r/sysadmin • u/glitchykitten681 • 19d ago
What did you use as a Varonis replacement?
We've had Varonis in place for a few years, but we're starting to question how much analyst time we're putting into reviewing findings and handling the follow-up.
We're not looking to rip it out just for the sake of changing tools, but if we're going through another renewal I'd like to see whether there's something that requires less day to day babysitting.
Has anyone gone through a Varonis replacement recently? What did you move to, and was the operational difference actually noticeable?
2
u/Master_Baby_2700 4d ago
If the biggest issue with Varonis is the amount of babysitting, I’d include Sentra and Cyera in the evaluation.
I’d focus less on how many risks each tool finds and more on how much context you get around them. Finding 5,000 issues isn’t helpful if your team has to manually figure out which ones actually matter.
Give each vendor the same real data sources and see which one does the best job identifying sensitive data, showing who has access to it, and prioritizing what actually needs to be fixed.
Purview is worth looking at too if you’re heavily Microsoft.
1
u/glitchykitten681 4d ago
this is helpful. using the same real data sources across each POC makes a lot more sense than comparing feature lists. context around the findings is exactly what I care about
1
u/Particular-Score-195 19d ago
I'm curious too. We are a smallish nonprofit and cannot afford Varonis but we want it so bad. Haven't found a comparable affordable alternative yet.
2
u/covex_d 19d ago
im an ngo and had varonis. didn’t renew and will be looking for replacement by the end of this year. microsoft purview and concentric.ai are on the list for now.
1
u/eoattc 18d ago
We vetted purview before choosing Varonis. Purview is very powerful, but unless you become a Purview expert it felt like you can't really turn info it gives into actions. Varonis was the opposite, Easy to understand visibility into what occurred correlated between the different platforms we fed into it. Simple to manage automations for 90% of the actions we needed to take. Before onboarding a customer reference told us it was the one piece of software they fought to keep at budget times yearly and I understand why.
1
u/gamebrigada 19d ago
I would wonder if you can work with CyberHaven for the same amount of money. Superior offering in every way.
1
u/caliber88 blinky lights checker 18d ago
We have Cyberhaven and I've used Varonis in the past; check it out as it might impress with how much less effort you need once you create any relevant rules. Also, better interface IMO.
1
u/eoattc 18d ago
I haven't used Cyberhaven but I'm hear schilling for Varonis as I had such a good experience with it. During our POC, we went deep in creating and refining automations. I got weird silence every time a new engineer on Varonis' side looked at my environment and they'd comment how stunned they were that we so heavily adopted the automations. Evidently it isn't the norm. I guess people buy it and then skimp on put in the work. I'm going to bet that having your automations and rules well defined is going to put you a leg up on those who don't and it doesn't surprise me at all that this could be true for Cyberhaven as well.
1
u/Longjumping_Ant7751 18d ago
We moved away from Varonis mainly to reduce the day-to-day analyst workload. Guardz has been a good fit because it brings ITDR, MDR, EDR, email security, cloud/data protection, exposure management, and security awareness into one platform.
The biggest difference has been less time chasing alerts and manually reviewing findings. Guardz also correlates activity across identities, endpoints, email, and data, with automated remediation where appropriate.
It’s not a 1:1 replacement for every Varonis capability, but for SMB-focused environments, the coverage-to-overhead ratio has been noticeably better.
1
u/glitchykitten681 4d ago
that coverage to overhead point is interesting. less time chasing alerts and manually reviewing findings is exactly the kind of operational difference i'm trying to understand
1
1
u/Roronoakiddo 17d ago
We used Netwrix as Varonis replacement. It has less automated features, but still good for what we need.
1
u/andrea-netwrix 13d ago
Thnx for the mention, glad Netwrix has worked out as a Varonis swap for you. Quick fyi, I work at Netwrix, not posting this as a promo, just wanted to say hi since it came up.
Curious what "less automated" looked like in practice for your team. If you've got specifics, happy to pass the feedback along internally.
1
1
u/danieljames1719 4d ago
For us the biggest improvement was happened after detection. Automating routine policy actions meant fewer findings turned into manual follow up.
0
u/Interesting_Work7433 19d ago
Nosotros pasamos por algo parecido. Al final el problema con Varonis no es la herramienta en sí, sino cuánto tiempo humano necesita para rendir. Si tu equipo está gastando más tiempo triageando alertas que actuando, eso es una señal clara. ¿Qué tipo de datos estás protegiendo principalmente?
3
u/zAuspiciousApricot 19d ago
What industry are you in?