Sign in Agent Mode
Categories
Your Saved List Become a Channel Partner Sell in AWS Marketplace Amazon Web Services Home Help

Reviews from AWS customer

12 AWS reviews

External reviews

81 reviews
from and

External reviews are not included in the AWS star rating for the product.


4-star reviews ( Show all reviews )

    reviewer2783034

Centralized threat detection has reduced incident noise and improves endpoint risk visibility for faster response across our environment

  • November 27, 2025
  • Review provided by PeerSpot

What is our primary use case?

I work on Trend Vision One endpoint security in the XDR part. I have been working with Trend Vision One for approximately two years. We manage multiple endpoints, approximately 3,000 endpoints. We collect telemetric data from there and check all the servers in our inventory, whether they are online or offline. We troubleshoot whether there is unusual activity happening on the endpoint. Trend Vision One generates alerts for any suspicious activity, and then we mitigate accordingly. We are using Trend Vision One's sensors on endpoints and servers.

What is most valuable?

The versatility of Trend Vision One is what I like the most; we have a lot of options. The segregation is best, with endpoints divided into separate parts and servers into different parts. The policies are well-figured and well-maintained. We have the threat hunting part, the mitigation part, and the sandboxing capabilities. The areas to explore in Trend Vision One are fabulous. We can divide the endpoint on our own, and the server part is also great. It is very user-friendly, and we can segregate it on our basis. We can generate alerts on the basis of what we want. We have the option of playbooks, which makes it a more user-friendly and understandable environment that gives us exactly what we want.

Trend Vision One is very critical for us because we do not use an EDR tool; we use an XDR tool only, and we have integrated it with the SIM solution. If we did not have Trend Vision One, we would not be receiving the traffic or SIM data, and if there is any individual traffic or any individual behavior in the network, we would not be able to recognize it without it.

The biggest challenge is that users take care of their laptops approximately 80% of the time, but when there is an outbound connection, the user is not able to do anything. The user does not understand if he gets redirected from a legitimate site to another site through backtracking. At that time, the user is not itself involved in this, but Trend Vision One blocks the site on its own. It blocks the traffic on its own, which is the greatest thing and the live working thing with Trend Vision One that helps us.

We have the Cyber Risk Exposure Management capabilities in Trend Vision One. It shows us how much risk is in our environment based on the data it takes from the endpoints and the environment. We check that on a regular basis and develop a report every day on the basis of that. It is very great and gives us much more visualization. We do not need to go anywhere; we just need to open that and check where it is happening, and it gives us the best results.

What needs improvement?

In exposure management, we have multiple parts covering spyware and malware. Approximately six or seven months ago, one of the users was trying to access a website and it was getting linked to another website which was carrying grayware, which is a kind of spyware. Usually, the EDR solution does not track that because it is a web traffic issue, and EDR solutions are not able to track spyware much because it is only a bit suspicious without anything malicious in it. However, in the exposure management part, we received an alert of unusual traffic. We checked the telemetric data and all other things through our VTA and other tools. We did not find much that was malicious, but Trend Vision One was generating an alert again and again. We deep-dived into it and found that the website itself was not malicious, but it was carrying some spyware and was redirecting to something different. That was the best experience I had from the past two years.

When we started to use the product, the policies were not fitted properly. At that time, we used to receive a lot of false positive alerts. After doing some fine-tuning and adjusting some playbooks, the noise has been reduced to 80 to 90 percent. A lot of data has started coming in, and the data we get now is mostly true positive. We get to segregate it easily because the noise is reduced.

The AI of Trend Micro is really very good. If we are getting an alert and analyzing it, people sometimes ask to charge ChatGPT, but that is not good because that data is going to ChatGPT and that is not safe either. If we are asking the AI model of Trend Micro only, that is the best thing because our data is not going to anyone external, and Trend Micro already has that data. At that time, the threat gets less. However, the area where it should improve is that it gets stuck. It does not have that much amount of data. It does not understand easily, and we have to explain it more. I suggest that you make sure to train that model a bit more.

Apart from that, the rest of the things are really very fine. Only the AI part needs to be learned more. The AI should be given more data and should be made to understand more how to work. The rest of things are great, really great.

For how long have I used the solution?

I have been working with Trend Vision One for approximately two years.

What do I think about the stability of the solution?

On Diwali, I do not remember the exact date, but it may have coincided with the AWS outage. We were not able to log into Trend Vision One due to a problem in the back end, which I believe was due to the AWS outage. We were not able to log in for approximately an hour or two. At that time, it caused us a lot of crisis because anything could have happened at that time. Fortunately, everything was on its case after we logged in. No attack happened during that one to two hours, and everything was fixed.

What do I think about the scalability of the solution?

I found Trend Vision One to be very scalable because it is adaptive in nature. It takes care of vulnerabilities on its own. Its core services and AI-driven capabilities are also good. It has threat management on its own, and its effectiveness is also good; it is efficient.

How are customer service and support?

I would rate customer service as 4 out of 10.

How would you rate customer service and support?

Positive

How was the initial setup?

The setup process of Trend Vision One is pretty quite easy. We set up a path and keep the sensor there and then run it as an illustrator and perform some basic steps. We check the telnet of the URL and ping the IPs. If everything is working fine, then the connectivity is perfect and we are good to go.

What about the implementation team?

I work in the Cybersecurity department. We do the deployment and take care of the security part end-to-end. I have not personally done the implementation myself, but I have done this work and I have knowledge about this all.

Which other solutions did I evaluate?

I have used Centra one, which is a very small product compared to Trend Vision One. Trend Vision One has many things in it and takes care of many servers. In Centra one, we have global sites and endpoints, but all the policies are at one place with all the endpoints and servers at one place, which is a bit of a hurdle when we take care of compliance. In Trend Vision One, we have that at different places, which makes it help us a lot. Centra one is an EDR solution that takes care of endpoints only and does not take care of the network. Trend Vision One takes care of the network also. If we have ten laptops in the environment and only eight of them are integrated with the XDR, then the remaining two will sometimes generate an alert on the basis of network. In EDR, if the eight endpoints are integrated, we will get the data of those eight only. That is the plus point here. If there is anything in the network, we will get to know. I also use other India solutions like Sentinel One and CrowdStrike.

What other advice do I have?

I gave my highest consideration to Trend Vision One based on its integration and its user-friendly nature. Everything is segregated properly. The servers we get on the different part, and the endpoints we get on the different part. The alerts for the servers we get on the different part and for the endpoints we get on the different part. One more thing that is great is the workbench part. We have OAT, we have EPR, we have other things, but the best thing about it is its workbench. If we get an alert anywhere in the EDR XDR part and if that is much critical and it is getting an alert again and again, then Trend Vision One on its own generates its workbench. What makes it easy is the check that this one is more critical, and we should go and check this one first and then move to another part. It helps us to reduce the time to check which one we should go first and which we should check second. As an incident responder, it is very good to segregate the criticality of the function. If Trend Vision One gives that on its own, it becomes really very helpful.

We do face vulnerabilities. I know of Zbot, which is one vulnerability. We were getting an OAT alert over that vulnerability, and we were getting many more alerts also. We got approximately 40 to 50 alerts in an hour. For an incident responder, it becomes hard to decide which one to pick first and which one to resolve first. The workbench came here and analyzed all of the data and generated one workbench indicating that we should first go for this host and check the details here because it is more crucial than the other one. Security is never complete, so we can go for the more critical one which will be affecting the business more, and then we should resolve that first and then move to the other part. That is the best thing ever.

Whenever Trend Vision One gets connected to any malicious IPs or URLs or anything, it blocks it first and then generates the alert. If it is not blocked, it generates the alert, and then we analyze the telemetric data and find the URL and IPs from it. We then make sure to block it from our end, not from the XDR only, but from the SIM and other firewalls and all the tools. We do threat hunting from it. We check the telemetric data on a regular basis and find some URLs and IPs, and then we block it from the firewall and our SIM, EDR, XDR, and another tool. What happens from it is we know that this IP is malicious. We get the advisory, we block it from our side, and we give these IPs and URLs to another security tool so they block it. In the future, if a user clicks that malicious IP or visits those malicious links, Trend Vision One will block it on its own.

I would also like to mention that we do isolate the machines from the back end when they are not compliant or when the version is older. After isolation, the network gets completely isolated, the user tends to work faster, and our compliance gets maintained much more easily. The data encryption and access controls across the isolated system for the non-compliance does not get much of the risk, and our data also gets out of the control. The inconsistency of security comes into the point, and then our compliance gets maintained properly, and it is all because of the silo performance. I know that Trend Micro works for the hybrid environment, but right now we do not use that. We have on-premises for all the things. We are thinking to shift over the cloud, but right now we have not shifted.

One thing I would like to suggest is the user login and log out time. If we have ten users integrated with the XDR solution, it should show us when the user was last logged in and when it was logged out. That time should reflect over the console. The blocking capability works most of the time, but it does not work every time, which is a bit problematic.

I rate this product 9 out of 10.


    Pavan_Sharma

Security monitoring has transformed incident investigations and now detects ransomware and phishing attacks in minutes across hundreds of client environments

  • November 26, 2025
  • Review provided by PeerSpot

What is our primary use case?

My use case for Trend Vision One is in a SOC, specifically for Security Operation Monitoring. I am a SOC analyst responsible for over 200 clients. Trend Vision One works effectively for us because it alerts us when suspicious activities occur, such as ransomware attacks. For example, if a possible spear-phishing attack happens where a phishing email comes into our organization, Trend Vision One monitors it as a SIEM tool. It captures logs from servers, desktops, and users, generating alerts for suspicious activities. If a malicious phishing email arrives, we investigate where it originated, such as if it came from external sources in London or Germany. We contact our clients to determine if they have any relationships with those regions, and if not, we block the malicious phishing email.

Trend Vision One is deployed on-premises and also in the cloud, depending on what clients prefer. Some clients use cloud workload security while others rely on on-premises setups. With more than 200 clients, I log into each client's Trend Vision One setup based on their environment.

What is most valuable?

The best features of Trend Vision One include its ability to provide virtual patching. Virtual patching protects an organization's systems. For instance, if a hacker attempts a ransomware attack, Trend Vision One detects vulnerabilities in the system, such as outdated Windows 10 versions. If ransomware is launched, Trend Vision One informs the hacker that the system is already patched, preventing the attack. Additionally, it alerts developers to update any outdated applications or network settings.

The time to detect and respond to threats has been reduced significantly. For each alert, I typically need 30 minutes or even 15 minutes to investigate, prepare a report, and send it to clients, especially for high-priority cases. We categorize alerts into P1, P2, P3, and P4, where P1 is critical, and we prioritize those. We focus on critical alerts and can report back within 30 to 15 minutes. Overall, we have managed to reduce our resolution time by approximately 99% due to our multiple teams working 24/7.

What needs improvement?

We need to improve the reports generated in Trend Vision One. Currently, we prepare our own reports after alerts are triggered, which is time-consuming. It would be beneficial if Trend Vision One offered automated reports summarizing alerts over a specified period, such as one month, which would simplify reporting to clients.

For how long have I used the solution?

I have been using Trend Vision One for approximately two years, and I have experience working with Trend Vision One.

What do I think about the stability of the solution?

Trend Vision One has a stability rating of ten out of ten.

What do I think about the scalability of the solution?

I find the scalability of Trend Vision One to be ten out of ten. As a partner, Trend Micro provides educational resources that allow users to learn through various templates and videos available on their portal.

How are customer service and support?

I rate the technical support from Trend Micro as a nine out of ten.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup process for Trend Vision One typically takes about two to three days but can vary. It depends on the client's infrastructure and whether they require support from their network team or need cloud integration. Smaller organizations might complete deployment in one or two days, while larger organizations could take about 10 to 15 days.

What's my experience with pricing, setup cost, and licensing?

Trend Vision One is expensive. While it provides extensive services for clients, including integration capabilities, the overall cost is high. It is an XDR, and while some other products such as Trend Micro Deep Security and Apex Central are somewhat cheaper, the comprehensive nature of Trend Vision One contributes to its higher pricing.

Which other solutions did I evaluate?

Compared to other products in the market such as CrowdStrike or Azure Sentinel, Trend Vision One excels. While Azure Sentinel relies on complex KQL for deeper analysis, Trend Vision One provides accessible insights for both junior and experienced analysts, making it comprehensible even to those new to cybersecurity.

What other advice do I have?

The false positives have been reduced by about 60 to 70%. Many clients experience low-category alerts. For instance, if someone such as Olga logs into her laptop and enters the wrong password multiple times, Trend Vision One triggers an alert for suspicious login attempts. We hold all related logs and investigate but often find these to be legitimate activities, which we confirm before closing them as false positives.

The ease of use is quite significant. Trend Vision One simplifies processes for junior analysts, offering clear diagrams of data analysis and providing sandbox analysis. It features a user-friendly design that aids learning for those less familiar with cybersecurity.

There are about 200 clients, and 30 employees monitor Trend Vision One. We maintain a 24/7 operation, with eight people scheduled for morning, afternoon, and night shifts.

Trend Vision One sensors are not critical but are quite easy to use. The sensors collect logs from desktops, laptops, servers, and cloud services, storing them in an encrypted database, making the gathering of data seamless.

I am a partner with Trend Micro and utilize their partner portal. Trend Vision One was purchased through Trend Micro's website and partner portal. If a client intends to create a SOC environment or work with many clients, they can consult with Trend Micro's team to establish a proper SOC setup to serve their clients effectively.

My overall rating for this review is 9.5 out of 10.


    GANESAN K

Manages cyber risk across endpoints and email while simplifying detection and response workflows

  • November 24, 2025
  • Review from a verified AWS customer

What is our primary use case?

I work with Trellix, Trend Micro, Fortinet, and Netrix for DLP solutions. For Netrix DLP, I use Forcepoint, and for email security, I use Barracuda.

I have been working with Trend Micro for the past six years. I started with Apex One and Worry-Free, which evolved to Trend Vision One. Trend Vision One is a collaborative XDR platform designed to bring all security solutions such as mail security, cloud security, endpoint security, and identity security together and manage them from a single console. That is the main goal of Trend Vision One.

From my end, I have deployed email security, endpoint security, XDR, and web security from Trend Vision One. We are using Trend Vision One with both business essentials and pro bundle.

Trend Vision One has two kinds of solutions for endpoint security: standard endpoint protection for desktop machines and server and workload protection for existing Linux servers, Windows servers, or even containers and workloads in the cloud where you can install agents for those containers as well. These are the deployments which we have done for endpoint security.

What is most valuable?

The detection part works well for me. The response part, including automatic containment, requires creating playbooks. Even though I create them, I have faced many threat attack scenarios where detection pops up, but the appropriate response action is not being taken.

Attack discovery and attack surface discovery are valuable features. Every organization has endpoints, and no organization will be willing to do a full discovery or testing on all those endpoints or devices. Attack discovery helps us know which endpoints we have with Trend Micro, what vulnerabilities and loopholes are available in the endpoints, and provides insights into our attack surface.

I have used the cyber risk exposure management product completely except for security awareness. I have used data security posture, identity security posture, and network security functionalities. I have not ensured cloud security yet, but we are yet to have hands-on experience with that. I have showcased these functionalities to customers and conducted many POCs for new clients covering cyber risk exposure management, XDR, email security, endpoint security, and network security. I have explained how well Trend Vision One captures the correct data.

The response time after detection is approximately three hours.

What needs improvement?

Visibility is good, but Trend Vision One can improve the response part. Compared to other vendors like SentinelOne or CrowdStrike, all of them are providing detection and response methodology. However, Trend Vision One provides more visibility but has limitations on the response part.

If Trend Vision One can improve the response time and playbooks, particularly with more customizable playbooks, it would be greatly helpful. We have raised feature requests to Trend Micro. If they have more predefined playbooks and more options for response management, it would be beneficial because that is what end users are expecting.

As a reseller, we are dealing with the pain because customers are asking why response is not being taken even though Trend Vision One detects suspicious files. In some cases, I follow best practices by updating playbooks at regular intervals, but that is a manual process. An automated process to take appropriate action for suspicious and malicious files would be necessary. The response part might be improved to provide better value.

For how long have I used the solution?

I have been working with Trend Micro for the past six years.

What do I think about the stability of the solution?

Trend Vision One is stable. Before Trend Vision One, Trend Micro had Apex One and Worry-Free products for endpoint security that were not stable. However, after Trend Vision One was introduced, I do not see any stability issues.

What do I think about the scalability of the solution?

Scalability is good. Previously, it was good because they were using a credit system where they would give credits and based on the credits we could allocate our own licenses. Right now they have removed this feature, so we are yet to do some testing on that. The credit system was effective because we had flexible licensing and scalability, and we were able to use the resources when and if it was necessary.

How are customer service and support?

Two factors are important: the time to give the first response and the technical ability of the engineers. I heard that they have laid off many old employees and senior employees.

The integration part is good. They also have an AI platform built into the console which provides more details in layman's terms. When explaining an attack to management, you can communicate it to a CIO in technical terms because they are from a technical background and will understand all the details. However, when taking this to a CEO or CFO who are not technical persons with backgrounds based on industry, you should explain it in simple terms. The AI integration with Trend Vision One gives the details in a much simpler way in layman's understanding. That feature is good.

How would you rate customer service and support?

Neutral

How was the initial setup?

The installation is easy. Even for Linux and Mac machines, it is just two or three commands.

What was our ROI?

ROI is absolutely achievable, especially with Trend Vision One and server Trend Vision One platform. Previously, they had MSVA, which was a virtual appliance that on-premises clients needed for mail security. After they came up with the cloud email security solution, many customers are feeling relief, and the latency is much better when compared to an on-premise solution.

For ROI in email security, they provide BEC, which is the best ROI for every customer. If there is an outage that occurs in Microsoft or AWS or any other cloud platform, there is an email continuity platform for emails. That is good ROI.

From a deployment perspective, it shows around fifty to sixty percent. The impact given to the business in terms of real impact is up to ten to twenty percent.

What's my experience with pricing, setup cost, and licensing?

This is quite affordable. It is not that expensive.

Which other solutions did I evaluate?

We buy from Trend Micro. Trend Vision One definitely falls in the leader quadrant in Gartner, and its capabilities are good. It can be in that leader quadrant. For an endpoint security solution, managing attacks is the key thing. It is not about daily activities like what policies and functionalities are provided. These matter, but at the end of the day, if an attack is going to happen, the end user will assess the support of Trend Vision One and the response part of Trend Vision One. These two parameters are going to be assessed, and based on these two parameters, any quadrant achievement from labs like Gartner or Forrester will be based on these two parameters only.

What other advice do I have?

For standard endpoint protection, if it is a detection, it is a detection. When compared to CrowdStrike, Trend Vision One creates much less false positives. There is no big noise on this, but that is one way to consider it. False positives do come, and it is completely based on the configuration which we do. On the initial phase of the deployment, after a month or two, we keep it in detection mode, and after that, we pursue the prevention mode so that blocking is enabled.

If the containment functionality gets automated, it would be on a better note. The response part, if improved, will be very helpful. From a deployment perspective, it shows around fifty to sixty percent.

Trend Vision One is fully on the cloud with no on-premise option. They tie up with multiple cloud vendors, but they provide a SaaS platform built by Trend Micro. Trend Micro itself is hosted on some AWS servers, which is what I have heard, but I do not want to comment on that.

I would rate this review an eight.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)


    SemihDalkıran

Built faster threat response and improved visibility with real-time monitoring and flexible deployment

  • November 14, 2025
  • Review provided by PeerSpot

What is our primary use case?

A few use cases for Trend Vision One include end user installation by my company distributor company. We sell Trend Micro products, focusing on dealers rather than end user sales. My role is in technical engineering, particularly in Turkey, where I handle all Trend Micro product installation and training.

What is most valuable?

Trend Vision One allows us to monitor attacks in real time, which is a significant benefit. We can quickly see where the attack is coming from. Trend Vision One enables us to use different products with a flexible license. For example, if a customer is using endpoint security and wants to switch to another solution, they can instantly use a different Trend Micro product, such as email.

Trend Vision One has helped to reduce the time to detect and respond to different threats, as it can respond to attacks very quickly. With playbook templates, in cases of recurring attacks, responses can be made quickly using predefined playbooks.

Trend Vision One has helped to reduce noise from false positives. There have been false positives before, but it was due to the customer not telling us which app they were using. Best practice configurations must be applied properly to avoid such issues.

Trend Vision One helps customers consolidate the use of security vendors and reduce silos by offering one platform for all product management.

What needs improvement?

In comparison to Trellix, one disadvantage of Trend Micro is the DLP feature. Trend Micro has a light DLP, while Trellix offers a perfect DLP. Trend Micro's DLP is busy and does not use OCR.

In the future, I would like to see Trend Vision One improved by making it easier if the endpoint had a single agent. Currently, there are two agents for different antivirus and EDR solutions, making it seem advantageous to have just one.

DLP can be developed further, and the platform could benefit from additional IPS products.

For how long have I used the solution?

I have been working with Trend Vision One for three years.

What do I think about the stability of the solution?

Trend Vision One is stable, and there has been a problem once so far, which was quickly resolved with very fast problem-solving capabilities.

What do I think about the scalability of the solution?

When needing to scale Trend Vision One, I find it very easy to do so.

How are customer service and support?

Local support for Trend Micro is available in Turkey, including both local and global support teams.

I would rate the technical support of Trend Micro as an eight on a scale of one to ten.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Before Trend Micro, I worked with other solutions such as Trellix and McAfee. Trellix had performance problems, but with Trend Micro, there are no issues, and it offers the best performance compared to other products such as Trellix's EDR and proxy.

How was the initial setup?

Setting up Trend Vision One is straightforward, but someone with IT knowledge should handle it since it requires technical know-how.

What was our ROI?

Switching to Trend Vision One reduced our risk by 90 percent.

What's my experience with pricing, setup cost, and licensing?

Trend Vision One is a price performance product compared to competitors. On-premises solutions are more expensive than local solutions, and it is more affordable than leading competitors.

What other advice do I have?

Sensor coverage is critical for my customers' networks because we can see instant attacks on the network and computers.

It is very important that Trend Vision One has AI built into its platform as we currently use it, and it provides great convenience in understanding events.

My organization uses Trend Vision One for consolidated security across hybrid environments, as a single screen simplifies management, making it very easy to understand with one platform for all products.

For other organizations considering Trend Vision One, I suggest that using NDR for visibility is nice and easy.

I would rate this review a nine out of ten.


    Michael Leeb

A Unified and AI-Driven Security Platform That Strengthens Endpoint Protection and Risk Management

  • November 09, 2025
  • Review provided by PeerSpot

What is our primary use case?

Trend Vision One is deployed for endpoint security on both clients and servers. Integration with Microsoft Azure, local Active Directory, Email Security, and Cloud Collaboration has been implemented, with efforts to integrate as many modules and interfaces as possible into the platform.

Centralized collection and evaluation of security-related information at a single point is essential for the company's network. Operating in the construction planning industry with clients that are mostly public authorities, the constant exchange of files and collaboration with other companies across various platforms presents significant challenges. Communication occurs via email and Teams, making endpoint protection critical. Trend Vision One ensures endpoints and users are well-protected, detects threats quickly, and provides strong security assurance.

Attack Surface Risk Management features are utilized, and its ability to identify blind spots is highly valued. The platform categorizes the biggest risks with a score, allowing specific risk management.

How has it helped my organization?

Trend Vision One has consolidated the use of security vendors and reduced multiple vendors. The solution offers far more than initially used, with usage expanding gradually. The Managed Detect and Response Service is utilized, where Trend Micro checks critical cases, providing confidence that data is protected.

Centralizing everything in one cloud platform has improved the company significantly. Integration with third-party products provides additional security and helps the IT team remain calm and confident during incidents. Incidents can be reviewed quickly with clear traceability of events, which reduces stress across the company.

Risk management has been positively affected by the ability to generate reports and gain detailed insight into access attempts, helping reassess risks and identify patterns.

Threat detection and response time has been reduced by 70–90%. Risks are now identified within minutes instead of half an hour. False positives have decreased significantly because alerts can be quickly validated, especially with the new app. Overall cyber risk has been reduced substantially, and the company now feels very secure.

AI integration is very important for the organization. Trend Micro's AI is well-developed and continues to improve, providing faster recognition of threats and specific security support.


What is most valuable?

The sensors and their visual representation provide a quick and clear overview of the situation and are the most valuable features. The mobile app is highly useful, allowing immediate isolation of a client and instant assessment of alarms without logging into the system. This evolution makes the platform more powerful with every update.

Centralized visibility and management across all protection layers are excellent. Trend Vision One helps identify sources of problems quickly and offers great support contact with Trend Micro. The centralization of data collection and evaluation gives significant control over the security landscape.

AI integration within Trend Vision One enhances detection and analysis, enabling quick recognition of security issues and strengthening trust in the platform. The Managed Detect and Response service further adds value by providing expert monitoring of critical cases.

Integration capabilities and automation, particularly compatibility with local and cloud systems, have significantly improved operational efficiency and reduced manual workload.


What needs improvement?

The platform's development is satisfactory. There are no specific missing features at the moment, though improvement is always possible in making things more intuitive and easier to use. Trend Vision One continues evolving in the right direction and has become very stable recently.

For how long have I used the solution?

Trend Vision One has been used since November 2023.

What do I think about the stability of the solution?

Trend Vision One is very stable, and no issues have been experienced with the solution. Microsoft systems cause more concern than Vision One. The platform runs smoothly and reliably.

What do I think about the scalability of the solution?

Trend Vision One's scalability is good. The goal is to integrate as much as possible and collect all security-relevant information. The platform's scalability supports expansion and additional integrations with AI-driven analysis.

How are customer service and support?

Service and technical support are excellent. Direct contact is available with Trend Micro employees, including local representatives from Switzerland. When MDR tickets are opened, the service team responds quickly with clear instructions. The overall experience is very positive, and customer service and technical support are rated at the highest level.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Before using Trend Vision One, a local Trend Micro solution was used. The move to Vision One occurred when a setup renewal was needed and more security and centralized management options were sought. Trend Micro was recommended and proved to be the right choice.

How was the initial setup?

The initial setup was very simple due to the existing Trend Micro solution. Migration was smooth and supported by a partner, allowing devices to be moved seamlessly to the new platform. The onboarding process was completed within one week, with optimization occurring gradually afterward.


What about the implementation team?

The implementation was handled by the in-house IT team and UniQconsulting, a long-time partner. Only two people were needed for deployment. Approximately one week was required, with a half-day workshop for introduction and several nights spent migrating and optimizing devices. Support from UniQconsulting and Trend Micro ensured a smooth process.

What was our ROI?

ROI was achieved primarily through reduced IT workload and cost savings from avoiding external managed security providers. The Managed Detect and Response Service allows security to be maintained internally without outsourcing, which significantly reduces expenses.

Some time was required to realize the benefits after implementation. As a small team, the endpoint migration began slowly. By the end of the first year, everything desired had been integrated, including the local Active Directory and firewall. The platform's evolution and AI chatbot have made usage easier over time.


What's my experience with pricing, setup cost, and licensing?

A credits-based licensing model is used. Each function costs credits per device or user. Credits can be reallocated flexibly, and even minor negative balances are tolerated. The model is fair and adaptable to organizational needs. Overall costs are reasonable for the value provided

What other advice do I have?

Foreign Language: (German)

Eine einheitliche und KI-gestützte Sicherheitsplattform zur Stärkung des Endpunktschutzes und Risikomanagements

Was ist unser primärer Anwendungsfall?

Trend Vision One wird eingesetzt, um Endpunkte sowohl in Client- als auch in Serverumgebungen abzusichern. Die Lösung integriert sich nahtlos mit Microsoft Azure, dem lokalen Active Directory, der E-Mail-Sicherheit und der Cloud Collaboration, wobei fortlaufend daran gearbeitet wird, so viele Module und Oberflächen wie möglich innerhalb der Plattform zu vereinheitlichen.

Die zentrale Sammlung und Auswertung sicherheitsrelevanter Informationen an einem einzigen Punkt ist für das Unternehmensnetzwerk unerlässlich. Als Unternehmen in der Bauplanungsbranche, in der man hauptsächlich mit öffentlichen Auftraggebern arbeitet, steht die Organisation vor erheblichen Herausforderungen durch den ständigen Dateiaustausch und die Zusammenarbeit mit vielen Firmen über unterschiedliche Plattformen hinweg. Die Kommunikation erfolgt hauptsächlich per E-Mail und Teams, weshalb Endpointschutz von entscheidender Bedeutung ist. Trend Vision One sorgt dafür, dass Endpunkte und Benutzer gut geschützt sind, Bedrohungen schnell erkannt werden und ein hohes Maß an Sicherheit gewährleistet wird.

Die Cyber Risk Exposure Management (CREM) Funktionen werden sehr geschätzt, unter anderem, weil sie Blind Spots identifizieren. Die Plattform priorisiert die größten Risiken anhand eines Scores, was ein gezieltes Risikomanagement ermöglicht.

Wie hat die Lösung unserem Unternehmen geholfen?

Trend Vision One hat die Sicherheitsabläufe optimiert, indem mehrere Anbieter auf einer einzigen Plattform konsolidiert wurden. Das Deployment wurde schrittweise erweitert, wodurch weit mehr Funktionen als ursprünglich geplant war freigeschaltet wurden. Der Managed Detection and Response (MDR)-Service sorgt für zusätzliche Sicherheit, da Trend Micro kritische Fälle überwacht und so den Schutz der Daten gewährleistet.

Die Zentralisierung aller Systeme auf einer Cloud-Plattform hat die Leistungsfähigkeit des Unternehmens erheblich gesteigert. Die Integration mit Drittanbieterprodukten bietet zusätzliche Sicherheit und hilft dem IT-Team, bei Vorfällen ruhig und selbstbewusst zu bleiben. Durch die klare Nachvollziehbarkeit können Incidents schnell überprüft werden, was den Stress für die gesamten Organisation reduziert.

Durch die Möglichkeit, Berichte zu erstellen und detaillierte Einblicke in Zugriffsversuche zu erhalten, hat sich das Risikomanagement deutlich verbessert. So können Risiken neu bewertet und Muster erkannt werden.

Die Erkennungs- und Reaktionszeit auf Bedrohungen wurde um 70–90 % reduziert. Risiken werden nun innerhalb von Minuten statt in einer halben Stunde erkannt. False positives sind deutlich zurückgegangen, da Warnungen – insbesondere mit Hilfe der neuen App – schnell überprüft werden können. Das allgemeine Cyberrisiko wurde erheblich reduziert, und das Unternehmen fühlt sich nun viel sicherer.

Die Integration von KI ist ein weiterer entscheidender Vorteil. Die KI von Trend Micro wird kontinuierlich weiterentwickelt und ermöglicht eine schnellere Erkennung von Bedrohungen sowie gezielte Sicherheitsunterstützung.

Was ist am wertvollsten?

Die Sensoren und ihre visuelle Darstellung bieten einen schnellen und klaren Überblick über die Situation und gehören zu den wertvollsten Funktionen. Die mobile App ist äußerst hilfreich, da sie die sofortige Isolierung eines Clients und die schnelle Bewertung von Alarmen ermöglicht, ohne sich ins System einloggen zu müssen. Jedes Update stärkt die Plattform und macht sie mit der Zeit noch leistungsfähiger. Die zentrale Sichtbarkeit und Verwaltung über alle Schutzebenen hinweg sind ausgezeichnet. Trend Vision One hilft, Problemquellen schnell zu identifizieren, und bietet hervorragenden Support durch den direkten Kontakt zu Trend Micro. Die Zentralisierung der Datensammlung und -auswertung ermöglicht eine signifikante Kontrolle über die Sicherheitslandschaft.

Die KI-Integration in Trend Vision One verbessert die Erkennung und Analyse, ermöglicht eine schnelle Identifizierung von Sicherheitsproblemen und stärkt das Vertrauen in die Plattform. Der Managed Detect and Response Service bietet zusätzlichen Mehrwert durch die professionelle Überwachung kritischer Fälle.

Die Integrationsfähigkeit und Automatisierung, insbesondere die Kompatibilität mit lokalen und Cloud-Systemen, haben die betriebliche Effizienz erheblich verbessert und die manuelle Arbeitsbelastung reduziert.

Was könnte verbessert werden?

Insgesamt ist die Entwicklung der Plattform zufriedenstellend. Derzeit fehlen keine bestimmten Funktionen, allerdings wären Verbesserungen hinsichtlich Benutzerfreundlichkeit wünschenswert. Trend Vision One entwickelt sich weiterhin in die richtige Richtung und ist in letzter Zeit sehr stabil geworden.

Wie lange wird die Lösung bereits verwendet?

Trend Vision One wird seit November 2023 eingesetzt.

Wie beurteile ich die Stabilität der Lösung?

Trend Vision One ist sehr stabil, und es sind bisher keine Probleme aufgetreten. Die Plattform läuft reibungslos und zuverlässig. Tatsächlich geben Microsoft-Systeme mehr Anlass zur Sorge als Trend Vision One.

Wie beurteile ich die Skalierbarkeit der Lösung?

Trend Vision One bietet eine hohe Skalierbarkeit. Ziel ist es, so viele sicherheitsrelevante Informationen wie möglich zu integrieren und zu konsolidieren. Die Skalierbarkeit der Plattform unterstützt die Erweiterungen und zusätzliche Integrationen mit KI-gestützten Analysen.

Wie sind Kundenservice und Support?

Service und technischer Support sind ausgezeichnet. Es besteht ein direkter Kontakt zu Mitarbeitern von Trend Micro, einschließlich lokaler Vertreter aus der Schweiz. Bei geöffneten MDR-Tickets reagiert das Serviceteam schnell mit klaren Anweisungen. Die Gesamterfahrung ist sehr positiv, und Kundenservice sowie technischer Support werden auf höchstem Niveau bewertet.

Wie würde ich den Kundenservice und Support bewerten?

Negativ doesn’t make sense when you read what they said about the Customer service and Support in the question before

Welche Lösung wurde zuvor verwendet und warum wurde gewechselt?

Vor der Einführung von Trend Vision One wurde eine lokale Lösung von Trend Micro verwendet. Der Wechsel erfolgte, weil eine Erneuerung der Infrastruktur anstand und mehr Sicherheit sowie zentralisiertes Management gesucht wurden. Trend Micro wurde empfohlen

Wie verlief die Ersteinrichtung?

Die Ersteinrichtung war aufgrund der bestehenden Trend Micro-Lösung sehr einfach. Die Migration verlief reibungslos und wurde von einem Partner unterstützt, wodurch Geräte problemlos auf die neue Plattform transferiert werden konnten. Der Onboarding-Prozess war innerhalb einer Woche abgeschlossen, die Optimierung erfolgte anschließend schrittweise.

Wie war das Implementierungsteam aufgestellt?

Die Implementierung wurde vom internen IT-Team und Uni Consulting, einem langjährigen Partner, durchgeführt. Für das Deployment waren nur zwei Personen erforderlich. Der Prozess dauerte etwa eine Woche, einschließlich eines halbtägigen Einführungsworkshops und mehrerer Nächte für die Migration und Optimierung der Geräte. Die Unterstützung durch Uni Consulting und Trend Micro sorgte für einen reibungslosen Ablauf.

Wie sieht unser ROI aus?

Der ROI wurde hauptsächlich durch die Reduzierung der IT-Arbeitsbelastung und Kosteneinsparungen, da man auf externe Managed Security Provider verzichten konnte. Der Managed Detection and Response Service ermöglicht es, die Sicherheit intern aufrechtzuerhalten, ohne auszulagern, was die Kosten erheblich reduziert.

Es dauerte einige Zeit, bis die Vorteile nach der Implementierung vollständig sichtbar wurden. Als kleines Team begann die Migration der Endpunkte langsam. Am Ende des ersten Jahres waren alle gewünschten Integrationen abgeschlossen, einschließlich des lokalen Active Directory und der Firewall. Die Weiterentwicklung der Plattform und der KI-Chatbot haben die Nutzung im Laufe der Zeit weiter vereinfacht.

Wie sind meine Erfahrungen mit Preisgestaltung, Setup-Kosten und Lizenzierung?

Es wird ein kreditbasiertes Lizenzmodell verwendet, bei dem jede Funktion Credits pro Gerät oder Benutzer kostet. Die Credits können flexibel umverteilt werden, und kleine negative Salden werden toleriert. Das Modell ist fair und an die Bedürfnisse der Organisation anpassbar. Die Gesamtkosten sind im Verhältnis zum gebotenen Wert angemessen.

Welches Bereitstellungsmodell wird für diese Lösung verwendet?

Hybrid Cloud

Wenn Public Cloud, Private Cloud oder Hybrid Cloud – welcher Cloud-Anbieter wird genutzt?

Microsoft Azure


    reviewer1072692

Provides centralized visibility and improves threat response across hybrid environments

  • November 03, 2025
  • Review provided by PeerSpot

What is our primary use case?

Trend Vision One sensors are used at the endpoint to gather information from endpoints, which has proven to be very useful. The coverage provided by Trend Vision One is critical for our organization's network because it's a comprehensive way to get all the relevant data from the endpoints regarding antivirus security and similar security settings.

Some basic features of the Cyber Risk Exposure Management capabilities in Trend Vision One are being used. Plans exist to expand the usage, but currently the overview of the cyber risk settings is checked, though it hasn't been used much in the last few months.

Trend Vision One has helped consolidate the use of security vendors and reduce silos, but other vendors have not been replaced. Trend Vision One alone is sufficient for current needs, so other vendors for such solutions do not need to be used, at least not for now.

Trend Vision One is used for consolidated security across hybrid environments.

What is most valuable?

The comprehensive overview of the security status is the most valuable feature of Trend Vision One. Trend Vision One platform's ability to provide centralized visibility and management is quite good because all the relevant data are present, providing everything needed. The interface is quite simple to use and all the relevant data can be seen there.

Trend Vision One has helped reduce the time to detect and respond to threats because information is gathered more quickly and all the relevant points are visible. If there's any problem, it can be seen much easier and quicker.

Trend Vision One has also helped reduce cyber risks because it decreases cyber risks as there is more control over the environment.

What needs improvement?

There are currently no particular suggestions on how Trend Vision One can be improved because improvements have been seen in nearly every version, and satisfaction with what can be seen and used is high.

Additional features are not desired to be seen in the next release of Trend Vision One because not all the features that are available now are being used. For current needs, everything is already there. Perhaps in the future something else will be needed, but everything that is currently needed is already included.

Trend Vision One has improved its integration with other products, with other vendors, or with mobile device management. The mobile device management solution has improved over the years and was pretty basic when it started, but now it has much more options. Some improvements could be made, but all the possibilities of the platform are not being fully utilized, so some features that could be discussed may not have been explored yet, though they may already be available.

For how long have I used the solution?

Trend Vision One has been used for a couple of years.

What do I think about the scalability of the solution?

There have been no problems with scaling Trend Vision One. The organization is not large, so there were no problems in scaling. Trend Vision One appears to be tailored for much bigger organizations, so no scaling problems were encountered.

How are customer service and support?

There has not been much contact with technical support, though some checks and presentations were conducted, which were quite good. The response was very quick and all the information needed was received, resulting in high satisfaction.

Technical support would be rated nine out of ten. Regarding local technical support, it is also quite good through the partner network and directly. If something is escalated directly to Trend Micro, responses are received. There is high satisfaction with the current support level.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup of Trend Vision One was seamless because it was a migration from an on-premises Trend Micro service to a cloud-based one, so there were no particular problems.

What about the implementation team?

External partners were used for the implementation of Trend Vision One, though the process was overseen. There was a transfer of knowledge during the implementation.

What was our ROI?

Return on investment from Trend Vision One has not been calculated in the traditional sense, but price-wise, it's a better solution than some others that have been looked at or researched. Trend Vision One is quite convenient for the organization.

Which other solutions did I evaluate?

Before Trend Vision One, a broader marketplace was evaluated. A granular possibility to purchase only needed options without purchasing unnecessary components was not observed in other solutions. The licensing model of Trend Vision One is the best among other solutions that have been seen.

What other advice do I have?

For integrations with third-party solutions, integration was done for log management. Logs are downloaded or shipped from Trend Micro solutions to internal log management solutions, and there were no particular problems in integrations. Many other integrations specifically with Trend Micro were not conducted.

Trend Vision One is considered the best option on the market at the moment for this organization. Trend Vision One appears to be quite popular in the region, with many companies using it, both bigger and smaller organizations. A community provides information and support, making Trend Vision One popular in the area.

Trend Vision One has been using AI technologies already for some time, which shows awareness of the landscape. It is believed that Trend Vision One will tailor the solution accordingly, as AI is already being used in some solutions within the platform, indicating good direction for the product.

Trend Vision One provides learning courses, and events from partners sometimes offer opportunities to gather new information on the products. Additionally, a community is available, creating a good landscape for learning and support in the region.

The partnership program is not well known because collaboration is through partners, but it is believed that partner satisfaction is high.

Trend Vision One received an overall rating of eight out of ten.


    reviewer2772045

Provides comprehensive transparency in hybrid environments and improves day-to-day operations in threat detection.

  • October 28, 2025
  • Review provided by PeerSpot

What is our primary use case?

I use Trend Vision One basically for the entire endpoint security setup for both client and server, in addition to the SOC service that we booked, and the goal is to set up a complete centralized management with Trend.

I deploy Trend Vision One sensors everywhere, and this coverage is very important for our company's network. So, as I said, server and client, but we also have the interfaces to network and to cloud solutions, and security tools such as firewalls and so on. The log files—everything—flows into Trend Vision One in order to detect anomalies. That is why it is actually very important for us to have a tool that covers everything, so to speak.

My company uses the Trend Vision One platform for consolidated security in hybrid environments. As I said, we also have the cloud with connected Azure, MS 365 and also the on-premises. So we are hybrid.

My work environment where this solution is deployed includes three locations. We have two external data centers that we operate—we are tenants, but the hardware all belongs to us. So we operate everything on-premises. We have an office where approximately fifty to sixty employees are. We also have approximately twenty to thirty external partners who also work on our systems, as well as a few clients who work on the ERPs that we provide. So there are approximately one hundred and fifty to two hundred users who access our systems. We operate approximately one hundred and fifty virtual servers at highly redundant data center locations. In addition, we are also in the cloud—Microsoft Azure—where we operate certain services for ourselves and also for our customers.


What is most valuable?

The functions I find particularly valuable are generally the ones that Trend Vision One offers, with the vulnerability analyses, so it already shows the vulnerabilities and possible anomalies. It has already displayed compromised user accounts, and so we can assess how the tool works. It is actually the symbiosis of everything, that we can see how Trend actually works.

My impression of the ability of the Trend Vision One platform to offer central visibility and management across all layers of protection is that the visibility is very good. As I said, the challenge is there—have we covered everything? For that we need support from Trend, which is very good. Also, the technical know-how on Trend's side is very well positioned.

Trend Vision One has helped to consolidate the use of security providers and reduce numbers. When we have everything from a single source, like from Trend, including the SOC service, we didn't have to evaluate other possible tools, and so we were basically able to save costs in terms of licenses.

use the features of Attack Service Risk Management (ASRM), and its ability to support our organization in identifying and assessing blind spots is very good. The visibility is very good, also from ASRM—it helps us to perform analyses. So far we haven't had any major incidents, which is of course optimal, but it definitely helps us in our daily work. We look every day—do we have System Engineers who work with this console?

It is important for our company that Trend Vision One has integrated AI into its platform. If the AI works the way Trend envisions it, then we will also have fewer problems, but of course, if it helps to detect anomalies, all the better in any case.

The solution has improved our company by providing advantages we didn't have before. We didn't have this visibility before through the Endpoint Protection solution. That is why we chose Trend, because we have everything in one tool, and it is actually so consolidated. The visibility over everything—over all systems or network and security—has improved us massively. Now the second step is to see if we have everything configured correctly, so that we can then get the maximum out of the functions of Trend.

The Trend Vision One platform has positively impacted our ability to manage risk because we see more now, we can analyze more, and create more communication or reports for management, and show how good our E Score is as we use the tools correctly.

Trend Vision One has helped our company reduce the number of false positive alerts. We didn't have any tools before, so now we have everything new with Trend, and the false positive alerts are marginal—so there are few. So it fits. We don't have a big time saving, but it helps us.

Trend Vision One has helped our organization overall to reduce our cyber risk. Definitely.

Trend Vision One manages to reduce our cyber risk based on the risk score, where we see where we have vulnerabilities, and of course also can better protect the systems, better patch them, so that the risk score is really reduced. We have been in the green zone for quite some time now, as far as the risk score is concerned, so we have massively achieved an improvement.

Trend Vision One has resulted in us spending less time on threat detection and response. As I said, we haven't had a threat in that sense yet, but we have received certain false positive reports that show the tool is working in the background. As I said, the challenge is to see if we have covered everything. But we have other projects planned for that.


What needs improvement?

The solution could be improved in the area of support from the beginning, for the implementation of all services. We actually think we have covered everything, but what could be better is the support from the beginning. I think you offer everything, but that is with the customer—with us—it always comes, there is too little know-how transferred. You get the tool and you should then install it with the external partner, but there are many know-how gaps. I think the advantage where we can counter the trend is in the fact that you might do a better onboarding, with the external partner, together with Trend, with the customer, to use the tool from the beginning as it was intended, so that you don't waste any time.

We are just having a problem with Trend right now. We have had short problems twice before—in the sense that when Trend does an upgrade on the platform, or anything else, there are disruptions afterwards. We had that a while ago, which meant you couldn't log in anymore, which was of course suboptimal. Now something is wrong, and we are having problems with the clients with the Zero Trust—that, for example, websites are blocked that shouldn't be blocked, and nothing has been changed. Trend announced some kind of update on Sunday or Monday. Otherwise, everything is running except for these small points, which each lead to misunderstanding.

For how long have I used the solution?

I have been using this solution for 3 years.

What do I think about the stability of the solution?

My impression of the stability of this solution is very good

What do I think about the scalability of the solution?

I think the scalability of this solution is good. We plan to increase the use in the sense that, as I said, we want to use all the logs that we already get as a central management solution, if possible.

How are customer service and support?

I rate the service and technical support for the solution from Trend Micro's side as very good.

On a scale of one to ten, I would rate the customer service and technical support for this solution as nine.


How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Before using Trend Vision One, I used another solution, but it was just one endpoint protection for servers and clients. We didn't have any other tools for network monitoring or cloud solutions.

I switched to Trend Vision One because the other solution didn't have those features, and also because the support wasn't satisfactory before.

I switched to Trend Vision One because the other solution didn't have those features, and also because the support wasn't satisfactory before.


How was the initial setup?

The setup was relatively simple in the first phase, where the old client was gone and the new client was installed via software distribution. That goes relatively quickly. Then standard configurations were done through the partner. What was delayed was that you bought these credits from the beginning—these modules—but until you had them fully configured, it took a while. From my point of view, almost a year and a half, and we simply didn't fully use the credits because certain modules weren't activated. That is why I earlier mentioned the need for better onboarding.

Our implementation strategy was simply to remove the old behavior, add new trends, and initially cover the server and client, then integrate the network and cloud, and finally build the CM solution and then build the SOC service on top of that.


What about the implementation team?

We used an integrator, reseller, or consultant for the implementation—this was our external IT partner.

My experience with them is difficult to say. As I said, it is now down to the onboarding or the time that the external partner didn't have to really fix—to provide their tool in the way that we needed it.

We needed a small team for the implementation of this solution. There were two of us, practically fully together with the external partner for a while, to implement the whole thing.


What was our ROI?

I have identified a Return on Investment more on the security side. I didn't have this visibility before. I didn't have this security to look at where we have vulnerabilities, what is being monitored. From that point of view, you can already say that we have profited from it, but you cannot really describe that monetarily.

What's my experience with pricing, setup cost, and licensing?

It took us about a year, a year and a half, to realize these benefits from the time of implementation. We took two steps: first we replaced the servers and then waited a year until we could add the clients and afterwards added the additional sensors, such as network and so on. I would now say that we have been working for about a year, a year and a half, to optimize these sensors and work more intensively with the tool.

Which other solutions did I evaluate?

Before deciding on this product, I considered other options. We looked at two others—the existing supplier we had, plus Trend—and then looked at others, but we ultimately came to Trend because the price-performance ratio and also the support actually showed the best offer.

The main differences between the products we considered were that the main trigger was Vision One, that we have everything on one console and can actually connect everything. Others have more difficulty even presenting it that way or don't have such a wide range of interfaces to bring everything into Trend Vision One. That would mean you need several tools or suppliers for, in the end, the same result.

What other advice do I have?

What I would recommend to others evaluating this solution is to take advantage of the flexibility that we can also try things out with certain credits, to test the modules. How can you use that? Also the flexibility to support us or the customers in such a way that they can try out the products as much as possible and not just buy something and then realize that they might need other modules in addition or wouldn't have needed them.

My opinion of the pricing and licensing of this solution is that prices could always be lower, of course, but I think the model is good with these points. It is a bit opaque—with these credits—when you have to order certain modules and then get these credits. When you have the credits, you can actually use them as you want later in the console. That makes it flexible in part, but it is a bit opaque sometimes. Then the Key Account from Trend helps, who explains it to us each time.

Foreign Language: (German)

Sorgt für umfassende Transparenz in hybriden Umgebungen und verbessert die täglichen Abläufe in der Bedrohungserkennung

Was ist unser Hauptanwendungsfall?

Ich nutze Trend Vision One für den gesamten Endpoint-Sicherheits-Setup, sowohl für Clients als auch für Server, zusätzlich zu dem SOC-Service, den wir gebucht haben. Das Ziel ist es, ein vollständiges SIEM mit Trend Micro aufzubauen.

Ich setze die Trend Vision One Sensoren flächendeckend ein, das ist sehr wichtig für unser Unternehmensnetzwerk. Die Lösung umfasst Server und Clients aber auch Schnittstellen zu Netzwerk- und Cloud-Lösungen sowie zu Sicherheitstools wie Firewalls usw.

Alle Logdateien laufen in Trend Vision One zusammen, um Anomalien zu erkennen. Deshalb ist es für uns so wichtig, ein Tool zu haben, das alles abdeckt.

Mein Unternehmen nutzt die Trend Vision One-Plattform für konsolidierte Sicherheit in hybriden Umgebungen. Wir verfügen außerdem über Cloud-Integrationen mit Azure und Microsoft 365 sowie über lokale Systeme, sodass wir hybrid aufgestellt sind.

Meine Arbeitsumgebung umfasst drei Standorte: zwei externe Rechenzentren, die wir als Mieter betreiben, sodass die Hardware uns gehört, und ein Büro mit etwa 50 bis 60 Mitarbeitern. Darüber hinaus arbeiten etwa 20 bis 30 externe Partner an unseren Systemen sowie einige Kunden, die auf den von uns bereitgestellten ERPs arbeiten. Insgesamt greifen etwa 150 bis 200 Benutzer auf unsere Systeme zu. Wir betreiben etwa 150 virtuelle Server an hochredundanten Rechenzentrumsstandorten. Darüber hinaus betreiben wir bestimmte Services in Microsoft Azure für uns selbst und auch für unsere Kunden.

Was ist am wertvollsten?

Die wertvollsten Funktionen sind diejenigen, die Trend Vision One für Schwachstellenanalysen bietet, da es Schwachstellen und Anomalien identifiziert. Es wurden auch bereits kompromittierte Benutzerkonten angezeigt, sodass wir sehen können, wie das Tool funktioniert.

Die Fähigkeit der Plattform, zentrale Transparenz und Verwaltung über alle Schutzebenen hinweg zu bieten, ist ausgezeichnet. Die Herausforderung besteht darin, eine vollständige Abdeckung sicherzustellen, dafür benötigen wir Unterstützung von Trend Micro, die sehr gut ist. Auch das technische Know-how auf der Seite von Trend ist sehr gut aufgestellt.

Trend Vision One hat dazu beigetragen, Sicherheitsanbieter zu konsolidieren und die Anzahl zu reduzieren. Alles aus einer Hand zu haben, einschließlich des SOC-Services, hat dafür gesorgt, dass wir keine anderen Tools evaluieren mussten und Lizenzkosten eingespart haben.

Das Cyber Risk Exposure Management (CREM) hilft dabei, Blind Spots zu identifizieren und zu bewerten, und bietet eine gute Übersicht für die Analyse. Bislang hatten wir keine größeren Vorfälle, was natürlich optimal ist, aber CREM unterstützt uns definitiv bei unserer täglichen Arbeit.

Für unser Unternehmen ist es wichtig, dass Trend Vision One KI in seine Plattform integriert hat. Wenn die KI von Trend wie vorgesehen funktioniert, wird sie Probleme reduzieren und die Erkennung von Anomalien verbessern.

Die Lösung hat unser Unternehmen verbessert, indem sie uns Transparenz verschafft hat, die wir mit früheren Endpoint-Protection-Lösungen nicht hatten. Deshalb haben wir uns für Trend Micro entschieden, da alles in einem Tool konsolidiert ist. Für uns hat sich die Sichtbarkeit über alle Systeme, Netzwerke und Sicherheitsaspekte hinweg massiv verbessert. Der nächste Schritt besteht darin, sicherzustellen, dass alles korrekt konfiguriert ist, um die Funktionalität maximal auszuschöpfen.

Trend Vision One hat sich positiv auf unsere Fähigkeit Risiken zu managen ausgewirkt, da es eine bessere Analyse, Berichterstattung und Kommunikation mit dem Management ermöglicht. Wir können nun unsere Risikobewertung darlegen und Verbesserungen aufzeigen.

Trend Vision One hat die Anzahl der Fehlalarme (False Positives) deutlich reduziert. Früher hatten wir keine Tools, jetzt sind Fehlalarme auf ein Minimum reduziert. Die Zeitersparnis war nicht enorm, aber ist dennoch sehr hilfreich.

Insgesamt hat Trend Vision One unserem Unternehmen dabei geholfen, unser gesamtes Cyberrisiko zu reduzieren. Der Risk Score zeigt Schwachstellen auf und ermöglicht so einen besseren Schutz und ein besseres Patchen, was dazu beiträgt, den Risk Score zu senken. Wir befinden uns seit geraumer Zeit im grünen Bereich, was eine erhebliche Verbesserung darstellt.

Insgesamt hat Trend Vision One unserem Unternehmen geholfen, das gesamte Cyberrisiko zu reduzieren. Der Risk Score zeigt Schwachstellen auf und ermöglicht dadurch besseren Schutz und effektiveres Patching, was wiederum zur Senkung des Risk Scores beiträgt. Wir befinden uns seit geraumer Zeit im grünen Bereich, was eine massive Verbesserung ist.

Trend Vision One hat den Zeitaufwand für die Erkennung und Reaktion auf Bedrohungen reduziert. Wir wurden bisher noch nicht mit echten Bedrohungen konfrontiert, aber einige False Positives bestätigen, dass das Tool im Hintergrund funktioniert. Die Herausforderung besteht weiterhin darin, eine vollständige Abdeckung sicherzustellen, und dafür haben wir entsprechende Projekte geplant.

Was muss verbessert werden?

Die Lösung könnte beim Support zu Beginn, insbesondere bei der Implementierung aller Services, verbessert werden. Zwar gehen wir davon aus, dass wir alles korrekt eingerichtet haben, doch die anfängliche Unterstützung könnte besser sein.
Man erhält das Tool und soll es gemeinsam mit dem externen Partner installieren, aber es gibt doch Wissenslücken. Ein strukturierteres Onboarding, bei dem Trend Micro, der externe Partner und der Kunde von Anfang an zusammenarbeiten, wäre sehr hilfreich, um die Lösung direkt richtig nutzen zu können.

Wir haben kurzfristige Probleme nach Plattform-Upgrades erlebt. Beispielsweise war nach einem Update der Login vorübergehend nicht möglich, was suboptimal war. Aktuell haben wir Schwierigkeiten mit Zero Trust, da Webseiten fälschlicherweise blockiert werden, obwohl keine Änderungen vorgenommen wurden. Trend hat kürzlich ein Update angekündigt, und obwohl sonst alles reibungslos läuft, führen diese kleinen Probleme immer wieder zu Missverständnissen.

Seit wann benutze ich die Lösung?

Ich nutze die Lösung seit drei Jahren.

Wie ist die Stabilität der Lösung?

Mein Eindruck von der Stabilität dieser Lösung ist sehr gut.

Wie ist die Skalierbarkeit der Lösung?

Ich halte die Skalierbarkeit dieser Lösung für gut. Wir planen, die Nutzung zu erhöhen. Nach Möglichkeit sollen alle Protokolle (Logs), die wir erhalten, als SIEM-Lösung genutzt werden.

Wie sind Kundenservice und Support?

Ich bewerte den Service und technischen Support von Trend Micro als sehr gut.
Auf einer Skala von 1 bis 10 vergebe ich eine 9.

Wie würden Sie den Kundenservice und Support bewerten?

Positiv

Welche Lösung habe ich vorher verwendet und warum gewechselt?

Vorher habe ich eine andere Lösung genutzt, die nur grundlegende Endpoint-Protection für Server und Clients bot. Wir hatten keine weiteren Tools für die Netzwerküberwachung oder Cloud-Sicherheit.

Ich bin zu Trend Vision One gewechselt, weil die vorherige Lösung diese Funktionen nicht bot und der Support nicht zufriedenstellend war.

Wie war die Ersteinrichtung?

Die Installation war relativ einfach. In der ersten Phase wurde der alte Client entfernt und der neue Client über die Softwareverteilung installiert, was schnell ging. Die Standardkonfigurationen wurden dann über den Partner vorgenommen. Was die vollständige Implementierung verzögerte, war die Aktivierung der gekauften Credits und Module. Obwohl wir diese im Voraus gekauft hatten, dauerte es fast anderthalb Jahre, bis sie vollständig konfiguriert und einsatzbereit waren. Aus diesem Grund habe ich zuvor die notwendige Verbesserung des Onboardings erwähnt.

Unsere Implementierungsstrategie: Alte Lösung entfernen → Trend einführen → Server & Clients abdecken → Netzwerk & Cloud integrieren → SIEM aufbauen → SOC-Service ergänzen.

Wie war das Implementierungsteam?

Wir haben einen Integrator/Reseller/Berater für die Implementierung beauftragt – unseren externen IT-Partner. Meine Erfahrungen mit ihnen sind gemischt. Das Hauptproblem war das Onboarding, da der Partner nicht das erforderliche Maß an Unterstützung geleistet hat, um das Tool optimal zu nutzen.
Für die Implementierung dieser Lösung benötigten wir ein kleines Team. Wir waren zu zweit und haben eine Zeit lang eng mit dem externen Partner zusammengearbeitet, um das Deployment abzuschließen.

Wie war der ROI?

Der Return on Investment liegt vor allem im Bereich Sicherheit. Vorher hatten wir keinen Überblick über Sicherheitslücken und Überwachung. Mit Trend Vision One haben wir jetzt diesen Überblick, was ein großer Vorteil ist, auch wenn es schwer ist, das finanziell zu beziffern.

Wie ist meine Erfahrung mit Preisgestaltung, Einrichtung und Lizenzierung?

Es dauerte etwa anderthalb Jahre, bis wir diese Vorteile nach der Implementierung erreicht hatten. Wir haben zwei Schritte unternommen: Zuerst haben wir die Server ausgetauscht und dann ein Jahr gewartet, bis wir die Clients hinzufügen konnten, und anschließend die zusätzlichen Sensoren, wie z. B. Netzwerk und so weiter. Ich würde sagen, dass wir nun seit etwa anderthalb Jahren daran arbeiten, diese Sensoren zu optimieren und intensiver mit dem Tool zu arbeiten.

Welche anderen Lösungen habe ich bewertet?

Vor der Entscheidung haben wir zwei weitere Anbieter geprüft – den bestehenden Lieferanten und Trend – und uns schließlich wegen des Preis-Leistungs-Verhältnisses und des Supports für Trend entschieden.
Der Hauptunterschied war, dass Trend Vision One alles in einer Konsole vereint. Andere haben mehr Schwierigkeiten, das so darzustellen, oder weniger Schnittstellen, um alles zu integrieren.

Bevor wir uns für dieses Produkt entschieden haben, haben wir andere Optionen in Betracht gezogen. Wir haben zwei Alternativen geprüft, unseren bestehenden Lieferanten und Trend Micro. Letztendlich haben wir uns für Trend entschieden, weil das Preis-Leistungs-Verhältnis und der Support insgesamt den besten Mehrwert boten.

Der Hauptunterschied war, dass Trend Vision One, alles auf einer Konsole bereitstellt und alle Lösungen nahtlos miteinander verbindet. Andere Anbieter haben größere Schwierigkeiten, dies zu realisieren, oder verfügen nicht über eine so breite Palette an Schnittstellen, um alles in Trend Vision One zu integrieren. Um das gleiche Ergebnis zu erzielen benötigt man mehrere Tools oder Anbieter.

Welchen Rat habe ich für andere?

Ich empfehle, die Flexibilität des Credit-Systems zu nutzen, um verschiedene Module auszuprobieren, um herauszufinden, welche am besten zu Ihren Anforderungen passen. Außerdem können Sie Produkte testen, bevor Sie sie kaufen – so vermeiden Sie, später festzustellen, dass Sie zusätzliche Module benötigen oder einige gar nicht verwenden.

Das Lizenzmodell halte ich grundsätzlich für gut. Es ist allerdings etwas intransparent, da man zunächst bestimmte Module bestellt, dafür Credits erhält und diese später in der Konsole flexibel einsetzen kann. Das macht das System zwar sehr flexibel, wirkt aber manchmal etwas undurchsichtig. Unser Kundenbetreuer von Trend unterstützt uns dabei und erklärt uns jedes Mal den Ablauf.

Welches Bereitstellungsmodell verwenden wir?

Hybrid Cloud.

Wenn Public Cloud, Private Cloud oder Hybrid Cloud, welchen Cloud-Anbieter nutzen Sie?

Microsoft Azure.



    Joerg Kaelin

Centralized visibility and consolidated insights make vulnerability management easy and fast

  • October 09, 2025
  • Review provided by PeerSpot

What is our primary use case?

We started with the antivirus solution, Trend Vision One Endpoint Security, after switching from Sophos. Initially, our focus was antivirus, but later we expanded to include multiple Trend Vision One products: XDR for Networks, Managed SOC, and Cloud Endpoint Security.

Our deployment covers endpoints, network sensors, and integrations with Active Directory and Microsoft. We use virtual sensors for full network visibility and maintain a hybrid environment with both private and Azure cloud infrastructure.

How has it helped my organization?

Our customers are mainly in the public sector—municipalities, cities, healthcare, and retirement homes—so ransomware is a major concern. Trend Vision One provides tools to fend off attacks and allows us to use virtual patching to quickly close vulnerabilities without waiting for traditional patches.

Trend Vision One has significantly enhanced our visibility into vulnerabilities and security incidents. Unlike Sophos, which only offered basic antivirus protection, Trend Vision One provides comprehensive insight into user behavior, dark web login monitoring, and open vulnerabilities.

We can now see everything from a single platform, which simplifies security operations and reduces complexity. It also allows for real-time risk management linked to live data, enabling continuous improvement rather than periodic reviews.

The Swiss Trend Vision One team supported us closely in refining our cybersecurity processes, leading to substantial overall progress and reduced cyber risk across the organization.

What is most valuable?

The rollout was quick thanks to the cloud-based infrastructure of Trend Vision One Complete, which eliminated the need for additional hardware. The central visibility of the platform is particularly valuable: users can log in and immediately identify areas of high risk. The unified dashboard highlights vulnerable areas at a glance, streamlining remediation.

Attack Surface Risk Management (ASRM) is also a key feature, helping prioritize assets based on criticality and data sensitivity. For instance, devices holding high-value data receive more attention in risk scoring.

The platform's ability to provide insights across multiple protection layers helps us address vulnerabilities quickly and efficiently. The system's simplicity and consolidated data have also made managing risks far more effective than before.

What needs improvement?

The main area of improvement lies in the Workbench interface. When investigating alerts, users often have to navigate through multiple windows and tabs to gather all relevant information. Consolidating case details into a single, more intuitive view would streamline investigations and save time. Otherwise, the solution's functionality is well-balanced.

For how long have I used the solution?

We've had the solution for a little more than two years.

What do I think about the stability of the solution?

The solution's stability is excellent. We have not experienced any issues or downtime since implementation.

What do I think about the scalability of the solution?

Scalability has been strong. We began with server deployments and are now rolling out to 2,200 client devices. The process has been seamless, requiring minimal additional configuration.

How are customer service and support?

We have had an excellent experience with Trend Vision One's customer and technical support. The Swiss Trend Vision One team provides consistent, personalized assistance, with dedicated contacts who understand our setup well.

They have been very responsive, and we even have an ongoing relationship with them beyond technical support. Overall, I would rate the service a nine out of ten for professionalism, consistency, and expertise.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Our previous solution was Sophos Endpoint Protection, which reached end-of-life. We evaluated multiple vendors, including Sophos's new offerings, but Trend Vision One stood out due to its platform capabilities, the SOC integration potential, and especially the excellent support from the Swiss Trend Vision One team.

The switch was smooth, and Trend Vision One's modern detection capabilities and compatibility with both legacy and modern systems were major advantages over Sophos's on-premises, outdated setup.

How was the initial setup?

There were no major deployment issues. The initial rollout was phased, starting with servers before moving to clients. Trend Vision One Switzerland supported the implementation directly, ensuring smooth execution.

The initial setup was straightforward. We rolled out the solution to around 1,000 on-premises data center servers over two to three months. The process was divided into test, review, and full rollout phases, which helped minimize issues. The overall setup was simple and efficient, especially for the scale of deployment.

What about the implementation team?

Implementation was handled internally by two people: myself and one team member. We managed all phases from planning and clarification to deployment.

Trend Vision One Switzerland provided close technical guidance during the process, and later, the service provider Pingas in Germany assisted with SOC integration. Our ongoing maintenance involves eight people from our team, although the Trend Vision One solution itself requires little upkeep.

What was our ROI?

Return on investment was not a primary goal. We offer managed services to our clients, with antivirus protection included as part of the package rather than a separate revenue stream. The investment was made to ensure robust cybersecurity and operational reliability. However, we plan to expand some of these services to external customers to achieve a return in the future.

What's my experience with pricing, setup cost, and licensing?

We have an Enterprise Agreement with Trend Vision One, a six-year strategic partnership covering a defined consumption volume. Pricing is considered fair for the range of functions included. It's neither excessively high nor low, and overall, it aligns well with the value provided.

Which other solutions did I evaluate?

We evaluated multiple alternatives, including Sophos's updated solutions, but Trend Vision One prevailed due to its modular service structure, modern platform design, and strong support from the Swiss Trend Vision One team.

What other advice do I have?

I would recommend others to evaluate this solution, especially with the support of a trusted partner during the introduction phase. Having expert guidance early on helps with configuration and understanding the platform's capabilities. Trend Vision One also consolidates vendor management effectively, reducing the need for multiple partners.

I would rate Trend Vision One a nine out of ten.

Foreign Language: (German)

Zentralisierte Sichtbarkeit und konsolidierte Einblicke – für ein schnelleres und einfacheres Schwachstellenmanagement.

Was ist unser primäres Einsatzszenario?

Wir haben mit Trend Vision One™ – Endpoint Security begonnen, nachdem wir von Sophos gewechselt hatten. Anfangs lag der Schwerpunkt ausschließlich auf dem Antivirenschutz. Inzwischen nutzen wir jedoch mehrere

Module der Plattform Trend Vision One – darunter XDR (Extended Detection & Response) für Netzwerke, Managed SOC und Cloud Endpoint Security.

Unsere Implementierung umfasst Endpoints, Netzwerksensoren sowie Integrationen mit Active Directory und Microsoft. Durch den Einsatz virtueller Sensoren erreichen wir vollständige Netzwerksichtbarkeit. Unsere Umgebung ist hybrid aufgebaut – mit privater sowie Azure-Cloud-Infrastruktur.

Wie hat die Lösung unserem Unternehmen geholfen?

Unsere Kunden stammen überwiegend aus dem öffentlichen Sektor – Gemeinden, Städte, das Gesundheitswesen und Pflegeeinrichtungen – für die Ransomware eine zentrale Bedrohung darstellt. Trend Vision One bietet leistungsstarke Tools zur Abwehr solcher Angriffe und ermöglicht virtuelles Patchen, sodass Schwachstellen umgehend geschlossen werden können, ohne auf klassische Patches warten zu müssen.

Trend Vision One hat unsere Transparenz hinsichtlich Schwachstellen und Sicherheitsvorfällen erheblich verbessert. Im Gegensatz zu Sophos, das lediglich grundlegenden Antivirenschutz bot, liefert Trend Vision One umfassende Einblicke in Nutzerverhalten, Dark-Web-Anmeldungen und offene Schwachstellen.

Heute haben wir alle sicherheitsrelevanten Daten auf einer einzigen Plattform, was den Betrieb vereinfacht und Komplexität reduziert. Zudem erlaubt die Lösung Echtzeit-Risikomanagement auf Basis von Live-Daten – ein kontinuierlicher Verbesserungsprozess statt punktueller Überprüfungen.

Das Schweizer Trend Micro Team hat uns bei der Optimierung unserer Cybersecurity-Prozesse eng begleitet. Das führte zu deutlichen Fortschritten und einer spürbaren Reduktion des Cyberrisikos in der gesamten Organisation.

Was ist am wertvollsten?

Die Implementierung verlief zügig, dank der Cloud-basierten Architektur von Trend Vision One, die keine zusätzliche Hardware erforderte. Besonders wertvoll ist die zentrale Transparenz der Plattform: Nutzer können sich einloggen und sofort risikoreiche Bereiche identifizieren. Das einheitliche Dashboard zeigt Schwachstellen auf einen Blick und erleichtert deren Behebung.

Ein herausragendes Feature ist das Cyber Risk Exposure Management (CREM), das Assets nach Kritikalität und Datenwert priorisiert. Systeme mit sensiblen oder geschäftskritischen Daten werden im Risikoscore entsprechend stärker gewichtet.

Durch die ganzheitliche Sicht über mehrere Schutzebenen hinweg können Schwachstellen schnell und effizient adressiert werden. Die einfache Bedienbarkeit und die konsolidierten Daten haben das Risikomanagement deutlich effektiver gemacht.

Was könnte verbessert werden?

Der Hauptverbesserungsbedarf liegt in der Workbench-Benutzeroberfläche. Bei der Untersuchung von Warnmeldungen müssen Anwender häufig zwischen mehreren Fenstern und Tabs wechseln, um alle relevanten Informationen zu erfassen. Eine konsolidierte, intuitivere Fallansicht würde Analysen beschleunigen und Zeit sparen. Abgesehen davon ist die Funktionalität der Lösung sehr ausgewogen.

Wie lange nutzen wir die Lösung?

Wir verwenden Trend Vision One seit etwas mehr als zwei Jahren.

Wie beurteile ich die Stabilität der Lösung?

Die Stabilität ist ausgezeichnet. Seit der Implementierung kam es zu keinerlei Ausfällen oder Problemen.

Wie beurteile ich die Skalierbarkeit?

Die Lösung ist hochgradig skalierbar. Wir begannen mit Server-Deployments und haben die Nutzung mittlerweile auf 2.200 Client-Geräte ausgeweitet – reibungslos und ohne größeren Konfigurationsaufwand.

Wie ist der Kundenservice und Support?

Unsere Erfahrungen mit dem Kunden- und technischen Support von Trend Micro sind durchweg positiv. Das Schweizer Trend Micro Team bietet eine konstante, persönliche Betreuung mit festen Ansprechpartnern, die unsere Umgebung bestens kennen.

Die Reaktionszeiten sind hervorragend, und die Zusammenarbeit geht über reine Supportfälle hinaus. Insgesamt bewerten wir den Service mit neun von zehn Punkten – für Professionalität, Zuverlässigkeit und Fachkompetenz.

Welche Lösung haben wir zuvor genutzt und warum der Wechsel?

Zuvor setzten wir Sophos Endpoint Protection ein, dass das End-of-Life-Stadium erreicht hatte. Nach Evaluierung mehrerer Anbieter – auch der neuen Sophos-Lösungen – überzeugte Trend Vision One durch seine Plattformfähigkeiten, SOC-Integrationspotenziale und den hervorragenden Support des Schweizer Teams.

Der Wechsel verlief reibungslos. Besonders die modernen Erkennungsmechanismen und die Kompatibilität mit sowohl älteren als auch modernen Systemen stellten deutliche Vorteile gegenüber der veralteten On-Premises-Struktur von Sophos dar.

Wie war die Erstimplementierung?

Es traten keine nennenswerten Probleme auf. Die Einführung erfolgte phasenweise, zunächst auf Servern, danach auf Clients. Die Implementierung wurde direkt vom Schweizer Trend Micro Team unterstützt und verlief reibungslos.

Insgesamt war die Einrichtung unkompliziert: Rund 1.000 Server im Rechenzentrum wurden innerhalb von zwei bis drei Monaten in Test-, Review- und Rollout-Phasen eingeführt. Der Prozess war effizient und gut strukturiert – besonders angesichts der Deployment-Größe.

Wer war am Implementierungsprozess beteiligt?

Die Implementierung erfolgte intern durch zwei Personen – mich selbst und einen weiteren Kollegen. Wir betreuten alle Phasen, von der Planung bis zum Rollout.

Das Schweizer Trend Micro Team leistete dabei enge technische Unterstützung. Später übernahm der deutsche Dienstleister PingUs die Integration des SOC. Die laufende Wartung wird von acht internen Mitarbeitenden übernommen, wobei der Pflegeaufwand der Lösung insgesamt gering ist.

Wie war der ROI?

Ein direkter Return on Investment war kein vorrangiges Ziel. Wir bieten unseren Kunden Managed Services an, bei denen Antivirenschutz im Gesamtpaket enthalten ist. Die Investition diente vor allem der Cyber-Resilienz und Betriebssicherheit. Künftig planen wir jedoch, Teile dieser Services auch extern anzubieten, um einen ROI zu erzielen.

Wie bewerte ich Preisgestaltung, Einrichtung und Lizenzierung?

Wir verfügen über ein Enterprise Agreement mit Trend Micro – eine sechsjährige strategische Partnerschaft mit definiertem Verbrauchsvolumen. Das Preisniveau ist für den Funktionsumfang angemessen: weder überhöht noch niedrig, sondern im Einklang mit dem gebotenen Mehrwert.

Welche Alternativen wurden evaluiert?

Wir haben mehrere Anbieter geprüft, darunter auch die neuen Sophos-Lösungen. Trend Vision One setzte sich durch – dank modularer Servicearchitektur, moderner Plattformstruktur und der starken Unterstützung durch das Schweizer Team.

Welchen Rat würde ich anderen geben?

Ich empfehle, diese Lösung in Betracht zu ziehen – insbesondere mit Unterstützung eines kompetenten Partners in der Einführungsphase. Fachliche Begleitung hilft, die Plattform optimal zu konfigurieren und ihr volles Potenzial auszuschöpfen. Zudem vereinfacht Trend Vision One das Vendor Management, da mehrere Anbieter überflüssig werden.

Ich bewerte Trend Vision One mit neun von zehn Punkten.

Welches Bereitstellungsmodell nutzen wir?

Hybrid-Cloud-Umgebung


    reviewer2754906

We've ease of configuration and customization and improvement in threat response

  • September 04, 2025
  • Review provided by PeerSpot

What is our primary use case?

We use Trend Vision One for our endpoint protection in our data center, mostly focused around our server assets, and we do anti-malware, intrusion prevention, as well as firewall, host-based firewall capabilities.

What is most valuable?

The ease of configuration, customization, and organization are what I appreciate the most about Trend Vision One.

What needs improvement?

It is a bit slow to implement kernel support on the Linux side. When doing patching and upgrades on our Linux servers, we often find that the Trend agent doesn't support the kernel version. It's usually not far behind, but we often are in a position where we may not be properly protected for a period.

For how long have I used the solution?

We started using Trend Deep Security, which was the product prior to Trend Vision One, seven or eight years ago, and then we transitioned to Trend Vision One two years ago. While we have been using Trend Vision One proper for two years, we had essentially the same product in an on-prem version for seven or eight years.

What do I think about the stability of the solution?

We've had performance issues with the agents of Trend Vision One at odd times, but I wouldn't say it's been a widespread issue or a common issue. Once in a while, there have been things that we've attributed to Trend.

What do I think about the scalability of the solution?

The scalability of Trend Vision One seems infinite. We're not a huge organization, so we haven't really run into any limitations, but it appears it can scale to accommodate and serve any of our purposes.

How are customer service and support?

The quality of support for Trend Vision One is generally very good. If we have any issues with support, we can leverage our sales engineer for support or escalation. I really haven't had any concerns. I have contacted the technical support or customer support via phone number or ticket.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We have used Microsoft Defender, Sophos, as well as McAfee as alternatives to Trend Vision One. I prefer Trend Vision One more compared to those alternatives.

How was the initial setup?

We transitioned from our on-premises Deep Security deployment to Vision One, and the process was relatively smooth. However, we encountered a few challenges related to legacy configurations and ensuring proper connectivity to our server assets. With an on-premises software application, we didn’t have to worry about internet accessibility for some of our server nodes. Consequently, we faced issues getting non-internet-connected server endpoints to communicate with the cloud. Luckily, there is a solution for that, but it took some time to get everything functioning properly.

Trend Vision One is a large product suite. There are many features that we don't have fully deployed, but the amount of time it took for us to go from on-prem to the cloud for similar services without onboarding anything new that Trend Vision One offered was two months for 400 assets, server nodes.

What was our ROI?

It has reduced our time to detect and respond to threats, but I don’t have a way to quantify that.

What's my experience with pricing, setup cost, and licensing?

I know the pricing for Trend Vision One. It's been a while, but it doesn't seem bad. They made some changes to their pricing in the past. It used to be a per-server node pricing structure, but now they do it by credits. I would say it's improved because we can, for the same investment, shift and adjust which capabilities we're leveraging within the platform. It's not super expensive. It's definitely an increased cost over leveraging Microsoft Defender, which we already have the licensing and capability for. We chose to spend money on this as opposed to leveraging a product that we already had, but the cost is fair.

What other advice do I have?

The sensors we're using include the anti-malware products, and we have the EDR sensors deployed on our server endpoints. They have network sensors and other features, but we're not leveraging any of those.

We started onboarding some of our services in the last three or four months to Trend Vision One to gain more visibility, so it's early in that adoption. We haven't taken any action based on alerts or notifications from Trend Vision One, as we're still in the early stages of getting our third-party services set up and monitored.

Trend Vision One hasn't helped us consolidate use of security vendors. This product is solely used for one purpose. We're not leveraging Trend Vision One for other areas within IT or at our company, so we haven't reduced silos. We had an opportunity to go with Defender, which would have reduced the number of products we use, but instead we decided to keep using Trend because we did appreciate it. I'm not sure if Trend Vision One has helped me to reduce the noise from false positives.

I would rate Trend Vision One a nine out of ten.


    Alexander Lung

Worldwide Protection of the Entire IT Infrastructure with Just One Central Platform

  • August 31, 2025
  • Review provided by PeerSpot

What is our primary use case?

Our main goal with Trend Vision One is to ensure comprehensive security coverage for all our devices and clients worldwide. We're concerned with far more than just traditional antivirus protection. With this solution, I can now see in detail which software updates have already been installed and which security vulnerabilities still exist. The comprehensive reporting and intelligent protective measures give me significantly more control than before. We can now cover all servers uniformly and completely, which is something that wasn’t possible with our previous solution at this level of quality.


What is most valuable?

The dashboard is the heart of Trend Vision One for me. What I particularly appreciate is the flexibility: each colleague can create their own dashboard, and I still maintain an overview of the big picture. This granular way of working while maintaining a holistic view motivates me to engage with the tool.

The cloud-based architecture offers considerable advantages over local, individual solutions. Previously, I had to manage patching across various Trend Micro systems manually - now, that’s centrally handled. However, I need to be cautious that updates aren't rolled out too quickly, which could impact notebooks or servers.

The global overview has definitely helped me a lot. The only drawback is the usual subscription model - unfortunately, prices tend to move upward.

Since I've been working with Trend Micro for over 20 years, we’ve been able to consolidate our security landscape and source everything from one vendor, rather than juggling multiple providers.

Trend Vision One gives us better visibility to detect and respond to threats because we can now see more than ever before. We've always made every effort to receive notifications quickly so we could act immediately. Now, I have a much clearer, centralized platform where I can manage all incidents in a structured way.

Interestingly, Trend Vision One shows us more error messages than before, not because more problems are occurring, but because I can now see them for the first time and address them systematically.

Trend Vision One helps us reduce our overall cyber risk. I've always had good experiences with Trend Micro. It gives me the confidence to recognize well-protected areas and uncover vulnerabilities that need attention. Even though I've achieved a good security level, I can't afford to relax. For security audits, the solution helps us demonstrate compliance with certain standards.

Regarding AI integration, I can't make a final judgment yet. AI has both advantages and disadvantages, and attackers are increasingly using it too. However, I believe that AI will become indispensable in security platforms.


What needs improvement?

The expansion of Phish Insight would be desirable, especially for employee training. Also, in the MDM area for mobile devices, not all functions are available that I know from on-premise or other cloud variants. There's still development potential there.

For how long have I used the solution?

We began implementing the current Trend Vision One solution in June 2024. However, Trend Micro has been our vendor for about ten years.


What do I think about the stability of the solution?

I'm very satisfied with the stability. I haven't experienced any direct outages so far. Occasionally, there were connection problems with individual clients, but those were exceptions.

What do I think about the scalability of the solution?

I think Trend Vision One offers very good scalability.

How are customer service and support?

I would rate the service and technical support for Trend Vision One at nine to ten points. Of course, it depends on the specific situation, but overall, I'm very satisfied.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We didn't switch from another solution but rather implemented Trend Vision One as an evolution of our existing Trend Micro infrastructure. I had explored Microsoft solutions in recent years and attended related training, but ultimately, we stayed with Trend Micro.


How was the initial setup?

The initial setup has a certain complexity that varies by area. Some areas are relatively easy to configure; others definitely require expertise and practice. Without professional support, the start would have been difficult.

We had two German partners on board for several weeks and months. In short, intensive sessions of two to four hours, they developed a structured onboarding process with us. After about three two-hour sessions, we could work independently with the product.

Our implementation strategy for Trend Vision One was three-tiered: First, we migrated from our on-premise Apex One solution to Trend Vision One in the cloud. In the second step, we migrated the servers, and finally we checked all sensors.

What about the implementation team?

We worked with a Trend Micro partner for onboarding. With Trend Micro's recommendation, we also purchased the licenses through them. The partner guided us during the sessions, then we carried out the actual integration and migration ourselves.

For implementation, we needed two to three employees. A colleague and I carried the main responsibility, my colleague handled the cloud migration, agents, and clients. I brought in two additional colleagues for servers and local infrastructure, particularly for Mac systems.

From mid-June to mid-September, an average of two to three people were involved in the project.


What was our ROI?

I can't definitively evaluate the return on investment yet, since we've only been working productively for a few months. We had a very good onboarding process and worked intensively on it, but for a solid ROI evaluation, it's still too early. I plan to have meaningful numbers by year-end, particularly through patch management and sensor detections.


What's my experience with pricing, setup cost, and licensing?

As usual, we work with twelve-month or multi-year licenses on a subscription basis. The subscription model is ideal for the vendor and predictable for us, but still quite expensive.

I would like more flexibility - for example, the ability to purchase individual modules separately.

What other advice do I have?

For others evaluating Trend Vision One, I recommend checking whether the vendor is a pure security specialist or also active in other, non-security-related areas. That can be an important decision factor.

Overall, I rate the solution 9 out of 10 points.

Foreign Language: (German)

Weltweiter Schutz der gesamten IT-Infrastruktur mit nur einer zentralen Plattform

Was ist unser primärer Anwendungsfall?

Unser Hauptziel mit Trend Vision One ist es, eine lückenlose Sicherheitsabdeckung für alle unsere Geräte und Clients weltweit zu gewährleisten. Dabei geht es uns um weit mehr als nur klassischen Antivirenschutz. Mit der Lösung kann ich nun detailliert einsehen, welche Software-Updates bereits installiert sind und welche Sicherheitslücken noch bestehen. Das umfassende Reporting und die intelligenten Schutzmaßnahmen geben mir deutlich mehr Kontrolle als früher. Wir können jetzt alle Server einheitlich und vollständig abdecken, was mit unserer vorherigen Lösung nicht in dieser Qualität möglich war.

Was ist am wertvollsten?

Das Dashboard ist für mich das Herzstück von Trend Vision One. Was ich besonders schätze, ist die Flexibilität: Jeder Kollege kann sich sein eigenes Dashboard erstellen, und trotzdem behalte ich den Überblick über das große Ganze. Diese granulare Arbeitsweise bei gleichzeitigem Gesamtüberblick motiviert mich mit dem Tool zu arbeiten.

Die Cloud-basierte Architektur bringt mir erhebliche Vorteile gegenüber lokalen Einzellösungen. Früher musste ich mich um das individuelle Patching verschiedener Trend Micro Systeme kümmern, das ist jetzt zentral verwaltet. Allerdings muss ich aufpassen, dass Updates nicht zu schnell ausgerollt werden und dabei Notebooks oder Server beeinträchtigen.

Der globale Überblick hat mir definitiv sehr geholfen. Einziger Nachteil ist das übliche Abonnementmodell, die Preise entwickeln sich leider nur in eine Richtung und das ist nach oben.

Da ich bereits seit über 20 Jahren mit Trend Micro arbeite, konnten wir unsere Sicherheitslandschaft gut konsolidieren und alles aus einer Hand beziehen, anstatt verschiedene Anbieter zu jonglieren.

Trend Vision One verschafft uns deutlich bessere Sichtbarkeit, um Bedrohungen zu erkennen und darauf zu reagieren, weil wir jetzt noch mehr sehen können als zuvor. Wir haben immer alles darangesetzt, Informationen sehr schnell über Benachrichtigungen zu erhalten, damit wir sofort daran arbeiten können. Aber jetzt habe ich eine wesentlich klarere, zentrale Plattform, auf der ich alle Vorfälle strukturiert bearbeiten kann.

Interessant ist, dass Vision One uns mehr Fehlermeldungen anzeigt als früher, nicht weil mehr Probleme auftreten, sondern weil ich sie jetzt überhaupt erst sehen und systematisch abarbeiten kann.

Trend Vision One hilft uns, unser gesamtes Cyber-Risiko zu reduzieren. Ich habe immer gute Erfahrungen mit Trend Micro gemacht. Es gibt mir das Sicherheitsgefühl, gut geschützte Bereiche zu erkennen, aber auch Schwachstellen aufzudecken, an denen wir arbeiten müssen. Auch wenn ich bereits ein gutes Sicherheitsniveau erreicht habe, darf ich mich nicht darauf ausruhen. Bei Sicherheits-Audits hilft uns die Lösung definitiv, bestimmte Standards nachzuweisen.

Zur KI-Integration kann ich noch nicht abschließend urteilen. KI hat Vor- und Nachteile, und auch Angreifer nutzen sie zunehmend. Ich gehe aber davon aus, dass KI in Sicherheitsplattformen unverzichtbar werden wird.

Was muss verbessert werden?

Der Ausbau von Phish Insight wäre wünschenswert, besonders für Mitarbeiterschulungen. Auch im MDM-Bereich für mobile Geräte sind nicht alle Funktionen verfügbar, die ich von On-Premise oder anderen Cloud-Varianten kenne. Da ist noch Entwicklungspotential vorhanden.

Wie lange nutze ich die Lösung schon?

Wir haben im Juni 2024 mit der Implementierung der aktuellen Vision One Lösung begonnen. Trend Micro als Anbieter begleitet uns aber bereits seit etwa zehn Jahren.

Was halte ich von der Stabilität der Lösung?

Ich bin mit der Stabilität sehr zufrieden. Direkte Ausfälle hatte ich bisher keine. Gelegentlich gab es Verbindungsprobleme bei einzelnen Clients, aber das waren eher Ausnahmen.

Was halte ich von der Skalierbarkeit der Lösung?

Ich denke, Trend Vision One bietet eine sehr gute Skalierbarkeit.

Wie sind Kundenservice und Support?

Ich würde den Service und technischen Support für Trend Vision One mit neun bis zehn Punkten bewerten. Es hängt natürlich immer von der konkreten Situation ab, aber grundsätzlich bin ich sehr zufrieden.

Welche Lösung habe ich zuvor verwendet und warum habe ich gewechselt?

Wir haben nicht von einer anderen Lösung gewechselt, sondern Vision One als Weiterentwicklung unserer bestehenden Trend Micro Infrastruktur implementiert. Ich hatte mir in den letzten Jahren zwar Microsoft-Lösungen angeschaut und entsprechende Schulungen besucht, aber letztendlich sind wir bei Trend Micro geblieben.

Wie war das initiale Setup?

Die Ersteinrichtung hat eine gewisse Komplexität, die je nach Bereich variiert. Einige Bereiche sind relativ einfach zu konfigurieren, andere erfordern definitiv Fachwissen und Übung. Ohne professionelle Unterstützung wäre der Start schwierig gewesen.

Wir hatten zwei deutsche Partner über mehrere Wochen und Monate im Boot. In kurzen, intensiven Sitzungen von zwei bis vier Stunden entwickelten sie mit uns einen strukturierten Onboarding-Prozess. Nach etwa drei zweistündigen Sitzungen konnten wir eigenständig mit dem Produkt arbeiten.

Unsere Implementierungsstrategie für Trend Vision One war dreistufig: Zunächst migrierten wir von unserer On-Premise Apex One Lösung zu Vision One in der Cloud. Im zweiten Schritt haben wir die Server migriert, und abschließend überprüften wir alle Sensoren.

Wie war das Implementierungsteam?

Wir arbeiteten mit einem Trend Micro Partner für das Onboarding zusammen. Auf Empfehlung von Trend Micro kauften wir auch die Lizenzen dort. Der Partner leitete uns während der Sitzungen an, die eigentliche Integration und Migration führten wir dann selbst durch.

Für die Implementierung benötigten wir zwei bis drei Mitarbeiter. Ein Kollege und ich trugen die Hauptverantwortung, wobei sich mein Kollege um den Cloud-Umzug, Agents und Clients kümmerte. Ich zog zwei weitere Kollegen für Server und lokale Infrastruktur, insbesondere für Mac-Systeme, hinzu.

Von Mitte Juni bis Mitte September waren durchschnittlich zwei bis drei Personen gleichzeitig am Projekt beteiligt.

Wie war unser ROI?

Den Return on Investment kann ich noch nicht definitiv bewerten, da wir erst seit wenigen Monaten produktiv arbeiten. Wir hatten einen sehr guten Onboarding-Prozess und haben intensiv daran gearbeitet, aber für eine fundierte ROI-Bewertung ist es derzeit noch zu früh. Ich plane, bis Jahresende aussagekräftige Zahlen zu haben, insbesondere durch das Patch-Management und die Sensor-Erkennungen.

Wie sind meine Erfahrungen mit Preisgestaltung, Einrichtungskosten und Lizenzierung?

Wie üblich arbeiten wir mit zwölfmonatigen oder mehrjährigen Lizenzen auf Abonnementbasis. Das Abonnementmodell ist für den Anbieter ideal und für uns kalkulierbar, auch wenn nicht ganz günstig.

Ich würde mir mehr Flexibilität wünschen – zum Beispiel die Möglichkeit, einzelne Module separat zu erwerben.

Welche weiteren Ratschläge habe ich?

Anderen, die Trend Vision One evaluieren, empfehle ich zu prüfen, ob der Anbieter ein reiner Sicherheitsspezialist ist oder ob er auch in anderen, sicherheitsfremden Bereichen tätig ist. Das kann ein wichtiger Entscheidungsfaktor sein.

Insgesamt bewerte ich die Lösung mit 9 von 10 Punkten.