Ot Cybersecurity Systems Analyst at a real estate/law firm with 1,001-5,000 employees
Real User
Top 20
Aug 24, 2026
I would suggest that Nozomi Networks could bring up a feature to link the risk rating of the client's assets to the business importance. For example, a building automation system is more important to a building than a traffic counter. An access management system is more important than a lighting control because when access management is lost, the building's security is at question, so that becomes a digital crown jewel for them. It would be great if Nozomi Networks could do some learning about the business critical functions and assign risk scores to assets based on these critical functionality scores and risk scores.
Senior Ot Security Consultant at a tech vendor with 10,001+ employees
Real User
Top 5
Aug 3, 2026
I think Nozomi Networks should still work on the graphical user interface because it can be more friendly in terms of user experience, especially regarding the flows, the workflows, the intuitiveness of certain things and positions of certain buttons or even creating a dashboard for yourself in a way easier manner. This is something that they can work on. Apart from that, I believe that continuing to incorporate AI features, which they already did, is important, especially in terms of alerts and incidents and how they can be flagged. I am not saying AI should decide whether this is an alert or false positive, but it can certainly advise or recommend something such as, "This seems like a false positive, but perhaps you should troubleshoot," or "This seems serious, so you had better watch this."
I see challenges with Nozomi Networks mainly as a detection or visibility tool, but it does not actively block traffic by design for safety reasons. If it detects any abnormalities, it suggests using firewalls, NAC, or manual actions at the time of threat detection. For deeper asset context beyond the network layer, it does not provide that for engineering systems, and sometimes it falls short in SMTP. The main challenges I have noted are cost and scaling considerations; sometimes, clients directly deny requests for additional integration due to Nozomi Networks' high costs. Regarding Nozomi Networks' AI capabilities, I have a mixed opinion. On one hand, I think it is very effective and helpful in strengthening Nozomi Networks itself, but on the other hand, I see potential risks and gaps in governance that are easily detectable. For AI in governance, I recommend creating strong controls along with privacy awareness, data security, operational safety, and most importantly, AI transparency. Much transparency with limited external visibility would be beneficial. Integrating Nozomi Networks with our existing systems was relatively easy at level three due to established tie-ups, but I faced issues when integrating at level two with some OEMs, like Emerson, who do not allow deep dives for monitoring and collecting all data from Nozomi Networks from the tap one.
Sr. Storage And Backup Engineer at a comms service provider with 51-200 employees
Real User
Top 10
May 11, 2026
The potential area of improvement I see for Nozomi Networks is that there are many unknown malwares that cannot be identified because they are not updated in the National Vulnerability Database. Those malwares can infiltrate your system, which Nozomi Networks cannot identify. My suggestion is that Nozomi Networks' operating system should be inbuilt with AI and machine learning. Even though many malwares exist, modern malware can bypass endpoint detection and all security elements. Those malwares should be identified with advanced AI and machine learning. I believe Nozomi Networks needs to work on this continuously. Regarding the functionality of Nozomi Networks, the query syntax is very complicated. The syntax of the queries is very complex, so sometimes you will not get what you want. The command line functionality is not as good as it could be.
On the negative side, I believe their AI, which is IQ, could be more improved. For example, when I export any data, there are only 50 columns available. What if there were more columns? Nozomi Networks does not provide that data, so I have to go to the query section. The AI is currently useful for writing queries in English that are converted into their coding language for queries. Sometimes it provides the correct data, and sometimes it does not understand the request. From my attempts, I would say 50 percent of the time it has given me the proper data, and 50 percent of the time it might need improvement. Every day or week, new threat intelligence and AI upgrades are being released for Vantage, and all those upgrades are being implemented. Things are getting better, but I believe there are areas of improvement.
Country Sales Manager at a computer software company with 51-200 employees
Real User
Top 20
Feb 17, 2026
I would like to see improvements in Nozomi Networks, probably more AI-based integration and better native integration with SOC and SOAR platforms. I would like to see specific features included in the next releases of Nozomi Networks, such as improvements in threat intelligence. They have competition from Dragos, which I believe is better in threat intelligence. I do not have much of an answer about the key differences of Nozomi Networks in comparison to other cyber defense solutions because I only work with Nozomi Networks. However, I heard from the market that they might lack in threat intelligence compared to Dragos. Other than that, I see Nozomi Networks as the best platform for customers, easy to manage, deploy, and operate. The cons might be that they lack some threat intelligence features that Dragos offers.
Security Specialist at a tech consulting company with 51-200 employees
Real User
Top 5
Mar 12, 2025
Nozomi Networks currently offers add-ons, such as ARP agents, that can be installed on machines to expand the information we receive from sensors. However, these are part of a licensing structure, which can be costly. It would be very helpful if these agents were available free of charge. The solution itself has no major problems, but this is a feature request I would make for improvement.
Production Quality Engineer Specialist at a manufacturing company with 10,001+ employees
Real User
Top 10
Nov 12, 2024
I would like more customizable options for configurations. Creating custom queries is time-consuming. It would be beneficial if more options were added for easier configurations.
Nozomi Networks enhances ICS and OT cybersecurity through threat detection, monitoring, and comprehensive asset management. Users value its real-time anomaly detection, advanced threat detection via machine learning, and intuitive interface, which streamline workflows and boost efficiency, ensuring compliance and robust network security.
I would suggest that Nozomi Networks could bring up a feature to link the risk rating of the client's assets to the business importance. For example, a building automation system is more important to a building than a traffic counter. An access management system is more important than a lighting control because when access management is lost, the building's security is at question, so that becomes a digital crown jewel for them. It would be great if Nozomi Networks could do some learning about the business critical functions and assign risk scores to assets based on these critical functionality scores and risk scores.
I think Nozomi Networks should still work on the graphical user interface because it can be more friendly in terms of user experience, especially regarding the flows, the workflows, the intuitiveness of certain things and positions of certain buttons or even creating a dashboard for yourself in a way easier manner. This is something that they can work on. Apart from that, I believe that continuing to incorporate AI features, which they already did, is important, especially in terms of alerts and incidents and how they can be flagged. I am not saying AI should decide whether this is an alert or false positive, but it can certainly advise or recommend something such as, "This seems like a false positive, but perhaps you should troubleshoot," or "This seems serious, so you had better watch this."
I see challenges with Nozomi Networks mainly as a detection or visibility tool, but it does not actively block traffic by design for safety reasons. If it detects any abnormalities, it suggests using firewalls, NAC, or manual actions at the time of threat detection. For deeper asset context beyond the network layer, it does not provide that for engineering systems, and sometimes it falls short in SMTP. The main challenges I have noted are cost and scaling considerations; sometimes, clients directly deny requests for additional integration due to Nozomi Networks' high costs. Regarding Nozomi Networks' AI capabilities, I have a mixed opinion. On one hand, I think it is very effective and helpful in strengthening Nozomi Networks itself, but on the other hand, I see potential risks and gaps in governance that are easily detectable. For AI in governance, I recommend creating strong controls along with privacy awareness, data security, operational safety, and most importantly, AI transparency. Much transparency with limited external visibility would be beneficial. Integrating Nozomi Networks with our existing systems was relatively easy at level three due to established tie-ups, but I faced issues when integrating at level two with some OEMs, like Emerson, who do not allow deep dives for monitoring and collecting all data from Nozomi Networks from the tap one.
The potential area of improvement I see for Nozomi Networks is that there are many unknown malwares that cannot be identified because they are not updated in the National Vulnerability Database. Those malwares can infiltrate your system, which Nozomi Networks cannot identify. My suggestion is that Nozomi Networks' operating system should be inbuilt with AI and machine learning. Even though many malwares exist, modern malware can bypass endpoint detection and all security elements. Those malwares should be identified with advanced AI and machine learning. I believe Nozomi Networks needs to work on this continuously. Regarding the functionality of Nozomi Networks, the query syntax is very complicated. The syntax of the queries is very complex, so sometimes you will not get what you want. The command line functionality is not as good as it could be.
On the negative side, I believe their AI, which is IQ, could be more improved. For example, when I export any data, there are only 50 columns available. What if there were more columns? Nozomi Networks does not provide that data, so I have to go to the query section. The AI is currently useful for writing queries in English that are converted into their coding language for queries. Sometimes it provides the correct data, and sometimes it does not understand the request. From my attempts, I would say 50 percent of the time it has given me the proper data, and 50 percent of the time it might need improvement. Every day or week, new threat intelligence and AI upgrades are being released for Vantage, and all those upgrades are being implemented. Things are getting better, but I believe there are areas of improvement.
I would like to see improvements in Nozomi Networks, probably more AI-based integration and better native integration with SOC and SOAR platforms. I would like to see specific features included in the next releases of Nozomi Networks, such as improvements in threat intelligence. They have competition from Dragos, which I believe is better in threat intelligence. I do not have much of an answer about the key differences of Nozomi Networks in comparison to other cyber defense solutions because I only work with Nozomi Networks. However, I heard from the market that they might lack in threat intelligence compared to Dragos. Other than that, I see Nozomi Networks as the best platform for customers, easy to manage, deploy, and operate. The cons might be that they lack some threat intelligence features that Dragos offers.
Nozomi Networks currently offers add-ons, such as ARP agents, that can be installed on machines to expand the information we receive from sensors. However, these are part of a licensing structure, which can be costly. It would be very helpful if these agents were available free of charge. The solution itself has no major problems, but this is a feature request I would make for improvement.
I believe there is room for improvement regarding on-premises AI.
I would like more customizable options for configurations. Creating custom queries is time-consuming. It would be beneficial if more options were added for easier configurations.
Nozomi Networks should improve its pricing.
The solution should include an integration library.
Proof of concept could be improved. It could be more tangible to the customer and the end users to have a video presentation or something like that.