ETP vs CTP:
two layers, not a choice.
They protect different things. One guards the device; the other controls the risky activity that puts the device at risk. Your customer needs both — here's how to say why.
Where each one fires
CTP reduces how often ETP ever has to fire. ETP is the safety net for anything that gets through.
A click, a site, an upload
Someone clicks a link, visits a risky site, or uploads data to an unsanctioned cloud app. This is where most breaches begin.
Stops it at the source
Blocks the phishing link, the malicious or risky domain and the unsafe upload — and surfaces shadow IT before anything reaches the device.
Protects the device
If a threat still reaches the device, ETP detects, prevents and responds — isolating it, killing the process, quarantining the file.
Remove either layer and you leave a gap the other was never built to cover.
Seven gaps, and how CTP closes each one
ETP protects the device. It's not built to control what users do online — and that's exactly the gap CTP closes.
Side by side
| Aspect | Endpoint Threat Protect ETP | Cloud Threat Protect CTP |
|---|---|---|
| Centres on | The device | The user, and what they're doing |
| Stops | Malware, ransomware, malicious processes and exploits on the machine | Phishing, malicious or risky websites, unsafe uploads and downloads, shadow IT and risky or unauthorised SaaS use |
| Acts | On the endpoint, once a threat has reached the device | At the point of use, before the user reaches the threat |
| Strongest at | Isolating a compromised machine, quarantining files, killing processes, forensic response | Controlling web, email and cloud activity; visibility of shadow IT; policy by user, group, device, location or risk score |
| Doesn't do | Control web, email or cloud activity, or reveal shadow IT | Replace AV or EDR, or do device-level malware response |
When a customer asks “why both?”
“Endpoint Threat Protect protects the device — it's the safety net if something malicious lands on the machine.”
“Cloud Threat Protect works a step earlier. It stops your people reaching the malicious link, site or cloud app in the first place, and gives you visibility of shadow IT and risky data movement.”
“One guards the device, the other controls the activity that puts the device at risk. That's why they sit together — not instead of each other.”
Landed the CTP alongside their ETP?
That's the conversation this page exists for. Log the order while the number is still in front of you — the five working days run from the order date, not from when you remember.