What is our primary use case?
My main use case for Nozomi Networks is threat detection.
I mentioned briefly about the second use case, which is asset discovery, because OT people oftentimes do not know what assets they have in their networks. Nozomi Networks is quite a useful tool to create an asset inventory, at least for starters. With Smart Polling, which is an active polling method not necessarily always allowed, but if a certain company permits it, Smart Polling is quite good in enriching data about assets. The second very strong and probably the second most important use case is asset discovery. Obviously, the third one is vulnerability management if you combine everything with ServiceNow.
What is most valuable?
I think the best features Nozomi Networks offers include the number of industrial protocols that it can monitor, which is outstanding and no other tool is equally capable as Nozomi Networks. Secondly, the user interface is quite good and clear, especially for someone using it quite heavily as I do. Thirdly, Nozomi Networks has their own threat intelligence team that enriches the global vulnerable databases with their own work. This is quite important. Quite recently, they added a lot of machine learning AI features to the Vantage.
Nozomi Networks has impacted my organization positively because, keeping in mind that I am an implementer and I implement this to many other organizations. In terms of how this improved, if implemented correctly, which means that fine-tuning is also done and the number of false positives is low, then not only threat monitoring and asset discovery are there, but some organizations whose maturity is high enough are using Nozomi Networks tools, meaning Guardians and sensors, as an OT tool, not only an OT security tool. For example, they can troubleshoot the networks through capabilities that this tool offers. Sometimes it is more than an OT security tool; it is also an OT tool.
What needs improvement?
I think Nozomi Networks should still work on the graphical user interface because it can be more friendly in terms of user experience, especially regarding the flows, the workflows, the intuitiveness of certain things and positions of certain buttons or even creating a dashboard for yourself in a way easier manner. This is something that they can work on. Apart from that, I believe that continuing to incorporate AI features, which they already did, is important, especially in terms of alerts and incidents and how they can be flagged. I am not saying AI should decide whether this is an alert or false positive, but it can certainly advise or recommend something such as, "This seems like a false positive, but perhaps you should troubleshoot," or "This seems serious, so you had better watch this."
For how long have I used the solution?
I have been working in my current field for almost four years.
I have been using Nozomi Networks ever since I started my career in OT security, so also almost four years, let us say three and a half.
What do I think about the stability of the solution?
Nozomi Networks is very stable.
What do I think about the scalability of the solution?
The scalability of Nozomi Networks is super easy to scale up as long as you have a Vantage solution, meaning the private cloud connected to on-premises or on-premises Guardians connected to the private Nozomi Networks cloud. This is super easy to scale. The other type of solution, which is fully on-premises, is also scalable, but not that easy.
How are customer service and support?
The customer support from Nozomi Networks is very helpful. There are dedicated teams for clients, and the response times are quite fast. My experience so far with them is excellent.
Which solution did I use previously and why did I switch?
The majority of our clients are using either Nozomi Networks or, in some cases, Claroty, because Claroty and Nozomi Networks are the best in class, with Nozomi Networks being a little ahead. In our client environments, we sometimes encounter Armis and also sometimes Microsoft Defender for IoT, which is very subpar in terms of the features and capabilities. In some cases, companies are trying to apply more IT-oriented IDSs to their industrial environments, which is also not the best possible way of doing things. For example, Dragos.
How was the initial setup?
My experience with pricing, setup cost, and licensing is that it is pretty straightforward for Nozomi Networks. The whole license model is based on how many assets you need to protect. Previously, it was on-premises versus cloud. So there are two tiers or perhaps more tiers, but two ways of structuring the pricing, and it is quite clear and transparent. I do not think that anyone can be confused by the way they are structuring it. The one caveat is that they recently increased their prices by approximately 30 percent from July 1st, so that is something worth considering.
What about the implementation team?
We have a business relationship with Nozomi Networks as a partner. We are not reselling their offerings, but we are implementing their solutions to our client environments.
What was our ROI?
To be honest, I do not have anything specific regarding a return on investment. Our clients usually focus more on one metric that is always there: adherence to the regulations. This is quite important because some regulations are enforcing network monitoring for industrial networks, and this is what Nozomi Networks is capable of. In terms of reducing the workforce needed to do this work, it is more creating a field of OT security, and an IDS is also always or quite often the first step to create a separate OT security practice that is separated from IT security.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing is that it is pretty straightforward for Nozomi Networks. The whole license model is based on how many assets you need to protect. Previously, it was on-premises versus cloud. So there are two tiers or perhaps more tiers, but two ways of structuring the pricing, and it is quite clear and transparent. I do not think that anyone can be confused by the way they are structuring it. The one caveat is that they recently increased their prices by approximately 30 percent from July 1st, so that is something worth considering.
Which other solutions did I evaluate?
We evaluated and our clients are evaluating many different options for costs and also for the features. So apart from Nozomi Networks, we also consider Claroty, Armis, Dragos, CrowdStrike, and Microsoft Defender for IoT, and one more that I forgot.
What other advice do I have?
I find myself relying on the ability to monitor so many industrial networks, which is the most important part when it comes to my day-to-day workflow. Usually, I do not have to bother about other tools because Nozomi Networks is quite capable on layers zero to three of the Purdue Model. That is something that is usually a selling point when it comes to Nozomi Networks implementations to many different clients that we have.
I would say that the AI features and the machine learning in terms of the alerts and capability of especially lowering the number of false positives is promising, and I am expecting that this will evolve in the nearest future because this is what they are telling us and what we see in the product development on a day-to-day basis in our clients.
I think that the accuracy and reliability of output from Nozomi Networks is adequate. Every tool and every LLM has to be supervised by a human. The last step should always be taking an assessment of the results. In terms of how this is applied and to what it is applied, I do not think that the danger is too high. It is just helping you with the queries. The worst thing that can happen is that this query will show you a different type of things, such as assets or alerts, than you expected, but nothing major will happen.
The level at which AI is implemented now is not raising any red flags because it is usually an easier way to create queries, for example, inside the graphical user interface, the dashboard, or the management tool in order to show only a certain number of alerts that are very precisely described. This was not the case before. The rest of the so-called AI is the machine learning applied to the analysis of packets. So there are no real security flaws in my opinion at this point of the implementation of AI.
My advice for others looking into using Nozomi Networks is to make sure that you really understand your network topology before trying to implement. The best possible solution first is to have an asset inventory, but even if you do not have an asset inventory, you should make sure that you understand what kind of VLANs you have and how your network is segmented. That will make it easier to know how many and what type of devices you need so you do not overspend this way. I rate this product a 9 out of 10.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner