ISEC7 Digital Workplace Blog

Solution Highlight: BlackBerry Cyber Suite (2021)

Written by Remi Keusseyan | Jul 19, 2021, 7:30:00 AM

Editor's note, October 2026: This article was first published in July 2021 and describes BlackBerry Cyber Suite as it was offered then. BlackBerry later marketed these products under the Cylance brand; BlackBerry Gateway, for example, was relaunched as CylanceGATEWAY in 2022. In February 2025, BlackBerry completed the sale of its Cylance endpoint security assets to Arctic Wolf, which now offers the technology as Aurora Endpoint Security. BlackBerry kept its secure communications business, including BlackBerry UEM, AtHoc and SecuSUITE. The product names and module structure below are therefore no longer current. For an overview of today's endpoint protection categories, read Demystifying Security: EPP, EDR and MTD; ISEC7's current services, including managed detection and response through our partner Arctic Wolf, are described under Endpoint Security.

In our last article, we talked about behavior-based security, a new approach to today's security challenges that aims to stop an attack before it happens. This may have seemed outlandish a few years ago, but progress in Artificial Intelligence (AI), Machine Learning (ML) and Big Data now provides the computational power needed to get in front of an attack.

This week we introduce a next-generation cybersecurity solution that uses these technologies, from one of the most renowned vendors in mobile security: BlackBerry Cyber Suite.

BlackBerry Cyber Suite is a Unified Endpoint Security (UES) suite that prevents, detects and responds to cybersecurity threats. It integrates natively with BlackBerry unified endpoint management (UEM) software to add an extra layer of security and device management, and it is also compatible with UEM software from other vendors.

The suite consists of several modules, each with a specific role, which can work independently or together depending on the needs of each customer environment.

BlackBerry Protect

BlackBerry Protect detects and blocks malicious threats before they can affect a device.

Its protection includes automated malware prevention, application and script control, memory protection and device policy enforcement. It uses a mathematical model to identify malware and potential threats, and keeps the load on system resources low by relying on the cloud-based AI and ML services of CylanceINFINITY.

Unlike reactive techniques that rely on signatures, this approach uses mathematical models to prevent threats that have not been seen before.

BlackBerry Persona

BlackBerry Persona uses a behavioral model that monitors user activity and detects deviations that indicate potential risk, such as accessing work resources from an unknown location at an unusual time, or from an unknown, untrusted device. App usage, network access, process invocation patterns and other information feed this model.

Whenever something is detected as unusual, the risk score rises, and the service adapts the behavior of the device and apps to that level of risk. For example, even on a known, trusted device and after successful authentication, a user might still be denied access to specific resources if company policy classifies the location as unsafe, such as a foreign country or an airport.

BlackBerry Gateway

BlackBerry Gateway provides Zero Trust network access for endpoints, with end-to-end security, both to private, on-premises resources and to public, cloud-based Software-as-a-Service (SaaS) solutions such as Microsoft 365 or Salesforce. It continuously analyzes user actions, and when it detects unexpected or anomalous behavior, it requires additional authentication or blocks access to the resource until the risk is mitigated.

It works with public and in-house apps without reconfiguring them and only routes necessary traffic through your internal network. That keeps the load off your VPN and saves battery life, which matters to users, especially when travelling. Data in transit is encrypted using TLS. We took a closer look at this module in Solution Highlight: BlackBerry Gateway.

BlackBerry Optics

BlackBerry Optics tracks, alerts on and responds to malicious activity by collecting information from the endpoints through sensors. It aggregates and stores that data in a cloud-based analytics infrastructure, where AI looks for recognizable patterns that could indicate threats and complex attacks, now and in the future.

Prevention is the ultimate protection

BlackBerry draws on several disciplines to address the major security risks that consumers, companies and public bodies all face today. Attackers do not only go after large organizations; they will go after anyone they can get money from.

We have discussed recent attacks on major infrastructure with tremendous impact on everyday life, in which companies had to pay hefty ransoms to get their systems or data back; see Post-Ransomware Recovery: What Do I Do Now?. Implementing a strong security solution is an investment, but it saves significant time and effort when an attack happens. The real cost is hard to calculate, because your reputation takes the biggest hit.

According to BlackBerry, its solution would have prevented recent zero-day attacks even while running offline, for example on an isolated, segmented network. The idea behind this generation of security is to detect and prevent new threats instead of waiting for them to happen and doing extensive damage control afterwards.

No security solution covers everything. Even with strong endpoint protection, you still need to assess your own environment for improvements and train your employees on security best practices.

At the time of writing, BlackBerry Cyber Suite was available for desktop computers (Windows, macOS, Linux) and mobile devices (iOS, Android, Chromebook). A different approach to the same problem is covered in Solution Highlight: VMware Carbon Black.

Want to know which endpoint protection fits your environment today? Our endpoint security team will help you compare the options. Contact us.