WatchGuard named leader in GigaOm’s 2025 EDR Radar Report
WatchGuard has been recognised as both a Leader and an Outperformer in the 2025 GigaOm Radar Report for Endpoint Detection and Response, reflecting an expanded role in the cybersecurity sector for organisations and managed service providers.
The GigaOm Radar Report assesses vendors based on three primary criteria: innovation, execution, and deployment models. According to the report, WatchGuard attained Outperformer status due to its "delivery of an extensive array of innovative features, consistent release cadence, and execution against an ambitious roadmap." The report further highlighted WatchGuard's commitment to delivering an endpoint security solution that merges prevention, detection, and investigation within a single, accessible platform.
Endpoint Detection and Response (EDR) solutions have become increasingly important as businesses face a dynamic threat landscape. The Radar Report identified WatchGuard's ongoing focus on simplifying and strengthening endpoint protection, particularly for managed service providers (MSPs) and organisations that require agile defences against rapidly evolving cyber attacks.
Recognition and roadmap
GigaOm's 2025 analysis noted that WatchGuard's status as a Leader and Outperformer was attributed to its innovation, including the introduction of AI-assisted threat detection, default zero-trust enforcement, and the newly launched GenAI Telemetry Assistant, which assists security teams in investigating incidents more efficiently. These features, combined with supply chain risk mitigation via XDR integration, have resulted in measurable benefits for both end-user organisations and service providers.
"Our customers already know they get elevated protection from our innovative endpoint capabilities like the Zero-Trust Application Service, and it's exciting to see that reflected in the latest GigaOm EDR Radar report," said Andrew Young, Chief Product Officer at WatchGuard Technologies. "Being named both a Leader and an Outperformer underscores our commitment to simplifying security while delivering the industry's most advanced and unified defenses through an intuitive, easy-to-use platform."
Among the capabilities emphasised by GigaOm, WatchGuard's Advanced EPDR solution received particular mention for its Zero-Trust Application Service. This functionality, present in WatchGuard's EPDR product, applies mandatory classification to all applications before they can execute, aiming to halt unknown and zero-day threats prior to their initiation.
AI in endpoint security
The report cited WatchGuard's incident-centric model, in which related alerts are consolidated into a single timeline aligned with the MITRE ATT&CK framework. Each incident timeline is supplemented with entity context and root cause evidence, helping analysts make sense of security events. GigaOm recognised that WatchGuard's use of artificial intelligence for aggregation and correlation substantially lessens alert fatigue by allowing analysts to focus on key incidents rather than numerous discrete alerts.
WatchGuard's GenAI Telemetry Assistant has also received attention. This feature enables analysts to pose natural-language questions, which are converted into optimised telemetry queries to assist with investigations. The objective is to reduce false positives, improve analyst efficiency, and help both organisations and MSPs increase their incident response capabilities.
Focus on zero trust
The report highlighted WatchGuard's supply chain risk mitigation through its Extended Detection and Response (XDR) integration and the application of default zero-trust controls. These capabilities, along with AI-driven signal correlation and containment, provide a multi-layered approach aimed at reducing attack surfaces and strengthening organisational defences.
To support the practical implementation of its Zero Trust and endpoint protection capabilities, WatchGuard is conducting a series of global roadshows focusing on securing distributed workforces and responding to AI-driven threats. These sessions demonstrate how WatchGuard's AI-powered detection and GenAI Telemetry Assistant can assist in real-world security operations.
As endpoint-centric threats become a focal point for attackers, measures such as unified threat detection, real-time incident response, and built-in zero-trust policies are seen as vital for safeguarding users and assets. The GigaOm Radar Report's assessment reflects broader industry trends prioritising integration, automation, and simplicity in cybersecurity defences while maintaining rigorous standards for detection and response.