TrustRadius: an HG Insights company

NetWitness

Score6.2 out of 10

16 Reviews and Ratings

What is NetWitness?

NetWitness Network is a cybersecurity solution designed to detect and respond to network threats. According to the vendor, it provides real-time visibility into an organization's IT infrastructure, making it suitable for businesses of various sizes. This product is utilized by cybersecurity professionals, IT administrators, security operations centers (SOCs), network administrators, and financial institutions to enhance network security and protect against emerging threats.

Read more details.

NetWitness Incident Response & Cyber Defense Services- Best SOC Solution for all Industries

Pros

  • Comprehensive security services to improve threat detection & response.
  • Holistic Security program for targeted attack defense -across three interrelated areas of expertise people(including organization model), process & technology -with particular emphasis on threat detection& response.
  • Assess organization security gap & provide a detailed improvement plan that is specific for the organization.

Cons

  • NetWitness Incident Response and Cyber Defense Services SIEM managed services which we call managed SOC requires multiple resources with expertise in different domains like Threat forensics & Logs Analytics ..etc. Sometimes it gets tough to get the right resources.
  • Difficulty in navigating & configuring, which is necessary for any solution to get the best result & reporting part.
  • Commercial of solution in comparison to competitors is at the higher end.

Alternatives Considered

FireEye Security Suite, FireEye Security Orchestrator and IBM Security QRadar

If you think of advances... think of NetWitness.

Use Cases and Deployment Scope

RSA NetWitness is one of the products that we implement for our clients as a solution provider. Threat protection is its primary purpose, which we share with them.

Pros

  • The sense of safety it affords
  • An excellent set of log-related features is provided.
  • With other risk-assessment tools, it works well.

Cons

  • This product isn't very customizable.
  • The cost is prohibitive.
  • Certain tools need to be improved and further developed to ensure security in specific implementation scenarios.

Most Important Features

  • Data analysis
  • The projection in data
  • we believe that the security it provides is enough but the support support makes it better

Return on Investment

  • We believe that the implementation in the beginning suffered many adversities making us lose more than half of the time.
  • We believe that we are not yet profitable with the objectives that we have with the program that this will be achieved in 1 month.
  • Although the implementation was difficult, we believe we will increase our productivity by 25% in 3 years.

NetWitness Orchestrator is a good goal-achieving program.

Use Cases and Deployment Scope

Real-time threat prediction is our primary use case for reducing the number of hours spent by IT security analysts too. One of our clients uses it to gather logs from all of their devices so that they have a single point of view into the trace information in their environments.

Pros

  • Threat prediction and network forensics are the most useful features. It's possible for me to see who received and clicked on any malware on the network, for example. This is the feature I enjoy the most.
  • In addition, the capture packet provides a wealth of information.
  • The support.

Cons

  • Improved reporting would be beneficial.
  • The inclusion of vulnerability protection, as found in many competing products, would enhance this solution.
  • In the beginning, it's a lot of work.

Most Important Features

  • Good ability to grow.
  • It's possible to determine their endpoints and circuit paths using this approach. Both the logs and the packets should be taken into account.
  • Good return on investment.

Return on Investment

  • ROI is projected for 6 months from today which outperforms other competitors on price
  • Early scalability makes ROI possible and sustained over time
  • The proposed objectives of the team in it have been met in half of the requirements.

Incident Response by RSA

Pros

  • Able to investigate threats faster.
  • Faster and more advanced treat detection.
  • Analytics.

Cons

  • Documentation.
  • Parsing of logs.
  • User interface.

Alternatives Considered

Splunk Enterprise Security (SIEM)

RSA SA - Security expert

Pros

  • Easy to use and understand
  • Provides extensive details to analyze the threat with more accuracy
  • It is a smart tool with graphical display of data for easier interpretation

Cons

  • The meta part to form the dashboards were a bit complicated
  • The user interface could be made more understandable

Return on Investment

  • Increased efficiency
  • Reduced the number of web attacks and data is more secured
  • Better customer service

Other Software Used

SolarWinds Log & Event Manager, IBM Security Network Intrusion Prevention System