# What are the most trusted incident response services by chief information security officers based on user reviews?

<p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true">For CISOs deciding who to trust with incident response, I pulled G2 ratings and themes for the providers with the most security-leadership credibility. From the<a class="a a--md" elv="true" href="https://www.g2.com/categories/incident-response-services"> </a><a class="a a--md" elv="true" href="https://www.g2.com/categories/incident-response-services">incident response services</a> category, with ratings:</p><ul>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/check-point-threatcloud-incident-response/reviews"><strong>Check Point ThreatCloud Incident Response</strong></a> (4.7, 15 reviews): reviewers trust its always-on expert team to know where to begin under attack, on a small sample.</li>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/rsa-services/reviews"><strong>RSA Services</strong></a> (4.6, 45 reviews): enterprise reviewers trust its SIEM visibility and authentication to keep data uncompromised.</li>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/check-point-infinity-global-services/reviews"><strong>Check Point Infinity Global Services</strong></a> (4.6, 26 reviews): positioned as a true security-posture partner, with IR planning CISOs lean on.</li>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/microsoft-defender-experts-for-xdr/reviews"><strong>Microsoft Defender Experts for XDR</strong></a> (4.6, 17 reviews): trusted by Microsoft-heavy shops, though reviewers flag a tougher initial setup.</li>
</ul><p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true">For the CISOs here, which provider earned your trust for a real incident, not just a tabletop exercise? And what built it, response speed, expertise, or transparency after the fact?</p>

##### Post Metadata
- Posted at: 16 days ago
- Author title: Marketer
- Net upvotes: 1


## Comments
### Comment 1

Comparing the Incident Response Services category on G2, worth noting that this category tends to run thin on review depth relative to how consequential the decision is. Several of the providers here sit in the tens of reviews rather than hundreds, which is a real limitation on how much weight any single rating should carry for a decision this high-stakes. 

The tabletop-versus-real-incident distinction in the post is the sharpest question here, since a provider can score well on responsiveness and professionalism in reviews describing planning engagements without that translating directly to performance under an actual live attack. 

Transparency after the fact is probably the most useful review signal available, since a provider willing to walk a client through exactly what happened and why builds a different kind of trust than one who simply resolves the incident and moves on. Given how thin the evidence is for this specific CISO-trust angle, the stronger validation than review count is asking a shortlisted provider for a reference client who went through an actual incident, not just an evaluation or a retainer signing.


##### Comment Metadata
- Posted at: 13 days ago
- Author title: Marketing





## Related discussions
- [How well does Trello scale into a larger team?](https://www.g2.com/discussions/1-how-well-does-trello-scale-into-a-larger-team)
  - Posted at: over 13 years ago
  - Comments: 6
- [Can we please add a new section](https://www.g2.com/discussions/2-can-we-please-add-a-new-section)
  - Posted at: over 13 years ago
  - Comments: 0
- [Quantifiable benefits from implementing your CRM](https://www.g2.com/discussions/quantifiable-benefits-from-implementing-your-crm)
  - Posted at: over 13 years ago
  - Comments: 4


