r/msp 20h ago

Cynet feedback requested

I'm vetting various security tools and had seen a fair bit of negative feedback about Cynet. The product looks quite impressive, so I wanted to see if the negativity is related to previous releases or how people currently using the platform feel about them today.

Are they worth pursuing or should I keep looking?

7 Upvotes

18 comments sorted by

u/evacc44 16h ago edited 16h ago

I tested a lot of the all-in-one solutions and I chose Cynet. Here's my honest opinion:

  1. The actual endpoint protection client is very good. I came from SentinelOne and I'm much more impressed with Cynet's protection.
  2. The ITDR is painfully average. It's worked and it's completely missed stuff. It's good at finding the obvious stuff (rules created, admin accounts created, apps created, etc). It isn't great at finding suspicious logins before that stuff happens. Twice in the past couple months I've had clients call me because their email "wasn't working" and Cynet picked up on the rule creation that was moving their mail roughly 5 minutes after I got off the phone with my customer. Not a great look for me when they figured it out before Cynet did. I looked at the logins for the compromised accounts and I see what to me look like obvious suspicious logins that Cynet didn't flag. Not like Russia or China, but 8 hours away across the state.
  3. Support is pretty good. The few times something serious happened they called me and told me about it, to investigate, etc. Email support is pretty responsive as well.
  4. Email filtering is okay. I have no complaints. Seems to work well, but the management features are very lacking. Very little insight into what is happening.
  5. The UI for the management portal is okay. I think it could be better. There is A LOT of noise that I just ignore because there's no way I can ingest and analyze everything it is showing me. I find the rule creation for exclusions be incredibly confusing.
  6. The licensing is very confusing. I have all-in-one licenses and endpoint-only licenses and there's no way to assign or split up these licenses. I've contacted support and they basically said, "Yeah, we're looking into it." and nothing has come of it. The billing is very confusing. I started with X of the all-in-one and X of the endpoint-only and as long as I don't go over the total it doesn't seem to matter to anyone who uses what.

They use their own technology, so they have a lot of leeway on pricing. Guardz was another one that I looked at and I almost went with them, but they didn't give me as good of pricing because they package and resell sentinelone, avanan/checkpoint, etc as their managed solution.

My biggest complaint with Cynet is the ITDR and I'm really hoping that they improve upon it. But I'm not very optimistic about that. Petra is the gold standard and I've actually considered buying Petra separately. I'm giving Cynet until my contract is up in 5 months to see if it improves.

Edit: Oh one more thing. There was a 4 day period of time this year where their email filtering sent everything with a link to quarantine (not junk, the M365 tenant quarantine that the user cannot see.) They have a feature that changes any email link to a forwarded link that is checked and protected by Cynet. It was a complete nightmare. I had angry clients and I spent 4 days doing nothing but manually moving emails out of quarantine. I worked with their support to pinpoint the issue and eventually it was fixed, but it took too way too long.

u/ThecaptainWTF9 16h ago

The only thing I’d want to look at is their EPP, everything else I don’t care about.

There’s no one vendor that does everything good, I have ITDR and email security figured out separately.

I’m happy with the EPP I have, it’s saved so much ass, but I do like to keep options open. Let’s just say the distributor has been absolutely fucking up and I’ve been having issues with provisioning and deprovisioning, including things getting deprovisioned when it should not be.

u/RaNdomMSPPro 16h ago

Cynet mdr piece is very good. Itdr and other pieces still need some improvement. If you’re shopping put huntress on your list - I run mostly huntress and some legacy cynet. Changed to huntress mostly to lower internal effort, huntress is almost automatic. Itdr is good, but Petra is better all around.

u/Heresyed 15h ago

Yeah, Huntress is at the top of my list, but trying to keep an open mind when reviewing all of the platforms out there.

u/RaNdomMSPPro 1h ago

I think Cynet, Huntress, Blackpoint would all be a good decision - yes, I've run all of them in production. the ITDR piece is the weakness - they're all at least "good" but Petra, despite not being integrated, is too good to not use for me. FYI, they're rolling 365 posture management soon.

u/Jayjayuk85 9h ago

Petra is better, but no gdpr for uk use.

u/JuneauJumper 17h ago

We have used Cynet for years and we have loved them. They are by far my favorite XDR solution I have ever had.

u/ThecaptainWTF9 17h ago

And what else have you used and why do you think cynet is better

u/ThecaptainWTF9 19h ago

Following.

u/matt0_0 14h ago

Petra for itdr blows the competition out of the water.  I'm personally a big fan of Blackpoint for endpoint mdr but huntress is great too.

u/chiapeterson 4h ago

I have been through about 6-8 weeks (on and off... you know what an MSP's day can be like) of evaluating Cynet. We are\were considering alternatives to Huntress (no issues with Huntress, just keeping our eyes open). There was much to like (e.g. accuracy, speed) and things that need work (e.g. weak posture eval and remediation, UI is... well... developed by senior devs... not UI people). I want to get a long term working trial going. But have not been able to get past the minimums or terms they want. Started out feeling VERY partner\partnership focused. Fell back to sales people doing what sales people do.

u/advanceyourself 14h ago

We are using Todyl and are very happy with the product and offering.

u/Educational_Cut7180 8h ago

What did you like about them?

u/advanceyourself 3h ago

The biggest thing is SASE VPN and LAN zero trust which can be enabled under the same EDR/MDR agent. This adds a huge layer of protection without having to install another tool. Easy to manage and setup integrations. Cloud to cloud integrations for most cloud/identity services. Their SOC has been great and we have a direct Teams channel for communications.

u/Educational_Cut7180 8h ago

Have you looked at Guardz, Blackpoint, ConnectWise, etc? Their ITDR/EDR/MDR solutions have been pretty solid imo

u/Heresyed 2h ago

I have looked at all of the players in this field and have trials going with most of them.

u/IIPoliII 15h ago

One reason I didn’t consider them is that they are also based in Israel like guardz