying alerts. Additionally, real-time inspection of LLM interactions helps secure operations within private and public environments. The centralized Vision One console hosted in a cloud-native environment also contributes greatly by ensuring robust security coverage.
What needs improvement?
TrendAI Vision One can improve in control responsiveness, particularly in navigating through heavy analytics interfaces like workbench, where execution graphs can experience noticeable latency. This occurs during multi-complex layers correlation and high volume of queries load. Secondly, I suggest improving license and credit allocation transparency.
A deep ecosystem integration with deeper non-Trend native telemetry ingestion would help significantly.
For how long have I used the solution?
I have used TrendAI Vision One for almost two years.
What do I think about the stability of the solution?
TrendAI Vision One is stable.
What do I think about the scalability of the solution?
TrendAI Vision One's scalability is quite good; it benefits from cloud-native elasticity, which I use most often. The centralized Vision One console runs in the cloud-native environment, hosted on a public backbone like AWS and Azure. It is very easy for me to automatically scale based on log flow.
How are customer service and support?
The customer support has been acceptable.
Which solution did I use previously and why did I switch?
I previously used a different solution, Sophos, but it was too costly and very limited compared to TrendAI Vision One.
What was our ROI?
I have seen a return on investment financially, with up to a 79% reduction in security costs and a 70% faster incident investigation and response time.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing has been quite acceptable, especially with the flexibility of having a credit-based licensing architecture by using TrendFlex.
Which other solutions did I evaluate?
Before choosing TrendAI Vision One, I did not evaluate other options.
What other advice do I have?
My advice to others looking into using TrendAI Vision One is to utilize the powered API connectors, link your SaaS with Office 365 and endpoint security, and evaluate it thoroughly before proceeding. I would rate this product a 10.
Centralized XDR has improved investigations and now simplifies endpoint and email threat response
What is our primary use case?
My main use case for TrendAI Vision One is endpoint security, server security, or network security.
For endpoint server security, we have been using it as an essential endpoint security module where we deploy an agent on the client machines and maintain or monitor application control, firewall, anti-malware, spam, web reputation, spam reputation, and other similar capabilities, which is the same for servers including intrusion prevention and detection and response.
Furthermore, for the servers, we use it on-prem and on-cloud, specifically on-prem deep security, which we can migrate and integrate to TrendAI Vision One cloud.
What is most valuable?
In my experience, one of the best features of TrendAI Vision One is the XDR capability, which involves a centralized console collecting logs from multiple sources, correlating them, and telling us a story.
TrendAI Vision One positively impacts my organization because it is the tool we utilize more than any other cybersecurity-providing tool, as it has a very user-friendly console that I can easily explain to clients, allowing them to understand and carry forward investigations.
For specific outcomes or metrics showcasing how TrendAI Vision One has benefited my organization, it includes playbooks that run on the workbench's correlations, correlating all log sets, pinpointing exact alerts so that the SOC team cannot waste more time and can simply investigate and address them.
What needs improvement?
An area for improvement for TrendAI Vision One that I notice is on the support side; if any support issues arise or bugs I report can be remediated or addressed more promptly.
Additionally, regarding needed improvements, I pointed out to Trend Micro an issue related to email security, where an inbound protection policy I created, aimed at handling email attachments above a certain size, resulted in all emails being quarantined, and I reported that TrendAI Vision One lacked the capability to adequately manage this.
For how long have I used the solution?
I have been using TrendAI Vision One for more than five years.
What do I think about the stability of the solution?
TrendAI Vision One is stable in my experience, but some clients using data centers hosted in the Gulf region, mainly Dubai, face downtime issues.
What do I think about the scalability of the solution?
In terms of scalability, it performs well for endpoints, servers, email, network level, and sandboxing.
How are customer service and support?
I would rate customer support as average, about four out of five. On a scale of one to ten, I would rate customer support an eight.
Which solution did I use previously and why did I switch?
I have not switched from a different solution since my company provides multiple solutions as per client needs, leveraging various security vendors while finding TrendAI Vision One's features user-friendly and easy to understand.
How was the initial setup?
My advice to others looking into using TrendAI Vision One is that it is very user-friendly and easy to deploy, requiring some firewall rules, and you can deploy an agent to easily access control and investigate.
What about the implementation team?
We are using TrendAI Vision One sensors on endpoints and at the network level as well.
This coverage is critical for my organization's network because the sensors collect XDR telemetry and forward it to the main console, TrendAI Vision One.
What was our ROI?
I have seen a return on investment, as I can affirm that employees save time dealing with complexities from other products due to TrendAI Vision One's ability to address many issues at the investigation, deployment, and analysis levels.
What's my experience with pricing, setup cost, and licensing?
Regarding my experience with pricing, setup cost, and licensing, I am uncertain about the exact price but note that TrendAI Vision One has shifted to a credit-based license model allowing flexible use across solutions.
Which other solutions did I evaluate?
Before choosing TrendAI Vision One, we evaluated other options including Kaspersky for endpoint security and FortiGate EDR.
What other advice do I have?
The governance and security of TrendAI Vision One's AI capabilities are actually good; I notice it provides alerts regarding exposure management and threats, along with compliance scores, overall scores, and risk scores to help mitigate and address concerns.
In our industry, the top security challenges include securing endpoints against ransomware and malware attacks, which TrendAI Vision One covers well, along with email security.
My impressions of TrendAI Vision One's ability to provide centralized visibility and management across protection layers are very good, as it collects data from all products and resources, correlating it to tell a cohesive story.
TrendAI Vision One helps consolidate our use of security vendors and reduces silos, covering key areas such as endpoint encryption, compliance, and vulnerabilities, which I validate and remediate.
The importance of TrendAI Vision One having AI built into its platform is high, as it helps explain alerts, attack phases, and process chains with ease. I would rate this review as eight out of ten.
Unified security platform has reduced risk exposure and simplified threat detection and response
What is our primary use case?
TrendAI Vision One provides multiple security solutions including email security, endpoint security, XDR, and identity security, as well as cyber risk exposure management.
For a Sri Lanka organization requesting a tender related to endpoint detection and response (EDR) solutions for their workstations and servers, I proposed TrendAI Vision One Standard Endpoint Protection.
I also use TrendAI Vision One email security for customer requirements, such as securing their email traffic from attackers, and I have proposed an email security solution as well.
What is most valuable?
The best feature that is trending is cyber risk exposure management, which can be used to identify the risk score of the whole organization's security threat landscape.
In customer environments where separate solutions exist to secure the environment, I integrate those third-party solutions with TrendAI Vision One, which analyzes the whole logs and shows a detailed view of the risk related to misconfigurations, vulnerabilities, and incidents captured from those third-party logs.
When a customer comes with security solutions for their security landscape, including endpoint security, email security, and network security, I can propose a single solution to cater to all those requirements.
The single solution approach allows me to avoid a siloed architecture. When I log into the solutions, I can use a single dashboard to navigate all security solutions, including endpoint security, email security, and cyber risk exposure management. Customers can identify their organization's risk and minimize that risk by following the remediation actions shown in TrendAI Vision One platform.
What needs improvement?
When it comes to challenges, I am using the Singapore region tenant, and I suggest adding more regions that come with the solution in the future.
Regarding improvements, I believe they need to develop some dashboards with correlations; that would be better.
For how long have I used the solution?
I have been using TrendAI Vision One for nearly three-plus years.
What do I think about the stability of the solution?
TrendAI Vision One is stable.
What do I think about the scalability of the solution?
TrendAI Vision One now uses credits to manage the licensing part, so if I have free credits, I can utilize them for additional security requirements in TrendAI Vision One.
How are customer service and support?
Customer support is reliable. I have access to a support portal where I can raise support tickets according to severity levels, which are responded to quickly based on that severity.
Which solution did I use previously and why did I switch?
I started with TrendAI Vision One solution and have exclusively used that.
What was our ROI?
After deploying our solutions for customers, I find that there is no need for multiple admins to configure and monitor, as everything works independently from the configuration policies.
Which other solutions did I evaluate?
In the market, there are solutions such as Microsoft clouds or SentinelOne. As we are distributors for Trend Micro, I considered Trend Micro for our company domain.
What other advice do I have?
They are looking for new solutions with AI involvement while improving their policy levels and dashboards. They are also integrating their AI Chat companion into TrendAI Vision One console.
Coverage is very critical for my organization's network because the threat landscape is increasing today, and attackers are using new techniques to compromise organizations. This is very critical for security solutions, and TrendAI provides security solutions to minimize the threat landscape.
When it comes to remote code executions, I can use endpoint detection and response solutions. For spam and phishing mails, I can utilize TrendAI Vision One email security solution.
These solutions are fully cloud-based, allowing access to the console from anywhere in the world using secure communications through the HTTPS protocol. If deployed as on-premise, I can use secure web gateways to communicate with that cloud console.
TrendAI Vision One helps consolidate my use of security vendors and reduces silos since it provides multiple security solutions through one single dashboard, including email security, endpoint security, network security, and identity security.
In today's threat landscape, it is important that TrendAI Vision One has AI built into its platform because I cannot rely solely on signatures, especially with attacks such as fileless attacks. I need AI and ML techniques to identify the behavior of these attacks.
I use TrendAI Vision One in my hybrid environments to address security requirements, including Azure VMs where I have deployed TrendAI Vision One Server security agents, as well as on-premise deployments such as fingerprint and file servers to secure critical assets.
TrendAI Vision One helps reduce my time to detect and respond to threats significantly due to its massive threat intelligence and the Zero-Day Initiatives team focusing on zero-day attacks and providing the best possible mitigation actions.
When it comes to attacks, the solution carries out response actions quickly. I have not heard of any breaches from TrendAI Vision One platform.
After analyzing logs from third-party solutions, TrendAI Vision One maps the risks and provides mitigation actions to reduce those risks. By following those steps, I can minimize risks.
I use the cyber risk exposure management capabilities, which show me, for instance, what vulnerable software is installed on endpoints, helping me to identify versions, vulnerabilities, and risk scores. From there, I can determine necessary actions such as patching or protecting with endpoint security solutions.
I rate this product nine out of ten based on my overall experience.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Central monitoring has reduced investigation time and now protects endpoints from ransomware
What is our primary use case?
As an endpoint protection app, TrendAI Vision One allows us to monitor and protect our 100 or so devices centrally and easily while working in tandem with Windows Defender to block viruses, ransomware, and other malicious code from damaging devices or stealing our data.
We used TrendAI Vision One last quarter when it flagged a suspicious email attachment that bypassed our gateway, and the XDR correlation linked it to an endpoint trying to reach a C2 server and auto-isolated it. It saved us from a possible ransomware incident and made investigation much faster because all the logs were in one place.
We use TrendAI Vision One endpoint security on all our Windows workstations in our organization, and we use the product as our malware, stroke, antivirus software, and as an EDR. I am able to use the dashboard to monitor our workstations and make sure everything is staying healthy and running smoothly.
We are using TrendAI Vision One sensors mainly on endpoints, Windows laptops, and some Linux servers, and we also have it connected to email for Microsoft 365 to scan inbound attachments and links, as well as on our cloud workloads in AWS to monitor EC2 instances. This coverage is very critical for our organization's network because most attacks we see start from email phishing and endpoints.
What is most valuable?
Some of the best features that I really love in TrendAI Vision One include the centralized console, light performance consumption, and comprehensive security suite.
The centralized console of TrendAI Vision One allows for easy updates on all our computers within the network, and these features are very particularly useful for us because we are not in the same network as the console, so we can still receive updates directly from TrendAI Vision One server. With the comprehensive security suite offered by TrendAI Vision One, I appreciate that it provides peace of mind by offering protection against various threats such as viruses and malware.
I would also add that the interface is very clean and intuitive, making it very easy to use even for non-technical users. The endpoint protection has been great.
TrendAI Vision One has helped us because we have not had any viruses in the past six years we have used this, which is a good sign. It works well when paired with MS Defender, allowing us to use both simultaneously. It is a great tool because it has been really effective, and although I do not have hard numbers, the product does a great job of keeping us running and not having to worry about cyber-related issues.
AI is very important for us in TrendAI Vision One because it helps prioritize security alerts, identify suspicious patterns, and reduce the time our team spends manually analyzing large volumes of security data. It enables us to respond to potential threats faster and focus our resources on the highest risk incidents.
What needs improvement?
One improvement I would suggest for TrendAI Vision One is the friendly interaction with the call center regarding the support, license updates, and related matters.
Additionally, I believe the malware scanning can be a little bit too strict at times, preventing the use of needed files.
TrendAI Vision One can sometimes be very hard to log out of.
For how long have I used the solution?
My experience with TrendAI Vision One extends five to six years.
What do I think about the stability of the solution?
TrendAI Vision One has been very stable and reliable for day-to-day security operations with consistent monitoring and few disruptions.
What do I think about the scalability of the solution?
TrendAI Vision One scales well as our environment grows, allowing us to extend protection across additional endpoints, servers, cloud workloads, and network assets while maintaining centralized visibility and management, which helps us avoid adding separate security tools as we expand.
How are customer service and support?
Customer support for TrendAI Vision One is very responsive and knowledgeable, providing quick help when we encounter configuration or troubleshooting issues.
Which solution did I use previously and why did I switch?
We previously relied on a mix of separate endpoint and network security tools, and we switched to TrendAI Vision One to consolidate those capabilities, reduce tool silos, and provide our team with better centralized visibility and faster incident response.
How was the initial setup?
The pricing for TrendAI Vision One is very reasonable for the coverage provided, and the setup was straightforward while the licensing model is flexible enough for us to scale protection as our environment grows without adding unnecessary complexity.
What was our ROI?
We have seen a return on investment mainly through time savings rather than headcount reduction. Centralized monitoring and automated alert prioritization have reduced manual investigation time by roughly thirty to forty percent, allowing our security team to respond to incidents faster and spend more time on high-value work.
What's my experience with pricing, setup cost, and licensing?
The pricing for TrendAI Vision One is very reasonable for the coverage provided, and the setup was straightforward while the licensing model is flexible enough for us to scale protection as our environment grows without adding unnecessary complexity.
Which other solutions did I evaluate?
Before choosing TrendAI Vision One, we evaluated other options including Microsoft Defender XDR, CrowdStrike Falcon, and SentinelOne.
What other advice do I have?
My advice for others looking into using TrendAI Vision One is to start with the core integrations, define clear security policies, and gradually expand coverage as your team becomes familiar with the platform.
TrendAI Vision One provides our team with a centralized view across endpoints, servers, email, and network activity, making it easier to correlate alerts, investigate threats, and manage security responses without switching between multiple tools.
TrendAI Vision One has helped us reduce security silos by bringing together endpoint network, email, and workload protection into a more centralized platform, which provides our team with a consistent view of threats, reduces the need to switch between multiple consoles, and speeds up investigation and incident response.
We use TrendAI Vision One to consolidate security across our hybrid environment, which gives us a centralized view of endpoints, servers, workloads, and network activity. This improves risk management by helping us identify threats earlier, prioritize high-risk incidents, and respond consistently across different environments.
TrendAI Vision One is deployed in our organization via public cloud SaaS because it is a SaaS solution. I would rate this product a five out of five.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Unified security console has simplified endpoint protection and improved user awareness
What is our primary use case?
TrendAI Vision One is used primarily in endpoint security, email security, mobile security, cyber risk exposure management, and XDR.
For mobile security, TrendAI Vision One is used for mobile threat detection as an MTD solution, and it allows enrollment of both BYOD devices and company-owned devices while providing protection for mobile devices. The solution supports Android, iOS, and similar platforms.
My main use case for TrendAI Vision One is endpoint security, and I am also familiar with mobile security. TrendAI Vision One functions as a full-fledged next-generational antivirus solution for users, and it prevents malware, viruses, and similar threats. The solution has many machine learning features as well.
What is most valuable?
The best feature in my experience with TrendAI Vision One is that when implementing endpoint security and email security for an organization, there is no need to use multiple consoles. With TrendAI Vision One, a single console provides access to all these solutions, making it a comprehensive platform that includes all of the solutions. This consolidated approach is the main usefulness for users.
TrendAI Vision One can integrate with third-party solutions as well. Regarding usability, I credit TrendAI Vision One since it uses a credit-based model. Additionally, the licensing for TrendAI Vision One is very flexible for users and organizations.
TrendAI Vision One is a full-fledged platform for combining multiple solutions, making it easy for administrators to navigate and configure the console. It provides comprehensive security for devices and users, and the flexible licensing is very useful for organizations.
Regarding the platform's ability to provide centralized visibility and management across protection layers, the centralized visibility is really helpful for administrators to configure settings without having to navigate multiple consoles. This streamlines issue resolution and ensures that protection is covered from multiple aspects within the same console.
TrendAI Vision One has helped consolidate the use of security vendors and reduced silos significantly.
What needs improvement?
TrendAI Vision One has recently added updates and new features, which can be a bit confusing. However, those features are helpful but not organized clearly. When an administrator logs into the console, it can be difficult to find some features because of the organization.
Regarding documentation improvements for TrendAI Vision One, it would be easier with the TrendAI companion. Most of the documentation and answers can be found, but it would be helpful if the company could provide more data sheets or whitepapers as well as configuration support.
Additional improvements needed for TrendAI Vision One include issues where the console sometimes indicates that services are not available. I believe these issues are being improved, but they do not constantly display as expected.
For how long have I used the solution?
I have been using TrendAI Vision One for more than one and a half years.
What other advice do I have?
TrendAI Vision One provides more security for users regarding detections and security incidents, such as warnings on unsecured websites and detecting viruses. The solution has really reduced the number of detections over time while providing full protection for users.
The top security challenge in the industry is user awareness since users are often unaware of the dangers posed by certain applications and websites. TrendAI Vision One helps address this issue by providing user awareness training, such as phishing campaigns that inform users to avoid threats.
My main advice for others considering TrendAI Vision One is that it provides both basic and advanced protection for every user, while the licensing is very flexible compared to other solutions. With TrendAI Vision One, most features are included in basic licensing, unlike other solutions that require payment for simple features.
TrendAI Vision One is a great solution for users requiring advanced protection. Over the past 20 years, it has provided as many features as possible for every user, so I can confidently recommend it for organizations. I would rate this solution an 8 out of 10.
Centralized threat visibility has improved response times and simplifies incident investigations
What is our primary use case?
The main use case for TrendAI Vision One in my organization is that we manage client assets such as endpoints, servers, and email.
What is most valuable?
TrendAI Vision One has positively impacted my organization. TrendAI Vision One has helped us reduce the time to detect and respond to threats, as with the correlation of events across various security layers, I benefit from a complete view of incidents from a single platform without the need to jump around.
The investigation and alert prioritization tools expedite analysis significantly, automating many detection and containment tasks even before the analyst reviews the event viewer.
What needs improvement?
I think there are quite a few things that could improve TrendAI Vision One. The console or the graphical interface of the console is a bit complex, with several sections for each module where information is spread out among them and some is repeated across sections. Console updates change the layout of sections and modules significantly, without any notice or alert informing me of these changes. The APIs section is also a bit confusing, as I understand there is a general API, but then each module has its own, and it is not very well explained when to use one or the other.
Vendor support can feel random; depending on who you get, resolving an incident can be easy or very difficult. Some support members do not have sufficient knowledge about the platform or the relevant concepts, and response times can be very variable—sometimes they can respond the next day or it can take a week. If it is a serious incident, you might be stuck for the entire week. Report generation is a bit basic; the reports are simple and I cannot customize them effectively. Licensing is also confusing because we seem to have the same license duplicated with similar functionality for different teams, which is not clearly reflected.
At the Endpoint Security level, the agents being used in TrendAI Vision One have several problems; we frequently encounter incidents where the agent consumes resources uncontrollably. Many servers or endpoints can manage this easily, but some have limited resources and processing power. It often interferes with the company's internal processes, creating delays, communication issues, and data loss, forcing us to disable modules on machines. Furthermore, support for different operating systems is limited; many clients use devices with older, unsupported operating systems, resulting in fewer modules being available.
At the Cloud level, I also experience several issues with Cloud Email Gateway Protection in TrendAI Vision One, such as problems with DKIM validation where the platform often fails to provide clear information on whether the cause is a poorly made signature or DNS resolution failures; sometimes the header indicates the absence of a DKIM signature when there actually is one. Additionally, the API for Cloud Email Gateway Protection has limitations, such as a 72-hour log retrieval limit that feels excessive. I also cannot filter mail traffic by user or specific address and must retrieve the entire domain's data. This means pulling in around 300,000 emails for a 24-hour period only to filter it myself, which consumes resources and time. Certain functions are available in the console but not through the API, which I find critical. Lastly, we have faced issues where emails that should bypass Inbound Protection based on our defined rules still get blocked, which does not make much sense.
For how long have I used the solution?
I have been using TrendAI Vision One for one year and five months.
What do I think about the stability of the solution?
Overall, it has proven to be a pretty stable platform. The main services, dashboards, APIs, and security modules generally provide consistent availability and performance. Of course the are some occasional issues, specially during maintenance, service updates, or when processing a high volume of data, but these don't significantly affected the overall reliability of the platform in our experience.
What do I think about the scalability of the solution?
It offers a very strong scalability, particularly for enterprise environments with a large number of users, endpoints, and security events. The platform also provides a centralized visibility of the security layers and products, which makes it really easy to manage a growin environment without increasing the operational complexity.
How are customer service and support?
4
Which solution did I use previously and why did I switch?
No
How was the initial setup?
I didn't took part on that process
What about the implementation team?
I didn't took part on that process
What was our ROI?
We have, but I can't share any data
What's my experience with pricing, setup cost, and licensing?
I didn't took part on that process
Which other solutions did I evaluate?
I didn't took part on that process
What other advice do I have?
The features of TrendAI Vision One are really useful and have improved my work. The main security challenges in my sector include managing diverse threats. I have covered everything I had to say and do not remember anything else important that I have left out. My review rating for TrendAI Vision One is 8.
Centralized security visibility has improved threat response while kernel-level impact needs work
What is our primary use case?
TrendAI Vision One has helped my customers consolidate their use of security vendors and reduce silos. If you purchase multiple technologies or products provided by TrendAI, that unified visibility console gives you full visibility across all the products provided by TrendAI across the network. This facilitates management and policy deployment for customers.
My customers do not purchase TrendAI Vision One directly from TrendAI or from any third party. TrendAI is not considering selling directly to end users unless it is a big corporate arrangement or an OEM agreement. Usually, sales should occur through a reseller, then a distributor, or directly through a distributor to TrendAI.
What is most valuable?
User behavior analysis is the most important feature of TrendAI Vision One, in addition to the zero-day feature within that application. When customers upsell or add an XDR license, the product becomes a closed, solid endpoint protection solution that wins against the competition.
TrendAI Vision One has helped my customers consolidate their use of security vendors and reduce silos. If you purchase multiple technologies or products provided by TrendAI, that unified visibility console gives you full visibility across all the products provided by TrendAI across the network. This facilitates management and policy deployment for customers.
What needs improvement?
TrendAI Vision One should learn from its competitors that having everything managed in one single platform gives strength to the product itself. However, instead of focusing on easing access for administrators, they should pay more attention to development itself and staying up to date. There was an initiative in the early days called Zero-Day, which means that before a threat is announced, they would hire specialists who immediately learn about threats and push updates directly to the product.
Customers are protected even before the threat is announced. Currently, the Zero-Day initiative is not as active as it once was.
Additional features I expect from TrendAI Vision One in the future to make it more competitive could be more technical in nature. A product working on the kernel level of a PC, machine, or server consumes significantly more resources than other products that work on runtime memory. If an application is attached to the operating system of the machine itself, it consumes more resources from the PC or server than running that product on the memory level. Memory-level products read all running activities across the memory when the machine is on, and when they detect malicious activity, they cut or end the session, which is lighter on the operating system and does not consume many resources.
For how long have I used the solution?
I have been working with TrendAI Vision One for around five years.
How are customer service and support?
TrendAI Vision One's technical support is adequate because they recently implemented a good methodology of supporting their customers. They initiated a Major Service Center divided across the globe, with a dedicated support center for the Middle East, another for Europe, a third one in the American market, and a final one in Singapore dedicated to supporting Far East customers. This has enhanced their support.
What gives more strength to their products is that they enable business partners, distributors, resellers, and others with sufficient tools to identify problems and provide first and second level support themselves. When an engineering intervention is needed, the case can be escalated to their support team, which is more effective than the old model. They initiated this Major Service Center two or three years ago, which makes it easier for customers and enhances support.
What other advice do I have?
My impressions of TrendAI's ability to provide centralized visibility and management across protection layers are positive. They had, in the early beginning, a unified management console called Apex One. The commercial name has changed over time, and it is now called Apex Central. TrendAI Vision One Apex Central gives full visibility across the customer network, including all solutions provided by TrendAI, with unified visibility, policy deployment, and plug-in extensibility.
TrendAI Vision One has helped my customers reduce their time to detect and respond to threats. There have been a few incidents where intruders could get into the network even while the product was deployed. TrendAI ranks third globally as an endpoint or EDR solution. There are pros and cons to the product. I would rate TrendAI Vision One between seven and eight out of ten.
My customers may use the Cyber Risk Exposure Management capabilities of TrendAI Vision One. However, I do not think they are using or activating that feature because it can conflict with other products. Most banking customers prefer not to activate EDR and endpoint protection from the same vendor, as a compromise could become a significant issue. Therefore, I did not use this feature.
Unified security has improved threat prevention and simplifies managing endpoints and email
What is our primary use case?
My main use case for TrendAI Vision One is catching threats across all XDR channels like email, endpoint, Windows server, and Linux server, collecting the alerts so that we can defend against attacks using these channels.
My main use case for TrendAI Vision One is the protection of server-side and email-side infrastructure, where we can use capabilities across all channels. We can prevent attacks and monitor endpoints, check reports, and review workbenches, alerts, and the MITRE attack framework.
Prevention of attacks is more important than just catching threats. The deep security module with IPS protects servers from zero-day vulnerabilities. All alerts and prevention-related information are available in the report.
TrendAI Vision One has different modules, such as the attack surface module, which enables me to see alerts from sites, networks, and email. I can manage my attack surface and understand how to protect internal data more easily with Trend Micro.
What is most valuable?
The best features TrendAI Vision One offers include strong endpoint protection, endpoint asset management, and the ability to monitor and respond to actions. It prevents issues from the email side and different channels, allows me to start antivirus protection, and makes managing endpoints, computers, and servers straightforward.
TrendAI Vision One positively impacts my organization by providing a budget-friendly solution for security products. Since I am paying for security licenses, I can be confident in my protection with Trend Micro's monthly payment options, including managed detection and response for more secure protection.
These features make my job easier because I can create my own directory structure, establish policies for different organizational units, and easily enable or disable different antivirus modules, such as scheduled scans or script protections, making management straightforward.
What needs improvement?
TrendAI Vision One can be improved in some areas. I wish the scan modules were better when it comes to patching and following critical zero-day threats. A different dashboard for security assessments would be beneficial and make the solution stronger.
TrendAI Vision One needs additional improvements, but it is already very useful due to the AI and Trend Micro combination.
For how long have I used the solution?
I have been working with cybersecurity for five years.
What do I think about the stability of the solution?
TrendAI Vision One is very stable and easy to manage.
What do I think about the scalability of the solution?
The scalability of TrendAI Vision One is good and can support thousands of clients or servers.
How are customer service and support?
Customer support for TrendAI Vision One is very good, and we can reach the support portal and receive help easily.
Which solution did I use previously and why did I switch?
I previously used different solutions such as Symantec and Kaspersky, but they were less complex and provided fewer security modules compared to Trend Micro.
What was our ROI?
I have not explicitly calculated the money saved, but it is clear that using one solution on one platform combines the capabilities of different email gateways and network NDRs into one, which offers perhaps two to three times the cost-benefit for overall savings.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing for TrendAI Vision One is that it is easy to manage, and we can take credits.
Which other solutions did I evaluate?
I evaluated other options such as CrowdStrike before choosing TrendAI Vision One.
What other advice do I have?
My impressions of TrendAI Vision One's ability to provide centralized visibility and management across protection layers are positive, especially regarding XDR, Deep Discovery inspection, and email inspection.
TrendAI Vision One has helped consolidate my use of security vendors and reduced silos by providing email protection and MDR capabilities, making it very useful without the need to purchase numerous solutions.
It is important for my organization that TrendAI Vision One has AI built into its platform because it enhances our security capabilities significantly.
My organization uses TrendAI Vision One for consolidated security across hybrid environments, which has improved our ability to manage risk by offering solutions that protect both cloud and on-premises services.
TrendAI Vision One has helped reduce my time to detect and respond to threats, though I do not quantify the exact reduction.
My advice to others looking into TrendAI Vision One is that if it is important to manage email, attack surfaces, server-side IPS, and zero-day protection, it is the best choice with Trend Micro. I would rate this product an eight out of ten.
Centralized threat views have improved detection and response but support and AI still need work
What is our primary use case?
We work for Tenable, AWS, Azure, GCP, and CrowdStrike, and we are also working on Trend Micro, though we are currently in a transition phase with a few Trend Micro products.
We work on TrendAI Vision One as a customer. We are using TrendAI Vision One for overall threat management, including endpoint XDR, Apex Central, and Trend Micro web proxy, which is now ZTNA. Overall, I would say we use it from an overall threat management perspective.
What is most valuable?
I like that TrendAI Vision One is a single pane of glass, which gives me near real-time security posture information of my environment, and it correlates everything. Since we have most of our items on Trend Micro, it correlates logs and gives me a real security posture of my environment.
TrendAI Vision One provides a single platform that gives me a deep dive of my environment. If I want to know something about any of my servers, I can go to the deepest level and see what software is installed and how it is working. The deep drill capability is something I really appreciate because I can exactly find out what I need. I also really like that it has more than 800 playbooks that are preventive.
Whenever any type of attack or malicious activity occurs, they preventively work and block malicious activity. When I mention playbooks, whenever any threat activity is activated or just starts, they prevent it at the beginning. This definitely prevents and reduces my mean time to detect and mean time to respond.
If something happens that I have not enabled any playbook, then it gives me an email and alert, and I have a SOC monitoring team that helps me respond to this. Overall, it helps a lot in both mean time to detect, mean time to prevent, and response.
It has helped me to reduce silos, as it gives me visibility into what is inside my environment. Sometimes we provide admin access to users to do their jobs, and during that time, they install other software and many other things. TrendAI Vision One also discovers across my cloud because it has integration with cloud environments.
Whenever I have some rules and configurations in place, if something is not discovered by IT and created by someone, it really helps me a lot to reduce the silos.
What needs improvement?
TrendAI Vision One is still struggling in some areas. There are a few false positives that are not actually false positives at all but have been reported multiple times to the Trend Micro team, and they have not been rectified, which is sometimes irritating.
I would say TrendAI Vision One is expensive as of now because the competitive market in India has some better solutions at a lower cost.
From the technical side, the innovation in TrendAI Vision One is less. When you configure it at the back end, for example, it says that it will run X and Y rules, but sometimes they do not work, and that happens across multiple places in the platform.
The major disadvantages of TrendAI Vision One would be the CREM feature, the price being slightly pricey, and the backend rules sometimes having problems. There is one more thing to mention: support is not good.
AI built into TrendAI Vision One is something that is a fancy feature, but they have not integrated it effectively.
For how long have I used the solution?
We have been using TrendAI Vision One since 2020, and during this time, it has changed. It has been with platform TrendAI Vision One, and then it became TrendAI.
What do I think about the stability of the solution?
TrendAI Vision One is stable.
What do I think about the scalability of the solution?
Scaling up and down with TrendAI Vision One is manageable.
How are customer service and support?
Support for TrendAI Vision One does not respond adequately. They respond, but they do not understand, and when they do understand, they do not resolve the issues. The support experience is inadequate.
How was the initial setup?
The installation of TrendAI Vision One is straightforward, and I have never faced any issues.
What was our ROI?
I would say that in the last four years since I joined this organization in 2021, as TrendAI Vision One has been innovated and matured, there is tremendous time savings, more than 50% saving of time when we conduct security activities.
I would say the risk reduction from switching to TrendAI Vision One is quite good because we have everything integrated here. It is difficult to say in percentage, but the incidents have reduced significantly, achieving a coverage of about 7 to 8 out of 10.
Which other solutions did I evaluate?
TrendAI Vision One is more expensive than its competitors.
What other advice do I have?
There are a few false positives that are not actually false positives at all but have been reported multiple times to the Trend Micro team, and they have not been rectified. Sometimes these false positives are irritating and cause disruptions in the workflow. We are working with AWS and GCP. I have not purchased any TrendAI Vision One products from the AWS marketplace, as I think they have discontinued one product I purchased from AWS, which was Trend Micro Cloud Conformity. My overall review rating for TrendAI Vision One is 7 out of 10.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Centralized detection has reduced false positives and improves ransomware and email threat response
What is our primary use case?
A common use case for TrendAI Vision One is ransomware detection and response, and we also use it for business email compromise. Our SOC team uses it for advanced threat hunting and insider threat detections.
Recently, my team used TrendAI Vision One for ransomware detection and response when a user executed a malicious attachment, leading to the detection of suspicious process executions. TrendAI Vision One helps us by correlating emails with endpoints, identifying host details, network activity, user device activity, and infected sources, allowing for quick resolution of threats in the organization.
We have also been using TrendAI Vision One for identifying suspicious or compromised emails and insider threat detections, which aids us in quickly identifying and investigating malicious emails.
What is most valuable?
TrendAI Vision One offers excellent extended detection and response capabilities through EDR and XDR solutions, as it is a complete package for organizational threat protection across email, endpoints, cloud networks, servers, and data centers. It helps us quickly identify attacks and provides deep insights into attacker movements as well as a centralized investigation workbench from a single dashboard.
Having everything in one dashboard allows our SOC team to quickly identify details across the network or organization level, such as the number of created tickets, false positives, true positives, actions taken, SLAs, threat metrics, and attack path details. It reduces alert fatigue for SOC analysts by providing a consolidated view of all details across the organization.
TrendAI Vision One has positively impacted our organization by identifying real-time threats and proactively isolating threats while alerting the SOC team for further investigations and remediation actions.
Since implementing TrendAI Vision One, it has reduced noise from false positive alerts by 80% and enabled the SOC team to focus on true positives, thus improving incident response and operational efficiency. TrendAI Vision One is highly reliable; it provides centralized visibility across protection layers and is stable and scalable, making it a suitable solution for organizations looking for thorough threat detection and response capabilities.
What needs improvement?
I believe that if the reporting features of TrendAI Vision One could be improved, it would help SOC analysts retrieve comprehensive reports detailing true positive incidents, top email threats, quarantined emails, and common malware, enhancing our analytics capabilities.
The TrendAI Vision One support system is not very good. They charge extra for premium support, while basic support does not adequately assist with investigations and troubleshooting. Improvements in this area are needed, and there should also be enhancements in third-party integrations to reduce alert noise and false positives.
TrendAI Vision One's governance and security capabilities are excellent, and while the security is always very good, they can still improve on compliance and regulations.
If they fix automated root cause analysis reports and AI-generated incident summaries, it can enhance capabilities further and reduce investigation times.
For how long have I used the solution?
I have been using TrendAI Vision One for more than two years.
What do I think about the stability of the solution?
TrendAI Vision One is stable.
What do I think about the scalability of the solution?
TrendAI Vision One is highly scalable as per our requirements, as user licenses can be improved if we have a greater number of users.
How are customer service and support?
The customer support is not very good, and they need to improve their premium license support.
Which solution did I use previously and why did I switch?
Previously we were using a different endpoint solution due to setup cost and support issues, so we switched to TrendAI Vision One for better SOC capabilities for threat detection.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing was very good. The top leadership is engaged in identifying pricing and licensing features, although licensing renewal is challenging and the setup cost can be high, but it remains manageable for quality solutions.
Which other solutions did I evaluate?
We evaluated other options such as FireEye Helix, Symantec, and Microsoft Sentinel during our assessment process.
What other advice do I have?
My advice to others looking into using TrendAI Vision One is to definitely proceed with this solution as it is a complete package for SOC teams regarding threat identification and remediation, although there is room for improvement in support. This review has a rating of 9.