

Find out in this report how the two Risk-Based Vulnerability Management solutions compare in terms of features, pricing, service and support, easy of deployment, and ROI.
I have seen a return on investment with Armis, as it definitely improved remediation with fewer employees.
A reduction in remediation time has been seen because it is finding things before they happen.
Being able to find them because there have been no eyes on that particular section so far ever, and fixing those potentially prevented those companies from getting breached.
So far, I have seen a return on investment with The NodeZero Platform by Horizon3.ai, as we managed to save a lot of time and effort with this because this is an autonomous tool, and our manual effort is significantly reduced because of a product of this type.
I have not faced challenges with Armis support, as pre-sales engineers have been helpful.
I would rate it ten out of ten.
Overall, when it comes to The NodeZero Platform's tech support, you can reach them via a chat message on their website, and they respond almost immediately.
Previously, with time-sensitive engagements, I would worry about resolving issues before deadlines. That concern has diminished as they've become more responsive and require less escalation to engineering.
The vast majority of times they are able to resolve the exact questions my team has on the first attempt, which is really good for customer or technical support.
As a SaaS platform, it is highly scalable.
It is very scalable and easy to scale, as I also rated it eight on a scale of one to ten.
We have conducted pen tests in environments with hundreds of thousands of IP addresses without any scalability issues.
We currently scan approximately 1,500-2,000 assets and haven't encountered any scaling or throughput issues.
The platform offers various insider threats, segmentation tests, phishing tests, and PCI DSS tests.
We have not encountered any issues on the platform regarding accessibility, performance, or stability.
Regarding stability, it has never crashed, and there has not been any lagging from deployment or running.
I would rate the stability of The NodeZero Platform by Horizon3.ai as a ten.
Armis cannot be used as a standalone solution and should be integrated with other solutions.
The needed improvements I see include implementing cloud features, as the market, particularly in Brazil, is moving to cloud environments to reduce costs and time spent on upgrades and server management.
It misses out on a lot of vulnerabilities.
This service reveals which credentials and email addresses are available on the deep web, as well as which domains have been set up using typo-squatting techniques.
The one thing that is very much asked from us as a service provider is DAST testing, so when a company is building a software, they could see their current security status while they are building the application.
One of the areas where improvement is needed is in the visibility and reporting for large enterprises.
Armis pricing is average, neither cheaper nor more expensive than other solutions.
Armis is slightly on the expensive range based on what I have observed.
The pricing and licensing of the product are average, and I rate it six out of ten.
The pricing is much more affordable than traditional penetration tests.
It's a bit cheaper than manual penetration testing because manual testing typically allows you to scan only a few subnets.
Usually, manual penetration test scans take considerable time and money.
Armis is very easy to implement due to its agentless design and offers a granular level of visibility for all assets in the network.
It assesses open vulnerabilities, provides traffic flow insights, integrates with ticketing workflows, and aggregates security solutions like Active Directory and EDR.
Armis provides full visibility on OT devices and in the medical industry for devices such as ECG machines, X-rays, and infusion pumps.
When a new vulnerability, such as a zero-day exploit, is identified, they review your previous scans to determine if you might be vulnerable to it, and they proactively notify you.
The detailed reports not only list the vulnerabilities that matter, but they also include direct links to patches.
The NodeZero Platform's real attack capabilities help in identifying vulnerabilities on our on-prem systems because it provides actual vulnerabilities by attacking our systems.
| Product | Mindshare (%) |
|---|---|
| The NodeZero Platform by Horizon3.ai | 3.5% |
| Armis | 3.1% |
| Other | 93.4% |

| Company Size | Count |
|---|---|
| Small Business | 7 |
| Midsize Enterprise | 2 |
| Large Enterprise | 7 |
| Company Size | Count |
|---|---|
| Small Business | 14 |
| Midsize Enterprise | 4 |
| Large Enterprise | 7 |
Armis is a comprehensive cybersecurity solution used for continuous monitoring and threat detection across IT and IoT devices. It excels in spotting vulnerabilities, managing device compliance, and tracking assets to enhance security protocols and network management. Key features include real-time threat detection, comprehensive visibility, and granular risk assessments. Armis boosts organizational productivity by streamlining workflows and enhancing operational accuracy.
NodeZero by Horizon3.ai is an offensive security platform that enables users to adopt an attacker’s perspective, reveal vulnerabilities, and verify defense effectiveness with evidence-backed insights.
NodeZero provides autonomous pentesting, showing how attackers exploit misconfigurations, credentials, and exposures into attack paths. It helps focus on real risks rather than hypothetical ones, integrating seamlessly into existing IT and security workflows to streamline processes. The platform drives risk-based vulnerability management and CTEM by validating vulnerabilities and measuring resilience.
What standout features improve your security?NodeZero assists in automated penetration testing and vulnerability management in industries like finance and healthcare. It enhances security processes by complementing or replacing existing solutions, enabling efficient testing, feedback, and control validation.
We monitor all Risk-Based Vulnerability Management reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.