Nucleus Enterprise Vulnerability Management Platform
Filters
Review type
Unified vulnerability data has transformed risk prioritization and optimized remediation effort
What is our primary use case?
My main use case for Nucleus Security is unifying the vulnerability management landscape, providing a single source of truth for vulnerabilities.
What is most valuable?
The best features that Nucleus Security offers in my experience are the unified integrations with all of the different vulnerability management platforms. It is helping quite a lot to unify all of that. It also offers good prioritization based on the EPSS or the CVSS score, as well as different other factors including Mandiant threat intelligence and similar aspects. It helps bring it all into one big picture instead of different silos of vulnerabilities.
The integrations make my job easier because I can connect my other tools, which is the most important part of this tool to bring in all the vulnerabilities from the different other tools. The prioritization changed it from chasing vulnerabilities or pushing colleagues to patch vulnerabilities to providing colleagues with their vulnerabilities and requesting remediation and patching.
Nucleus Security positively impacts my organization by bringing awareness to vulnerability management since we can actually determine how many vulnerabilities we have and how critical the risk is, or we can quantify the risk overall for the company.
What needs improvement?
Nucleus Security needs a better view into exposure management, as exposure management and attack path management are missing. It also needs better and easier self-service integrations, as the integration might take longer than desired.
I do not really use the integration with the ticketing systems. It is reliable, but it is not that easy. I think they will improve it in the future to make it easier to integrate new tools.
For how long have I used the solution?
I have been using Nucleus Security for around two years.
What do I think about the stability of the solution?
Nucleus Security is stable most of the time, but not always; the performance varies.
What do I think about the scalability of the solution?
As long as I purchase enough licenses, Nucleus Security can scale as much as I want.
How are customer service and support?
Customer support has met our expectations. While faster response times would enhance the experience, the support provided has been reliable and effective.
Which solution did I use previously and why did I switch?
I did not previously use a different solution; the topic of unified vulnerability management is rather new, so I did not have any solution before that.
How was the initial setup?
The pricing, setup costs, and licensing are reasonable; while it isn’t a budget option, it offers fair value for the price.
What was our ROI?
I have seen a return on investment. With security, it is always hard to quantify, and we did not really save money, but we used time more effectively and changed our way of working. I would say time saved is the primary benefit.
Which other solutions did I evaluate?
Before choosing Nucleus Security, I evaluated other options and looked into all the other solutions, but at that point in time, Nucleus Security was the main company offering something like this, making it clear that Nucleus Security would be the company to go with.
What other advice do I have?
I assess Nucleus Security's feature of providing unified exposure visibility across all tools I use as great because I can use all of the data and get all the vulnerabilities in one central place. It has a lot of capabilities, and this is the strongest feature of Nucleus Security. Providing this unified exposure visibility is doing a good job. The integrations could be easier, but the rest is working rather well. I have to work a lot with asset rule lists, so I have to do a lot of automation or processing of the data in Nucleus Security, but at the end of the day, as soon as I set up those rules, I am good to go.
Risk-based prioritization is crucial for addressing vulnerabilities in my organization because I cannot fix all the vulnerabilities; I have to know what I need to handle, how big the risk is, and what the highest risk is that I need to tackle. That is exactly what Nucleus Security is offering.
I did not use the risk reduction measurement feature in Nucleus Security, as risk reduction measurement is not something I am familiar with, but I have used the metrics and trends from Nucleus Security to assess how we are developing, especially regarding the remediation performance.
My advice for others looking into using Nucleus Security is to think about your processes as well. You need to consider where you want to go and think a lot about how you want to use and work with vulnerabilities in the future. I have given this review a rating of eight out of ten.