
Nozomi Networks Vantage OT & IoT Security Solution
Comprehensive industrial monitoring has improved threat detection and asset visibility
What is our primary use case?
My main use case for Nozomi Networks is threat detection.
I mentioned briefly about the second use case, which is asset discovery, because OT people oftentimes do not know what assets they have in their networks. Nozomi Networks is quite a useful tool to create an asset inventory, at least for starters. With Smart Polling, which is an active polling method not necessarily always allowed, but if a certain company permits it, Smart Polling is quite good in enriching data about assets. The second very strong and probably the second most important use case is asset discovery. Obviously, the third one is vulnerability management if you combine everything with ServiceNow.
What is most valuable?
I think the best features Nozomi Networks offers include the number of industrial protocols that it can monitor, which is outstanding and no other tool is equally capable as Nozomi Networks. Secondly, the user interface is quite good and clear, especially for someone using it quite heavily as I do. Thirdly, Nozomi Networks has their own threat intelligence team that enriches the global vulnerable databases with their own work. This is quite important. Quite recently, they added a lot of machine learning AI features to the Vantage.
Nozomi Networks has impacted my organization positively because, keeping in mind that I am an implementer and I implement this to many other organizations. In terms of how this improved, if implemented correctly, which means that fine-tuning is also done and the number of false positives is low, then not only threat monitoring and asset discovery are there, but some organizations whose maturity is high enough are using Nozomi Networks tools, meaning Guardians and sensors, as an OT tool, not only an OT security tool. For example, they can troubleshoot the networks through capabilities that this tool offers. Sometimes it is more than an OT security tool; it is also an OT tool.
What needs improvement?
I think Nozomi Networks should still work on the graphical user interface because it can be more friendly in terms of user experience, especially regarding the flows, the workflows, the intuitiveness of certain things and positions of certain buttons or even creating a dashboard for yourself in a way easier manner. This is something that they can work on. Apart from that, I believe that continuing to incorporate AI features, which they already did, is important, especially in terms of alerts and incidents and how they can be flagged. I am not saying AI should decide whether this is an alert or false positive, but it can certainly advise or recommend something such as, "This seems like a false positive, but perhaps you should troubleshoot," or "This seems serious, so you had better watch this."
For how long have I used the solution?
I have been working in my current field for almost four years.
I have been using Nozomi Networks ever since I started my career in OT security, so also almost four years, let us say three and a half.
What do I think about the stability of the solution?
Nozomi Networks is very stable.
What do I think about the scalability of the solution?
The scalability of Nozomi Networks is super easy to scale up as long as you have a Vantage solution, meaning the private cloud connected to on-premises or on-premises Guardians connected to the private Nozomi Networks cloud. This is super easy to scale. The other type of solution, which is fully on-premises, is also scalable, but not that easy.
How are customer service and support?
The customer support from Nozomi Networks is very helpful. There are dedicated teams for clients, and the response times are quite fast. My experience so far with them is excellent.
Which solution did I use previously and why did I switch?
The majority of our clients are using either Nozomi Networks or, in some cases, Claroty, because Claroty and Nozomi Networks are the best in class, with Nozomi Networks being a little ahead. In our client environments, we sometimes encounter Armis and also sometimes Microsoft Defender for IoT, which is very subpar in terms of the features and capabilities. In some cases, companies are trying to apply more IT-oriented IDSs to their industrial environments, which is also not the best possible way of doing things. For example, Dragos.
How was the initial setup?
My experience with pricing, setup cost, and licensing is that it is pretty straightforward for Nozomi Networks. The whole license model is based on how many assets you need to protect. Previously, it was on-premises versus cloud. So there are two tiers or perhaps more tiers, but two ways of structuring the pricing, and it is quite clear and transparent. I do not think that anyone can be confused by the way they are structuring it. The one caveat is that they recently increased their prices by approximately 30 percent from July 1st, so that is something worth considering.
What about the implementation team?
We have a business relationship with Nozomi Networks as a partner. We are not reselling their offerings, but we are implementing their solutions to our client environments.
What was our ROI?
To be honest, I do not have anything specific regarding a return on investment. Our clients usually focus more on one metric that is always there: adherence to the regulations. This is quite important because some regulations are enforcing network monitoring for industrial networks, and this is what Nozomi Networks is capable of. In terms of reducing the workforce needed to do this work, it is more creating a field of OT security, and an IDS is also always or quite often the first step to create a separate OT security practice that is separated from IT security.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing is that it is pretty straightforward for Nozomi Networks. The whole license model is based on how many assets you need to protect. Previously, it was on-premises versus cloud. So there are two tiers or perhaps more tiers, but two ways of structuring the pricing, and it is quite clear and transparent. I do not think that anyone can be confused by the way they are structuring it. The one caveat is that they recently increased their prices by approximately 30 percent from July 1st, so that is something worth considering.
Which other solutions did I evaluate?
We evaluated and our clients are evaluating many different options for costs and also for the features. So apart from Nozomi Networks, we also consider Claroty, Armis, Dragos, CrowdStrike, and Microsoft Defender for IoT, and one more that I forgot.
What other advice do I have?
I find myself relying on the ability to monitor so many industrial networks, which is the most important part when it comes to my day-to-day workflow. Usually, I do not have to bother about other tools because Nozomi Networks is quite capable on layers zero to three of the Purdue Model. That is something that is usually a selling point when it comes to Nozomi Networks implementations to many different clients that we have.
I would say that the AI features and the machine learning in terms of the alerts and capability of especially lowering the number of false positives is promising, and I am expecting that this will evolve in the nearest future because this is what they are telling us and what we see in the product development on a day-to-day basis in our clients.
I think that the accuracy and reliability of output from Nozomi Networks is adequate. Every tool and every LLM has to be supervised by a human. The last step should always be taking an assessment of the results. In terms of how this is applied and to what it is applied, I do not think that the danger is too high. It is just helping you with the queries. The worst thing that can happen is that this query will show you a different type of things, such as assets or alerts, than you expected, but nothing major will happen.
The level at which AI is implemented now is not raising any red flags because it is usually an easier way to create queries, for example, inside the graphical user interface, the dashboard, or the management tool in order to show only a certain number of alerts that are very precisely described. This was not the case before. The rest of the so-called AI is the machine learning applied to the analysis of packets. So there are no real security flaws in my opinion at this point of the implementation of AI.
My advice for others looking into using Nozomi Networks is to make sure that you really understand your network topology before trying to implement. The best possible solution first is to have an asset inventory, but even if you do not have an asset inventory, you should make sure that you understand what kind of VLANs you have and how your network is segmented. That will make it easier to know how many and what type of devices you need so you do not overspend this way. I rate this product a 9 out of 10.
Improved monitoring has given us real‑time visibility and faster response on factory shop floors
What is our primary use case?
My main use case for Nozomi Networks is monitoring OT assets at Volkswagen's factories.
The specific example of how I use Nozomi Networks for monitoring OT assets is that the monitoring occurs in the factories at Volkswagen. We have the collectors acting at the switches, the access switches, and then we have a CMC collector, a VM positioned in the data center that collects the logs. With the logs and the metrics, we act by creating playbooks for addressing the alerts. That is the case for monitoring with Nozomi Networks appliances.
It has a simple interface, so it is easy to use and configure, but the network needs to be very well structured to receive the logs and capture all Nozomi Networks assets for the shop floor.
How has it helped my organization?
Nozomi Networks has positively impacted my organization by providing observability of the environment and the assets in the OT environment of the shop floor. Prior to this, we did not have observability over the legacy devices. Receiving these logs allows us to address threats occurring in real time in the environment, enabling us to fortify the network and equipment.
I can share that since implementing Nozomi Networks, we have seen an improvement in response times. Alerts coming to Nozomi Networks dashboards have led us to automate by sending alerts to email and generating weekly reports for analysts. This means the analyst reads and verifies a set of alerts and then handles the incident in a very fast and efficient manner.
What is most valuable?
The best features Nozomi Networks offers include polling for shop floor assets, alerts based on CVSS, which is a great feature, and BPF filters at Nozomi Networks interfaces that filter the traffic we do not want to see.
The CVSS-based alerts help my team by allowing us to determine if an alert is critical or a false positive based on the CVSS score. CVSS is a market standard for classifying vulnerabilities, so it is great that we have alerts based on it.
What needs improvement?
I think Nozomi Networks can be improved by enhancing the size of the boxes and the performance for collecting logs, and of course, the price. The most efficient way to implement Nozomi Networks is by positioning small boxes at the access switches, which enables them to capture more details, such as MAC addresses and all the packets transmitting across the network. When there are few boxes positioned above the network, the data and packets can be broken, limiting our ability to capture packets, which is not an issue with the switches but rather a capacity limitation for Nozomi box. Improving the ability to capture packets with smaller boxes would be great.
Regarding Nozomi Networks's AI capabilities, I think its governance and security are currently lacking as we do not have AI capabilities at Nozomi at this moment. However, I believe AI analysis, particularly regarding the high volume of logs, would help analysts make decisions and classify alerts more effectively. AI is a very good trend in the market, and I think Nozomi Networks should incorporate this feature soon.
I believe that AI capabilities help improve the accuracy and reliability of the alerts and the classification for the assets. This feature enhances efficient reporting, and I think it would not introduce any negative aspects to the analysis. Having AI analyze and foster accuracy with Nozomi Networks collectors would be great.
For how long have I used the solution?
I have been using Nozomi Networks for about two years.
How are customer service and support?
The customer support is very great. The few times I had to open tickets for customer support, I was attended to very quickly and efficiently by good professionals and specialists.
Which solution did I use previously and why did I switch?
I did not previously use a different solution before Nozomi Networks.
Which other solutions did I evaluate?
Before choosing Nozomi Networks, we evaluated the Claroty solution.
What other advice do I have?
Nozomi Networks's scalability is enhanced by the strategy I mentioned; the best way to implement Nozomi Networks boxes is to distribute small Nozomi Networks boxes across the access switches and network, which allows us to capture more details about the packets being transmitted between the assets. The main feature to scale this is to implement more boxes that have the performance necessary to capture and send logs to the CMC, the centralized Nozomi Networks.
My advice to others looking into using Nozomi Networks would be to place more small boxes at the access switches, especially if their company has a larger network. More boxes positioned near the shop floor assets allow for greater detail capture about packets and richer information regarding threats.
I am giving this review a rating of nine because it is a great tool, and although it has some areas for improvement, nine is a very high score.
I think Nozomi Networks is a good tool, and we will continue using it.
Unified teams have gained real-time visibility into IoT leaks and now plan maintenance proactively
What is our primary use case?
Nozomi Networks serves a critical function for water systems here in South Africa. For example, a government utility called Rand Water uses IoT sensors to detect leaks on water supply systems. However, two divisions in their IT department had been operating in silos: the networking side and the IoT side. The IoT side lacked comprehensive security measures and only ran a firewall, which is not true IoT security. Their approach was reactive rather than proactive when solving problems. Nozomi Networks came into the picture and provided them with visualization of their IoT network, which they had never had before.
This solution helped them become aware of where everything is located, where all the sensors are, how they are interconnected, which ones are working properly, and which ones are not. Initially, they had to log into each device individually just to find out if it was still working or if it had detected any issues. They were not proactive at all; they were reactive when it came to managing their infrastructure.
What is most valuable?
The best features Nozomi Networks offers include the ability to drill into every IoT device and get detailed information on make, model, performance, and what type of errors the sensor has picked up. This provides useful information on the entire IoT network versus individual sensors scattered throughout the network that they had to manually check to try and find problems. Now they receive real-time alerts on any issues.
Getting real-time alerts and detailed information impacts my team and clients because they can respond quickly and are more organized now. They are no longer chasing their tails. Now they can plan properly for the day and plan ahead on what needs to be resolved. This made them aware of where everything is, where all the sensors are, and how they are interconnected, which ones are working properly, and which ones are not.
Initially, they could not do any reporting or planning because they did not have real-time data. Now they do. Now they can do all those things because they have gained visibility and information on their inventory. They are also able to do capacity planning, which is something they could not do before.
What needs improvement?
Nozomi Networks can be improved by integrating with other technologies so that teams look at a single dashboard when it comes to security issues. Instead of looking at two different dashboards, integration would create a single dashboard that shows where the IoT meets the network. This way, if they need to isolate any threats, those threats can be isolated on the networking side as well.
I would give Nozomi Networks an eight because there is still room for improvement. The key issues involve reporting that needs to be integrated with networking reporting, and real-time alerts that need to be integrated into a single dashboard with other technologies. Integration is the most important part for future development.
For how long have I used the solution?
I have been using Nozomi Networks since five years ago, around 2021.
What do I think about the stability of the solution?
Nozomi Networks is very stable.
What do I think about the scalability of the solution?
Nozomi Networks's scalability is very impressive. I can support a huge number of IoT devices. One of the key benefits is that we do not have to use multiple tools. Nozomi Networks covers the entire infrastructure when it comes to IoT.
How are customer service and support?
Customer support in terms of sales and technical assistance is very good.
Which solution did I use previously and why did I switch?
Previously, there was no solution. That is why they relied on the network and network security to protect IoT, which was not really ideal.
How was the initial setup?
Deployment is quick and very easy to hand over to the customer team because it is not complicated. It works from day one.
What about the implementation team?
Our relationship with this vendor is structured as a reseller relationship.
What was our ROI?
I would say the ROI is significant in terms of time saved and resources. The IT team and the IoT team managed to combine into a single team that can handle both IoT and networking troubleshooting because of the information they receive from Nozomi Networks.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing has been very seamless. The Nozomi Networks team was very helpful throughout the process.
Which other solutions did I evaluate?
We looked at various other technologies that were primarily open source, but nothing was examined in terms of doing a proof of concept with those technologies. We primarily focused on what information we could get from our chosen tool and what other functionality it provides.
What other advice do I have?
The features are great and very easy to use. The ability to navigate the platform and get useful information and reporting is much easier now. Before, it was a manual exercise where they had to try to put everything into spreadsheets and create diagrams manually to report.
Nozomi Networks has impacted our organization positively as we have gained trust from customers in terms of the technology results and everything that the technology brings. We presented and managed to demonstrate the value for money.
Solving incidents has improved drastically. The team is now able to plan properly. They do not spend over budget or under budget because they know exactly what needs to be resolved due to the information and visibility they have. The IoT team and the network team managed to integrate into a single team because they no longer operate as silos but as a single team that can resolve both IoT and networking security issues together.
The security of Nozomi Networks is great. The governance complies with government security laws.
Nozomi Networks is a very good tool, which is why we recommend it before any other product. I would give this product a rating of eight out of ten.
Comprehensive monitoring has strengthened fragile OT networks and improved threat detection
What is our primary use case?
My main use case for Nozomi Networks is as an IDS, so we are selling our cybersecurity services and SOC that is primarily based on Nozomi Networks portfolio. We place them at the user's location and send the logs to the SOC, and then we do the triage, escalations, and related tasks.
In my day-to-day work, I use Nozomi Networks for monitoring and cybersecurity. Since OT networks are very fragile, you cannot install regular SIEM agents. You have to do passive network traffic analysis instead.
How has it helped my organization?
Nozomi Networks has impacted my organization positively because we have experience with a few other vendors, and their configuration, reliability, and even threat identification are significantly lower than Nozomi Networks capabilities.
I can tell you about specific outcomes I've seen with Nozomi Networks. For example, it definitely improved visibility because most of the clients don't know what they have in their networks. That is the first benefit. The second benefit is the fact that even though you make site visits, site surveys, and acquire asset information, there are still some remote devices that you cannot see or the customer doesn't know about. You only discover them in Nozomi Networks. The alerting options are also definitely a benefit because even though there are false positives and a required learning time, we haven't had any real incidents, but the mere fact that you are alerted for strange or unusual behaviors in the network is more than enough for us. As far as the client goes, they are also happy because we noticed the addition of new nodes to their network. They are always surprised when we alert them to these discoveries.
What is most valuable?
The best features Nozomi Networks offers include reliability and ease of implementation because the platform is excellently made. Many other competitors use Docker instances. The configuration of the devices itself is straightforward. The documentation could be better, but overall, it is a great platform and we are satisfied with it.
What makes the implementation process of Nozomi Networks stand out for me is that you only need to place network parameters such as IP address. You can use DHCP for acquiring those. There is no extra configuration step regarding SPAN ports. You just need to make mirror ports on the switches that you want to sniff traffic from, and the connectivity to either central management or Vantage is almost 100 percent.
What needs improvement?
Regarding improvements for Nozomi Networks, it is hard to provide recommendations because they are already among the best vendors in the market. They are a Swiss firm that was acquired by Mitsubishi. They have grown their portfolio from an NIDS over VMs to even embedded solutions that you can put on switches, routers, or PLCs themselves. I do not see much room for improvement beyond what they currently offer. They also have wireless solutions. In the few years after I started working with them, they introduced Arcs, which are host-based sensors similar to SIEM agents. I believe they have covered everything.
I would add that the documentation is lacking some information, so you need to ask customer support for it, but you cannot have everything. Their customer support is excellent. They are answering tickets in an hour or two, with a maximum of a day.
For how long have I used the solution?
I have been working in OT cybersecurity for four years.
What do I think about the stability of the solution?
Nozomi Networks is stable in my experience.
What do I think about the scalability of the solution?
The scalability of Nozomi Networks is excellent. They have many different options so you can choose the one based on requirements and tailor it to the needs of the customer. We are primarily using Guardian, which I believe is the 100 series. It is more than enough for most of our clients. We also use Remote Collectors in some places and Arc sensors. We also have one Guardian Air which is currently unused because the customer doesn't know their OT networks and since it is gathering all the Wi-Fi, there are a lot of noise from IT, so we turned that off.
How are customer service and support?
Customer support is excellent. They give concise answers in a short time, around one or two hours. We have never waited more than a day for customer support.
Which solution did I use previously and why did I switch?
We have started with Nozomi Networks and we are still using it. I doubt that we will stop using it in the near future because of its reliability.
What about the implementation team?
We contacted Nozomi Networks directly. We are a big company and we are not using smaller distributors.
What's my experience with pricing, setup cost, and licensing?
I am not familiar with the pricing, setup cost, and licensing since I am in an engineering department. I just received the device and went to the customer location. I am not involved in billing and administrative matters.
Which other solutions did I evaluate?
Before choosing Nozomi Networks, I believe that Dragos was one of the options, but since we started using Nozomi Networks during the Corona pandemic and customs and tax import output were favored on the side of Nozomi Networks, we proceeded with that solution.
What other advice do I have?
Regarding Nozomi Networks AI capabilities, IQ is a nice add-on feature because it can give you guidance and direction without reading the documentation because it works for you. It can also give you many ideas regarding playbook creation, alert triage, query generation, and assertions. I believe it is pretty useful, but it is entirely dedicated to Nozomi Networks. It doesn't know anything beyond that.
Regarding Nozomi Networks accuracy and reliability of output, I would rate it about 70-30 because every once in a while I catch it in some inaccuracies, and then when I ask it again, it corrects itself. I believe it is a good starting place and as with any AI, you need to know about the subject matter that you are asking about. You cannot entirely rely on it blindly.
My advice to others looking into using Nozomi Networks is that they should definitely start by making a proof of concept. The people responsible for Nozomi Networks should at least have their Nozomi certified engineer and troubleshooting certification, and the people working with the security side should have their security analyst certifications. I would rate this product a 10 out of 10.
Gained deep OT network visibility and now seek stronger integrations and localized reporting
What is our primary use case?
My main use case for Nozomi Networks is to find possible vulnerabilities and threats and create a network map in operational technology networks (OT networks). I mainly accomplish this by showing customers the OT network map along with the possible threats and vulnerabilities within these networks.
For example, in an industrial company in Peru, a customer tried to find some vulnerabilities in the OT networks. They connected the Nozomi Networks appliance to the OT network to display a map of the devices within the network and highlight the possible vulnerabilities present.
In end customer use cases, the main use remains the same, but another use has been to try to integrate this solution with security devices, such as firewalls, to generate policies that either block or allow certain traffic, whether it is allowed traffic or potentially threatening traffic.
How has it helped my organization?
Nozomi Networks has positively impacted our organization as we can visualize the traffic within the OT networks and identify the potential threats or vulnerabilities. We can generate reports for analyzing possible countermeasures and determine what improvements are needed in the future to protect the traffic and the company from such vulnerabilities.
Concrete outcomes include generating reports on the types of traffic in the OT networks, improving our decision-making regarding security incident countermeasures, and reducing response times to incidents in the OT network because, prior to Nozomi Networks, we did not have another viable solution.
What is most valuable?
The best features Nozomi Networks offers include the capability to show the network map while operating in remote or sniffer mode, which is a good feature. Another feature is its ability to display vulnerabilities in OT networks, as very few solutions in the market can accurately operate within these networks to reveal potential vulnerabilities and threats. Additionally, it allows for integration with additional security devices and provides reports about this feature.
What needs improvement?
Integrating with other security devices is a little difficult because this process is not currently automated. I potentially need future integrations via APIs; however, at the moment there is limited integration with firewalls, such as Fortinet, but they require more development to properly integrate and generate policies in the correct order based on specific traffic, destinations, and services. Overall, while this could be a challenging integration with other security devices, it is a significant advancement compared to alternatives, but it does need further development in the future.
Improvements for Nozomi Networks should focus on integrating with other security devices. Since Nozomi Networks operates in OT networks, I need to connect this solution with others such as SIEM, XDR, and firewalls. Additionally, the reporting system currently displays in English, but I need to enhance these reports to be in native Spanish, not merely translated, and aim for those reports to be aligned with ISO, NIST, or other frameworks to generate a greater impact within the company.
I would also like to highlight the need for better support because when we attempt to deploy this solution with partners, the solution remains within the company but requires ongoing support for its deployment across OT networks.
For how long have I used the solution?
I have been using Nozomi Networks for demos and proof of concepts to review the technology and the solution, and how this solution could provide insights into threats and vulnerabilities in the network. I have been engaging in tests with end customers for around six months to one year.
What do I think about the stability of the solution?
At the moment I believe the features are acceptable.
What do I think about the scalability of the solution?
Nozomi Networks can handle growth in my organization easily. In the on-premise solution, there are various options to scale, such as considering hybrid or public cloud models, but at the moment, the company is not evaluating scaling.
How are customer service and support?
I have had one experience with customer support at Nozomi Networks, and it was great.
Which solution did I use previously and why did I switch?
I have not used a different solution before Nozomi Networks. This is my first experience with such a solution.
Which other solutions did I evaluate?
I evaluated other options before choosing Nozomi Networks, including options to create similar functions with firewalls using OT signatures and Nessus software. However, the final decision was to select Nozomi Networks.
What other advice do I have?
My advice for others looking to use Nozomi Networks is that if you are searching for a solution that provides network visibility, AI capabilities, and easy integration and deployment, then Nozomi Networks is a viable option. I would rate this product a seven out of ten.
Network visibility has improved and monitoring of iot devices and vulnerabilities is stronger
What is our primary use case?
My main use case for Nozomi Networks is to detect devices in the environment, especially IoT devices, or any kind of devices that connect to the network, and we need to detect them. We normally check through our console for any kind of device. For example, if a user tries to connect any device to the network or any unrecognized device is available, we monitor it. Beyond that, we check vulnerabilities of our IoT devices, mainly. We monitor any kind of abnormal traffic or any kind of abnormality on those devices, and we get a report if we want to do any patching for devices.
What is most valuable?
The best features Nozomi Networks offers are device detection and vulnerability checking, including CVEs, and reports. In my scenario, for some of the devices, we cannot always know the location or whether we have missed any vulnerabilities. There is a large-scale variety of devices, so we cannot go through each device one-by-one and check if any CVEs were detected recently or are up to date. In that case, Nozomi Networks portal is good for us. For now, we use it for device detection and vulnerabilities only, and I am satisfied with the current functionality.
Nozomi Networks has impacted my organization positively because our technical staff changes. In those cases, we sometimes do not know about certain devices. For example, it can be difficult with some devices, and they operate in unknown locations, such as webcams or IoT devices located in different areas. In that case, we can get an idea about what devices are in our network and any abnormal traffic or any kind of abnormality on our network. Nozomi Networks could be a positive impact for the organization because if any staff, such as a network engineer or other technical engineers, changes, the next new engineer can still move forward with this portal.
Nozomi Networks has led to specific outcomes or measurable improvements for my team, including faster response times. We can say there is a faster response time because, for example, if any kind of IoT device failure occurs, we can detect it from here. Also, we can identify any kind of vulnerability impact or any incidents that happen on those devices because of vulnerabilities. We can do incident investigation through this portal as well, so it is good for the company's security posture.
What needs improvement?
I feel Nozomi Networks can be improved by integrating SIEM features on this portal. If we integrate both features, such as SIEM on top of Nozomi Networks, then the analysis part would be much easier for the users, and we can improve the company's security posture. In that case, sometimes we could avoid using so many tools, such as Nozomi Networks for device detection and a SIEM for different checks. If we use one tool for all of them, that would be beneficial for the company. I did not feel any kind of issue up to now, and I am not sure about the future.
For how long have I used the solution?
I have been using Nozomi Networks for around one year.
What do I think about the scalability of the solution?
I have not felt anything about Nozomi Networks' scalability in this scenario since it is already deployed.
How are customer service and support?
The customer support was good as one time I contacted support, and I got a good reply from them. It was quite an effective response at that time.
Which solution did I use previously and why did I switch?
I do not have any idea about a different solution used before Nozomi Networks. When I joined this company, it was already deployed.
What other advice do I have?
My advice to others looking into using Nozomi Networks is that if any organization has large-scale OT devices or does not have a clear picture of their network diagrams or has a messy network, it is better to deploy a tool such as Nozomi Networks to keep track of the devices. Then the security posture can be improved with this portal. It is better to deploy this product. Even if a company changes their technical staff, the other team members can function well with this tool. I would rate this product an eight out of ten.
Improved OT visibility has protected geothermal operations and now secures critical power assets
What is our primary use case?
For the utility company named KenGen, Nozomi Networks is used for their OT security. They monitor their power infrastructure within the power stations located in Olkaria. We are currently connected to about four different power stations and all interconnected to the head office within the same area.
Right now they use it to monitor all their IoT and OT networks within the power grid. For example, they have most of their IoT sensors which are used to monitor the geothermal power plant where they have steam wells which have been dug in different areas and they use IoT connectivity which is connected via 4G network and LTE. Before Nozomi Networks, they had no visibility of all these remote sites. With Nozomi Networks, they have been able to monitor and see every single packet that passes through all these IoT networks and it is all consolidated at the head office and now they have full visibility of these wells, which had been a challenge for quite some time. This particular use case has benefited them greatly.
For now, we are in discussions with the only oil and gas company in Kenya. They deliver oil and petroleum products all the way from the Mombasa port into Kenya, all the way to Uganda, which is a neighboring country and beyond. They are seeing the value of also monitoring and securing their SCADA networks which is also one of the use cases that Nozomi Networks shines a lot in delivering value for all the other oil and gas companies they have worked with. From my perspective, that could be a great next use case that we are really pursuing and hoping to bring extensive value into their organization.
What is most valuable?
The best features for Nozomi Networks include the fact that Nozomi Networks is able to offer more visibility on particular protocols that using current IT-focused security solutions, they are not able to monitor. The fact that it is able to integrate the IT and OT side of customer networks brings a lot of value to them and that is one feature I would say is the best currently within this particular market.
The one thing that we noticed with the current customer who is using the solution is that once we initially took them through the first training, they actually appreciated it very much and we did not need to keep redoing it, which shows the ease of use for the technical team as well as the way they are able to break down the reports. It is very easy to do various custom reports for the management, senior management, for the engineer levels, and for those who are actually on the ground. All this is done from a single pane of glass. It is not necessary to keep on initiating and drafting new reports. You are able to easily export and specify this is for the managerial level, they get a custom type of report. For those who are below, they are able to get different types of reports. The engineers get now more technical details about what is going on in the network.
Since we deployed the solution almost over three years back, it has to be three years by next year. The organization has gained greatly from the particular solution that we deployed. They have mitigated quite a number of attacks and incidents and ever since we started running the solution, there have not been any OT-based security breaches. The training has helped to avoid any in-house concerns that would be resulting from internal users making mistakes. The solution has been really well absorbed and utilized well to secure their infrastructure.
What needs improvement?
Customer support is something I think there is a slight challenge on responses on email. But on escalating with the team in Dubai, then we get things solved. If the support could be improved on that, that would be a good thing.
The pricing was quite high based on the end customer's perspective. They negotiated, but they would have preferred a cheaper option. Though Nozomi Networks offered all the features that they needed and they had to invest in that. So also the partners had to reduce our margins, which was quite painful for us, but we still delivered the solution. If something can be done on pricing, that can be quite good, especially for the African region.
For how long have I used the solution?
I have used Nozomi Networks for almost five years.
Which solution did I use previously and why did I switch?
We were not using any other solutions. Nozomi Networks was the first OT security solution. The customers had considered Darktrace, but they did not want any cloud offering. So we had to pitch Nozomi Networks for their on-premises offering.
How was the initial setup?
Running a proof of concept is always the best way to go, to enable us to clearly see the depth of the particular scope of the deployment. This way now we are able to understand how many Guardians are needed, how many remote collectors are needed, and what type of connectivity will be used and gives us more insight on the IP allocation and the likes. That would be a good place to start from my perspective.
What was our ROI?
Definitely there are fewer employees needed, so there is savings on that. Now that monitoring is real-time and more dispatched, the actions are such that notifications come in promptly and the engineering team is able to act on any issue that comes up faster. There is a lot of time saved in terms of incident response and also the reduced number of incidents. The efficiency of the organization, the fewer employees needed, and the time saved has greatly offered the customer a decent return on investment on this particular solution.
Which other solutions did I evaluate?
Darktrace was the only other contender which was considered. We only reviewed Darktrace and Nozomi Networks, and Nozomi Networks came out the winner in this particular case.
What other advice do I have?
In terms of response time, it has greatly improved because they have notifications and emails which are always sent when there is any incident that has happened. The notifications are very prompt and very specific to particular staff and personnel who are able to approach and solve and deal with a particular issue immediately. The response time has increased by about 70% based on how it was. Before, it was a very manual way of doing it and until there is a breakdown or something has happened and sending an engineer to the ground, that part has been eliminated. The notifications are quite direct and straight. This has really improved their delivery. In terms of incidents, before, they were not even monitored, but now incidents have actually, in the plant, there is no security incident that has come up that has caused the plant to be maybe out of commission or any part of the network which is negatively affected. For the entire time Nozomi Networks has been running within the network, incidents have reduced by almost 50-60%.
Nozomi Networks has really offered a stellar performance within the organization and there is not any specific part that needs improvement for now.
The AI aspect is quite secure for now, so long as the AI is not connected to the internet, there is a lot of security because most of these customers, even in the country, these are utility, government, national infrastructure organizations. The security and connectivity out, just being on-premises and all the models are running within the network really helps to offer that additional security. In terms of the governance side, we just need more education to be done to the end customers just to make sure they align to the governance of the organization when it comes to AI.
The accuracy of Nozomi Networks is quite standard. It is quite good. The accuracy is above 90%. I have not experienced any breakdowns or issues, so the reliability is quite good. The output is quite specific for the end customer, which is quite beneficial and I commend Nozomi Networks for delivering that.
The scalability is quite easy. The remote collectors can be deployed across regions and also there is the vantage offering which offers for organizations distributed across different geographical regions. The scalability is quite easy and straightforward to achieve.
So far, we may need a bit more marketing within the market, because I think of the price of the solution, we have a very limited range of customers to offer the solution to due to the cost implication. If there is an option which is a cheaper option for Nozomi Networks that could come up with to offer the enterprise market within Kenya and the East African region, that would be a better way now of getting the solution into enterprise-level organizations like the banks and maybe hospitals and the like. I would rate this review overall as a 9.
OT visibility has transformed asset discovery and now guides targeted vulnerability reduction
What is our primary use case?
My main use case for Nozomi Networks involves asset discovery and vulnerability management in OT environments.
For asset discovery and vulnerability management in my OT environments, I started using the passive mode and configured a SPAN port on a switch in the particular VLANs that I wanted to see. Then I collected that data, fed it to Nozomi Networks Guardian, and then figured out how to use active and Arc embedded to also see more assets in the field, including the Arc sensor.
In terms of my main use case and how I use Nozomi Networks day-to-day, I see many things that I do not expect. What is very handy within Nozomi Networks is that I can see the communication between the assets, clearly identifying what ports they are communicating on and what protocols they are using. It is really very insightful.
What is most valuable?
The best features Nozomi Networks offers, in my experience, are how quick it is to set up and how fast it can discover assets in the network.
The quick setup and fast asset discovery help me in my work by allowing me to see how OT assets are communicating, what versions I have on certain assets, and what vulnerabilities are present. With this information, I can figure out how to segment the network, enforcing firewalls between the VLANs based on the communication patterns I have identified.
Nozomi Networks has positively impacted my organization by allowing me to build a roadmap based on what I see, ultimately leading to a better security posture, which includes knowing what is inside the network and what vulnerabilities exist. Additionally, by making use of Vantage, I can query my asset database, which is very handy to discover what I should address first and how I can speed up the security posture of my OT networks.
What needs improvement?
To improve Nozomi Networks, I believe that it is less useful without Vantage if I have a multi-site setup. I really need Nozomi Networks Vantage and Vantage IQ to make the most of it. Additionally, the Arc sensor as well as the active polling features are subscription-based, whereas competitors often offer a one-size-fits-all subscription allowing immediate access to all features. With Nozomi Networks, it is often an add-on, which is sometimes a disadvantage when competing.
Regarding needed improvements, particularly around licensing and pricing, the add-on nature of the licensing could be improved. Vantage is rather expensive in comparison to the competition, and while the features are great, the licensing structure could be enhanced.
Concerning Nozomi Networks' AI capabilities, I think its governance and security are good, but it also requires a paying add-on, so while it looks great based on my experience, the need for payment is a disadvantage.
There's also room for improving on # of integrations.
For how long have I used the solution?
I have been using Nozomi Networks for about two years.
What do I think about the stability of the solution?
In my experience, Nozomi Networks is stable.
What do I think about the scalability of the solution?
Nozomi Networks is scalable if I purchase the Vantage part.
How are customer service and support?
The customer support for Nozomi Networks is great, demonstrating good response times and providing the right solutions. It is easy to work together with them.
Which solution did I use previously and why did I switch?
Previously, I used Claroty but switched to Nozomi Networks because I could perform asset inventory and vulnerability scanning in my setup.
How was the initial setup?
My experience with pricing, setup cost, and licensing is overall positive; it is a really straightforward process, not too difficult to set up, with great training material provided. The downside is that I also need to pay for some features, but overall, NNCE is a great course.
What was our ROI?
In terms of specific outcomes or metrics showing how Nozomi Networks improved my security posture and sped up my processes, I have saved time, and I have also gotten compliance reports regarding compliance with IEC 62443, which is very handy in terms of the assets I see.
Since I started seeing what is inside the network, I transitioned from just guessing what was there to having a clear view. This clarity makes me better prepared for setting up and segmenting the environment as well as managing how communication flows to keep things up and running.
Which other solutions did I evaluate?
Before choosing Nozomi Networks, I evaluated options including Claroty, Nozomi Networks, and Armis.
What other advice do I have?
I would rate the customer support an eight on a scale of one to ten.
My advice for others looking into using Nozomi Networks is to start with a small setup and then expand. You can trust that the active polling operates effectively.
I would rate Nozomi Networks an eight out of ten because it is a great product, but it is missing some features, such as secure remote access, so that is why I cannot give a maximum score.
Regarding Nozomi Networks' AI capabilities, I find its accuracy and reliability of output to be rather reliable; I have not discovered big inaccuracies or issues, so that is acceptable.
My overall review rating for Nozomi Networks is eight out of ten.
Improved OT visibility has transformed monitoring and empowers precise threat hunting
What is our primary use case?
For visibility into my OT network, I usually find that if the OT network is not built on a Purdue model or layered approach as segmentation or conduits, whatever you want to use with it, IEC 62443 says conduits, then you don't know which traffic is talking to what, and the security model for OT is not well established. I put in a Nozomi Networks device, start building, and gather the asset inventory. It has special pages that show the communication between cross-layers and all that, and I start segmentation. It helps me with segmentation, shows me what is happening in my network, which device is communicating what, and then I can use that to do threat hunting in the OT network.
How has it helped my organization?
Regarding a specific example or a measurable outcome, I can say that SCADA is already there, and the teams are monitoring what is happening in OT. However, the way Nozomi Networks generates alerts is really helpful. For example, we give them a range of a variable, for example the temperature should not go below a certain degree. In a SCADA network, you always have those alarms, the lights, they pop up, but the alerts that Nozomi Networks gives me are much more valuable than those which I see in there.
What is most valuable?
The depth knowledge Nozomi Networks has of the OT protocols is the feature I find most valuable day-to-day because it enables it to do the man-in-the-middle attack, or maybe if some device is not responding as it should be, it helps me in all that. This is what I use mostly in OT every day.
What needs improvement?
For how long have I used the solution?
What other advice do I have?
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Asset monitoring has become proactive and threat detection now reduces incidents quickly
What is our primary use case?
My main use case for Nozomi Networks is asset tracking. I use Nozomi Networks day-to-day primarily for threat detection.
For threat detection in my work, I track vulnerability based on CVE codes and easily manage the status of the required patch.
What is most valuable?
The best features Nozomi Networks offers include its querying capabilities.
The querying and searching capabilities are most valuable to me, which makes my job easier when monitoring network traffic.
Nozomi Networks has positively impacted my organization by ensuring my assets remain secure.
Since using Nozomi Networks, it immediately identifies application patches and CVE codes, leading to fewer incidents and improved response times.
What needs improvement?
I do not have any suggestions for how Nozomi Networks can be improved.
For how long have I used the solution?
I have been using Nozomi Networks for two years.
What do I think about the stability of the solution?
In my experience, Nozomi Networks is stable.
What do I think about the scalability of the solution?
I believe Nozomi Networks' scalability may be a concern.
How are customer service and support?
The customer support is good.
I would rate the customer support a 10 on a scale of 1 to 10.
Which solution did I use previously and why did I switch?
I have not used a different solution before Nozomi Networks; I have only used Nozomi Networks.
What was our ROI?
I mention fewer employees needed when discussing the return on investment.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing for Nozomi Networks is that I think it is a bit expensive, but it is reliable.
Which other solutions did I evaluate?
Before choosing Nozomi Networks, I did not evaluate other options.
What other advice do I have?
I would definitely recommend Nozomi Networks for security to others looking into using it.
I would rate this product a 10 on a scale of 1 to 10.