Nozomi Networks Vantage OT & IoT Security Solution logo

    Nozomi Networks Vantage OT & IoT Security Solution

    SaaS-Powered Security and Visibility of OT and IoT Networks

    Ratings and reviews

    4.3
    24 ratings
    3 star
    2 star
    1 star
    58%
    42%
    0%
    0%
    0%
    4 AWS reviews
    |
    20 external reviews
    External reviews are from G2  and PeerSpot .

    Filters

    Review type

    AWS Marketplace reviews
    External reviews
    Reviews (24)
    Gustavo Miretki

    Improved monitoring has given us real‑time visibility and faster response on factory shop floors

    Reviewed on Jul 04, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for Nozomi Networks is monitoring OT assets at Volkswagen's factories.

    The specific example of how I use Nozomi Networks for monitoring OT assets is that the monitoring occurs in the factories at Volkswagen. We have the collectors acting at the switches, the access switches, and then we have a CMC collector, a VM positioned in the data center that collects the logs. With the logs and the metrics, we act by creating playbooks for addressing the alerts. That is the case for monitoring with Nozomi Networks appliances.

    It has a simple interface, so it is easy to use and configure, but the network needs to be very well structured to receive the logs and capture all Nozomi Networks assets for the shop floor.

    How has it helped my organization?

    Nozomi Networks has positively impacted my organization by providing observability of the environment and the assets in the OT environment of the shop floor. Prior to this, we did not have observability over the legacy devices. Receiving these logs allows us to address threats occurring in real time in the environment, enabling us to fortify the network and equipment.

    I can share that since implementing Nozomi Networks, we have seen an improvement in response times. Alerts coming to Nozomi Networks dashboards have led us to automate by sending alerts to email and generating weekly reports for analysts. This means the analyst reads and verifies a set of alerts and then handles the incident in a very fast and efficient manner.

    What is most valuable?

    The best features Nozomi Networks offers include polling for shop floor assets, alerts based on CVSS, which is a great feature, and BPF filters at Nozomi Networks interfaces that filter the traffic we do not want to see.

    The CVSS-based alerts help my team by allowing us to determine if an alert is critical or a false positive based on the CVSS score. CVSS is a market standard for classifying vulnerabilities, so it is great that we have alerts based on it.

    What needs improvement?

    I think Nozomi Networks can be improved by enhancing the size of the boxes and the performance for collecting logs, and of course, the price. The most efficient way to implement Nozomi Networks is by positioning small boxes at the access switches, which enables them to capture more details, such as MAC addresses and all the packets transmitting across the network. When there are few boxes positioned above the network, the data and packets can be broken, limiting our ability to capture packets, which is not an issue with the switches but rather a capacity limitation for Nozomi box. Improving the ability to capture packets with smaller boxes would be great.

    Regarding Nozomi Networks's AI capabilities, I think its governance and security are currently lacking as we do not have AI capabilities at Nozomi at this moment. However, I believe AI analysis, particularly regarding the high volume of logs, would help analysts make decisions and classify alerts more effectively. AI is a very good trend in the market, and I think Nozomi Networks should incorporate this feature soon.

    I believe that AI capabilities help improve the accuracy and reliability of the alerts and the classification for the assets. This feature enhances efficient reporting, and I think it would not introduce any negative aspects to the analysis. Having AI analyze and foster accuracy with Nozomi Networks collectors would be great.

    For how long have I used the solution?

    I have been using Nozomi Networks for about two years.

    How are customer service and support?

    The customer support is very great. The few times I had to open tickets for customer support, I was attended to very quickly and efficiently by good professionals and specialists.

    Which solution did I use previously and why did I switch?

    I did not previously use a different solution before Nozomi Networks.

    Which other solutions did I evaluate?

    Before choosing Nozomi Networks, we evaluated the Claroty solution.

    What other advice do I have?

    Nozomi Networks's scalability is enhanced by the strategy I mentioned; the best way to implement Nozomi Networks boxes is to distribute small Nozomi Networks boxes across the access switches and network, which allows us to capture more details about the packets being transmitted between the assets. The main feature to scale this is to implement more boxes that have the performance necessary to capture and send logs to the CMC, the centralized Nozomi Networks.

    My advice to others looking into using Nozomi Networks would be to place more small boxes at the access switches, especially if their company has a larger network. More boxes positioned near the shop floor assets allow for greater detail capture about packets and richer information regarding threats.

    I am giving this review a rating of nine because it is a great tool, and although it has some areas for improvement, nine is a very high score.

    I think Nozomi Networks is a good tool, and we will continue using it.

    Tumi Masobe

    Unified teams have gained real-time visibility into IoT leaks and now plan maintenance proactively

    Reviewed on Jul 02, 2026
    Review provided by PeerSpot

    What is our primary use case?

    Nozomi Networks serves a critical function for water systems here in South Africa. For example, a government utility called Rand Water uses IoT sensors to detect leaks on water supply systems. However, two divisions in their IT department had been operating in silos: the networking side and the IoT side. The IoT side lacked comprehensive security measures and only ran a firewall, which is not true IoT security. Their approach was reactive rather than proactive when solving problems. Nozomi Networks came into the picture and provided them with visualization of their IoT network, which they had never had before.

    This solution helped them become aware of where everything is located, where all the sensors are, how they are interconnected, which ones are working properly, and which ones are not. Initially, they had to log into each device individually just to find out if it was still working or if it had detected any issues. They were not proactive at all; they were reactive when it came to managing their infrastructure.

    What is most valuable?

    The best features Nozomi Networks offers include the ability to drill into every IoT device and get detailed information on make, model, performance, and what type of errors the sensor has picked up. This provides useful information on the entire IoT network versus individual sensors scattered throughout the network that they had to manually check to try and find problems. Now they receive real-time alerts on any issues.

    Getting real-time alerts and detailed information impacts my team and clients because they can respond quickly and are more organized now. They are no longer chasing their tails. Now they can plan properly for the day and plan ahead on what needs to be resolved. This made them aware of where everything is, where all the sensors are, and how they are interconnected, which ones are working properly, and which ones are not.

    Initially, they could not do any reporting or planning because they did not have real-time data. Now they do. Now they can do all those things because they have gained visibility and information on their inventory. They are also able to do capacity planning, which is something they could not do before.

    What needs improvement?

    Nozomi Networks can be improved by integrating with other technologies so that teams look at a single dashboard when it comes to security issues. Instead of looking at two different dashboards, integration would create a single dashboard that shows where the IoT meets the network. This way, if they need to isolate any threats, those threats can be isolated on the networking side as well.

    I would give Nozomi Networks an eight because there is still room for improvement. The key issues involve reporting that needs to be integrated with networking reporting, and real-time alerts that need to be integrated into a single dashboard with other technologies. Integration is the most important part for future development.

    For how long have I used the solution?

    I have been using Nozomi Networks since five years ago, around 2021.

    What do I think about the stability of the solution?

    Nozomi Networks is very stable.

    What do I think about the scalability of the solution?

    Nozomi Networks's scalability is very impressive. I can support a huge number of IoT devices. One of the key benefits is that we do not have to use multiple tools. Nozomi Networks covers the entire infrastructure when it comes to IoT.

    How are customer service and support?

    Customer support in terms of sales and technical assistance is very good.

    Which solution did I use previously and why did I switch?

    Previously, there was no solution. That is why they relied on the network and network security to protect IoT, which was not really ideal.

    How was the initial setup?

    Deployment is quick and very easy to hand over to the customer team because it is not complicated. It works from day one.

    What about the implementation team?

    Our relationship with this vendor is structured as a reseller relationship.

    What was our ROI?

    I would say the ROI is significant in terms of time saved and resources. The IT team and the IoT team managed to combine into a single team that can handle both IoT and networking troubleshooting because of the information they receive from Nozomi Networks.

    What's my experience with pricing, setup cost, and licensing?

    My experience with pricing, setup cost, and licensing has been very seamless. The Nozomi Networks team was very helpful throughout the process.

    Which other solutions did I evaluate?

    We looked at various other technologies that were primarily open source, but nothing was examined in terms of doing a proof of concept with those technologies. We primarily focused on what information we could get from our chosen tool and what other functionality it provides.

    What other advice do I have?

    The features are great and very easy to use. The ability to navigate the platform and get useful information and reporting is much easier now. Before, it was a manual exercise where they had to try to put everything into spreadsheets and create diagrams manually to report.

    Nozomi Networks has impacted our organization positively as we have gained trust from customers in terms of the technology results and everything that the technology brings. We presented and managed to demonstrate the value for money.

    Solving incidents has improved drastically. The team is now able to plan properly. They do not spend over budget or under budget because they know exactly what needs to be resolved due to the information and visibility they have. The IoT team and the network team managed to integrate into a single team because they no longer operate as silos but as a single team that can resolve both IoT and networking security issues together.

    The security of Nozomi Networks is great. The governance complies with government security laws.

    Nozomi Networks is a very good tool, which is why we recommend it before any other product. I would give this product a rating of eight out of ten.

    reviewer2867280

    Comprehensive monitoring has strengthened fragile OT networks and improved threat detection

    Reviewed on Jul 01, 2026
    Review from a verified AWS customer

    What is our primary use case?

    My main use case for Nozomi Networks is as an IDS, so we are selling our cybersecurity services and SOC that is primarily based on Nozomi Networks portfolio. We place them at the user's location and send the logs to the SOC, and then we do the triage, escalations, and related tasks.

    In my day-to-day work, I use Nozomi Networks for monitoring and cybersecurity. Since OT networks are very fragile, you cannot install regular SIEM agents. You have to do passive network traffic analysis instead.

    How has it helped my organization?

    Nozomi Networks has impacted my organization positively because we have experience with a few other vendors, and their configuration, reliability, and even threat identification are significantly lower than Nozomi Networks capabilities.

    I can tell you about specific outcomes I've seen with Nozomi Networks. For example, it definitely improved visibility because most of the clients don't know what they have in their networks. That is the first benefit. The second benefit is the fact that even though you make site visits, site surveys, and acquire asset information, there are still some remote devices that you cannot see or the customer doesn't know about. You only discover them in Nozomi Networks. The alerting options are also definitely a benefit because even though there are false positives and a required learning time, we haven't had any real incidents, but the mere fact that you are alerted for strange or unusual behaviors in the network is more than enough for us. As far as the client goes, they are also happy because we noticed the addition of new nodes to their network. They are always surprised when we alert them to these discoveries.

    What is most valuable?

    The best features Nozomi Networks offers include reliability and ease of implementation because the platform is excellently made. Many other competitors use Docker instances. The configuration of the devices itself is straightforward. The documentation could be better, but overall, it is a great platform and we are satisfied with it.

    What makes the implementation process of Nozomi Networks stand out for me is that you only need to place network parameters such as IP address. You can use DHCP for acquiring those. There is no extra configuration step regarding SPAN ports. You just need to make mirror ports on the switches that you want to sniff traffic from, and the connectivity to either central management or Vantage is almost 100 percent.

    What needs improvement?

    Regarding improvements for Nozomi Networks, it is hard to provide recommendations because they are already among the best vendors in the market. They are a Swiss firm that was acquired by Mitsubishi. They have grown their portfolio from an NIDS over VMs to even embedded solutions that you can put on switches, routers, or PLCs themselves. I do not see much room for improvement beyond what they currently offer. They also have wireless solutions. In the few years after I started working with them, they introduced Arcs, which are host-based sensors similar to SIEM agents. I believe they have covered everything.

    I would add that the documentation is lacking some information, so you need to ask customer support for it, but you cannot have everything. Their customer support is excellent. They are answering tickets in an hour or two, with a maximum of a day.

    For how long have I used the solution?

    I have been working in OT cybersecurity for four years.

    What do I think about the stability of the solution?

    Nozomi Networks is stable in my experience.

    What do I think about the scalability of the solution?

    The scalability of Nozomi Networks is excellent. They have many different options so you can choose the one based on requirements and tailor it to the needs of the customer. We are primarily using Guardian, which I believe is the 100 series. It is more than enough for most of our clients. We also use Remote Collectors in some places and Arc sensors. We also have one Guardian Air which is currently unused because the customer doesn't know their OT networks and since it is gathering all the Wi-Fi, there are a lot of noise from IT, so we turned that off.

    How are customer service and support?

    Customer support is excellent. They give concise answers in a short time, around one or two hours. We have never waited more than a day for customer support.

    Which solution did I use previously and why did I switch?

    We have started with Nozomi Networks and we are still using it. I doubt that we will stop using it in the near future because of its reliability.

    What about the implementation team?

    We contacted Nozomi Networks directly. We are a big company and we are not using smaller distributors.

    What's my experience with pricing, setup cost, and licensing?

    I am not familiar with the pricing, setup cost, and licensing since I am in an engineering department. I just received the device and went to the customer location. I am not involved in billing and administrative matters.

    Which other solutions did I evaluate?

    Before choosing Nozomi Networks, I believe that Dragos was one of the options, but since we started using Nozomi Networks during the Corona pandemic and customs and tax import output were favored on the side of Nozomi Networks, we proceeded with that solution.

    What other advice do I have?

    Regarding Nozomi Networks AI capabilities, IQ is a nice add-on feature because it can give you guidance and direction without reading the documentation because it works for you. It can also give you many ideas regarding playbook creation, alert triage, query generation, and assertions. I believe it is pretty useful, but it is entirely dedicated to Nozomi Networks. It doesn't know anything beyond that.

    Regarding Nozomi Networks accuracy and reliability of output, I would rate it about 70-30 because every once in a while I catch it in some inaccuracies, and then when I ask it again, it corrects itself. I believe it is a good starting place and as with any AI, you need to know about the subject matter that you are asking about. You cannot entirely rely on it blindly.

    My advice to others looking into using Nozomi Networks is that they should definitely start by making a proof of concept. The people responsible for Nozomi Networks should at least have their Nozomi certified engineer and troubleshooting certification, and the people working with the security side should have their security analyst certifications. I would rate this product a 10 out of 10.

    reviewer2867253

    Gained deep OT network visibility and now seek stronger integrations and localized reporting

    Reviewed on Jun 30, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for Nozomi Networks is to find possible vulnerabilities and threats and create a network map in operational technology networks (OT networks). I mainly accomplish this by showing customers the OT network map along with the possible threats and vulnerabilities within these networks.

    For example, in an industrial company in Peru, a customer tried to find some vulnerabilities in the OT networks. They connected the Nozomi Networks appliance to the OT network to display a map of the devices within the network and highlight the possible vulnerabilities present.

    In end customer use cases, the main use remains the same, but another use has been to try to integrate this solution with security devices, such as firewalls, to generate policies that either block or allow certain traffic, whether it is allowed traffic or potentially threatening traffic.

    How has it helped my organization?

    Nozomi Networks has positively impacted our organization as we can visualize the traffic within the OT networks and identify the potential threats or vulnerabilities. We can generate reports for analyzing possible countermeasures and determine what improvements are needed in the future to protect the traffic and the company from such vulnerabilities.

    Concrete outcomes include generating reports on the types of traffic in the OT networks, improving our decision-making regarding security incident countermeasures, and reducing response times to incidents in the OT network because, prior to Nozomi Networks, we did not have another viable solution.

    What is most valuable?

    The best features Nozomi Networks offers include the capability to show the network map while operating in remote or sniffer mode, which is a good feature. Another feature is its ability to display vulnerabilities in OT networks, as very few solutions in the market can accurately operate within these networks to reveal potential vulnerabilities and threats. Additionally, it allows for integration with additional security devices and provides reports about this feature.

    What needs improvement?

    Integrating with other security devices is a little difficult because this process is not currently automated. I potentially need future integrations via APIs; however, at the moment there is limited integration with firewalls, such as Fortinet, but they require more development to properly integrate and generate policies in the correct order based on specific traffic, destinations, and services. Overall, while this could be a challenging integration with other security devices, it is a significant advancement compared to alternatives, but it does need further development in the future.

    Improvements for Nozomi Networks should focus on integrating with other security devices. Since Nozomi Networks operates in OT networks, I need to connect this solution with others such as SIEM, XDR, and firewalls. Additionally, the reporting system currently displays in English, but I need to enhance these reports to be in native Spanish, not merely translated, and aim for those reports to be aligned with ISO, NIST, or other frameworks to generate a greater impact within the company.

    I would also like to highlight the need for better support because when we attempt to deploy this solution with partners, the solution remains within the company but requires ongoing support for its deployment across OT networks.

    For how long have I used the solution?

    I have been using Nozomi Networks for demos and proof of concepts to review the technology and the solution, and how this solution could provide insights into threats and vulnerabilities in the network. I have been engaging in tests with end customers for around six months to one year.

    What do I think about the stability of the solution?

    At the moment I believe the features are acceptable.

    What do I think about the scalability of the solution?

    Nozomi Networks can handle growth in my organization easily. In the on-premise solution, there are various options to scale, such as considering hybrid or public cloud models, but at the moment, the company is not evaluating scaling.

    How are customer service and support?

    I have had one experience with customer support at Nozomi Networks, and it was great.

    Which solution did I use previously and why did I switch?

    I have not used a different solution before Nozomi Networks. This is my first experience with such a solution.

    Which other solutions did I evaluate?

    I evaluated other options before choosing Nozomi Networks, including options to create similar functions with firewalls using OT signatures and Nessus software. However, the final decision was to select Nozomi Networks.

    What other advice do I have?

    My advice for others looking to use Nozomi Networks is that if you are searching for a solution that provides network visibility, AI capabilities, and easy integration and deployment, then Nozomi Networks is a viable option. I would rate this product a seven out of ten.

    Pasanj Pasanj

    Network visibility has improved and monitoring of iot devices and vulnerabilities is stronger

    Reviewed on Jun 30, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for Nozomi Networks is to detect devices in the environment, especially IoT devices, or any kind of devices that connect to the network, and we need to detect them. We normally check through our console for any kind of device. For example, if a user tries to connect any device to the network or any unrecognized device is available, we monitor it. Beyond that, we check vulnerabilities of our IoT devices, mainly. We monitor any kind of abnormal traffic or any kind of abnormality on those devices, and we get a report if we want to do any patching for devices.

    What is most valuable?

    The best features Nozomi Networks offers are device detection and vulnerability checking, including CVEs, and reports. In my scenario, for some of the devices, we cannot always know the location or whether we have missed any vulnerabilities. There is a large-scale variety of devices, so we cannot go through each device one-by-one and check if any CVEs were detected recently or are up to date. In that case, Nozomi Networks portal is good for us. For now, we use it for device detection and vulnerabilities only, and I am satisfied with the current functionality.

    Nozomi Networks has impacted my organization positively because our technical staff changes. In those cases, we sometimes do not know about certain devices. For example, it can be difficult with some devices, and they operate in unknown locations, such as webcams or IoT devices located in different areas. In that case, we can get an idea about what devices are in our network and any abnormal traffic or any kind of abnormality on our network. Nozomi Networks could be a positive impact for the organization because if any staff, such as a network engineer or other technical engineers, changes, the next new engineer can still move forward with this portal.

    Nozomi Networks has led to specific outcomes or measurable improvements for my team, including faster response times. We can say there is a faster response time because, for example, if any kind of IoT device failure occurs, we can detect it from here. Also, we can identify any kind of vulnerability impact or any incidents that happen on those devices because of vulnerabilities. We can do incident investigation through this portal as well, so it is good for the company's security posture.

    What needs improvement?

    I feel Nozomi Networks can be improved by integrating SIEM features on this portal. If we integrate both features, such as SIEM on top of Nozomi Networks, then the analysis part would be much easier for the users, and we can improve the company's security posture. In that case, sometimes we could avoid using so many tools, such as Nozomi Networks for device detection and a SIEM for different checks. If we use one tool for all of them, that would be beneficial for the company. I did not feel any kind of issue up to now, and I am not sure about the future.

    For how long have I used the solution?

    I have been using Nozomi Networks for around one year.

    What do I think about the scalability of the solution?

    I have not felt anything about Nozomi Networks' scalability in this scenario since it is already deployed.

    How are customer service and support?

    The customer support was good as one time I contacted support, and I got a good reply from them. It was quite an effective response at that time.

    Which solution did I use previously and why did I switch?

    I do not have any idea about a different solution used before Nozomi Networks. When I joined this company, it was already deployed.

    What other advice do I have?

    My advice to others looking into using Nozomi Networks is that if any organization has large-scale OT devices or does not have a clear picture of their network diagrams or has a messy network, it is better to deploy a tool such as Nozomi Networks to keep track of the devices. Then the security posture can be improved with this portal. It is better to deploy this product. Even if a company changes their technical staff, the other team members can function well with this tool. I would rate this product an eight out of ten.

    Edwin Kamunde

    Improved OT visibility has protected geothermal operations and now secures critical power assets

    Reviewed on Jun 30, 2026
    Review provided by PeerSpot

    What is our primary use case?

    For the utility company named KenGen, Nozomi Networks is used for their OT security. They monitor their power infrastructure within the power stations located in Olkaria. We are currently connected to about four different power stations and all interconnected to the head office within the same area.

    Right now they use it to monitor all their IoT and OT networks within the power grid. For example, they have most of their IoT sensors which are used to monitor the geothermal power plant where they have steam wells which have been dug in different areas and they use IoT connectivity which is connected via 4G network and LTE. Before Nozomi Networks, they had no visibility of all these remote sites. With Nozomi Networks, they have been able to monitor and see every single packet that passes through all these IoT networks and it is all consolidated at the head office and now they have full visibility of these wells, which had been a challenge for quite some time. This particular use case has benefited them greatly.

    For now, we are in discussions with the only oil and gas company in Kenya. They deliver oil and petroleum products all the way from the Mombasa port into Kenya, all the way to Uganda, which is a neighboring country and beyond. They are seeing the value of also monitoring and securing their SCADA networks which is also one of the use cases that Nozomi Networks shines a lot in delivering value for all the other oil and gas companies they have worked with. From my perspective, that could be a great next use case that we are really pursuing and hoping to bring extensive value into their organization.

    What is most valuable?

    The best features for Nozomi Networks include the fact that Nozomi Networks is able to offer more visibility on particular protocols that using current IT-focused security solutions, they are not able to monitor. The fact that it is able to integrate the IT and OT side of customer networks brings a lot of value to them and that is one feature I would say is the best currently within this particular market.

    The one thing that we noticed with the current customer who is using the solution is that once we initially took them through the first training, they actually appreciated it very much and we did not need to keep redoing it, which shows the ease of use for the technical team as well as the way they are able to break down the reports. It is very easy to do various custom reports for the management, senior management, for the engineer levels, and for those who are actually on the ground. All this is done from a single pane of glass. It is not necessary to keep on initiating and drafting new reports. You are able to easily export and specify this is for the managerial level, they get a custom type of report. For those who are below, they are able to get different types of reports. The engineers get now more technical details about what is going on in the network.

    Since we deployed the solution almost over three years back, it has to be three years by next year. The organization has gained greatly from the particular solution that we deployed. They have mitigated quite a number of attacks and incidents and ever since we started running the solution, there have not been any OT-based security breaches. The training has helped to avoid any in-house concerns that would be resulting from internal users making mistakes. The solution has been really well absorbed and utilized well to secure their infrastructure.

    What needs improvement?

    Customer support is something I think there is a slight challenge on responses on email. But on escalating with the team in Dubai, then we get things solved. If the support could be improved on that, that would be a good thing.

    The pricing was quite high based on the end customer's perspective. They negotiated, but they would have preferred a cheaper option. Though Nozomi Networks offered all the features that they needed and they had to invest in that. So also the partners had to reduce our margins, which was quite painful for us, but we still delivered the solution. If something can be done on pricing, that can be quite good, especially for the African region.

    For how long have I used the solution?

    I have used Nozomi Networks for almost five years.

    Which solution did I use previously and why did I switch?

    We were not using any other solutions. Nozomi Networks was the first OT security solution. The customers had considered Darktrace, but they did not want any cloud offering. So we had to pitch Nozomi Networks for their on-premises offering.

    How was the initial setup?

    Running a proof of concept is always the best way to go, to enable us to clearly see the depth of the particular scope of the deployment. This way now we are able to understand how many Guardians are needed, how many remote collectors are needed, and what type of connectivity will be used and gives us more insight on the IP allocation and the likes. That would be a good place to start from my perspective.

    What was our ROI?

    Definitely there are fewer employees needed, so there is savings on that. Now that monitoring is real-time and more dispatched, the actions are such that notifications come in promptly and the engineering team is able to act on any issue that comes up faster. There is a lot of time saved in terms of incident response and also the reduced number of incidents. The efficiency of the organization, the fewer employees needed, and the time saved has greatly offered the customer a decent return on investment on this particular solution.

    Which other solutions did I evaluate?

    Darktrace was the only other contender which was considered. We only reviewed Darktrace and Nozomi Networks, and Nozomi Networks came out the winner in this particular case.

    What other advice do I have?

    In terms of response time, it has greatly improved because they have notifications and emails which are always sent when there is any incident that has happened. The notifications are very prompt and very specific to particular staff and personnel who are able to approach and solve and deal with a particular issue immediately. The response time has increased by about 70% based on how it was. Before, it was a very manual way of doing it and until there is a breakdown or something has happened and sending an engineer to the ground, that part has been eliminated. The notifications are quite direct and straight. This has really improved their delivery. In terms of incidents, before, they were not even monitored, but now incidents have actually, in the plant, there is no security incident that has come up that has caused the plant to be maybe out of commission or any part of the network which is negatively affected. For the entire time Nozomi Networks has been running within the network, incidents have reduced by almost 50-60%.

    Nozomi Networks has really offered a stellar performance within the organization and there is not any specific part that needs improvement for now.

    The AI aspect is quite secure for now, so long as the AI is not connected to the internet, there is a lot of security because most of these customers, even in the country, these are utility, government, national infrastructure organizations. The security and connectivity out, just being on-premises and all the models are running within the network really helps to offer that additional security. In terms of the governance side, we just need more education to be done to the end customers just to make sure they align to the governance of the organization when it comes to AI.

    The accuracy of Nozomi Networks is quite standard. It is quite good. The accuracy is above 90%. I have not experienced any breakdowns or issues, so the reliability is quite good. The output is quite specific for the end customer, which is quite beneficial and I commend Nozomi Networks for delivering that.

    The scalability is quite easy. The remote collectors can be deployed across regions and also there is the vantage offering which offers for organizations distributed across different geographical regions. The scalability is quite easy and straightforward to achieve.

    So far, we may need a bit more marketing within the market, because I think of the price of the solution, we have a very limited range of customers to offer the solution to due to the cost implication. If there is an option which is a cheaper option for Nozomi Networks that could come up with to offer the enterprise market within Kenya and the East African region, that would be a better way now of getting the solution into enterprise-level organizations like the banks and maybe hospitals and the like. I would rate this review overall as a 9.

    G Neyrinck

    OT visibility has transformed asset discovery and now guides targeted vulnerability reduction

    Reviewed on Jun 30, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for Nozomi Networks involves asset discovery and vulnerability management in OT environments.

    For asset discovery and vulnerability management in my OT environments, I started using the passive mode and configured a SPAN port on a switch in the particular VLANs that I wanted to see. Then I collected that data, fed it to Nozomi Networks Guardian, and then figured out how to use active and Arc embedded to also see more assets in the field, including the Arc sensor.

    In terms of my main use case and how I use Nozomi Networks day-to-day, I see many things that I do not expect. What is very handy within Nozomi Networks is that I can see the communication between the assets, clearly identifying what ports they are communicating on and what protocols they are using. It is really very insightful.

    What is most valuable?

    The best features Nozomi Networks offers, in my experience, are how quick it is to set up and how fast it can discover assets in the network.

    The quick setup and fast asset discovery help me in my work by allowing me to see how OT assets are communicating, what versions I have on certain assets, and what vulnerabilities are present. With this information, I can figure out how to segment the network, enforcing firewalls between the VLANs based on the communication patterns I have identified.

    Nozomi Networks has positively impacted my organization by allowing me to build a roadmap based on what I see, ultimately leading to a better security posture, which includes knowing what is inside the network and what vulnerabilities exist. Additionally, by making use of Vantage, I can query my asset database, which is very handy to discover what I should address first and how I can speed up the security posture of my OT networks.

    What needs improvement?

    To improve Nozomi Networks, I believe that it is less useful without Vantage if I have a multi-site setup. I really need Nozomi Networks Vantage and Vantage IQ to make the most of it. Additionally, the Arc sensor as well as the active polling features are subscription-based, whereas competitors often offer a one-size-fits-all subscription allowing immediate access to all features. With Nozomi Networks, it is often an add-on, which is sometimes a disadvantage when competing.

    Regarding needed improvements, particularly around licensing and pricing, the add-on nature of the licensing could be improved. Vantage is rather expensive in comparison to the competition, and while the features are great, the licensing structure could be enhanced.

    Concerning Nozomi Networks' AI capabilities, I think its governance and security are good, but it also requires a paying add-on, so while it looks great based on my experience, the need for payment is a disadvantage.

    There's also room for improving on # of integrations.

    For how long have I used the solution?

    I have been using Nozomi Networks for about two years.

    What do I think about the stability of the solution?

    In my experience, Nozomi Networks is stable.

    What do I think about the scalability of the solution?

    Nozomi Networks is scalable if I purchase the Vantage part.

    How are customer service and support?

    The customer support for Nozomi Networks is great, demonstrating good response times and providing the right solutions. It is easy to work together with them.

    Which solution did I use previously and why did I switch?

    Previously, I used Claroty but switched to Nozomi Networks because I could perform asset inventory and vulnerability scanning in my setup.

    How was the initial setup?

    My experience with pricing, setup cost, and licensing is overall positive; it is a really straightforward process, not too difficult to set up, with great training material provided. The downside is that I also need to pay for some features, but overall, NNCE is a great course.

    What was our ROI?

    In terms of specific outcomes or metrics showing how Nozomi Networks improved my security posture and sped up my processes, I have saved time, and I have also gotten compliance reports regarding compliance with IEC 62443, which is very handy in terms of the assets I see.

    Since I started seeing what is inside the network, I transitioned from just guessing what was there to having a clear view. This clarity makes me better prepared for setting up and segmenting the environment as well as managing how communication flows to keep things up and running.

    Which other solutions did I evaluate?

    Before choosing Nozomi Networks, I evaluated options including Claroty, Nozomi Networks, and Armis.

    What other advice do I have?

    I would rate the customer support an eight on a scale of one to ten.

    My advice for others looking into using Nozomi Networks is to start with a small setup and then expand. You can trust that the active polling operates effectively.

    I would rate Nozomi Networks an eight out of ten because it is a great product, but it is missing some features, such as secure remote access, so that is why I cannot give a maximum score.

    Regarding Nozomi Networks' AI capabilities, I find its accuracy and reliability of output to be rather reliable; I have not discovered big inaccuracies or issues, so that is acceptable.

    My overall review rating for Nozomi Networks is eight out of ten.

    Kamran Rasul

    Improved OT visibility has transformed monitoring and empowers precise threat hunting

    Reviewed on Jun 29, 2026
    Review from a verified AWS customer

    What is our primary use case?

    My main use case for Nozomi Networks is visibility into the OT network.

    For visibility into my OT network, I usually find that if the OT network is not built on a Purdue model or layered approach as segmentation or conduits, whatever you want to use with it, IEC 62443 says conduits, then you don't know which traffic is talking to what, and the security model for OT is not well established. I put in a Nozomi Networks device, start building, and gather the asset inventory. It has special pages that show the communication between cross-layers and all that, and I start segmentation. It helps me with segmentation, shows me what is happening in my network, which device is communicating what, and then I can use that to do threat hunting in the OT network.

    How has it helped my organization?

    Nozomi Networks has positively impacted our organization by giving us more visibility into our OT network. Now we know what is happening in our OT network, and we can find things which were never there before and which we did not know before. Even at times, the variable monitoring in the OT by Nozomi Networks has helped us to know if there's something wrong with any of the field devices.

    Regarding a specific example or a measurable outcome, I can say that SCADA is already there, and the teams are monitoring what is happening in OT. However, the way Nozomi Networks generates alerts is really helpful. For example, we give them a range of a variable, for example the temperature should not go below a certain degree. In a SCADA network, you always have those alarms, the lights, they pop up, but the alerts that Nozomi Networks gives me are much more valuable than those which I see in there.

    What is most valuable?

    Nozomi Networks offers a lot more depth knowledge about the industrial OT protocols compared to any other, and the best thing I appreciate about Nozomi Networks is that it's straightforward. It does not go into irregular steps to perform the things required, so it's straightforward, plain passive integration. I just need a network port, and then it starts doing its analysis, baselining, and then I start adding logic to it, then alerts and all that. Nozomi Networks hardware and software have a very good training program, which enables me to start working on things and really go into the depth knowledge if I want to pass it.

    The depth knowledge Nozomi Networks has of the OT protocols is the feature I find most valuable day-to-day because it enables it to do the man-in-the-middle attack, or maybe if some device is not responding as it should be, it helps me in all that. This is what I use mostly in OT every day.

    What needs improvement?

    I cannot comment on how Nozomi Networks can be improved because I'm not an implementer or a researcher. However, I think that the more AI-enabled enabling happens in OT, that might help things.

    For how long have I used the solution?

    I have been using Nozomi Networks since December 2021.

    What other advice do I have?

    My advice for others looking into using Nozomi Networks is that they should do a deep dive into their own network and what they want to achieve. Then they should decide whether Nozomi Networks is the best solution for them or Clarity. If they look into what they want to do with it, then they will be able to make a better decision based on that. I would rate this product an 8 out of 10.

    Which deployment model are you using for this solution?

    Private Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Ibrahim Simsek

    Asset monitoring has become proactive and threat detection now reduces incidents quickly

    Reviewed on Jun 28, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for Nozomi Networks is asset tracking. I use Nozomi Networks day-to-day primarily for threat detection.

    For threat detection in my work, I track vulnerability based on CVE codes and easily manage the status of the required patch.

    What is most valuable?

    The best features Nozomi Networks offers include its querying capabilities.

    The querying and searching capabilities are most valuable to me, which makes my job easier when monitoring network traffic.

    Nozomi Networks has positively impacted my organization by ensuring my assets remain secure.

    Since using Nozomi Networks, it immediately identifies application patches and CVE codes, leading to fewer incidents and improved response times.

    What needs improvement?

    I do not have any suggestions for how Nozomi Networks can be improved.

    For how long have I used the solution?

    I have been using Nozomi Networks for two years.

    What do I think about the stability of the solution?

    In my experience, Nozomi Networks is stable.

    What do I think about the scalability of the solution?

    I believe Nozomi Networks' scalability may be a concern.

    How are customer service and support?

    The customer support is good.

    I would rate the customer support a 10 on a scale of 1 to 10.

    Which solution did I use previously and why did I switch?

    I have not used a different solution before Nozomi Networks; I have only used Nozomi Networks.

    What was our ROI?

    I mention fewer employees needed when discussing the return on investment.

    What's my experience with pricing, setup cost, and licensing?

    My experience with pricing, setup cost, and licensing for Nozomi Networks is that I think it is a bit expensive, but it is reliable.

    Which other solutions did I evaluate?

    Before choosing Nozomi Networks, I did not evaluate other options.

    What other advice do I have?

    I would definitely recommend Nozomi Networks for security to others looking into using it.

    I would rate this product a 10 on a scale of 1 to 10.

    reviewer2865966

    Comprehensive device visibility has improved OT and IoT security monitoring and control

    Reviewed on Jun 28, 2026
    Review provided by PeerSpot

    What is our primary use case?

    I have been involved in projects that used Nozomi Networks for Italian companies. At Advance, for example, we used it extensively, but in Italy, it is a brand that is quite expensive for many companies because the majority of the market is composed of small and medium companies, so a budget for Nozomi Networks is not very often available.

    When I have used it, I implemented it for OT and IoT environments in public administration in Rome. We conducted a trial and were followed by a Nozomi Networks technician directly here in Italy. Guardian takes all the information that it receives from the appliance that you have deployed, and after you have all the data, you can put it into your SIEM and or SOAR, even if SOAR is not a good idea to have in use in OT and IoT.

    In this particular customer, we had more or less 2,000 devices spread all over the city because they follow the traffic and also the parking and the IPTV cameras that are spread around the city in Rome. We deployed one Guardian and two remote devices that catch all the information that arrived from the devices spread all around the city. We conducted this kind of proof of concept in order to acquire and purchase Nozomi Networks instead of some other competitors.

    Another case that I have seen was a really interesting demo with my previous company. We created it using Nozomi Networks and also Rapid7 as a SIEM. We managed a really small beer production facility. We simulated a threat actor that was introduced into the farm. After we deployed Nozomi Networks, we showed the people how it works and what the main features of the product are, how it can overview all the nodes using the probes. The probes can send data to one unique central console that is named Guardian. After that, Guardian can send data, raw data to your SIEM in order to process it and have SOC services that can guarantee the complete overview of your infrastructure.

    What is most valuable?

    Nozomi Networks is the easiest to use, with the capability to build really quickly an overview of your infrastructure. You can have an inventory of all your OT and IoT devices. It is based on a really solid code instead of many other competitors that were born recently. Today, it is recognized as the milestone to follow, the GOAT in this kind of environment.

    Really often people do not know what they have put in place in their infrastructure. Especially in OT and IoT, you have to look into the complete environment in order to have a complete inventory. So, Shadow OT, which I have spoken about many times in terms of devices instead of Shadow IT in terms of applications, is a valuable feature.

    Starting from scratch, they did not have any kind of tool that takes care of OT and IoT. Starting from scratch implementing Nozomi Networks, people were really happy because they have seen for the first time all their infrastructure. They have seen for the first time the complete inventory of all devices that were spread into their network. Today they are really happy to feel safe and to be sure to have it all under the control of our SOC services.

    What needs improvement?

    Nozomi Networks can be improved in many points. First of all, reduce the cost. That is really important because many companies are not so huge and many companies cannot acquire this kind of licensing. The second improvement would be to have a much more solid and robust IT solution, something that works like a network detection and response, even if Nozomi Networks was not born for this.

    What do I think about the scalability of the solution?

    Nozomi Networks is absolutely scalable because you can introduce some other probes into your environment. You can also put some Guardians on-premise or have the SaaS solution that manages everything.

    Which solution did I use previously and why did I switch?

    I have always tried to sell Nozomi Networks instead of other competitors from Israel, for example, because I trust in this kind of technology. Although Nozomi Networks is not so up-to-date for IT infrastructure, it is used in OT and IoT environments. It is a really good brand.

    What about the implementation team?

    This kind of appliance is not so difficult to manage and not so specific. The customer is happy because today they have all things under control.

    Which other solutions did I evaluate?

    I am actually looking at another solution that is named LEX. It is another completely Italian solution and it is much cheaper than Nozomi Networks, but at this moment, it was born as a network detection and response. Now they are also working on OT/IoT protocols, CANbus, and all the other industrial protocols. For the moment, I think that if you have a really solid infrastructure and you are managing a more or less big customer, you have to choose Nozomi Networks.

    Another customer was also evaluating another Iranian solution. At this moment, I cannot remember the name, but it is really famous.

    What other advice do I have?

    Nozomi Networks works like a charm and works as expected. It is interesting to receive data from CTI and organize it in your infrastructure using the AI algorithms that can really save a lot of time for a SOC operator or SOC analyst. The capability is really good.

    Nozomi Networks is not as expensive as some other players like Darktrace, even if they do another job, but it is not so cheap either. I think that Nozomi Networks needs to have some discounts, additional discounts for some environments.

    SOC analysts are much happier because they already have good and clean data. In this way, they can reduce the mean time to acknowledge and the mean time to detect.

    Be sure that the probes are installed in the right network points. That is the most important thing I can advise.

    I would rate this product an eight out of ten.