Review Summary
See a synthesized overview of the key takeaways from verified reviews of Nozomi Networks Platform.
See a synthesized overview of the key takeaways from verified reviews of Nozomi Networks Platform.
Nozomi Networks is engaged in safeguarding critical infrastructure from cyber threats. The company's unique platform integrates network and endpoint visibility with threat detection, and utilizes artificial intelligence for quicker, more effective response to incidents. The services provided offer a reduction in risk and complexity while enhancing operational resilience.
Do You Manage Peer Insights at Nozomi Networks?
Access Vendor Portal to update and manage your profile.
OT Focused Cybersecurity - Unlike most IT cybersecurity tools, Nozomi can recognize assets that use protocols other than TCP/IP. Passive deep packet inspection - OT networks/assets are not as resilient to active scans as typical technology networks. Nozomi utilizes deep packet inspection to classify and harvest valuable information about assets on our network, providing insights unavailable to other tools. Actionable Insights - Nozomi maps out our network and provides actionable recommendations based on anomalous behavior, CVE correlation to our assets, and a robust Threat Intelligence feed. With the recent release and updates to Vantage IQ, the data driven platform has fully transformed into an analytics partner. The Agentic nature allows our analysts to focus on content instead of syntax. We were recently evaluating a Security Advisory, and it provided thoughts and insights beyond what we typically would have produced. VERY IMPRESSED!
Once we do get it fully functional, the outcome expected is a broader visibility of our devices throughout our IT and OT domains.
1. Vantage provides a comprehensive, intuitive view of our systems. 2. The Plant Asset Inventory has been of great value for visibilty and planning, though we are looking forward to enhancing this with ARC once we meet vendor approval. 3. Threat detection capabilities are top-notch, offering real-time alerts and deep insights that help us navigate potential security issues.
Rapid Updates/Improvements often leave published knowledge inaccurate Rapidly developing SAAS Platform is out of sync with their on-prem version of the GUI. Slight differences in reporting syntax and/or capabilities require a bit of re-learning Add-on licensing is required for data correlation and much of the actionable intelligence. The add-ons are blurred out or are presented as a paywall for features that seem like included links. OT/ICS Environments do well out of the box, hybrid or mixed environments suffer a bit of IT overload - It would be nice if there were an easier way to alow IT traffic to pass and be tracked as an asset - but NOT fed into the full stack analysis engine. Visibility to IT isn't bad necessarily; but with a full complement of IT cyber tooling - the Alerting, Vulnerability data, TI, and graphing tends to blur why we purchased this tool.
There are a few GUI suggestions that I would like to make, however, once we have the product fully deployed and functional pros/cons will be more visible and noticeable so they can be addressed appropriately.
1. The query language is quite a learning curve for me, but it just takes some practice. However, Vantage IQ has been a major development for this and can interpret queries in question form. 2. Remote Collectors are very good for their purpose, but are very limited in port availability. In some areas, we have had to use network switches for traffic aggregation. 3. Vantage presents information differently from Guardian and CMC. Each platform is strong, but displays data in unique ways. What is visible in one may not be in the other; the information is there, but you have to learn where to look for it. These are minor adjustments; again, it just takes practice.