Talk to us
by BroadcomTechBag Intel Page

Symantec Endpoint Security

Your laptops run an antivirus, an EDR sensor and a web client, each with its own console. One agent could do all three — Symantec Endpoint Security puts one agent on Windows, macOS, Linux, iOS and Android, managed from the cloud, from your own servers or both — with EDR and attack-surface hardening in the Complete edition.

One agent for five platformsCloud, hybrid or on-prem consoleQuote-only pricing

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
Broadcom publishes no SES price; a UK G-Cloud reseller lists Enterprise at £93.75 per user a year as MSRP
Quote
Editions
Enterprise prevents; Complete adds EDR, Threat Hunter, Adaptive Protection and Active Directory defence
2
Analysts
Gartner Endpoint Protection MQ 2026, per a distributor’s listing; no Gartner Leader placement for Broadcom security
Niche Player
India
No Indian region is documented for the ICDm cloud console; an on-prem console keeps management data on your site
Ask

Quick answer

Symantec Endpoint Security (SES) is Broadcom’s single endpoint agent for Windows, macOS, Linux, iOS and Android, run from the ICDm cloud console, in hybrid, or fully on premises. SES Enterprise is the prevention edition; SES Complete adds Adaptive Protection, Active Directory defence, EDR and Threat Hunter. Every edition is quote-only, and no Indian data region is documented for the cloud console, so ask where telemetry sits. Read more ↓ Show less ↑
Part 01 · Orient

The Broadcom platform family

This page covers Symantec Endpoint Security — the Enterprise and Complete editions, including on-prem SEP. The rest:

Quick facts

30-second orientation
Product
One endpoint agent for prevention, with EDR and attack-surface hardening in the Complete edition
Maker
Broadcom Inc., Palo Alto (CEO Hock Tan); Symantec sits in the Enterprise Security Group under Jason Rolleston
Editions
SES Enterprise for advanced prevention; SES Complete adds Adaptive Protection, AD defence, EDR and Threat Hunter
Platforms
Windows, macOS and Linux computers, plus iOS and Android phones and tablets
Management
Cloud through ICDm, hybrid, or on premises; the on-prem SEP line is current at 14.3 RU10
Price
Quote-only; Broadcom prints no list price and sells through partners
Web traffic
Web and Cloud Access Protection steers browsing to Cloud SWG, taking over from the end-of-line WSS Agent
Analysts
Niche Player in Gartner’s 2026 Endpoint Protection MQ, as distributor Softprom reports it
India
Offices in Bangalore, Hyderabad and Pune; Westcon-Comstor distributes; no Indian data region documented
In India via
TechBag — edition choice, console model, and a quote in INR with GST
Part 02 · Learn

Understand endpoint protection before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is endpoint protection with EDR?

An agent on every device blocks malware before it runs, and EDR records what slipped through so a person can act.

Three agents and a vendor-hosted console vs one SES agent — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionSeparate antivirus, EDR and web agentsSymantec Endpoint Security
Agents on a laptopAntivirus, an EDR sensor and a web clientOne SES agent, with web access built in
Attacks with no new fileMissed until someone reads the logsAdaptive Protection in the Complete edition
Where the console livesWhatever the vendor hostsICDm cloud, on-prem SEP, or a hybrid of both
Phones and tabletsA separate mobile productiOS and Android inside the same estate
Active Directory exposureOpen to any foothold on a laptopObfuscated by AD defence in Complete
What it is NOT—A managed SOC, a public price list, or CBX

The cheapest test is a pilot: put the agent on one team, run it beside your current antivirus, and get the telemetry location in writing.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
What runs on each device

Agent

The SES agent

One agent per computer or phone carries the prevention engines; buying Complete switches on EDR, Adaptive Protection and Active Directory defence without a second install.

02
Where a cloud estate is run

ICDm

Integrated Cyber Defense Manager

ICDm is the cloud console for policies, devices and incidents. Broadcom documents no Indian region for it, so the telemetry location is a question for your quote.

03
Where a self-hosted estate is run

On-prem

Symantec Endpoint Protection 14.3

Estates that keep management in-house run SEP on their own servers, now at 14.3 RU10; hybrid mode links those managers to ICDm so both can be used together.

04
How browsing reaches Cloud SWG

Web path

Web and Cloud Access Protection

The agent can tunnel or PAC-redirect web traffic to Symantec Cloud SWG on Windows and macOS, with near parity to the WSS Agent it replaces, per Broadcom’s KB.

One agent on every device — managed from the ICDm cloud, from your own SEP servers, or from both at once.

Part 03 · Evaluate

Nine capabilities. Prevent, detect, manage.

Symantec Endpoint Security is Broadcom’s single endpoint agent, run from a cloud, hybrid or on-premises console.

Prevent
Enterprise

Advanced prevention edition

SES Enterprise is Broadcom’s prevention tier for both traditional computers and mobile devices, sold without the EDR layer.

Prevent
Adaptive

Living-off-the-land control

Adaptive Protection, a Complete feature, targets attacks that abuse built-in admin tools rather than dropping new malware.

Prevent
Mobile

Phones in the same estate

iOS and Android devices are covered alongside Windows, macOS and Linux, so mobile is not a separate product to buy.

Detect
EDR

Detection and response

SES Complete records endpoint activity for investigation and response, the layer that Enterprise buyers do not receive.

Detect
Threat Hunter

Hunting in Complete

Threat Hunter is listed among the Complete additions; ask Broadcom how much of it is tooling and how much is analyst work.

Detect
AD defence

Active Directory obfuscation

Complete adds Active Directory defence that works by obfuscation, so an intruder probing AD from a laptop sees obfuscated data.

Manage
ICDm

Cloud, hybrid or on-prem

The same agent reports to the ICDm cloud console, to on-prem SEP managers, or to both in hybrid, so the console is your choice.

Manage
Web access

Roaming web security

Web and Cloud Access Protection hands browsing to Cloud SWG from the endpoint agent, so laptops need no separate web client.

Manage
Patch lines

Fixes on three release lines

Two SEP flaws published in January 2026 were fixed in 14.3 RU10 Patch 1, RU9 Patch 2 and RU8 Patch 3, per NVD records.

See it, don’t just read it

Watch Symantec Endpoint Security in action

Hunting with SES Complete (2023), a first-steps tour of the SES console (2021), and Adaptive Protection in the Complete edition (2021).

Symantec (official)·Demo, November 2023

Superior Threat Hunting by using Symantec Endpoint Security Complete.

A 2023 demo of hunting for an attacker with the EDR and Threat Hunter pieces of SES Complete.

Symantec (official)·Tutorial, August 2021

Getting Started with Symantec Endpoint Security (SES)

A 2021 first-steps tour of the SES console and agent rollout; some screens will have moved on since.

Symantec (official)·Overview, June 2021

Symantec Endpoint Security Complete (featuring Adaptive Protection)

Broadcom’s 2021 look at the Complete edition, built around Adaptive Protection against misuse of trusted tools.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why Symantec Endpoint Security

Many attacks use the tools already on the laptop. SES Complete hardens the endpoint against them, from a console you choose.

Here’s what genuinely sets it apart — and exactly where it stops.

01

Hardening that goes past signatures

Many attacks run through admin tools Windows already ships, leaving no new file to catch. SES Complete answers with Adaptive Protection, aimed at living-off-the-land techniques, and Active Directory defence that shows an intruder obfuscated AD data. EDR and Threat Hunter come in the same edition.

02

A console in the cloud or in your own rack

Most rivals run only from their own cloud. SES can be managed from the ICDm cloud console, from on-premises SEP managers at 14.3 RU10, or both in hybrid. For RBI-supervised or DPDP-minded teams that is a deployment choice, not a certification: management data stays on servers in India.

03

The endpoint agent also carries web traffic

Web and Cloud Access Protection lets the SES agent send browsing to Symantec Cloud SWG by tunnel or PAC file. Broadcom’s KB 264653 puts it at parity with the WSS Agent on Windows and macOS, minor exceptions aside, and status notices call WSS Agent v9 the last major release.

04

Where it stops

Pricing is by quote, and SES is sold on subscription only, by one licensing consultancy’s account. No Indian ICDm region, no agent file rollback and no managed SOC are documented for SES. A distributor lists Broadcom as a Niche Player in Gartner’s 2026 EPP MQ. Symantec CBX is announced, not shipped.

The idea
One agent: prevention, EDR and web access
The console
ICDm cloud, on-prem SEP, or hybrid
The price
Quote-only through partners
Proof, not promises

The numbers behind the platform

5 platforms
covered by the agent family: Windows, macOS, Linux, iOS and Android devices
— Vendor
3 console models
for running it: the ICDm cloud, on-premises SEP managers, or a hybrid of both
— Vendor
4 additions
that separate Complete from Enterprise: Adaptive Protection, AD defence, EDR, Threat Hunter
— Vendor
RU10
the current release update of on-prem SEP 14.3; its Patch 1 fixed two January 2026 CVEs
— NVD
180% ROI
for SES Complete in a Forrester TEI study that Broadcom commissioned; treat it as a vendor figure
— Commissioned
175M endpoints
feeding Symantec’s Global Intelligence Network, by Broadcom’s own count
— Vendor claim

What your Symantec Endpoint Security rollout looks like

Week 1Model

Count devices and pick the edition

List computers, servers and phones by OS, then decide which groups need Complete’s EDR and hardening and which need Enterprise.

Week 2Decide

Decide where the console lives

Choose ICDm, on-prem SEP managers or hybrid, and get Broadcom’s written answer on where cloud telemetry is held.

Week 3Pilot

Pilot on one department

Deploy the agent to one team, compare its detections with your current antivirus, and test the console model you chose.

Month 2Prove

Move web traffic onto the agent

If you own Cloud SWG, switch roaming users from the WSS Agent to Web and Cloud Access Protection and compare policy hits.

Month 3Commit

Roll out and set a patch rhythm

Extend to every site, bring on-prem SEP to the latest 14.3 RU and patch, and book a recurring EDR review for the team.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4
58+ reviews*
78% would recommend
Prevention4.3
Console choice4.2
EDR and hunting3.9
Ease of migration3.6
Value for money3.5
5★
38%
4★
40%
3★
14%
2★
6%
1★
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
BFSI
“We kept our on-prem SEP managers for the branches with poor links and put head office on ICDm. Hybrid let us move in stages.”
Endpoint Security Lead
BFSI
Manufacturing
“Adaptive Protection flagged PowerShell use that none of our admins could explain. That alone justified moving up to Complete.”
Security Analyst
Manufacturing
IT Services
“Dropping the separate WSS client was the quiet win. One agent now handles malware and sends browsing to Cloud SWG.”
Network Security Engineer
IT Services
Healthcare
“Ask early where ICDm keeps telemetry. Our auditor wanted an answer in writing and it took the partner three weeks.”
IT Risk Manager
Healthcare
Education
“Patch discipline matters: we were two release updates behind on SEP 14.3 and the January CVEs forced a weekend upgrade.”
Systems Administrator
Education
Retail
“Detection is solid, but the renewal quote came as a bundle with no line items. Get the edition and term spelled out.”
Head of IT
Retail
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the endpoint protection market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Endpoint Protection Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
Symantec Endpoint SecurityThis page

Quote-only through partners; Niche Player per a distributor (2026).

Grid 02 · The architecture

Console Choice × Detection Depth

The grid nobody publishes — where the management console can run vs how far detection, response and recovery go.

Deep detection, vendor cloudDeep detection, any consoleCloud prevention tiersFlexible consoles, lighter EDR
Symantec Endpoint SecurityThis page

Cloud, hybrid or on-prem console; EDR only in Complete, no rollback documented.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Symantec Endpoint Security vs the endpoint protection field

Against CrowdStrike Falcon Prevent, SentinelOne Singularity Endpoint, Microsoft Defender for Endpoint, Trend Vision One Endpoint Security and Sophos Intercept X — on consoles, platforms, price, EDR, rollback and India.

DimensionSymantec Endpoint SecurityCrowdStrike Falcon PreventSentinelOne Singularity EndpointMicrosoft Defender for EndpointTrend Vision One Endpoint SecuritySophos Intercept X
What it isBroadcom’s EPP + EDRFalcon NGAV tierAutonomous agentDefender XDR pillarVision One sensorSophos endpoint core
Deployment and consoleCloud, hybrid, on-premCrowdStrike cloud onlyVendor SaaS onlyDefender portalSaaS, or Apex OneSophos Central only
Computers and serversWin, Mac, LinuxWin, Mac, LinuxWin, Mac, LinuxWin, Mac, LinuxEndpoints and serversWin, Mac, Linux
Phones and tabletsiOS and Android inMobile is an add-onSingularity MobileiOS and Android inMobile add-onMobile add-on
Pricing modelPer user, by partnersPer device per yearPer endpoint, partnersPer user, or bundledPer device or creditsPer user, quoted
Published entry priceNone from Broadcom$59.99/device/year$179.99/endpoint/yr$3/user/month$2.25/endpoint/month~$25–66 reported
Included vs add-onEDR only in CompleteEDR is a higher tierMDR, mobile extraEDR needs Plan 2EDR in AdvancedXDR is a higher tier
Detection and responseEDR + Threat HunterNot in PreventStoryline EDRPlan 2 huntingFeeds Vision One XDRWith the XDR tier
Ransomware recoveryNo rollback listedNo file rollbackOne-click rollbackNo agent rollbackNot documentedCryptoGuard restore
Managed SOC optionNone named for SESFalcon CompleteWayfinder MDRDefender ExpertsService One MDRSophos MDR
Platform tiesAgent feeds Cloud SWGModules on one sensorMulti-tenant for MSSPsIntune and EntraVision One XDRTalks to the firewall
India data regionNot documentedAnnounced, not liveMumbai regionNot verifiedUnverified; on-premMumbai region
Lock-in and exitConsole you can hostCloud-only platformSaaS onlyMicrosoft estateCredits, or Apex OneCentral-only
Best fitSEP estates, on-premPrevention first, growLean teams, MumbaiMicrosoft 365 E5Trend XDR estatesRollback + MDR path
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Symantec Endpoint Security if…

  • ✓You run SEP today and want to move to cloud or hybrid management without retraining staff on a new vendor
  • ✓Policy or regulation means the endpoint console must run on servers you control, inside India
  • ✓You also buy Symantec Cloud SWG and want one agent to handle both malware and roaming web traffic

Compare alternatives if…

  • ✓You want a price you can read before talking to sales — CrowdStrike, Microsoft and Trend publish theirs
  • ✓Agent-level file rollback after ransomware is a requirement — SentinelOne and Sophos document it
  • ✓You want a vendor-run 24/7 SOC on the same agent — Sophos MDR, Wayfinder and Service One are sold that way

Do not expect…

  • ✓A documented Indian data region for the ICDm cloud console
  • ✓Symantec CBX on your order form — it was announced in March 2026 and has not shipped
  • ✓A Gartner Leader placement — a distributor reports Niche Player in the 2026 EPP Magic Quadrant

Symantec Endpoint Security is one of 47 endpoint protection products TechBag carries. The Endpoint Protection guide narrows them to a shortlist and shows the reasoning. →

Do the math

What do scattered endpoint agents cost you?

Drag the sliders (endpoints protected; IT-admin-hour cost). Estimates model admin time spent on cleaning up infections, re-imaging machines and keeping separate antivirus, EDR and web agents in step at an assumed 1.5 hours per endpoint a year, with 70% of it removed by one agent with prevention and EDR. Both figures are assumptions. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual endpoint-operations cost
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Not published: Broadcom prints no price for SES and sells through partners, by subscription per user. The only public figure is a UK G-Cloud reseller listing SES Enterprise at £93.75 per user a year as MSRP, ex-VAT, which is not Broadcom’s own price. Complete adds EDR, Threat Hunter, Adaptive Protection and AD defence. TechBag maps your devices to an edition, then quotes in INR with GST.

SES Enterprise

Best for prevention-first estates

  • Advanced prevention on computers and phones
  • Cloud, hybrid or on-prem console
  • Quote-only through partners

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

SES Complete

Best when a team will read EDR alerts

  • Adds EDR and Threat Hunter
  • Adaptive Protection and AD defence
  • Quote-only; no list price

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Edition

Which device groups need Complete’s EDR, Threat Hunter and AD defence, and which are fine on Enterprise alone?

2
Console

Will you run ICDm in the cloud, SEP managers on your own servers, or both in hybrid during the migration?

3
Data location

Has Broadcom or the partner stated in writing where ICDm stores telemetry? No Indian region is documented.

4
Analysts

Who will read EDR alerts each day? Broadcom names no managed SOC for SES, so staff it or ask your partner.

5
Ransomware

With no agent file rollback documented, are your backups immutable and tested for a full laptop restore?

6
Web traffic

Do you own Cloud SWG? If so, plan the move from the end-of-line WSS Agent to Web and Cloud Access Protection.

7
Patching

Is on-prem SEP at 14.3 RU10 Patch 1 or a fixed RU9/RU8 patch, which close the two January 2026 CVEs?

8
Licence

Does the quote name the edition, user count, term and any bundle minimum? Ask for INR with GST, line by line.

FAQ

Questions buyers ask

SES is Broadcom’s endpoint protection for Windows, macOS, Linux, iOS and Android, sold under the Symantec brand. One agent carries the prevention engines, and the Complete edition adds EDR and hardening. It can be managed from the ICDm cloud console, from on-premises SEP managers, or from both.

Ready to evaluate Symantec Endpoint Security?

Count your devices by OS and decide where the console should live first, or let a TechBag advisor scope a pilot on one department.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.