Seemplicity Exposure Management & Response
Single view has transformed client operations and builds trusted, collaborative partnerships
What is our primary use case?
My main use case for Seemplicity is that it offers a single pane of glass or SPoG, and I use them as a trusted supplier to provide it to my clients. Not only can we make use of the features and the quality of the product, they white-label it in order for me to present it to my clients and give them a unique Resilient experience.
A quick specific example of how I have used Seemplicity in this way for one of my clients is that we meet with clients who have a certain level of complexity being corporates where multiple data sources are used in order to run their operations. These data sources are not all in the same location, being a physical building, but they can be distributed across different countries. SPoG allows us to centralize all these different data sources on one single dashboard. That dashboard is not just a passive overview of the data sources; it actually helps to rank the different types of information, create a ticketing system, and have an urgency ranking system, and therefore allows our clients to be on top of everything operational that is happening in order to find solutions and keep operations running smoothly.
Regarding my main use case or how my clients benefit from it, clients learn more about their own operations when working with Seemplicity. The value that Seemplicity gives is not just to give us access to the product, but actually we can use and leverage their knowledge and their product experts, developers, and commercial and marketing managers join us when engaging with the clients in order to share deeper levels of knowledge and information about the tools, the features, and the benefits. We take the clients on a journey that actually helps them to learn more about their own operations and how they can discover ways to improve the day-to-day challenges that they have.
What is most valuable?
The best features that Seemplicity offers, from a tool perspective, are clarity, simplicity, and the capability of ranking information according to the urgency level that the client sets up. It adopts very quickly new types of challenges that the industry presents, such as the Mithos situation and the code review that they were able to do. A lot of these types of elements surprise clients and allow us to be one step ahead of the competition.
To tell you more about how the clarity and urgency ranking have impacted my clients, in an operational environment, there are also emotions. People react in relation to something as an overwhelming event. The capability of ranking, listing, and prioritizing based on data and fact changes perspective on something that might have been emotionally draining or demanding. Clients are able today to look into a specific environment, look into the ranking of urgency, apply the remediation that is required, clean the cluttering available in that area, and then focus on the next emergency without having to look back if something was forgotten. That level of simplicity, clarity, and transparency creates a better sense of control and professionalism when actually deploying or reporting about operational performances.
One of the key features is actually not directly related to the software but is actually the people that develop the software. Thanks to Seemplicity management, we access the people that are behind all the level of information required to not only use the tool but to explain the feature and then present them to the client in a form and shape that the client recognizes. Once this is implemented, it makes a massive difference for the client to feel comfortable about using the tool.
When I present my organization to a client, the culture of the company, the vision of the company, and our engagement to what the client is looking for, suddenly bringing a third party into the equation, I never know how the third party will be able to integrate into the previous picture. Seemplicity embraces our culture and commitment to the clients. When we go to clients together, there is never a question of what they will say or how they will be accepted. They become part of the Resilient team, and therefore, when presenting to the client, there are not two companies around the table; there is one—Resilient—making Resilient stronger when meeting with clients about solutions such as Seemplicity.
As for specific outcomes or metrics that show how Seemplicity has made our organization stronger or more effective, all of the above applies. Clients became very satisfied, not only by the fact that they were in control, but they were actually surprised about a number of activities that were duplicated across different environments. With Seemplicity, that duplication was immediately spotted, actions were taken to remove the duplication, and therefore the client was able to limit the amount of cluttering in front of them and start addressing the real challenges behind the whole thing.
What needs improvement?
In terms of how Seemplicity can be improved, the next step for Seemplicity is the complete adoption of AI. They are already very busy with it, and it is quite impressive what they are doing. Integrated into the value proposition that we are providing, that is something we are working on. The next generation will involve horizontal integration of more services, the capability of responding to challenges such as the Mithos challenge, and not just for Mithos itself, but all the siblings in the LLM world that are coming. Speed is going to be fundamental. Today we are challenged by LLMs; tomorrow there will be quantum computing. I know how Seemplicity is invested in looking into R&D and the next steps or the next generation of the tool, so I am really looking forward to it.
Regarding additional needed improvements, all of the above have already been addressed by Seemplicity, and naturally, there will be an integration or an evolution into a more language-based rather than text-based approach. So far, every time we look into a potential need for improvement, Seemplicity is one step ahead. I am more than happy about how its CEO, Yoran, has set up the culture of his company to not sit and wait, but to constantly challenge people to prepare for the next steps and anticipate needs.
I am very happy about the approach to development, R&D, and the overall direction of Seemplicity.
For how long have I used the solution?
I have been using Seemplicity for two years.
What do I think about the stability of the solution?
Seemplicity is 100 percent stable.
What do I think about the scalability of the solution?
Seemplicity's scalability is maximum flexibility; every time I presented a business case, the question was not why but how fast.
How are customer service and support?
Every time I ring or drop an email, there is immediately someone picking up or getting us an answer. I rate the customer support a 10 on a scale of 1 to 10.
Which solution did I use previously and why did I switch?
Seemplicity was the first time I used a solution of this kind.
How was the initial setup?
Seemplicity has been very smart regarding pricing, setup cost, and licensing. They did not come to us with a take-it-or-leave-it price; they sat down with us, we presented our business case, and we discussed our physical presence and needs in specific geographies. They opened a conversation about how to help us build and grow the market, and now we are looking into the next generation of how to expand. From a pricing perspective, they have shown maximum flexibility.
What about the implementation team?
We use AWS as our cloud provider. I did not purchase Seemplicity through the AWS Marketplace; instead, we have direct access to the CEO, his management team, and his engineering team.
What was our ROI?
Concerning return on investment, I cannot share specific details due to confidentiality agreements I have, but I can say that the major impact was on increasing our footprint within a strategic client, having the capability to present solutions within a certain price range, and therefore allowing us to compete against competitors.
What's my experience with pricing, setup cost, and licensing?
Seemplicity has been very smart regarding pricing, setup cost, and licensing. They did not come to us with a take-it-or-leave-it price; they sat down with us, we presented our business case, and we discussed our physical presence and needs in specific geographies. They opened a conversation about how to help us build and grow the market, and now we are looking into the next generation of how to expand. From a pricing perspective, they have shown maximum flexibility.
Which other solutions did I evaluate?
Before choosing Seemplicity, I did not evaluate other options; in fact, Seemplicity happened to be the one that was love at first sight. It really clicked from a cultural, business understanding, product, and ambitions of growth perspective. I started together very quickly and deployed.
What other advice do I have?
The advice I would give to others looking into using Seemplicity is to be very open and very transparent because every time you present a clear business case, they will put heart and soul into trying to give you the best answer, and you will receive a lot of flexibility in options whenever you are not sure about how to proceed. They have a lot of experience in a number of industries and geographies that I can leverage from, and that always helps me to make the right decision at the right time.
Regarding Seemplicity's AI capabilities, I am quite impressed by the way that CEO Yoran has set up his organization to adopt AI, put the right checks and balances in place, and the governance that is using internal and external supervision and involves us as one of their trusted partners whenever questions or suggestions need to be put on the table.
In terms of Seemplicity's AI capabilities, I have found its accuracy and reliability of output to be top of the ranks. Everything that they said they were going to do has happened. Every time we had a question, there was an answer, so I am quite impressed by their current position.
Seemplicity is deployed in my organization through a public cloud and on-premise because of the profile of our clients. I think of Seemplicity as a fantastic company and a fantastic partner to work with. I would rate my overall experience with Seemplicity a 10 on a scale of 1 to 10.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Platform has transformed noisy security telemetry into prioritized, actionable remediation work
What is our primary use case?
I have been using Seemplicity for the last two plus years across various different use cases and have been working closely with the company almost from day one, supporting client engagements and different use cases across various different geographies.
There are three main use cases for Seemplicity. The first use case is around signal to noise ratio. Seemplicity has an amazing capability to perform aggregation, deduplication, and consolidation of various different telemetry sources to help organizations limit the signal-to-noise ratio and get a better understanding from a visibility perspective in terms of what they are dealing with, and how they should prioritize elements. The second use case is around prioritization. Even once you have optimized the number, it is still very difficult for various different enterprises to understand the priority when you overlay the business context, when you take information from threat intelligence, exploitability, business criticality metrics, and other business-related context. This helps organizations and enterprises understand top-X priority, what they need to deal with first and why. The third use case, which is lately seeing growing focus around remediation with Mythos and others, is that Seemplicity has a great ability to integrate with systems such as Jira and ServiceNow, ingest ticket information, identify the right grouping in Jira, translate this into user stories so that they can be inserted into the next sprint and as such streamline remediation activities. The focus is shifting from purely operational related noise level into more advanced use cases, specifically in light of the recent focus around Mythos and the growing emphasis on remediation and streamlining remediation activities.
What is most valuable?
The biggest impact we have seen is around the first use case with the signal-to-noise ratio. What we are seeing in many client environments is exponentially growing incoming volume of telemetry from a growing number of sources. Gartner is saying close to thirty different telemetry sources in an environment from engines that are scanning code, applications, pipelines, configuration data, cloud telemetry, outputs from vulnerability scanning, threat intelligence, and much more. There is a lot of duplication and a lot of noise. Where we have been able to show immediate impact is through using this platform as an aggregator and as a business layer to really help organizations have better visibility, better context, limit the volumes, and have a better understanding of what they are dealing with.
It was really humbling to see how Seemplicity platform evolves. Initially, the key value and features were around the engine, the ability to correlate, aggregate, normalize, and deduplicate, as well as features around finding the developers, the ability to integrate with Confluence and Jira, identify where the different teams are, capture the information, the Jira stories, help them translate this into Jira points, and help them understand available velocity so that they can actually insert requests around security elements into the next sprint. This is where the traditional values for the platform reside. Recently, they have added some AI-related elements. The ability to use plain English to search for information, to look for certain patterns of behaviors, and to identify gaps and outliers is an amazing new feature with the platform and this is a recent addition.
What needs improvement?
Seemplicity has put tremendous effort into improving the overall user experience and UI. The recent versions of their platform provide quite a positive experience. There is always a need for new widgets and new metrics. The ability to allow every organization to build their own dashboard, metrics, trending, and reporting to their liking would be a great value add. Also, for every organization, given they are different, they need the ability to slice and dice information in a different way. This is some food for thought in terms of adding more metrics and adding more flexibility. The capability out of the box today is decent, but over time, if we can allow users and organizations to build their own view and how they want to report on things, that would be a great value add.
Governance and security have certainly been thought through in the product. If I look at where the market is going around governance and auditability, there is certainly room to think about integrating with other tools. For example, a central repository to track AI-related activities. At the moment, this is built into the platform. In terms of a roadmap item, thinking about governance, auditability, and integrating with other tools for a central repository would certainly be something to consider.
For how long have I used the solution?
I have been using Seemplicity for the last two plus years across various different use cases and have been working closely with the company almost from day one, supporting client engagements and different use cases across various different geographies.
What do I think about the stability of the solution?
I have no complaints. The overall experience and interactions with customer support and the product organization, both of which I have spoken to over the years, was quite positive. Seemplicity is quite accommodating, specifically if there is an issue with the platform, but also with requests for additional features and roadmap items. The business was overall quite accommodating, obviously in line with market demand and other requests from other clients.
What do I think about the scalability of the solution?
From our experience, the system was quite effective both in terms of availability and scalability. In terms of the operating region, data residency, and the ability to scale over time to accommodate growth in volume, additional operating regions, and additional zones, the system is quite scalable and was able to easily adapt to changes and growth within the business.
How are customer service and support?
I want to mention that over the last few years, we had an open communication channel with Seemplicity team. We had the ability to provide feedback and request for new features, and the team overall was quite accommodating. Most of the things we have been asking for have already been implemented, and the team has been quite aligned with market demand and where the market is going, so all very positive.
Which solution did I use previously and why did I switch?
This was not a one-for-one replacement. We had scanning engines and various different sources of telemetry. We were either in-house built, using Excel sheets, or native modules for VM scanners that offer some aggregation. However, we did not have anything to the extent of a single aggregator that takes feed from everything, gives us visibility and context across the board, and integrates with the back end. I see this as the next evolution in exposure management, and this tier of business logic in between is served well by Seemplicity.
What was our ROI?
The simple answer is yes. In my view, this is one of the areas, and in my experience, it is important to look for friction and pain. Seemplicity is certainly associated with a few areas where there is obvious friction and obvious pain, and as such, it was fairly easy to demonstrate value for money. Some of the recent focus areas such as remediation is obviously a slow move that requires a lot of education and multiple touch points. However, we certainly had multiple opportunities to demonstrate value for money and a good return on investment.
What's my experience with pricing, setup cost, and licensing?
Our overall experience was quite positive. Seemplicity had the ability to be competitive. I have dealt with them in several other opportunities as well. They know the market and they know the competitors. Seemplicity has a compelling offering in terms of the platforms and the module, and from a commercial perspective, we have not had cases where we lost on price. The value for money is seen by most clients and as a client as well, I think we got a fair price for what we pay for.
Which other solutions did I evaluate?
We did evaluate other options. On one hand there were solutions such as ServiceNow with the specific modules applicable here, and on the other hand there were enhancements of VM engines such as Rapid7, Tenable, and Qualys. They all offer some level of aggregation and reporting that can help. We explored developing certain capabilities in-house through various automation tools, from using things such as Ansible to various different coding we have implemented before. The conclusion was it is not scalable, it is not reputable, and it is too costly. We lost skills over the years, and investing in one platform that covers so much ground was the right decision for us.
What other advice do I have?
As I mentioned earlier, organizations are going through the journey. The low-hanging fruit is around operational issues where we have seen over the years high levels of friction. With the focus and urgency around Mythos, I can specify a few recent engagements where the focus was around remediation. The ability to integrate with different teams and build workflows with specific gates for approval to really have full control while streamlining, reducing, and better aligning with SLAs, and reducing response time to patch critical systems, has been instrumental. We had a few recent engagements where organizations were able to better meet their SLAs, better communicate to their leadership and executive level about the overall risk and exposure levels, and overall have a better understanding of what they are dealing with.
If I need to identify some of the areas that are big selling points, they would be visibility, having more accurate numbers, removing all the overhead in terms of duplication, and really understanding what you are dealing with. Being able to see the patterns or associate this with specific platforms and specific applications, then streamline conversations with the right business peers and owners is valuable. Now with the ability to use plain English, this is in support of a specific outbreak or specific element you are looking for, which now can be done within a few seconds to get the straight answer. Specifically with Mythos, to try and understand what is potentially exploitable and what are the true levels of exposure associated with key services you take to the market are amazing features on the platform.
Seemplicity is doing amazing work. Specifically with simple tasks, they are getting better at more complex, multi-dimensional tasks. This is in line with the recent enhancements we see with other LLMs. This is why I was saying earlier, it would be nice to see over time things such as bring your own LLM. That would allow access for an external module that can access the data and apply the different queries. Seemplicity is doing a decent job. However, as the market is getting more accommodated to this type of interface using smart bots with plain English, requirements are going to grow as well in terms of complex, multi-dimensional searches. This is a very positive add-on and it is worthwhile keeping an eye on this because this is going to evolve over the next coming months or years.
Organizations should think about the true cost of ownership and what it would take to implement and operate this type of platform. There are great opportunities and benefits around Seemplicity platform.
Unified vulnerability data has reduced risk and currently cuts duplicate tools and license costs
What is our primary use case?
My main use case for Seemplicity is aggregating vulnerability data and tool rationalization.
For aggregating vulnerability data, I connected all of our different data sources, deduplicated them, deduplicated the findings, and assigned them. For the data sources I used, Wiz, Qualys, Imperva, and Active Directory, I connected all of them together and ensured that I did not have duplicate findings going to individual users. I sent those findings via Jira and ServiceNow, two different platforms, based on where the users were located.
For tool rationalization, I had several different tools that were duplicative. Wiz and CrowdStrike were finding the same thing, so I was able to cut some licenses from Wiz. GitHub Advanced Security was doing the same thing as Snyk scans as well as several other tools. I was able to cut about $150,000 in licensing spend. I was able to evaluate all of our different tools and remove licenses that were not being used or were duplicative elsewhere. I was able to cut about 2x what I actually spent for the product.
What is most valuable?
Seemplicity's best features include deduplication and aggregation, tool rationalization, and the AI chatbot.
Regarding the AI chat feature for deduplication and aggregation, the time to market was extremely long for some of the other tools I evaluated. I had to manually map different tools and different vulnerabilities that I thought were important, where Seemplicity used AI to do that. As for the AI chatbot, Seemplicity does a fairly decent job at providing substantive dashboards to give me different metrics. When I want a deeper dive than what the dashboards can do, the chatbot is there to let me take an extremely deep dive. It lets me join different data sources, where I could not do that necessarily with some of the other tools.
Seemplicity has helped me draw down my known vulnerability count by about 45%.
What needs improvement?
Seemplicity can be improved by adding additional graphs and charts that make it easier to do trending over time. I had to do some of that manually via manual reports, but Seemplicity already has a feature request for this.
Seemplicity has done a pretty good job of keeping up with integrations. One gap that I identified and that Seemplicity is trying to fill now is having a complete end-to-end mapping. Seemplicity currently looks at the external attack surface using tools like Censys, and then looks at the internal side, examining what is in AWS and other clouds using CSPM. However, there is not anything that currently ties a property on the outside to a system on the inside, especially when you have additional security layers like web application firewalls that actually mitigate the risk.
For how long have I used the solution?
I have been using Seemplicity for two years.
What do I think about the stability of the solution?
Seemplicity is stable.
What do I think about the scalability of the solution?
Seemplicity's scalability is good because they changed out their data source type during the middle of my evaluation. I never hit any sort of wall. They went from a Postgres database to a ClickHouse database and that gave me the capability to build a lot more charts on the fly.
How are customer service and support?
Seemplicity's customer support has been excellent. I had a TAM, so it was never an issue for me. I have never had to actually open a ticket myself, neither has anyone on my team. I called my account manager and they handled it for me. I would rate the customer support a 15 on a scale of 1 to 10.
Which solution did I use previously and why did I switch?
I did not have a solution in place before, but I was manually aggregating things in a spreadsheet.
How was the initial setup?
My experience with pricing, setup cost, and licensing was that I first purchased for one year, as I always do, just to make sure that the tool has value, and then I purchased for three years after that. The pricing did not increase dramatically from year to year because I maintained a similar number of data sources and similar integrations.
What about the implementation team?
I use AWS as my cloud provider. I did not purchase Seemplicity through the AWS Marketplace.
What was our ROI?
I have seen a return on investment because the time to actually do the assignment of a task is much less. The number of employees that would have had to look at a particular set of errors from different tools or vulnerabilities has decreased dramatically. I had seven different tools that sometimes produced the same message. Because one employee can do a lot more vulnerabilities, it is a lot better from a timing perspective on how many people I would need to do the work. I was also able to pay for the tool twice over by using it for tool rationalization. I was able to cut the amount of licensing from other tools to make up for what the cost of Seemplicity was times two.
What's my experience with pricing, setup cost, and licensing?
My company has just the relationship with Seemplicity. I actually went through a VAR to purchase Seemplicity.
Which other solutions did I evaluate?
Before choosing Seemplicity, I evaluated other options including ArmorCode, Vulcan, and three other tools. The names of the three other tools are escaping me.
What other advice do I have?
The advice I would give to others looking into using Seemplicity is to make sure you correlate all your data sources that you are going to want to bring in up front. Make sure you have security review and API tokens ahead of time. Getting some of that data causes a little bit of churn, especially teams or systems managed by different teams, such as ticketing systems that were managed by different teams. Whether you are evaluating Seemplicity or other solutions, you are going to need access to that to be able to do a full end-to-end test. I would rate this product a 9 out of 10.
Platform has transformed vulnerability workflows and now enables teams to meet SLAs with clarity
What is our primary use case?
I have been working in my field for approximately 25 years. At my job, I am in charge of designing, scaling, and the governance aspect of AI and machine learning products. My primary focus is ensuring that the products we ship do not have any vulnerabilities. I work on the product security side.
What is most valuable?
Understanding the products that are going to be shipped and identifying which ones have the biggest impact to the business is really important to us. For example, if a certain team can only handle so many vulnerabilities within one sprint cycle, we are able to track that within Seemplicity and ensure that what they are focusing on is exactly what they should be focusing on. Seemplicity has remediation guidance built in.
My team is on the receiving end of things with Seemplicity at times, and what I love is that it integrates directly with Jira. There are AI capabilities that ensure the Jira tickets or the remediation requests that show up are actually the things that the team needs to be doing. The steps are very clear, the guidance is very clear, and the audit trail is very clear. The information that gets passed to the ticket is all very clear and straightforward, and the team understands exactly what they need to do.
Seemplicity has really helped the relationship that we have with the security operations team and the broader vulnerability management team because it helps us and them speak the same language and get on the same page when it comes to what we are focusing on.
Before we really struggled with meeting SLAs that were in place because we did not have the information we needed and there was too much back and forth. Now we nearly have a perfect SLA meeting time.
What needs improvement?
I would appreciate the ability to interact with Seema outside of Seemplicity. Seema is the chat assistant, and it would be great if my team could interact with her from Slack.
Because my team is happy, which makes me happy. Given that transparency and data usage are a specialty area of mine, I really appreciate the transparency and the thorough documentation Seemplicity has around the way they are using our data in models. That has been really great and it has definitely been adequate for our team.
For how long have I used the solution?
I actually just started using Seemplicity at my current job about four or five months ago when I started.
What do I think about the stability of the solution?
We have not had any issues, so I would say it is pretty good.
What do I think about the scalability of the solution?
A lot of it has to do with the audit trail, so every action is logged within Seemplicity, making sure we understand what happens with the particular vulnerabilities and findings that have been identified. Everything is very thorough.
How are customer service and support?
I have heard that customer support is good from my colleagues. I do not deal with it specifically. If we have any issues, usually the vulnerability management team reaches out. I have been on a couple of calls as an observer, and they have been fantastic.
Which solution did I use previously and why did I switch?
The vulnerability team was using a solution called Nucleus and they switched because it could not handle the scale that they were beginning to get and also really struggled with code-to-cloud use cases.
Which other solutions did I evaluate?
We actually considered building it ourselves but very quickly determined that that was not an adequate solution for us.
What other advice do I have?
I would recommend making sure you pull in all the stakeholders, including the recipients of the tickets, and give them a chance to see what will actually be coming to their team and ensure that it is adequate to get things done. I was not involved in the original negotiation, but I heard no complaints. I would rate this review a 10.
Prioritized remediation has reduced risk exposure and improves response times across environments
What is our primary use case?
My main use case for Seemplicity is that we service a lot of financial institutions and educational institutions, and what we do is help them.
We had a growing number of vulnerabilities that were being discovered really across their environments and even across our own environments, and we needed a faster way to remediate and respond to those vulnerabilities and keep up with patching systems across the cloud infrastructure, our applications, and even endpoint devices.
We certainly had a lot of concern about Claude Mythos and the advent of Claude Mythos amplifying a lot of what we were seeing in terms of these findings and discoveries of vulnerabilities. So we needed a faster way to respond to that.
A quick specific example of how I use Seemplicity in my day-to-day work is that we use it to quickly identify specific areas of compromise or exposure, and we use the tool to essentially direct what should be fixed in the most timely manner rather than having to try and fix everything all at once. We prioritize certain fixes that are more critical and help us really try and get in front of any sort of attack or exposure.
What is most valuable?
The best features Seemplicity offers, in my opinion, are the way they prioritize vulnerability findings and prioritize the workflow to remediate or essentially prevent any future exposures. So we can tell if a system has a higher likelihood of being compromised, and we will take action on that immediately versus maybe systems that are more isolated and can create less of a spider effect of exposure. Those are the key areas.
I can tell you more about how the prioritization feature works for me. In conjunction with using it, they have these AI analysts, which are a newer feature for the company that we have just started using, and these AI analysts almost behave as if we had more personnel on our team. They help us go in and prioritize the fixes, prioritize how to remediate, prioritize where to patch, and how to patch. They will actually direct to the right individuals on our team if something needs to be fixed in the cloud or if it needs to be fixed on an endpoint, so the AI analysts step in and do that for us. We have just started using that feature over the last couple of months.
Seemplicity has positively impacted our organization on two different fronts. For our internal infrastructure and cloud usage and our applications, it helps us accelerate the amount of time it takes to remediate and patch those systems and ensure that those systems are essentially secure and not vulnerable to exposure. It is also helping us provide more value to our customers by helping them understand through our other processes and consultancy services how to better protect their infrastructure and identify vulnerabilities across their infrastructure.
What needs improvement?
Seemplicity could use more improvement around the user interface. I have seen some other user interfaces that maybe have a little bit more of an intuitive workflow, but it is not stopping us really from achieving what we need to achieve. Some UI polish would be the only suggestion.
For how long have I used the solution?
I have been using Seemplicity for about 14 months.
What do I think about the stability of the solution?
Seemplicity has been stable in the 12 to 14 months that we have been using it.
What do I think about the scalability of the solution?
While we do not have a very big team, we do have a combined IT and security team. In terms of being able to force multiply a team that we otherwise do not have by using their AI analysts, it has been super helpful.
How are customer service and support?
Customer support has been top notch. We have a dedicated customer success manager that works with us day in and day out and is helping us through any challenges we have. Our CS person actually helped us with a third-party issue. It really was not their obligation to do so, but they have been very responsive and very in front of us. I am happy with the support and service so far. I would give them a 10 on customer support, considering the experiences we have had with customer support from other technologies of the past. Definitely a 10 out of 10.
Which solution did I use previously and why did I switch?
We did not use a solution previously. We had a homegrown process that we were using to try and remediate and identify some of these issues. We had actually coded some of our own solution for this, and we were also using a little bit of scanning technology that would scan for vulnerabilities, but that was determined to be inefficient in terms of speed and comprehensiveness. Mainly a homegrown solution was used before, not another vendor.
How was the initial setup?
Seemplicity has helped improve our risk exposure by helping us identify those vulnerable points across the applications, the cloud, and even the endpoint devices. It is absolutely helping improve our risk exposure.
What about the implementation team?
Seemplicity integrates with our existing security tools or workflows extremely smoothly. We have a ticketing system that we use. We also have data sources that help us scan infrastructure and understand where vulnerable points might exist. We are also using it to counterbalance Claude Mythos and the exploration of using Claude Mythos to identify what has been identified in terms of vulnerable points across the infrastructure. We also have to integrate with endpoint technologies, and we also have to integrate with various application technologies. There were a few minor implementation challenges once we got everything tied together, but once we had everything tied together, it has been smooth so far.
What was our ROI?
While it is definitely difficult to quantify the actual ROI, I can estimate that Seemplicity is saving us at least half the time that we would spend before trying to manually triage and identify where fixes need to happen across our entire infrastructure, whether it is cloud, whether it is applications, whether it is endpoints. Seemplicity is definitely saving time, and it is obviously saving money that we would have had to spend if we would have either hired more personnel to fix the vulnerabilities or to help manually go into these systems, determine whether or not it needs a fix or not, and then take action. There is definitely value there.
In regard to return on investment, I can say that Seemplicity definitely multiplies the personnel and the amount of personnel we have. We are not a big organization, and we do not have a ton of IT security staff. Seemplicity sort of multiplies maybe 4x what we would have to spend in terms of employee hiring or actual analysts to be able to triage and remediate these vulnerabilities. There is definitely ROI there.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing is that pricing is mostly in line. We would obviously prefer to spend less, but the licensing is fair and in line with other solutions that we look at in the market. I would say it is mostly in line with what we would expect for a solution of this nature.
Which other solutions did I evaluate?
We evaluated other options before choosing Seemplicity.
What other advice do I have?
I chose the number 10 because it was easy to get us up and running and deployed. Seemplicity is helping us generate immense ROI in terms of helping secure our infrastructure, applications, endpoints, and understanding vulnerabilities that we really did not have a good process of understanding before. Immediate value came after once we got up and running and then what it can mean for our customers as we consult with them and ensure that their infrastructure has continuity.
Seemplicity has impacted our incident response processes by providing faster response times in terms of responding to identified exposures or vulnerabilities across applications and systems. Speed is critical.
My advice to others looking into using Seemplicity is that they should know their use case very well and understand how they want to quantify ROI when they go into the project. That is something you have to have an idea of to demonstrate the benefit and to justify the cost. I gave this review a rating of 10 out of 10.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Centralizes vulnerabilities and has created accountable remediation and leadership reporting
What is our primary use case?
The main use case for Seemplicity is centralizing vulnerability and risk findings from multiple scanners and tools into a single queue instead of chasing spreadsheets across teams. I am also using it to drive remediation ownership, routing findings to the right infra, app, and dev teams instead of InfoSec manually triaging everything.
I have several additional angles I could add about my main use case for Seemplicity. One is about standardizing across a diverse group, as our X-Press Feeders Group has multiple subsidiaries that likely had inconsistent, siloed vulnerability processes before. Seemplicity gives us one standardized workflow across all of them instead of each entity managing remediation its own way. The next point is supporting a formal vulnerability management program; part of what I am doing is building out a more mature, structured VMT function this year, and Seemplicity is the backbone for that. It actually gives the actual workflow and accountability, not just a tool, but the operational layer for how vulnerability management gets done day to day. I am also using Seemplicity to feed the leadership reporting, primarily to pull remediation status into my quarterly reviews for our senior leadership.
What is most valuable?
Regarding Seemplicity's best features, a few things stand out for me. First, it pulls everything into one place: findings from the tech stack that we have and all our different tools. We use one for cloud, one for all our office systems, and some for our software engineering. Instead of my team jumping between five different dashboards, this tool is very helpful. Second, the way it handles ownership and routing is genuinely useful because it figures out who actually owns a finding and routes it there automatically, which used to be a huge manual headache for us, especially across a group with multiple entities. My favorite feature right now is Seema, their AI assistant; instead of digging through filters and dashboards to answer a simple question, I can just ask it directly, for example, "What's breaching SLA right now?" and get a quick summary I can bring straight to the leadership. This saves a lot of time for me, and it is one of those features that once you start using it, you do not want to go back to doing it manually.
The biggest impact Seemplicity has had on my organization is turning what used to be a fragmented, manual process into something structured and accountable. Before, we had vulnerability data scattered across multiple tools and multiple entities in our group, and a lot of time went into just chasing people down: Who owns this? Has it been fixed? Where does this stand? Seemplicity took that coordination overhead off our plate. Ownership gets mapped automatically, tickets get routed to the right team, and nothing falls through the cracks the way it used to. That has had a real ripple effect; my team spends less time on manual triage and more time on actual risk reduction. It also strengthened how we show up for compliance: Audit-ready reporting for things like ISO 27001 and SOC 2 used to mean pulling together data manually. Now, that visibility is just there when we need it. Seema has amplified all of that. She is my go-to person because I can just ask it questions directly instead of digging for answers. I can move faster and bring leadership clear, accurate updates without a lot of prep work. Overall, it has shifted us from being reactive and scattered to having a much more accountable, structured approach to vulnerability management across the whole group.
What needs improvement?
For Seemplicity, I would say two things for improvement. First, reporting customization could go further because this industry is evolving; the CEO tries to get much information that they are looking for. The dashboards are solid for the most part, but every now and then, I want to slice the data a slightly different way for a specific leadership ask, and I have to work around that a little. That is number one. Number two, with the introduction of AI and agentic AI and more involvement in day-to-day tasks, it would be great if this platform starts remediating the vulnerabilities as well. Right now, it just displays what is vulnerable and where it is coming from, but they need to go one step next by fixing it as well, provided the tool gets approval from the owner, from me. If I am okay and if this tool goes ahead and fixes it, then nobody can stop Seemplicity.
For how long have I used the solution?
I have been using Seemplicity in this current company for the last two years.
What do I think about the stability of the solution?
Seemplicity is stable.
What do I think about the scalability of the solution?
I do not see any challenges with Seemplicity's scalability. The only aspect is you need to make sure that whatever you want to integrate or ingest is covered as part of the contract. The contract is based on the data sources that you connect; as long as that is covered, connecting ten data sources or twenty data sources, then you are good. Other than that, when it comes to the volume of data ingestion, I have never had any challenges with them, and they pretty much stick to what they promise.
How are customer service and support?
The customer support for Seemplicity is fantastic.
Which solution did I use previously and why did I switch?
We did not have a direct predecessor doing what Seemplicity does; we use Lansweeper for asset discovery and inventory, and we actually looked at Axonius at one point for broader asset visibility. Neither of these tools is built for remediation orchestrations. They will tell you what assets you have, and in Axonius's case, give you a consolidated view of your attack surface, but they do not solve the problem of taking findings and actually driving it into a resolution, assigning ownership, routing it to the right team, and tracking it against SLA. That gap is really why we brought in Seemplicity. Instead, Seemplicity sits downstream and does the orchestration piece neither tool was designed for.
How was the initial setup?
On the integration side of Seemplicity, it has been seamless connecting it with our existing tools. We are not ripping out anything we already rely on; it just sits on top of these tools and pulls everything into one place. That vendor-agnostic approach matters a lot to us since we did not want to be locked into a scanner ecosystem, especially with a group as spread out as ours across multiple entities.
What was our ROI?
I have not put a formal dollar-for-dollar ROI calculation together, but directionally, Seemplicity has paid off. The clearest signal for me is time. Before Seemplicity, a meaningful chunk of my team's week went into manually chasing ownership, status updates, and pulling together reports across our different entities. That coordination overhead has dropped substantially. I could not give you an exact percentage, but it has freed my team to spend more of their time on actual remediation instead of admin work. On the compliance side, prep time for audits and leadership reporting has also gone down; what used to take real manual pulling together is largely already sitting in the dashboards now. Given what we are paying, I would want to see that translate into a harder number eventually, but qualitatively, the shift from reactive to structured and automated has been real.
What's my experience with pricing, setup cost, and licensing?
Regarding Seemplicity's pricing, setup cost, and licensing, I will be upfront that I cannot get into specific figures because that is commercially sensitive on our end. But directionally, the value has matched the investment. Setup was straightforward enough that we did not need any heavy professional services to get going, which kept implementation costs reasonable. Licensing was clear and predictable; I appreciate there being no surprise costs creeping in after the fact, especially as someone who has to plan budgets. Given the time it has saved my team on manual coordination and reporting, I would say it has paid for itself in efficiency even if I cannot put an exact ROI number on that.
Which other solutions did I evaluate?
We did not evaluate any other options other than Axonius, but Axonius and Seemplicity serve two different purposes. Seemplicity is something I got very positive feedback on from a very good friend who is a CISO. He recommended it, and that is how I started exploring Seemplicity, and it proved to be a good tool.
What other advice do I have?
A few pieces of advice I would give to others looking into using Seemplicity are as follows. First, go in with clear eyes on the investment; it is not cheap, and so it makes the most sense if you have real complexity to manage, as is the case with us: multiple teams, multiple entities, and findings scattered across several tools. If you are a small, single-team shop with a simple environment, the value proposition is a lot less obvious. Second, budget time up front to tune the prioritization and routing rules to match how your organization really works; do not expect it to be plug and play on day one. That initial setup iteration is worth doing properly rather than rushing. Finally, do not overlook Seema, their AI assistant; I use it constantly to pull answers instead of digging through dashboards myself, and if you are evaluating the platform, it is worth specifically testing that in a demo rather than just looking at the core orchestration feature. Overall, if you are dealing with fragmented vulnerability data across a complex, multi-entity environment, and the manual coordination overhead is a real pain point, it is worth the investment. If your environment is simpler, you may not need something this robust. I would rate this product a nine out of ten.
Automation has streamlined vulnerability ticketing and keeps teams focused on real security work
What is our primary use case?
The main use case for Seemplicity is automating vulnerability tickets creation by using predefined asset scopes. I use Seemplicity's remediation queues to automatically feed vulnerability tickets into our remediation owners native Jira projects, ensuring that the entire process end to end is automated. The automation allows us to maintain control over ticket volume while ensuring nothing falls through the cracks.
What is most valuable?
The best features Seemplicity offers from our perspective include the ticketing queue automation, which allows us to create unique ticketing queues specific to each remediating team, and the various customizability around severity assignment, and rules that help us alter the priority or severity level as appropriate to our business.
Ticketing queue automation in Seemplicity has freed time and resources for my team because it reduces the time we spend on manually cutting tickets. Instead we can focus on tuning the automation, scopes and queues which scales with time.
What needs improvement?
More customizations around the scoping, filters, dashboarding/metrics would be great.
For how long have I used the solution?
I have been working in my current field for about eight years.
What do I think about the stability of the solution?
Seemplicity is stable.
What do I think about the scalability of the solution?
For our use, the scalability is good because it is very easy to setup new scopes and remediations queues.
How are customer service and support?
Customer support for Seemplicity is quick to respond and provide feedback to any issues or feature requests that we have requested.
Which solution did I use previously and why did I switch?
We previously had Daz, which was acquired by Wiz, and we switched because the vulnerability management capabilities inside of Wiz were not satisfactory at the time of purchase.
What was our ROI?
I do not have any specific metrics to share regarding return on investment, but Seemplicity has saved us time and overhead.
What's my experience with pricing, setup cost, and licensing?
We found the pricing, setup costs, and licensing for Seemplicity to be extremely fair.
Which other solutions did I evaluate?
We evaluated a couple of other options before choosing Seemplicity, including Nucleus and Armis.
What other advice do I have?
My advice to others looking into using Seemplicity is to make sure that you have your primary use cases documented and measure the success of the proof of concept against your requirements.
Unified remediation workflow has improved vulnerability prioritization and reduced ticket churn
What is our primary use case?
My main use case for Seemplicity is ticketing all of our security findings to the service teams for remediation and prioritization. I use Seemplicity for our security tools such as Wiz in the SaaS environment, Tenable for on-prem, GitHub, and Fossa for our code side. Instead of ticketing everything critical, I rated it based on CVSS and EPSS so that the teams are focused on what needs to be fixed based on criticality.
What is most valuable?
I really appreciate the AI agents that test reachability and exploitability, particularly with the host agent which can look at CrowdStrike and Wiz telemetry and also the code analysis to see if a function is actually reachable.
They are really useful for exception requests, which used to be a manual analysis, but now it takes that burden off the analyst to allow them to look at all aspects of the CVE, the asset, what it is hosted on, and how it could be exploited.
Seemplicity has allowed us to have all findings in one single pane of glass and the service teams use it to track metrics, file exception requests, and our overall ticketing Kanban process.
We have seen improvements in remediation rates. Initially, a lot of our metrics were in the red, but now all are in the green or yellow.
What needs improvement?
Seemplicity could be improved with some of the aggregation accessibility. Currently, it is a bit of a black box and can be a bit of a bottleneck. It would be nice if customers could perform the aggregation themselves on the spot to reduce that bottleneck.
For how long have I used the solution?
I have been using Seemplicity for 1.5 years.
What do I think about the stability of the solution?
Seemplicity is stable.
What do I think about the scalability of the solution?
Seemplicity's scalability is great.
How are customer service and support?
Seemplicity's customer support is great.
Which solution did I use previously and why did I switch?
I previously used an in-house model and switched because it was not sustainable or scalable.
What was our ROI?
I have saved a significant amount in ticket churn and developer analysis when having them remediate vulnerabilities, though I do not have an exact number.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing for Seemplicity was great. They gave us unlimited licensing for automation and we have a lot of tools at Omnicell, so it has been very easy to work with them on this front.
Which other solutions did I evaluate?
I evaluated other options before choosing Seemplicity, specifically Brinqa and Nuclei.
What other advice do I have?
My advice to others looking into using Seemplicity is that if you do not have an existing RemOps platform or you are looking to improve, it is a great product. I would rate this product a 10.
Centralized security workflows have reduced alert noise and now prioritize critical remediation
What is our primary use case?
Seemplicity is the main tool where I manage our security events, incidents, alerts, and everything that is security-related. It is a central tool that receives all alerts, all events, and all findings and performs three primary functions: deduplication, prioritization, and managing the entire remediation process and queue.
Managing the remediation process with Seemplicity begins with receiving alerts from the source system of all our security tools. The alerts get deduplicated, which significantly reduces the noise that our teams used to experience and helps us considerably. The alerts are then prioritized, ensuring that we focus only on urgent topics and avoid dealing with low-risk or low-impact issues. Once ready, Seemplicity is configured to open a ticket for the specific team that should address a specific incident or alert. The team receives an open ticket based on standards and definitions; some teams can handle two tickets per sprint, while others can handle five per sprint, and this is all defined within the system. It opens the ticket and then helps me manage and track the remediation process or the fixing of the ticket as it happens, measuring SLA compliance and the actual work that was completed when the developer or security person indicates it is done. In essence, it helps me prioritize, select the right tickets, and share the right information in the ticket with the team, which is important because sometimes tickets from the original systems do not include all details and it ensures that everything is fixed on time. The management tools in Seemplicity help me ensure that nothing is stuck and that the teams across the organization, whether in security, DevOps, IT, or engineering, are addressing their tickets in the agreed-upon SLAs.
What is most valuable?
In recent months, we have started to use Seemplicity's investigations and analysts feature, and it also appears to be a good capability. It is not fully utilized yet, but it does show potential. We see many instances where based on the original data from security systems, Seemplicity determines that a certain ticket is of high priority and should be addressed, but when we handle it, we often find that some information is missing or it is not really such a high priority. The analysts feature brings in additional AI capabilities where they investigate the topic in depth. So far, we have found that their findings are very accurate. If we decide to implement it and turn it on for all cases, or at least for all high-critical and high-risk issues, it will probably reduce the workload on our human analysts.
Seemplicity offers three best features. One is the option to deduplicate alerts between security platforms, which is something we do not have the capability for anywhere else. The second is managing the remediation queues, which is truly useful; it ensures that developers and the security team receive the right tickets in the right amount, with the right priority and right details, and then tracking them is very useful. It is a single point to manage all our security activity.
The deduplication feature helps my team day-to-day by reducing the amount of work. When we examine security incidents, usually one security flaw—a new zero-day vulnerability in a library we use—triggers alerts across different systems, from our vulnerability management platforms to our real-time runtime monitoring systems to our Wiz platform, showing us the same issue across multiple instances. This might generate hundreds of different alerts. Seemplicity allows us to deduplicate them into one single action that a security person or developer needs to perform to fix all of these alerts. Instead of having 100 or 200 different tickets opened to different teams, we have a very specific team that receives one single ticket to solve it all. When we started with Seemplicity, we saw an 85% reduction in the number of tickets through deduplication, and that is significant for our teams who are swamped with issues.
Seemplicity has positively impacted our organization overall by reducing the number of tickets that are opened, allowing the team to really focus on what is important. We have less noise, so we are very focused, and using this tool has helped us reduce the number of vulnerabilities and issues we address. We are at the point where we have zero critical issues and probably less than ten high-risk issues, which we are constantly addressing and will likely resolve soon. We are also beginning to tackle medium and low-risk issues, which we never could before. Having this deduplication reduction helps us really focus on advancing our security posture.
What needs improvement?
Every tool, including Seemplicity, can improve, and I think it needs to further enhance its deduplication capabilities and understand how to integrate with more security tools, especially as new AI security tools emerge. Seemplicity needs to know how to digest data from these tools and how to deduplicate it. Additionally, there is room for improvement in a generic approach to queue management and more proactive collaboration with security analysts, developers, and infrastructure teams on tickets—not just opening them, but really collaborating.
For how long have I used the solution?
I have been using Seemplicity for the last four years.
What do I think about the stability of the solution?
Seemplicity is stable.
What do I think about the scalability of the solution?
Seemplicity has scaled to our needs without any issues.
How are customer service and support?
The customer support is excellent. They are actually located in the same building as we are, so it is really easy for us. If we need support, their team simply goes down the elevator and steps into our office. I would rate customer support a 10.
Which solution did I use previously and why did I switch?
When we started using Seemplicity four years ago, there was no other solution doing what Seemplicity does, at least none that we knew of, so we did not have such a solution before.
What was our ROI?
We estimate that Seemplicity actually saves us most of our resources by reducing the number of alerts, which allows us to maintain the same SLA with a smaller security team. We estimate that, on average, Seemplicity saves us two full-time employees in the security team.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing was positive. The cost was easy to manage, and we never had any issues. Pricing and licensing were straightforward, and we had direct discussions with the CEO of the company, which allowed us to arrive at a price point that worked for both sides.
Which other solutions did I evaluate?
Before choosing Seemplicity, we did not evaluate other options. We started with them in the very early stage since it was a very innovative startup, so we did not have any other options to choose from. As they grew, other tools like Dazz came to us and presented, and we saw them, but we never really tested them because we were happy with Seemplicity.
What other advice do I have?
Seemplicity's AI capabilities are good for us; we have integration to what we need, and I believe it is secure as it mostly keeps metadata, so there is no real personally identifiable information involved.
Its accuracy and reliability of output are mostly dependable. Over time, we have worked extensively with the team to ensure they can read from all our security systems, ingest the data, and deduplicate it well. It is not 100% perfect, and there are still some gaps, but overall, it is quite accurate.
I would advise others looking into using Seemplicity to check if it integrates with their security tools to ensure they have support for their main security tools. I would also tell them not to go slow when integrating but to fully integrate all their security tools in Seemplicity, because the value lies in using and deduplicating everything, not just part of the security tools. I would rate this solution an 8 overall.