Trend Vision One XDR is the enterprise security platform from Trend Micro (whose enterprise business unit has been known as TrendAI™ since March 2026) that collects and correlates telemetry from six native security sensors — endpoint, server, email, network, cloud and identity — in a single data layer (Trend Micro Newsroom, 2025). Detection and response (XDR), attack surface risk management (ASRM / Cyber Risk Exposure Management), automation (SOAR) and managed detection and response (MDR) all run in the same console; there is no need to switch between separate product interfaces.
The platform's detection strength is measurable through independent assessments: in the MITRE ATT&CK Evaluations round published in December 2024, Vision One achieved 100% analytic coverage across all major attack steps and 99% across all substeps (Trend Micro Newsroom, 2024). At Sora Yazılım, as an authorised channel partner, we handle this platform's licensing in Turkey, its rollout, its integration into your existing SIEM and SOC environments and its operation in line with KVKK (Turkey's data protection law).
What is Trend Vision One and which telemetry sources does it unify in one console?
Vision One is an XDR platform that, instead of having you review the alerts produced by individual security products one by one, combines the raw telemetry of those products in a common data model and presents it as a single incident chain. Six native sensors — endpoint, server and workload, email, network, cloud, identity — are fed by Trend's own agents. Third-party sources are added through the Agentic SIEM layer: this component, released on 1 August 2025, has supported more than 900 data sources since launch and provides up to 2 years of analytic and up to 7 years of archive data retention (Trend Micro Newsroom, 2025).
Operationally, one important detail is how long it takes to onboard a new log type to the platform. According to the vendor, that currently takes about three days, with a target of reducing it to three hours during 2026 (Trend Micro Newsroom, 2025). In practice this means you do not have to launch a separate development project to bring the logs of a niche in-house application into correlation. As soon as the data source is added, the same query language, the same workbench and the same automation rules cover it too.
Why are individual product consoles no longer enough?
Because attack chains do not stay in a single layer. Verizon's 2025 Data Breach Investigations Report examined 12,195 confirmed breaches across 139 countries; 60% of breaches involved a human element and 44% involved ransomware (Verizon 2025 DBIR). The same report notes that vulnerability exploitation as an initial access vector grew by 34% and now accounts for 20% of breaches. On the European side, ENISA Threat Landscape 2025 analysed 4,875 incidents targeting the EU between 1 July 2024 and 30 June 2025 and identified phishing as the most common initial access vector at 60%, followed by vulnerability exploitation at 21.3% (ENISA Threat Landscape 2025).
The cost side supports the same picture: according to IBM's 2025 Cost of a Data Breach Report, the global average breach lifecycle — the time until a breach is detected and contained — is 241 days, and the average breach cost is 4.44 million US dollars (IBM Newsroom, 2025). If an attack starts with an email, runs a tool on the endpoint, escalates privileges at the identity layer and exfiltrates data from a server, seeing those four steps one by one in four separate consoles will not shorten those 241 days. That is exactly the problem Vision One sets out to solve: connecting the steps to each other and reducing them to a single response decision.
How is Trend Vision One XDR positioned in independent analyst and technical evaluations?
Short answer: the platform holds Leader positions in both the endpoint protection and attack surface management categories, and has published full-coverage results in MITRE ATT&CK evaluations. The table below contains only verifiable results published by the vendor or an analyst firm.
| Evaluation | Period | Result |
|---|
| Gartner Magic Quadrant for Endpoint Protection Platforms | 2026 | Leader for the 21st consecutive time (Trend Micro Newsroom, 2026) |
| Gartner Critical Capabilities for EPP | 2026 | Highest score among all vendors in two of the three use cases (Trend Micro Newsroom, 2026) |
| Gartner Magic Quadrant for Endpoint Protection Platforms | 2025 | Leader for the 20th consecutive time; the product evaluated was Vision One Endpoint Security (Trend Micro Newsroom, 2025) |
| MITRE ATT&CK Evaluations | December 2024 | 100% analytic coverage on major steps, 99% on substeps (Trend Micro Newsroom, 2024) |
| MITRE Engenuity ATT&CK Evaluations — Managed Services | 2024 | All 15 major attack steps detected; 86% of the steps analysed in an actionable way (Trend Micro Newsroom, 2024) |
| The Forrester Wave: Attack Surface Management Solutions | Q3 2024 | Leader; the report notes that Vision One covers identities, networks and a broad range of devices (Forrester Wave ASM report, 2024) |
| IDC MarketScape: Worldwide Exposure Management | 2025 | Vision One Cyber Risk Exposure Management positioned as a Leader (TrendAI CREM product page, 2025) |
| IDC MarketScape: MDR for Midmarket | 2026 | Major Player (TrendAI Endpoint Security page, 2026) |
The service evaluated in MITRE's managed services round was the MDR delivered directly through Vision One; the scenario emulated the tactics, techniques and procedures of the state-linked menuPass (APT10) group and the ransomware-as-a-service collective BlackCat/AlphV (Trend Micro Newsroom, 2024). In the December 2024 round, 100% analytic coverage was achieved across all Linux and macOS substeps and on the Windows/Linux server platform; that round included ransomware attacks targeting Linux and macOS as well as North Korea-linked attacks targeting macOS (Trend Micro Newsroom, 2024). The vendor states that its products have achieved a 100% detection rate in MITRE Engenuity ATT&CK Evaluations since 2020.
Where does the vulnerability intelligence behind the platform come from?
Chief among the sources feeding detection content is the Zero Day Initiative (ZDI) programme, founded in 2005. ZDI today works with research teams across 14 global threat centres and more than 19,000 independent researchers; the programme has disclosed more than 15,000 vulnerabilities since 2007 and, according to Omdia Research data, accounted single-handedly for 73% of all global disclosures in 2024 (Zero Day Initiative, 2024). The Pwn2Own Ireland 2025 competition uncovered 73 unique zero-day vulnerabilities and awarded participants a total of 1,024,750 US dollars; the vendor states that thanks to this research it can protect customers against zero-day exploits an average of 71 days earlier than the industry (Trend Micro Newsroom, 2025).
Why did the brand name change to TrendAI?
Trend Micro's enterprise security business took the name TrendAI on 23 March 2026; the parent company retained the name Trend Micro Incorporated (Trend Micro Newsroom, 2026). On official pages the product name now appears as "TrendAI Vision One". This is a brand name change; the console, tenant structure, credit balance and contracts in force are unaffected. In Turkey, the entire Trend Micro solution family continues to be licensed through the same channel structure; seeing both the old and the new name side by side in documents and quotes is perfectly normal.
What is the relationship between Apex One, Deep Security and Trend Vision One?
Vision One is a platform, while Apex One and Deep Security are sensors that feed telemetry into it; they are complements, not alternatives. Apex One endpoint protection performs the EPP and EDR role on desktops and laptops. Deep Security server and workload protection runs the eight protection modules defined in the official documentation on physical, virtual and cloud servers: Intrusion Prevention, Anti-Malware, Firewall, Web Reputation, Integrity Monitoring, Log Inspection, Application Control and Device Control (Deep Security 20 Help Center, 2024).
Without Vision One, these products run in their own consoles and do their job perfectly well on their own. With Vision One, the endpoint leg, server leg and email leg of the same incident appear in a single chain, and the response decision is made from one place. The table below compares the roles of the three products.
| Criterion | Apex One | Deep Security | Trend Vision One |
|---|
| Scope | User endpoints | Physical, virtual and cloud server workloads | Six native sensors plus third-party sources via Agentic SIEM |
| Primary function | Endpoint protection and EDR | Server security, virtual patching, file integrity monitoring | XDR correlation, risk management, automation, managed service |
| Management interface | Its own management console | Deep Security Manager | Single platform console (workbench, search, Companion) |
| Example components | Behaviour monitoring, device control, application control | Eight protection modules (Trend, 2024) | Workbench, Search, Companion, Agentic SIEM, CREM |
| Deployment | On-premises and SaaS | On-premises and cloud | SaaS, sovereign and private cloud, on-premises, isolated installation (TrendAI, 2026) |
| Typical purchase rationale | Endpoint standardisation | Server compliance (PCI DSS 11.5.1 and 11.5.2) (PCI SSC) | Organisation-wide detection, response and cyber risk management |
The same logic applies at the network and email layers. The Deep Discovery network detection and response solution monitors all network ports and more than 100 network protocols to cover both north-south and east-west traffic (Deep Discovery Inspector datasheet, 2024). TippingPoint next-generation IPS customers begin to be protected against ZDI-sourced vulnerabilities an average of 96 days before the vendor patch (Omdia Research, 2025). On the Trend Email Security side, the platform detected and blocked 57 million high-risk email threats in 2024, a 27% increase over the 45 million in 2023 (Trend 2025 Cyber Risk Report). Each of these sensors can be purchased on its own; Vision One is the layer that brings them together in a common incident chain.
What do the Companion AI assistant and Agentic SIEM deliver to a SOC team?
Companion is a generative AI assistant embedded in the console: it summarises alerts in natural language, explains complex command lines and scripts, generates queries and suggests response steps. According to the vendor's launch announcement, Companion can accelerate incident response times by 30%, save up to two hours per incident report, and reduce the time spent on manual risk assessment and threat research by 50% or more (Trend Micro Newsroom, 2023).
What that means in practice: the tasks that consume most of a tier-one and tier-two analyst's time — decoding an obfuscated PowerShell command, finding which MITRE ATT&CK technique an alert maps to, writing the incident summary for management — are produced by the assistant as a first draft. The final decision stays with the analyst; the assistant is a preparation layer, not an approval authority. Questions can be asked in Turkish, although technical report output is produced predominantly in English. For teams looking to scale AI-assisted workflows across the organisation, our artificial intelligence and LLM consultancy service is used to connect Companion output to corporate reporting and approval processes.
Does Agentic SIEM replace our existing SIEM investment?
It depends. Agentic SIEM is the component that adds third-party log sources to the Vision One data layer and evaluates them in the same engine as XDR correlation; with support for more than 900 data sources plus 2 years of analytic and 7 years of archive retention capacity, it approaches the scope of a classic SIEM (Trend Micro Newsroom, 2025). That said, if your organisation runs a long-established Splunk, Microsoft Sentinel or QRadar deployment matured with custom correlation rules and compliance reports, the common approach is to position Vision One as a source feeding high-quality events into that SIEM. Which model is right is determined by your log volume, retention obligations and licence agreements in force; we make that decision together at the start of the project.
What does attack surface risk management (CREM) measure and how is the risk score reduced?
Cyber Risk Exposure Management (CREM) — the successor to what the platform called ASRM — combines asset inventory, vulnerability data, misconfiguration and identity risk to produce a continuously updated risk score for the organisation. This module was positioned as a Leader in the IDC MarketScape: Worldwide Exposure Management assessment (TrendAI, 2025); the platform's attack surface management capabilities were rated as a Leader in The Forrester Wave: Attack Surface Management Solutions, Q3 2024, with the report noting coverage of identities, networks and a broad range of devices (Forrester Wave ASM report, 2024).
For a risk score to be meaningful, it needs a basis for comparison. In the Cyber Risk Index calculated from Trend's own telemetry, the 2024 average for organisations fell into the "moderate risk" band at 38.4 on a 0-100 scale; over the year the index improved by 6.2 points, declining from 42.5 in February to 36.3 in December (Trend 2025 Cyber Risk Report). Comparing your own score against that average gives you a concrete starting point for budget prioritisation: if you are markedly above the average, the problem is most likely not a missing product but unaddressed basic hygiene items.
Indeed, a significant share of the actions that reduce the risk score require infrastructure discipline rather than a new security product: unpatched servers, management ports exposed to the internet, orphaned service accounts, expired certificates, administrator accounts without multi-factor authentication. On that side, our DevOps and infrastructure services connect CREM findings to patch, configuration and access automation, so the list that appears in the report turns into a durable improvement. For systems that cannot be patched, virtual patching steps in: Deep Security's Intrusion Prevention module shields known vulnerabilities on a rule basis until a patch is applied (Deep Security 20 Help Center, 2024).
How do Trend Vision One licensing, deployment and managed service options work?
What is credit-based Flex licensing?
Vision One is licensed through a credit-based model called Flex. Credits are purchased for a defined term, activated for a solution and drawn down monthly according to actual usage; unused credits can be transferred to another solution within the contract term, and there is no need to manage a separate licence key per product. The model makes more than 30 Vision One solutions available under a single contract line item (TrendAI Flex Licensing).
The practical benefit of this model is that needs can change during the year. An organisation that starts its pilot with an endpoint focus may shift weight to the email or cloud sensor six months later; the credit balance permits that shift and does not require launching a new procurement process. The unit price per credit varies with organisation size, contract term and the mix of solutions chosen; that is why, instead of a list price, we prepare a credit consumption estimate and a tailored quote based on your inventory.
Does Vision One only run in the cloud?
No. The frequently heard claim that "Vision One is SaaS only" is no longer accurate. The platform can run in the cloud operated by TrendAI, and it can equally be deployed in the organisation's own private cloud, in its own data centre and in isolated environments with no external connectivity (TrendAI Deployment Options, 2026).
| Deployment option | What it covers | Typical reason for choosing it |
|---|
| SaaS | Public cloud operated by TrendAI or an authorised partner; GovCloud option included | Fastest rollout, lowest operational overhead |
| Sovereign and private cloud | Deployment in the organisation's private cloud (AWS, Azure or Google Cloud) | Data sovereignty; key management and audit remaining with the organisation (TrendAI, 2026) |
| On-premises | Deployment in the organisation's own data centre within the same sovereign deployment scope | Regulatory or internal policy requirement for data to remain in the organisation's data centre |
| Isolated (air-gapped) or offline | Fully separated installation with no external connectivity | Critical infrastructure, defence and production (OT) environments closed to external networks |
| Service provider model | Multi-tenant hosting and delivery by an authorised service provider | Outsourced security operations and MSSP services |
In sovereign and private cloud deployments, all data, metadata and operations remain within the organisation's sovereignty boundary; key management, audit processes and operational controls stay with the customer (TrendAI Sovereign and Private Cloud, 2026). For organisations with strict data residency policies, this means the single biggest obstacle that previously ruled Vision One out has been removed.
Who is Service One (MDR) suitable for?
Short answer: organisations that cannot staff a 24/7 analyst rota but still expect enterprise-grade detection and response. Service One is the managed detection and response service delivered through the Vision One platform. It was also the service evaluated in the managed services round of the MITRE Engenuity ATT&CK Evaluations: all 15 major attack steps were detected and 86% of those steps were analysed in an actionable way (Trend Micro Newsroom, 2024). The vendor also states that it was named a "Major Player" in the 2026 IDC MarketScape for MDR for Midmarket (TrendAI, 2026).
In Turkey we run this service in two layers: the global MDR team takes on continuous monitoring and threat hunting, while Sora Yazılım handles rollout, policy changes, post-incident root cause analysis and internal reporting during local business hours. In organisations building their own security operations centre, the model is reversed: the platform and decision authority stay with you, and we provide rollout, scaling and periodic health checks.
What does Vision One provide for KVKK and PCI DSS compliance in Turkey?
Article 12 of Law No. 6698 on the Protection of Personal Data — KVKK, Turkey's data protection law — obliges the data controller to "take all necessary technical and administrative measures to ensure an appropriate level of security" in order to prevent the unlawful processing of personal data, prevent unlawful access to it and safeguard its retention (KVKK, Obligations Regarding Data Security). The Authority's Personal Data Security Guide explicitly lists intrusion detection and prevention systems, log records, firewalls and up-to-date anti-virus systems among the technical measures that can be taken (KVKK Personal Data Security Guide).
The same guide recommends applying layered, regularly reviewed complementary measures, stating that "the view that full security can be achieved through the use of a single cybersecurity product is not always correct" (KVKK guide). This is precisely where Vision One's compliance value lies: it does not replace layered measures, it gathers them into a single, auditable record chain. For audits requiring long retention, Agentic SIEM's archive retention capacity can be used, and for organisations with data residency requirements, the sovereign cloud or on-premises deployment option.
In organisations processing card data, the PCI DSS v4.0 framework comes directly into play. Requirement 11.5.1 mandates that intrusion detection and/or prevention techniques monitor all traffic at the perimeter of and at critical points inside the cardholder data environment and that signatures be kept up to date; 11.5.2 requires a change-detection mechanism such as file integrity monitoring to be deployed and critical file comparisons to be performed at least weekly. Requirement 6.3.3 additionally requires critical or high-severity security patches to be installed within one month of release (PCI DSS v4.0 SAQ D for Service Providers). The first two requirements have direct product counterparts: TippingPoint or Deep Security's Intrusion Prevention module for 11.5.1, and the Integrity Monitoring module for 11.5.2. The counterpart of 6.3.3 is the patch itself; virtual patching is a complementary control that reduces risk until the patch is applied, and does not substitute for the requirement. The PCI SSC does not pre-approve any technology as a compensating control — using a compensating control requires a documented technical or business constraint plus QSA assessment. Vision One gathers the output of these controls in a single reporting layer.
The equation changes as organisation size decreases. For businesses with tens to hundreds of users and no dedicated security team, Worry-Free Business Security may be a more appropriate starting point; choosing to roll out Vision One generally becomes meaningful once a multi-site structure, a regulated sector or an in-house security operations objective enters the picture.
In summary, Trend Vision One XDR is a security platform that unifies the telemetry of six native sensors in a single data layer, reduces analyst workload with the Companion AI assistant and Agentic SIEM, continuously scores the attack surface with CREM, and is licensed through the credit-based Flex model. Deployment options ranging from SaaS to isolated (air-gapped) installation also make it viable for organisations with data residency requirements. It does not replace Apex One and Deep Security; it brings them together in the same incident chain.
At Sora Yazılım, as an authorised Trend Micro channel partner, we handle inventory mapping, credit sizing, pilot deployment, SIEM and directory service integration, KVKK-aligned policy design, analyst training and incident response support from a single source. Share your current endpoint, server and email inventory and let us prepare a quote covering scope, credit estimate and rollout schedule — request a quote.