Overview

Product video
Trend Micro, a global cybersecurity leader, helps make the world safe for exchanging digital information. Fueled by decades of security expertise, global threat research, and continuous innovation, our cybersecurity platform protects 500,000+ organizations across cloud, networks, devices, and endpoints
Trend Micro Vision One is a purpose-built threat defense platform that provides added value and new benefits beyond XDR solutions, allowing you to see more and respond faster. Providing deep and broad extended detection and response.
Contact Trend Micro to put together a custom enterprise security solution for your organization! aws.marketplace@trendmicro.comÂ
Looking for our cloud security services platform for workloads, containers, network, serverless functions, storage and open source vulnerabilities? Check out our Trend Micro Cloud One offer.
Highlights
- Enterprise security solutions- including managed XDR. See more, respond faster.
- Increase risk visibility while decreasing response times.
- Greater Security Team Efficiency: one platform to respond faster with less resources and one source of truth
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Dimension | Description | Cost/month |
|---|---|---|
Enterprise Solution | Custom Security solutions - contact for more info and pricing | $10,000.00 |
Dimensions summary
Top-of-mind questions for buyers like you
Vendor refund policy
Refunds are not available at this time.
Custom pricing options
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Resources
Support
Vendor support
Your purchase also includes 24x7 support from Trend Micro. If you experience any issues or have questions, please contact our AWS Cloud Security experts by email at aws.marketplace@trendmicro.com . aws.marketplace@trendmicro.comÂ
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Standard contract
Customer reviews
Centralized threat detection has reduced incident noise and improves endpoint risk visibility for faster response across our environment
What is our primary use case?
I work on Trend Vision One endpoint security in the XDR part. I have been working with Trend Vision One for approximately two years. We manage multiple endpoints, approximately 3,000 endpoints. We collect telemetric data from there and check all the servers in our inventory, whether they are online or offline. We troubleshoot whether there is unusual activity happening on the endpoint. Trend Vision One generates alerts for any suspicious activity, and then we mitigate accordingly. We are using Trend Vision One's sensors on endpoints and servers.
What is most valuable?
The versatility of Trend Vision One is what I like the most; we have a lot of options. The segregation is best, with endpoints divided into separate parts and servers into different parts. The policies are well-figured and well-maintained. We have the threat hunting part, the mitigation part, and the sandboxing capabilities. The areas to explore in Trend Vision One are fabulous. We can divide the endpoint on our own, and the server part is also great. It is very user-friendly, and we can segregate it on our basis. We can generate alerts on the basis of what we want. We have the option of playbooks, which makes it a more user-friendly and understandable environment that gives us exactly what we want.
Trend Vision One is very critical for us because we do not use an EDR tool; we use an XDRÂ tool only, and we have integrated it with the SIM solution. If we did not have Trend Vision One, we would not be receiving the traffic or SIM data, and if there is any individual traffic or any individual behavior in the network, we would not be able to recognize it without it.
The biggest challenge is that users take care of their laptops approximately 80% of the time, but when there is an outbound connection, the user is not able to do anything. The user does not understand if he gets redirected from a legitimate site to another site through backtracking. At that time, the user is not itself involved in this, but Trend Vision One blocks the site on its own. It blocks the traffic on its own, which is the greatest thing and the live working thing with Trend Vision One that helps us.
We have the Cyber Risk Exposure Management capabilities in Trend Vision One. It shows us how much risk is in our environment based on the data it takes from the endpoints and the environment. We check that on a regular basis and develop a report every day on the basis of that. It is very great and gives us much more visualization. We do not need to go anywhere; we just need to open that and check where it is happening, and it gives us the best results.
What needs improvement?
In exposure management, we have multiple parts covering spyware and malware. Approximately six or seven months ago, one of the users was trying to access a website and it was getting linked to another website which was carrying grayware, which is a kind of spyware. Usually, the EDR solution does not track that because it is a web traffic issue, and EDR solutions are not able to track spyware much because it is only a bit suspicious without anything malicious in it. However, in the exposure management part, we received an alert of unusual traffic. We checked the telemetric data and all other things through our VTA and other tools. We did not find much that was malicious, but Trend Vision One was generating an alert again and again. We deep-dived into it and found that the website itself was not malicious, but it was carrying some spyware and was redirecting to something different. That was the best experience I had from the past two years.
When we started to use the product, the policies were not fitted properly. At that time, we used to receive a lot of false positive alerts. After doing some fine-tuning and adjusting some playbooks, the noise has been reduced to 80 to 90 percent. A lot of data has started coming in, and the data we get now is mostly true positive. We get to segregate it easily because the noise is reduced.
The AI of Trend Micro is really very good. If we are getting an alert and analyzing it, people sometimes ask to charge ChatGPT, but that is not good because that data is going to ChatGPT and that is not safe either. If we are asking the AI model of Trend Micro only, that is the best thing because our data is not going to anyone external, and Trend Micro already has that data. At that time, the threat gets less. However, the area where it should improve is that it gets stuck. It does not have that much amount of data. It does not understand easily, and we have to explain it more. I suggest that you make sure to train that model a bit more.
Apart from that, the rest of the things are really very fine. Only the AI part needs to be learned more. The AI should be given more data and should be made to understand more how to work. The rest of things are great, really great.
For how long have I used the solution?
I have been working with Trend Vision One for approximately two years.
What do I think about the stability of the solution?
On Diwali, I do not remember the exact date, but it may have coincided with the AWSÂ outage. We were not able to log into Trend Vision One due to a problem in the back end, which I believe was due to the AWSÂ outage. We were not able to log in for approximately an hour or two. At that time, it caused us a lot of crisis because anything could have happened at that time. Fortunately, everything was on its case after we logged in. No attack happened during that one to two hours, and everything was fixed.
What do I think about the scalability of the solution?
I found Trend Vision One to be very scalable because it is adaptive in nature. It takes care of vulnerabilities on its own. Its core services and AI-driven capabilities are also good. It has threat management on its own, and its effectiveness is also good; it is efficient.
How are customer service and support?
I would rate customer service as 4 out of 10.
How would you rate customer service and support?
Positive
How was the initial setup?
The setup process of Trend Vision One is pretty quite easy. We set up a path and keep the sensor there and then run it as an illustrator and perform some basic steps. We check the telnet of the URL and ping the IPs. If everything is working fine, then the connectivity is perfect and we are good to go.
What about the implementation team?
I work in the Cybersecurity department. We do the deployment and take care of the security part end-to-end. I have not personally done the implementation myself, but I have done this work and I have knowledge about this all.
Which other solutions did I evaluate?
I have used Centra one, which is a very small product compared to Trend Vision One. Trend Vision One has many things in it and takes care of many servers. In Centra one, we have global sites and endpoints, but all the policies are at one place with all the endpoints and servers at one place, which is a bit of a hurdle when we take care of compliance. In Trend Vision One, we have that at different places, which makes it help us a lot. Centra one is an EDR solution that takes care of endpoints only and does not take care of the network. Trend Vision One takes care of the network also. If we have ten laptops in the environment and only eight of them are integrated with the XDR, then the remaining two will sometimes generate an alert on the basis of network. In EDR, if the eight endpoints are integrated, we will get the data of those eight only. That is the plus point here. If there is anything in the network, we will get to know. I also use other India solutions like Sentinel One and CrowdStrike.
What other advice do I have?
I gave my highest consideration to Trend Vision One based on its integration and its user-friendly nature. Everything is segregated properly. The servers we get on the different part, and the endpoints we get on the different part. The alerts for the servers we get on the different part and for the endpoints we get on the different part. One more thing that is great is the workbench part. We have OAT, we have EPR, we have other things, but the best thing about it is its workbench. If we get an alert anywhere in the EDR XDR part and if that is much critical and it is getting an alert again and again, then Trend Vision One on its own generates its workbench. What makes it easy is the check that this one is more critical, and we should go and check this one first and then move to another part. It helps us to reduce the time to check which one we should go first and which we should check second. As an incident responder, it is very good to segregate the criticality of the function. If Trend Vision One gives that on its own, it becomes really very helpful.
We do face vulnerabilities. I know of Zbot, which is one vulnerability. We were getting an OAT alert over that vulnerability, and we were getting many more alerts also. We got approximately 40 to 50 alerts in an hour. For an incident responder, it becomes hard to decide which one to pick first and which one to resolve first. The workbench came here and analyzed all of the data and generated one workbench indicating that we should first go for this host and check the details here because it is more crucial than the other one. Security is never complete, so we can go for the more critical one which will be affecting the business more, and then we should resolve that first and then move to the other part. That is the best thing ever.
Whenever Trend Vision One gets connected to any malicious IPs or URLs or anything, it blocks it first and then generates the alert. If it is not blocked, it generates the alert, and then we analyze the telemetric data and find the URL and IPs from it. We then make sure to block it from our end, not from the XDR only, but from the SIM and other firewalls and all the tools. We do threat hunting from it. We check the telemetric data on a regular basis and find some URLs and IPs, and then we block it from the firewall and our SIM, EDR, XDR, and another tool. What happens from it is we know that this IP is malicious. We get the advisory, we block it from our side, and we give these IPs and URLs to another security tool so they block it. In the future, if a user clicks that malicious IP or visits those malicious links, Trend Vision One will block it on its own.
I would also like to mention that we do isolate the machines from the back end when they are not compliant or when the version is older. After isolation, the network gets completely isolated, the user tends to work faster, and our compliance gets maintained much more easily. The data encryption and access controls across the isolated system for the non-compliance does not get much of the risk, and our data also gets out of the control. The inconsistency of security comes into the point, and then our compliance gets maintained properly, and it is all because of the silo performance. I know that Trend Micro works for the hybrid environment, but right now we do not use that. We have on-premises for all the things. We are thinking to shift over the cloud, but right now we have not shifted.
One thing I would like to suggest is the user login and log out time. If we have ten users integrated with the XDR solution, it should show us when the user was last logged in and when it was logged out. That time should reflect over the console. The blocking capability works most of the time, but it does not work every time, which is a bit problematic.
I rate this product 9 out of 10.
Centralized threat investigations have improved visibility across hybrid environments while complex deployment and lagging dashboards still require attention
What is our primary use case?
What is most valuable?
Trend Vision One has greatly reduced my time to detect and respond to threats. After the implementation, I see how it integrates with the SOC team, and the XDR is so consolidated, making it easier for the SOC team to analyze tickets since it does not export logs from different components. The logs from Trend Vision One are easy to understand, which has helped me reduce false positives and determine whether they are true or not without checking each system individually, which made my job much easier.
The ability of Trend Vision One to provide centralized visibility and management across various protection layers is the best part for me. Many may not appreciate everything under one roof because it creates confusion, but once you get familiar with the dashboard, it becomes easy to navigate. However, it can create confusion because everything is under one roof, showcasing both pros and cons.
What needs improvement?
The UI does lag a bit.
The implementation of Trend Vision One was not easy; it is not a one-click process. I prefer it for larger organizations that can allocate team resources because the implementation can be complex. Resource utilization is quite high, and there is a scarcity of resources focused on Trend Vision One. The availability of troubleshooting guides is not as high as with some other vendors, creating some difficulties, but it is manageable because their support is good. When I open a ticket, they respond quickly.
For how long have I used the solution?
What do I think about the stability of the solution?
What do I think about the scalability of the solution?
How are customer service and support?
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
How was the initial setup?
What about the implementation team?
What was our ROI?
What's my experience with pricing, setup cost, and licensing?
Which other solutions did I evaluate?
What other advice do I have?
The switch to Trend Vision One did reduce risks significantly. Deploying XDR created a spiderweb effect, monitoring every endpoint and node, which mitigated many attacks and helped prevent some.
The built-in AI is important, and I am currently working on certifications from Trend Vision One to better pitch it to AI development companies to demonstrate its benefits. I need hands-on experience with it before I pitch to those companies.
Overall, from implementation to operations, I would rate it a seven.
I do recommend this product; it depends on the case-to-case scenario. If a customer wants everything in a single platform, I recommend Trend Vision One without hesitation. Its good support and lack of major issues influence my decision to pitch it to customers looking for a consolidated platform. My overall review rating for Trend Vision One is seven.
Security monitoring has transformed incident investigations and now detects ransomware and phishing attacks in minutes across hundreds of client environments
What is our primary use case?
Trend Vision One is deployed on-premises and also in the cloud, depending on what clients prefer. Some clients use cloud workload security while others rely on on-premises setups. With more than 200 clients, I log into each client's Trend Vision One setup based on their environment.
What is most valuable?
The time to detect and respond to threats has been reduced significantly. For each alert, I typically need 30 minutes or even 15 minutes to investigate, prepare a report, and send it to clients, especially for high-priority cases. We categorize alerts into P1, P2, P3, and P4, where P1 is critical, and we prioritize those. We focus on critical alerts and can report back within 30 to 15 minutes. Overall, we have managed to reduce our resolution time by approximately 99% due to our multiple teams working 24/7.
What needs improvement?
For how long have I used the solution?
What do I think about the stability of the solution?
What do I think about the scalability of the solution?
How are customer service and support?
How would you rate customer service and support?
Positive
How was the initial setup?
What's my experience with pricing, setup cost, and licensing?
Which other solutions did I evaluate?
What other advice do I have?
The ease of use is quite significant. Trend Vision One simplifies processes for junior analysts, offering clear diagrams of data analysis and providing sandbox analysis. It features a user-friendly design that aids learning for those less familiar with cybersecurity.
There are about 200 clients, and 30 employees monitor Trend Vision One. We maintain a 24/7 operation, with eight people scheduled for morning, afternoon, and night shifts.
Trend Vision One sensors are not critical but are quite easy to use. The sensors collect logs from desktops, laptops, servers, and cloud services, storing them in an encrypted database, making the gathering of data seamless.
I am a partner with Trend Micro and utilize their partner portal. Trend Vision One was purchased through Trend Micro's website and partner portal. If a client intends to create a SOC environment or work with many clients, they can consult with Trend Micro's team to establish a proper SOC setup to serve their clients effectively.
My overall rating for this review is 9.5 out of 10.
Manages cyber risk across endpoints and email while simplifying detection and response workflows
What is our primary use case?
I have been working with Trend Micro for the past six years. I started with Apex One and Worry-Free, which evolved to Trend Vision One . Trend Vision One is a collaborative XDR platform designed to bring all security solutions such as mail security, cloud security, endpoint security, and identity security together and manage them from a single console. That is the main goal of Trend Vision One.
From my end, I have deployed email security, endpoint security, XDRÂ , and web security from Trend Vision One. We are using Trend Vision One with both business essentials and pro bundle.
Trend Vision One has two kinds of solutions for endpoint security: standard endpoint protection for desktop machines and server and workload protection for existing Linux servers, Windows servers, or even containers and workloads in the cloud where you can install agents for those containers as well. These are the deployments which we have done for endpoint security.
What is most valuable?
Attack discovery and attack surface discovery are valuable features. Every organization has endpoints, and no organization will be willing to do a full discovery or testing on all those endpoints or devices. Attack discovery helps us know which endpoints we have with Trend Micro, what vulnerabilities and loopholes are available in the endpoints, and provides insights into our attack surface.
I have used the cyber risk exposure management product completely except for security awareness. I have used data security posture, identity security posture, and network security functionalities. I have not ensured cloud security yet, but we are yet to have hands-on experience with that. I have showcased these functionalities to customers and conducted many POCs for new clients covering cyber risk exposure management, XDR, email security, endpoint security, and network security. I have explained how well Trend Vision One captures the correct data.
The response time after detection is approximately three hours.
What needs improvement?
If Trend Vision One can improve the response time and playbooks, particularly with more customizable playbooks, it would be greatly helpful. We have raised feature requests to Trend Micro. If they have more predefined playbooks and more options for response management, it would be beneficial because that is what end users are expecting.
As a reseller, we are dealing with the pain because customers are asking why response is not being taken even though Trend Vision One detects suspicious files. In some cases, I follow best practices by updating playbooks at regular intervals, but that is a manual process. An automated process to take appropriate action for suspicious and malicious files would be necessary. The response part might be improved to provide better value.
For how long have I used the solution?
What do I think about the stability of the solution?
What do I think about the scalability of the solution?
How are customer service and support?
The integration part is good. They also have an AI platform built into the console which provides more details in layman's terms. When explaining an attack to management, you can communicate it to a CIO in technical terms because they are from a technical background and will understand all the details. However, when taking this to a CEO or CFO who are not technical persons with backgrounds based on industry, you should explain it in simple terms. The AI integration with Trend Vision One gives the details in a much simpler way in layman's understanding. That feature is good.
How would you rate customer service and support?
Neutral
How was the initial setup?
What was our ROI?
For ROI in email security, they provide BEC, which is the best ROI for every customer. If there is an outage that occurs in Microsoft or AWSÂ or any other cloud platform, there is an email continuity platform for emails. That is good ROI.
From a deployment perspective, it shows around fifty to sixty percent. The impact given to the business in terms of real impact is up to ten to twenty percent.
What's my experience with pricing, setup cost, and licensing?
Which other solutions did I evaluate?
What other advice do I have?
If the containment functionality gets automated, it would be on a better note. The response part, if improved, will be very helpful. From a deployment perspective, it shows around fifty to sixty percent.
Trend Vision One is fully on the cloud with no on-premise option. They tie up with multiple cloud vendors, but they provide a SaaS platform built by Trend Micro. Trend Micro itself is hosted on some AWSÂ servers, which is what I have heard, but I do not want to comment on that.
I would rate this review an eight.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Built faster threat response and improved visibility with real-time monitoring and flexible deployment
What is our primary use case?
A few use cases for Trend Vision One include end user installation by my company distributor company. We sell Trend Micro products, focusing on dealers rather than end user sales. My role is in technical engineering, particularly in Turkey, where I handle all Trend Micro product installation and training.
What is most valuable?
Trend Vision One allows us to monitor attacks in real time, which is a significant benefit. We can quickly see where the attack is coming from. Trend Vision One enables us to use different products with a flexible license. For example, if a customer is using endpoint security and wants to switch to another solution, they can instantly use a different Trend Micro product, such as email.
Trend Vision One has helped to reduce the time to detect and respond to different threats, as it can respond to attacks very quickly. With playbook templates, in cases of recurring attacks, responses can be made quickly using predefined playbooks.
Trend Vision One has helped to reduce noise from false positives. There have been false positives before, but it was due to the customer not telling us which app they were using. Best practice configurations must be applied properly to avoid such issues.
Trend Vision One helps customers consolidate the use of security vendors and reduce silos by offering one platform for all product management.
What needs improvement?
In comparison to Trellix, one disadvantage of Trend Micro is the DLPÂ feature. Trend Micro has a light DLPÂ , while Trellix offers a perfect DLP. Trend Micro's DLP is busy and does not use OCR.
In the future, I would like to see Trend Vision One improved by making it easier if the endpoint had a single agent. Currently, there are two agents for different antivirus and EDR solutions, making it seem advantageous to have just one.
DLP can be developed further, and the platform could benefit from additional IPS products.
For how long have I used the solution?
I have been working with Trend Vision One for three years.
What do I think about the stability of the solution?
Trend Vision One is stable, and there has been a problem once so far, which was quickly resolved with very fast problem-solving capabilities.
What do I think about the scalability of the solution?
When needing to scale Trend Vision One, I find it very easy to do so.
How are customer service and support?
Local support for Trend Micro is available in Turkey, including both local and global support teams.
I would rate the technical support of Trend Micro as an eight on a scale of one to ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Before Trend Micro, I worked with other solutions such as Trellix and McAfee. Trellix had performance problems, but with Trend Micro, there are no issues, and it offers the best performance compared to other products such as Trellix's EDR and proxy.
How was the initial setup?
Setting up Trend Vision One is straightforward, but someone with IT knowledge should handle it since it requires technical know-how.
What was our ROI?
Switching to Trend Vision One reduced our risk by 90 percent.
What's my experience with pricing, setup cost, and licensing?
Trend Vision One is a price performance product compared to competitors. On-premises solutions are more expensive than local solutions, and it is more affordable than leading competitors.
What other advice do I have?
Sensor coverage is critical for my customers' networks because we can see instant attacks on the network and computers.
It is very important that Trend Vision One has AI built into its platform as we currently use it, and it provides great convenience in understanding events.
My organization uses Trend Vision One for consolidated security across hybrid environments, as a single screen simplifies management, making it very easy to understand with one platform for all products.
For other organizations considering Trend Vision One, I suggest that using NDR for visibility is nice and easy.
I would rate this review a nine out of ten.