Cybersecurity · head to head
NordVPN vs VMware Carbon Black

NordVPN
Cybersecurity
Consumer and business VPN from Nord Security, registered in Panama, with repeated third-party no-logs audits.
- From
- $3.99/month
- Rated
- -
VMware Carbon Black
Cybersecurity
Cloud-delivered endpoint protection and EDR, now owned by Broadcom and positioned alongside Symantec.
- From
- On request
- Rated
- -
The short version
- Each has a real cost: NordVPN a server in a Finnish datacentre was accessed in March 2018 through a remote management interface left exposed by the hosting provider, and NordVPN did not disclose it until October 2019, so a buyer relying on the company's transparency is relying on a track record that includes a nineteen-month delay.; VMware Carbon Black broadcom's enterprise model concentrates direct sales and support on its largest accounts and moves everyone else to resellers, so a mid-size customer can lose named support contacts and face a substantially repriced renewal with limited notice.
- They diverge on capability: NordVPN covers NordLynx, VMware Carbon Black covers Endpoint Standard.
- Prices and features above were last checked on 30 August 2026.
Where they differ
Only the attributes on which NordVPN and VMware Carbon Black actually diverge.
| Attribute | NordVPN | VMware Carbon Black |
|---|---|---|
| Starting price | $3.99/month | On request |
| Platforms | Web, Desktop, Mobile, Api | Desktop, Api |
| Founded | 2012 | 2002 |
Identical on both: pricing model (subscription), free tier (No), user rating (Not yet rated), category (Cybersecurity).
What each one covers
Drawn from each product's published feature list. An absence here means we hold no record of it - not that the product lacks it.
Only in NordVPN
- NordLynx
- Audited no-logs policy
- RAM-only servers
- Threat Protection
- Obfuscated servers
- Double VPN
- Kill switch
- Dedicated IP
Only in VMware Carbon Black
- Endpoint Standard
- Enterprise EDR
- Audit and Remediation
- Single sensor
- Live Response
- Workload protection
- Container security
- Watchlists and feeds
What people use each for
The jobs each tool is most often brought in to do.
NordVPN
- A buyer choosing on evidence rather than claims, who wants a no-logs policy that has been audited more than once by a named firmnot VMware Carbon Black
- Households and individuals wanting one subscription across ten devices including a smart TVnot VMware Carbon Black
- Travellers and remote workers on hotel and airport networks who need obfuscation where plain VPN protocols are blockednot VMware Carbon Black
- Small teams needing basic remote access to a shared resource, via the NordLayer business product rather than the consumer appnot VMware Carbon Black
VMware Carbon Black
- A SOC that wants unfiltered endpoint telemetry to hunt over rather than only vendor-generated alertsnot NordVPN
- A vSphere estate that wants workload protection deployed through the hypervisor instead of installing an agent in every guestnot NordVPN
- Replacing signature antivirus after an incident where the incumbent product had no record of what the attacker didnot NordVPN
- An organisation already inside a Broadcom or Symantec enterprise agreement that can consolidate endpoint onto an existing contractnot NordVPN
Where each one falls short
Documented limitations, not opinions. Every one is a constraint you would hit in normal use.
NordVPN
- A server in a Finnish datacentre was accessed in March 2018 through a remote management interface left exposed by the hosting provider, and NordVPN did not disclose it until October 2019, so a buyer relying on the company's transparency is relying on a track record that includes a nineteen-month delay.
- Pricing depends on a long initial term and reverts to the standard rate at renewal, so the monthly figure that justified the purchase is not what the subscriber pays in the third year, and the cheapest way to stay is usually to cancel and re-subscribe.
- Panamanian registration is selected for the absence of a data retention law, but it also means a subscriber with a dispute has little practical recourse, and the protection rests on a corporate structure the customer cannot inspect or enforce against.
- NordLynx is unavailable for manual and router configurations, so the one device that could cover an entire home network falls back to OpenVPN or IKEv2 with the associated throughput loss, and obfuscated servers likewise only run over OpenVPN.
- Features such as Threat Protection are implemented in the client rather than in the network, so any device using a manual configuration, a router or an unsupported platform receives a bare tunnel without the protections the subscription is sold on.
VMware Carbon Black
- Broadcom's enterprise model concentrates direct sales and support on its largest accounts and moves everyone else to resellers, so a mid-size customer can lose named support contacts and face a substantially repriced renewal with limited notice.
- Continuous EDR recording is retained for a defined window and longer retention is a paid tier, so the investigation you most need is often the one whose telemetry has already aged out, and that is discovered during the incident rather than before it.
- The product assumes an operator: watchlists, policy tuning and alert triage are ongoing work, and organisations without a dedicated analyst or an MDR contract typically leave policies in monitor mode and pay for telemetry that is never reviewed.
- The sensor operates in the same kernel and file-filter territory as other endpoint agents, so running it alongside an incumbent antivirus, DLP or backup agent commonly produces performance complaints and requires maintained exclusion lists on both sides.
- Linux sensor support is tied to specific distribution and kernel versions, so a routine operating system upgrade can leave hosts without a supported sensor until a matching build ships, and anything outside the supported list gets no coverage at all.
Pricing, plan by plan
NordVPN
$3.99/month- Standard$3.99/month
- 6 devices
- 5,500+ servers
- Threat Protection Lite
- Plus$4.99/month
- All Standard features
- Threat Protection Pro
- NordPass password manager
- Complete$5.99/month
- All Plus features
- NordLocker 1TB encrypted cloud
- Identity theft protection
VMware Carbon Black
On request- CB Endpoint StandardFree
- NGAV
- Behavioral EDR
- Device control
- CB Endpoint AdvancedFree
- All Standard features
- Threat hunting
- Audit and remediation
- CB Endpoint EnterpriseFree
- All Advanced features
- Advanced threat hunting
- Live response
Which should you pick?
Choose NordVPN if
- You need nordlynx.
- You work on Web, Desktop, Mobile, Api.
- You also want audited no-logs policy.
Choose VMware Carbon Black if
- You need endpoint standard.
- You work on Desktop, Api.
- You also want enterprise edr.
Questions people ask
- Is NordVPN or VMware Carbon Black better?
- Neither clearly leads. NordVPN starts at $3.99/month and VMware Carbon Black at On request, and user ratings are close enough to be indistinguishable. Choose on capability and platform support.
- Which is cheaper, NordVPN or VMware Carbon Black?
- NordVPN starts at $3.99/month and VMware Carbon Black at On request.
- Does NordVPN or VMware Carbon Black run on more platforms?
- NordVPN runs on Web, Desktop, Mobile, Api. VMware Carbon Black runs on Desktop, Api.
- What is NordVPN best used for?
- NordVPN is most often used for a buyer choosing on evidence rather than claims, who wants a no-logs policy that has been audited more than once by a named firm, households and individuals wanting one subscription across ten devices including a smart tv, travellers and remote workers on hotel and airport networks who need obfuscation where plain vpn protocols are blocked, small teams needing basic remote access to a shared resource, via the nordlayer business product rather than the consumer app. Of those, a buyer choosing on evidence rather than claims, who wants a no-logs policy that has been audited more than once by a named firm and households and individuals wanting one subscription across ten devices including a smart tv are not what VMware Carbon Black is typically brought in for.
- What can NordVPN do that VMware Carbon Black cannot?
- NordVPN covers NordLynx, Audited no-logs policy, RAM-only servers, Threat Protection. VMware Carbon Black covers Endpoint Standard, Enterprise EDR, Audit and Remediation, Single sensor.
Answered from the vendors’ own pages
NordVPN: What jurisdiction is NordVPN under?
The VPN service company is registered in Panama, which has no mandatory data retention law for these services. The wider Nord Security group operates from Lithuania.
VMware Carbon Black: Who owns Carbon Black now?
Broadcom. It acquired VMware in November 2023, and Carbon Black now sits in Broadcom's enterprise security business alongside Symantec. VMware branding is being phased out.
NordVPN: Has the no-logs claim actually been audited?
Yes, more than once. PwC Switzerland examined it in 2018 and 2020 and Deloitte in later engagements. Each is a point-in-time assurance report over stated policy and server configuration, not ongoing monitoring.
VMware Carbon Black: Why do the docs use names I do not recognise?
The product has been renamed repeatedly. CB Defense is now Endpoint Standard, CB ThreatHunter is Enterprise EDR and CB LiveOps is Audit and Remediation. Older community answers and runbooks still use the previous names.
NordVPN: What happened in the 2018 breach?
An attacker reached one rented server in Finland via an insecure remote management tool left in place by the datacentre provider, and obtained a TLS key that had expired. NordVPN disclosed it in October 2019, nineteen months later, and afterwards moved the estate to RAM-only servers.
VMware Carbon Black: Does it replace my existing antivirus?
Yes on supported Windows, macOS and Linux versions, and running it alongside another antivirus is not recommended because the two agents contend for the same hooks. Check your compliance requirements, as some auditors still ask for a named antivirus product.
NordVPN: How many devices does one subscription cover?
Ten simultaneous connections. A router configured with the service counts as one connection regardless of how many devices sit behind it.
VMware Carbon Black: Do I need a full-time analyst to run it?
To get value from Enterprise EDR, effectively yes. The prevention tier can run with part-time attention, but the hunting and recording capability is only worth its cost if somebody is querying it, which is why many customers buy it through an MDR provider.
NordVPN: Does it work on restrictive networks?
There are obfuscated servers intended for networks that block VPN protocols, but they run over OpenVPN only and no provider can guarantee access in a country that actively filters. Treat it as best effort.
VMware Carbon Black: How is it licensed?
Per endpoint, per year, with the capability tier determining the rate and workload and container protection priced separately. Extended EDR data retention is an additional line item.
Related pages
More on VMware Carbon Black
Other head to heads
- NordVPN vs Surfshark
- NordVPN vs 1Password
- NordVPN vs Norton 360
- NordVPN vs LastPass
- NordVPN vs Bitdefender Total Security
- NordVPN vs ExpressVPN
- NordVPN vs IVPN
- NordVPN vs Mullvad VPN
- NordVPN vs Private Internet Access
- NordVPN vs Avast One
- NordVPN vs TunnelBear
- NordVPN vs JumpCloud
- NordVPN vs McAfee Total Protection
- NordVPN vs NICE Actimize
- NordVPN vs Semgrep
- NordVPN vs Spot AI
- NordVPN vs Syft
- NordVPN vs CyberGhost VPN
- NordVPN vs Microsoft Defender for Endpoint
- NordVPN vs Cybereason Defense Platform
- NordVPN vs CrowdStrike Falcon
- NordVPN vs SentinelOne
- NordVPN vs Trend Micro Vision One
- NordVPN vs Proofpoint
- NordVPN vs Sophos Intercept X
- NordVPN vs Descope
- NordVPN vs Drata
- NordVPN vs DTiQ
- NordVPN vs ESET NOD32 Antivirus
- NordVPN vs Falco
- NordVPN vs SentinelOne Singularity
- VMware Carbon Black vs Surfshark
- VMware Carbon Black vs 1Password
- VMware Carbon Black vs Norton 360
- VMware Carbon Black vs LastPass
- VMware Carbon Black vs Bitdefender Total Security
- VMware Carbon Black vs ExpressVPN
- VMware Carbon Black vs IVPN
- VMware Carbon Black vs Mullvad VPN
- VMware Carbon Black vs Private Internet Access
- VMware Carbon Black vs Avast One
- VMware Carbon Black vs TunnelBear
- VMware Carbon Black vs JumpCloud
- VMware Carbon Black vs McAfee Total Protection
- VMware Carbon Black vs NICE Actimize
- VMware Carbon Black vs Semgrep
- VMware Carbon Black vs Spot AI
- VMware Carbon Black vs Syft
- VMware Carbon Black vs CyberGhost VPN
- VMware Carbon Black vs Microsoft Defender for Endpoint
- VMware Carbon Black vs Cybereason Defense Platform
- VMware Carbon Black vs CrowdStrike Falcon
- VMware Carbon Black vs SentinelOne
- VMware Carbon Black vs Trend Micro Vision One
- VMware Carbon Black vs Proofpoint
- VMware Carbon Black vs Sophos Intercept X
- VMware Carbon Black vs Descope
- VMware Carbon Black vs Drata
- VMware Carbon Black vs DTiQ
- VMware Carbon Black vs ESET NOD32 Antivirus
- VMware Carbon Black vs Falco
- VMware Carbon Black vs SentinelOne Singularity
