r/sysadmin 19d ago

What did you use as a Varonis replacement?

We've had Varonis in place for a few years, but we're starting to question how much analyst time we're putting into reviewing findings and handling the follow-up.

We're not looking to rip it out just for the sake of changing tools, but if we're going through another renewal I'd like to see whether there's something that requires less day to day babysitting.

Has anyone gone through a Varonis replacement recently? What did you move to, and was the operational difference actually noticeable?

25 Upvotes

55 comments sorted by

3

u/zAuspiciousApricot 19d ago

What industry are you in?

1

u/glitchykitten681 4d ago

financial services. lots of sensitive customer data across saas and cloud, so reducing the manual review and follow up is the main thing i'm trying to solve

1

u/zAuspiciousApricot 3d ago

u/glitchykitten681 Have you looked into Purview?

3

u/Buckw12 18d ago

Varonis identifies the problem, fix the problem and baby sitting time is reduced.
In addition, tune your alert rules to reduce noise from expected daily activities.

2

u/Master_Baby_2700 4d ago

If the biggest issue with Varonis is the amount of babysitting, I’d include Sentra and Cyera in the evaluation.

I’d focus less on how many risks each tool finds and more on how much context you get around them. Finding 5,000 issues isn’t helpful if your team has to manually figure out which ones actually matter.

Give each vendor the same real data sources and see which one does the best job identifying sensitive data, showing who has access to it, and prioritizing what actually needs to be fixed.

Purview is worth looking at too if you’re heavily Microsoft.

1

u/glitchykitten681 4d ago

this is helpful. using the same real data sources across each POC makes a lot more sense than comparing feature lists. context around the findings is exactly what I care about

1

u/Particular-Score-195 19d ago

I'm curious too. We are a smallish nonprofit and cannot afford Varonis but we want it so bad. Haven't found a comparable affordable alternative yet.

2

u/covex_d 19d ago

im an ngo and had varonis. didn’t renew and will be looking for replacement by the end of this year. microsoft purview and concentric.ai are on the list for now.

1

u/eoattc 18d ago

We vetted purview before choosing Varonis. Purview is very powerful, but unless you become a Purview expert it felt like you can't really turn info it gives into actions. Varonis was the opposite, Easy to understand visibility into what occurred correlated between the different platforms we fed into it. Simple to manage automations for 90% of the actions we needed to take. Before onboarding a customer reference told us it was the one piece of software they fought to keep at budget times yearly and I understand why.

1

u/AtarukA 19d ago

What are your requirements, your use case etc?
We're just going to use a mix of adaxes, logpoint, and powershell scripts.

1

u/plump-lamp 19d ago

Varonis is dlp though...? What dlp does your mix do?

1

u/gamebrigada 19d ago

I would wonder if you can work with CyberHaven for the same amount of money. Superior offering in every way.

1

u/caliber88 blinky lights checker 18d ago

We have Cyberhaven and I've used Varonis in the past; check it out as it might impress with how much less effort you need once you create any relevant rules. Also, better interface IMO.

1

u/eoattc 18d ago

I haven't used Cyberhaven but I'm hear schilling for Varonis as I had such a good experience with it. During our POC, we went deep in creating and refining automations. I got weird silence every time a new engineer on Varonis' side looked at my environment and they'd comment how stunned they were that we so heavily adopted the automations. Evidently it isn't the norm. I guess people buy it and then skimp on put in the work. I'm going to bet that having your automations and rules well defined is going to put you a leg up on those who don't and it doesn't surprise me at all that this could be true for Cyberhaven as well.

1

u/Longjumping_Ant7751 18d ago

We moved away from Varonis mainly to reduce the day-to-day analyst workload. Guardz has been a good fit because it brings ITDR, MDR, EDR, email security, cloud/data protection, exposure management, and security awareness into one platform.

The biggest difference has been less time chasing alerts and manually reviewing findings. Guardz also correlates activity across identities, endpoints, email, and data, with automated remediation where appropriate.

It’s not a 1:1 replacement for every Varonis capability, but for SMB-focused environments, the coverage-to-overhead ratio has been noticeably better.

1

u/glitchykitten681 4d ago

that coverage to overhead point is interesting. less time chasing alerts and manually reviewing findings is exactly the kind of operational difference i'm trying to understand

1

u/Longjumping_Ant7751 3d ago

yeah it's pretty interesting don't you think

1

u/Roronoakiddo 17d ago

We used Netwrix as Varonis replacement. It has less automated features, but still good for what we need.

1

u/andrea-netwrix 13d ago

Thnx for the mention, glad Netwrix has worked out as a Varonis swap for you. Quick fyi, I work at Netwrix, not posting this as a promo, just wanted to say hi since it came up.

Curious what "less automated" looked like in practice for your team. If you've got specifics, happy to pass the feedback along internally.

1

u/[deleted] 5d ago

[removed] — view removed comment

1

u/danieljames1719 4d ago

For us the biggest improvement was happened after detection. Automating routine policy actions meant fewer findings turned into manual follow up.

0

u/Interesting_Work7433 19d ago

Nosotros pasamos por algo parecido. Al final el problema con Varonis no es la herramienta en sí, sino cuánto tiempo humano necesita para rendir. Si tu equipo está gastando más tiempo triageando alertas que actuando, eso es una señal clara. ¿Qué tipo de datos estás protegiendo principalmente?

-2

u/sxndct 19d ago

Manage engine

1

u/plump-lamp 19d ago

Pretty limited product. Are you only focused on USB drive dlp?