Fast, Accurate, and Versatile for Multiple Penetration Testing Types
What do you like best about the product?
Speed and accuracy. Support for the multiple types of penetration testing.
What do you dislike about the product?
The installation - docker solution that can be pain in real enterprise grade networks. Customization / fine tuning is missing. Support for custom templates, custom actions.
What problems is the product solving and how is that benefiting you?
I can run multiple pentests in parallel, which helps a lot with the work that can be automated. It delivers great results in a reasonable amount of time.
Automated testing has transformed how we deliver fast, consistent security assessments
What is our primary use case?
The primary use case for the NodeZero platform by Horizon3.ai is to deliver penetration testing as a service to our clients, enabling us to support their security assurance, risk reduction, and compliance obligations.
What is most valuable?
The key capabilities of the NodeZero platform by Horizon3.ai that I have found most valuable are its speed, scalability, and consistency. It is able to cover a broad scope in a relatively short period of time, which delivers significant efficiency gains when compared with traditional manual testing. It also provides a more consistent outcome, as the process is not influenced by human bias or variability.
One of the most valuable features is the ability for security teams to remediate and retest vulnerabilities immediately. The one-click verification capability is particularly effective, as it allows fixes to be validated quickly without the need to rerun the entire assessment. This streamlines the remediation cycle and supports faster confirmation of security improvements.
The platform’s real attack capabilities have also helped reduce false positives in the identification of vulnerabilities across our on-premises systems. Because the findings are evidence-based and validated prior to reporting, the results are more reliable and actionable. This enables us to focus our efforts on confirmed security issues that genuinely require attention, rather than spending time investigating theoretical or unverified exposures.
The NodeZero platform also strengthens my understanding of potential security threats through its continuously updated capabilities. With new vulnerabilities emerging and being exploited in the wild on a regular basis, it is valuable to have a platform backed by a strong research and development function that continuously updates attack content to reflect the current threat landscape. This makes the platform effective not only as a point-in-time validation tool, but as part of an ongoing and continuous security assurance programme.
What needs improvement?
At present, the platform is relatively rigid in how it operates and offers limited flexibility to align with individual user preferences or organisational requirements. While this structured approach has advantages in maintaining consistency, it can also be restrictive in practice.
In particular, greater flexibility around reporting and risk scoring would add significant value. For example, the ability for users to adjust or contextualise vulnerability ratings based on their own environment, risk appetite, or compensating controls would make the reporting more adaptable and relevant to different use cases.
For how long have I used the solution?
I have been working with the NodeZero platform by Horizon3.ai for nearly a year, with hands-on experience using the platform since August of last year.
What do I think about the stability of the solution?
I would evaluate the NodeZero platform by Horizon3.ai as excellent in terms of stability and reliability. We have not experienced any issues with accessibility or availability, and the platform has consistently performed as expected.
I would rate the stability of the NodeZero platform by Horizon3.ai as 10 out of 10.
What do I think about the scalability of the solution?
I consider the NodeZero platform by Horizon3.ai to be highly scalable. It is well-suited to enterprise environments, straightforward to deploy, and can be implemented within minutes. Its speed and breadth of testing enable it to assess large areas of network coverage in a relatively short period of time.
I would rate the scalability of the NodeZero platform by Horizon3.ai as 10 out of 10.
How are customer service and support?
I interact with both the technical support and customer service teams at Horizon3.ai in relation to the NodeZero platform.
I have direct access to representatives in my region through a dedicated messaging channel, which makes communication quick and efficient. Whenever I need assistance, I can reach out directly and typically receive a response within an hour, and often sooner. In my experience, the team has been consistently responsive, helpful, and easy to work with.
I would rate the technical support for the NodeZero platform by Horizon3.ai as 9 out of 10, with 10 representing the highest level of support.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
Prior to using the NodeZero platform by Horizon3.ai, our security testing activities were conducted entirely through manual methods, as we had not previously utilised an automated platform of this nature.
How was the initial setup?
The installation process for the NodeZero platform by Horizon3.ai is straightforward and easy to complete. The deployment workflow is simple: you download the preconfigured virtual machine from the Horizon3.ai website, run it within the target environment, and then copy and execute the provided script within the locally deployed agent. Once that is done, the platform is ready to begin testing almost immediately.
In my experience, I have not encountered any challenges or blockers during installation. The overall setup process has been smooth, intuitive, and reliable.
What about the implementation team?
I participated in the initial setup and deployment process of The NodeZero Platform by Horizon3.ai.
What was our ROI?
So far, I have seen a clear return on investment from the NodeZero platform by Horizon3.ai. As an autonomous solution, it has enabled us to save a significant amount of time and effort by reducing the level of manual work required. This has been one of the key benefits of adopting a platform of this type.
In addition, because the platform is designed to scale effectively for enterprise environments, it has also helped us improve efficiency on larger engagements. As a result, we are seeing cost savings through reduced effort and a more streamlined delivery model.
Which other solutions did I evaluate?
Before selecting the NodeZero platform by Horizon3.ai, I evaluated several alternative solutions from other vendors, including Pentera and RidgeBot.
We ultimately chose NodeZero for three main reasons. First, its technical capabilities were better aligned with the specific use cases and outcomes we were looking to achieve. Second, it was more commercially competitive and offered better value than the other solutions we assessed. Third, the quality of both customer and technical support was a key differentiator. Whenever we required assistance, advice, or issue resolution, the Horizon3.ai team was responsive, accessible, and highly supportive in working through our requirements.
What other advice do I have?
As a managed security service provider, we use the NodeZero platform by Horizon3.ai in both a reseller and advisory capacity.
Its impact on remediation has been particularly positive. The platform provides a clear and efficient way to manage remediation through its dedicated vulnerability management capabilities, with the added benefit of integration into platforms such as Jira and ServiceNow. Because findings are evidence-based and validated, the output is highly actionable and carries a low false-positive rate, making it a strong remediation enablement tool.
From a commercial perspective, I am familiar with the platform’s pricing and licensing structure and consider it to be well-positioned across market segments. Its tiered pricing model makes it accessible for small and medium-sized businesses, while its enterprise packages provide the additional functionality required by larger organisations.
The platform has helped us reduce our penetration testing delivery costs, which was a key objective for us as a consultancy and service provider. Although I cannot disclose a specific percentage reduction, the cost savings have been significant.
My overall rating for the NodeZero platform by Horizon3.ai is eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Deploying autonomous security tools improves network protection and efficiency
What is our primary use case?
The primary use case for the NodeZero Platform is as an extension to existing vulnerability management systems. Initially, it complemented solutions like Qualys or Tenable. However, there has been a shift towards using NodeZero to replace existing vulnerability management solutions altogether. The motivations include cost savings and addressing issues that traditional vulnerability managers might report but do not actually affect system security.
What is most valuable?
Deploying the NodeZero Platform is straightforward for me as it involves just a
Docker container in a network or a network segment, saving time and eliminating the need for agents on every endpoint. Its autonomous operation, safe for production use, makes it practical to schedule pen tests during business hours. The tripwires feature acts like a honeypot, providing network alerts for potential threats. These factors make it an effective tool for enhancing security in organizations.
What needs improvement?
One of the areas where improvement is needed is in the visibility and reporting for large enterprises. The existing GUI or NodeZero insights provide better visibility, but there's still room for enhancement. Moreover, there is a need to automate interactions with other systems, particularly in triggering or opening tickets in
ServiceNow. Adding the application layer would also be valuable for clients.
For how long have I used the solution?
I have used the solution for 1.5 years.
What was my experience with deployment of the solution?
No issues were encountered in deploying the NodeZero Platform. Once the firewalls are open and communication with the cloud is enabled, it's a matter of installing a
Docker container or VMware and opening the ports for smooth operation.
What do I think about the stability of the solution?
I rate the stability of the NodeZero Platform a ten out of ten. We have not encountered any issues on the platform regarding accessibility, performance, or stability.
What do I think about the scalability of the solution?
I rate the scalability of the NodeZero Platform a ten out of ten. We have conducted pen tests in environments with hundreds of thousands of IP addresses without any scalability issues. The platform is built for large scale deployment and operation.
How are customer service and support?
I rate their support an eight out of ten. The support is skilled and effective, although there are sometimes delays due to bandwidth issues, possibly due to the size of the team.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
Initially, NodeZero and similar solutions were used alongside existing vulnerability management solutions like Qualys or Tenable. However, there has been a shift towards replacing these existing solutions as businesses seek to address vulnerability issues more efficiently.
How was the initial setup?
The initial setup is very easy, rated 10 out of 10. It involves straightforward steps of installing a Docker container, configuring firewalls, and ensuring communication with the cloud.
What about the implementation team?
The deployment process involves an initial meeting with the client to choose the deployment method—either on a VMware or Docker container. This is followed by defining and setting up firewall rules. After preparing everything, deploying the Docker container or VMware takes a few minutes, and the pen test can begin.
What's my experience with pricing, setup cost, and licensing?
I rate the pricing a six out of ten. Pricing is moderate compared to competitors but depends on the solutions in comparison. While cheaper than
XM Cyber and human pen testers, it's more expensive than vulnerability managers.
Which other solutions did I evaluate?
I evaluated
Pentera and
XM Cyber alongside the NodeZero Platform at various points.
Pentera was assessed about two years ago, and we have clients currently using XM Cyber.
What other advice do I have?
I rate the NodeZero Platform an eight out of ten. The platform is scalable and stable, suitable for large enterprises and businesses. It needs improvement in areas like visibility, reporting, and automation with third-party systems. The overall product rating is eight.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Penetration testing adapts to our schedule with cloud integration
What is our primary use case?
To meet standards, I am required to do penetration testing periodically. This is something I can do on-demand anytime I choose, or I can set it up to recur on a recurring schedule.
What is most valuable?
The NodeZero Platform has a great cost, and its usability is straightforward. It can be deployed in the cloud. There is an on-premise container that I need to spin up to allow it to run in my environment, but it is automatically updated because it is cloud-based. It uses AI to try and gain access to my network and learns from the environment as it goes, providing a report on vulnerabilities, and demonstrates how their system exploits them to either elevate privilege or gain access to specific credentials or devices.
What needs improvement?
I haven't really come across anything that I say needs to be improved with it, other than the container runner, which tends to lose time. It does not always sync with the cloud versions, so I have to do it manually.
For how long have I used the solution?
I have used the solution for over a year.
What do I think about the stability of the solution?
Initially, there were some devices that, when it scanned, it caused network issues. So I had to exclude those, but that was fairly simple to do.
How are customer service and support?
I reached out to support and they were very responsive. I would rate them a nine out of ten.
Which solution did I use previously and why did I switch?
I have reviewed other penetration testing solutions but haven't used them due to cost constraints, as they were really expensive compared to the NodeZero Platform.
How was the initial setup?
The initial setup was simple and easy to operate.
What's my experience with pricing, setup cost, and licensing?
The pricing is much more affordable than traditional penetration tests.
Which other solutions did I evaluate?
I have reviewed other penetration testing solutions but did not use any due to cost constraints.
What other advice do I have?
I would advise taking advantage of the support when you have it. For Horizon360 NodeZero, they are always responsive. Let them show you how to use it and the best way to get the most out of it. Overall, I'd rate NodeZero at nine to 9.5 out of ten.