Hi everyone. I’m relatively new to security software selection, but I was recently part of a team that moved our endpoint protection from Symantec Endpoint Protection to VMware Carbon Black Cloud. We’re a mid-sized company, and I handled a lot of the vendor research and project tracking.
The main reason we switched was the console. Symantec’s felt outdated and alerts were noisy. We wanted something with better visibility and a more modern interface. Carbon Black Cloud’s dashboard seemed clearer, and the idea of seeing process lineages really appealed to our IT lead.
However, the transition wasn’t all smooth. The biggest gotcha for us was the initial policy setup. Coming from Symantec, we weren’t prepared for how granular Carbon Black can be. We accidentally blocked a critical legacy app because we set a policy too strictly. It took some back-and-forth with support to understand the “recommended” policies versus creating our own from scratch.
Another thing that caught us off guard was the resource usage on some older machines. The sensor is fine on modern laptops, but we have a handful of older desktops where users noticed a slowdown, especially during full scans. We had to adjust the scan schedules and exclusions carefully.
Overall, I’m cautiously optimistic. The investigation tools feel powerful, but there’s a learning curve. I’m curious if others who made a similar switch have advice on policy tuning or managing performance on older hardware.