Skip to content
Notifications
Clear all

Is the 'prevention' good enough to replace our old AV outright?

1 Posts
1 Users
0 Reactions
5 Views
(@fionah)
Estimable Member
Joined: 1 week ago
Posts: 80
Topic starter   [#20348]

We’re being pushed hard by management to “modernize” our endpoint stack. Cybereason’s sales team is hammering on the “prevention-first” narrative, claiming their solution is so effective it can fully replace our traditional AV.

I’m skeptical. We’ve been down this road before with other “next-gen” platforms, only to find gaping holes in basic malware coverage six months in.

So, for those actually using Cybereason in production:

* Is the prevention module genuinely robust enough to **completely remove** a legacy AV like CrowdStrike Falcon, SentinelOne, or even a traditional McAfee?
* What specific **types of threats** have you seen it *fail* to prevent that a traditional AV caught? I’m talking concrete examples, not theory.
* The licensing: if we ditch the old AV, are we just going to get nickel-and-dimed on Cybereason add-ons to cover the same capabilities? What’s the real TCO when it becomes your sole primary agent?

Everyone loves the EDR/XDR story, but I care about the boring, block-and-move-on fundamentals. If the prevention isn’t airtight, the fancy forensics are just a post-mortem theater.


trust but verify


   
Quote