Effortless Pentesting with Intuitive Insights
What do you like best about the product?
I like NodeZero from Horizon3.ai for its intuitive interface, which makes it easy to navigate the different sections of the portal. I also appreciate the remediation assistance it offers, as it provides steps to fix vulnerabilities. Additionally, the initial setup of NodeZero was very easy, which was a nice plus.
What do you dislike about the product?
I believe the external pentest can be improved to offer similar depth as the internal pentest. The external pentest can incorporate aspects of application vulnerability scans.
What problems is the product solving and how is that benefiting you?
I use NodeZero from Horizon3.ai to run regular internal pentests and password audits, identifying attack vectors that can exploit system vulnerabilities. The intuitive interface makes navigation easy, and remediation assistance provides steps to fix vulnerabilities.
Automated security testing has improved risk prioritization and reduced remediation efforts
What is our primary use case?
My main use case for The NodeZero Platform by Horizon3.ai includes pen testing and vulnerability management. I use The NodeZero Platform by Horizon3.ai to run weekly external and internal scans to identify configuration issues, software vulnerabilities, or misconfigurations.
How has it helped my organization?
The NodeZero Platform by Horizon3.ai has positively impacted my organization by allowing my security team to be more efficient and focus on the most valuable work at the highest criticality. My team's efficiency has improved by identifying what is truly a cybersecurity risk, allowing us to filter out vulnerabilities that are not exploitable and not worth the time and effort to remediate.
What is most valuable?
The best features The NodeZero Platform by Horizon3.ai offers include addressing security threats introduced by misconfigurations, identity, and vulnerability.
The NodeZero Platform by Horizon3.ai helps me identify security threats from misconfigurations or identity issues by conducting weekly scans of my entire environment to identify issues as an attacker would perceive them, starting from a patient zero.
What needs improvement?
The NodeZero Platform by Horizon3.ai could be improved by reducing the elapsed time from identifying a zero-day vulnerability from their QA environment to their production environment.
For how long have I used the solution?
I have been using The NodeZero Platform by Horizon3.ai for four years.
What do I think about the stability of the solution?
The NodeZero Platform by Horizon3.ai is stable.
What do I think about the scalability of the solution?
The NodeZero Platform by Horizon3.ai is very scalable.
How are customer service and support?
The customer support is excellent.
Which solution did I use previously and why did I switch?
I did not previously use a different solution.
What's my experience with pricing, setup cost, and licensing?
I had a very good experience with pricing, setup cost, and licensing.
Which other solutions did I evaluate?
I evaluated other options before choosing The NodeZero Platform by Horizon3.ai, specifically Pantera.
What other advice do I have?
My advice to others looking into using The NodeZero Platform by Horizon3.ai is to do yourself a favor and see what the product will find. The platform's real attack capabilities have helped in identifying vulnerabilities in my on-premises systems by allowing us to find even systems that made it off inventory; there is nowhere to hide from The NodeZero Platform by Horizon3.ai.
The NodeZero Platform by Horizon3.ai's endpoint security effectiveness feature impacts my understanding of potential security threats by allowing me to assess the efficacy of the EDR solution. The NodeZero Platform by Horizon3.ai has improved my remediation times in a meaningful way and has helped reduce my pen testing costs by approximately 25 percent. I would rate this product 8 out of 10.
Which deployment model are you using for this solution?
Private Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
NodeZero: A Game-Changer for Prioritizing Urgent Cybersecurity Issues
What do you like best about the product?
NodeZero has been a game changer for my team, helping us focus on the most relevant and urgent cybersecurity issues affecting our specific environment.
What do you dislike about the product?
There is occasional lag when moving issues from QA to Prod.
What problems is the product solving and how is that benefiting you?
Resource constraints are a constant challenge, especially when deciding how to deploy limited time and capacity against the most pressing, highest-value work in cyber defense. Node Zero helps me do more with less by keeping my focus on what matters most.
Fast, Accurate, and Versatile for Multiple Penetration Testing Types
What do you like best about the product?
Speed and accuracy. Support for the multiple types of penetration testing.
What do you dislike about the product?
The installation - docker solution that can be pain in real enterprise grade networks. Customization / fine tuning is missing. Support for custom templates, custom actions.
What problems is the product solving and how is that benefiting you?
I can run multiple pentests in parallel, which helps a lot with the work that can be automated. It delivers great results in a reasonable amount of time.
Automated testing has transformed how we deliver fast, consistent security assessments
What is our primary use case?
The primary use case for the NodeZero platform by Horizon3.ai is to deliver penetration testing as a service to our clients, enabling us to support their security assurance, risk reduction, and compliance obligations.
What is most valuable?
The key capabilities of the NodeZero platform by Horizon3.ai that I have found most valuable are its speed, scalability, and consistency. It is able to cover a broad scope in a relatively short period of time, which delivers significant efficiency gains when compared with traditional manual testing. It also provides a more consistent outcome, as the process is not influenced by human bias or variability.
One of the most valuable features is the ability for security teams to remediate and retest vulnerabilities immediately. The one-click verification capability is particularly effective, as it allows fixes to be validated quickly without the need to rerun the entire assessment. This streamlines the remediation cycle and supports faster confirmation of security improvements.
The platform’s real attack capabilities have also helped reduce false positives in the identification of vulnerabilities across our on-premises systems. Because the findings are evidence-based and validated prior to reporting, the results are more reliable and actionable. This enables us to focus our efforts on confirmed security issues that genuinely require attention, rather than spending time investigating theoretical or unverified exposures.
The NodeZero platform also strengthens my understanding of potential security threats through its continuously updated capabilities. With new vulnerabilities emerging and being exploited in the wild on a regular basis, it is valuable to have a platform backed by a strong research and development function that continuously updates attack content to reflect the current threat landscape. This makes the platform effective not only as a point-in-time validation tool, but as part of an ongoing and continuous security assurance programme.
What needs improvement?
At present, the platform is relatively rigid in how it operates and offers limited flexibility to align with individual user preferences or organisational requirements. While this structured approach has advantages in maintaining consistency, it can also be restrictive in practice.
In particular, greater flexibility around reporting and risk scoring would add significant value. For example, the ability for users to adjust or contextualise vulnerability ratings based on their own environment, risk appetite, or compensating controls would make the reporting more adaptable and relevant to different use cases.
For how long have I used the solution?
I have been working with the NodeZero platform by Horizon3.ai for nearly a year, with hands-on experience using the platform since August of last year.
What do I think about the stability of the solution?
I would evaluate the NodeZero platform by Horizon3.ai as excellent in terms of stability and reliability. We have not experienced any issues with accessibility or availability, and the platform has consistently performed as expected.
I would rate the stability of the NodeZero platform by Horizon3.ai as 10 out of 10.
What do I think about the scalability of the solution?
I consider the NodeZero platform by Horizon3.ai to be highly scalable. It is well-suited to enterprise environments, straightforward to deploy, and can be implemented within minutes. Its speed and breadth of testing enable it to assess large areas of network coverage in a relatively short period of time.
I would rate the scalability of the NodeZero platform by Horizon3.ai as 10 out of 10.
How are customer service and support?
I interact with both the technical support and customer service teams at Horizon3.ai in relation to the NodeZero platform.
I have direct access to representatives in my region through a dedicated messaging channel, which makes communication quick and efficient. Whenever I need assistance, I can reach out directly and typically receive a response within an hour, and often sooner. In my experience, the team has been consistently responsive, helpful, and easy to work with.
I would rate the technical support for the NodeZero platform by Horizon3.ai as 9 out of 10, with 10 representing the highest level of support.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
Prior to using the NodeZero platform by Horizon3.ai, our security testing activities were conducted entirely through manual methods, as we had not previously utilised an automated platform of this nature.
How was the initial setup?
The installation process for the NodeZero platform by Horizon3.ai is straightforward and easy to complete. The deployment workflow is simple: you download the preconfigured virtual machine from the Horizon3.ai website, run it within the target environment, and then copy and execute the provided script within the locally deployed agent. Once that is done, the platform is ready to begin testing almost immediately.
In my experience, I have not encountered any challenges or blockers during installation. The overall setup process has been smooth, intuitive, and reliable.
What about the implementation team?
I participated in the initial setup and deployment process of The NodeZero Platform by Horizon3.ai.
What was our ROI?
So far, I have seen a clear return on investment from the NodeZero platform by Horizon3.ai. As an autonomous solution, it has enabled us to save a significant amount of time and effort by reducing the level of manual work required. This has been one of the key benefits of adopting a platform of this type.
In addition, because the platform is designed to scale effectively for enterprise environments, it has also helped us improve efficiency on larger engagements. As a result, we are seeing cost savings through reduced effort and a more streamlined delivery model.
Which other solutions did I evaluate?
Before selecting the NodeZero platform by Horizon3.ai, I evaluated several alternative solutions from other vendors, including Pentera and RidgeBot.
We ultimately chose NodeZero for three main reasons. First, its technical capabilities were better aligned with the specific use cases and outcomes we were looking to achieve. Second, it was more commercially competitive and offered better value than the other solutions we assessed. Third, the quality of both customer and technical support was a key differentiator. Whenever we required assistance, advice, or issue resolution, the Horizon3.ai team was responsive, accessible, and highly supportive in working through our requirements.
What other advice do I have?
As a managed security service provider, we use the NodeZero platform by Horizon3.ai in both a reseller and advisory capacity.
Its impact on remediation has been particularly positive. The platform provides a clear and efficient way to manage remediation through its dedicated vulnerability management capabilities, with the added benefit of integration into platforms such as Jira and ServiceNow. Because findings are evidence-based and validated, the output is highly actionable and carries a low false-positive rate, making it a strong remediation enablement tool.
From a commercial perspective, I am familiar with the platform’s pricing and licensing structure and consider it to be well-positioned across market segments. Its tiered pricing model makes it accessible for small and medium-sized businesses, while its enterprise packages provide the additional functionality required by larger organisations.
The platform has helped us reduce our penetration testing delivery costs, which was a key objective for us as a consultancy and service provider. Although I cannot disclose a specific percentage reduction, the cost savings have been significant.
My overall rating for the NodeZero platform by Horizon3.ai is eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?