

XM Cyber and The NodeZero Platform by Horizon3.ai provide advanced solutions in the cybersecurity domain. While XM Cyber is favored for its competitive pricing and robust support, The NodeZero Platform leads with its exhaustive feature set, offering significant value despite potential cost implications.
Features: XM Cyber excels in proactive attack path management, continuous monitoring of exposures, and Attack Surface Management. The NodeZero Platform offers automated penetration testing, instant remediation advice, and impressive real attack capabilities to identify vulnerabilities in real-time scenarios.
Room for Improvement: XM Cyber may enhance its real-time breach simulation capabilities and reduce manual intervention in some configurations. Further refinement of user interface and improved integration with diverse third-party tools could be beneficial. The NodeZero Platform could develop its customer support channels for faster issue resolution, optimize costs for small businesses, and offer more detailed guidance for non-technical users to maximize product use.
Ease of Deployment and Customer Service: XM Cyber provides flexible deployment with excellent support options, ensuring smooth integration into existing infrastructure. The NodeZero Platform features a streamlined and automated deployment process that minimizes manual configurations, ideal for quick integration with ongoing operational use.
Pricing and ROI: XM Cyber offers competitive setup costs, providing tangible ROI through continuous risk reduction. Although The NodeZero Platform can be pricier, it provides a compelling ROI through comprehensive security improvements and automation in testing, justifying its value by safeguarding assets efficiently.
A reduction in remediation time has been seen because it is finding things before they happen.
Being able to find them because there have been no eyes on that particular section so far ever, and fixing those potentially prevented those companies from getting breached.
So far, I have seen a return on investment with The NodeZero Platform by Horizon3.ai, as we managed to save a lot of time and effort with this because this is an autonomous tool, and our manual effort is significantly reduced because of a product of this type.
There was a specific issue that our other security tooling did not pick up, but XM Cyber did.
It's reduced the timescale to remediate vulnerabilities that are identified as representing a high risk.
Overall, when it comes to The NodeZero Platform's tech support, you can reach them via a chat message on their website, and they respond almost immediately.
Previously, with time-sensitive engagements, I would worry about resolving issues before deadlines. That concern has diminished as they've become more responsive and require less escalation to engineering.
The vast majority of times they are able to resolve the exact questions my team has on the first attempt, which is really good for customer or technical support.
The customer support is fantastic; it's probably some of the best we've received across all our security vendors.
Customer support for XM Cyber is good, responsive, and it follows up on issues.
We have conducted pen tests in environments with hundreds of thousands of IP addresses without any scalability issues.
We currently scan approximately 1,500-2,000 assets and haven't encountered any scaling or throughput issues.
Anywhere you can put a VM, you can run another concurrent scan.
Its scalability is great; it's easy to deploy and fully scalable.
We have not experienced any issues with scalability or reached its limits.
We have not encountered any issues on the platform regarding accessibility, performance, or stability.
Regarding stability, it has never crashed, and there has not been any lagging from deployment or running.
I would rate the stability of The NodeZero Platform by Horizon3.ai as a ten.
We have quite a complex and large IT estate, and we've certainly experienced no limitations or problems arising from the ability of XM Cyber's product to scale across that estate.
This service reveals which credentials and email addresses are available on the deep web, as well as which domains have been set up using typo-squatting techniques.
The one thing that is very much asked from us as a service provider is DAST testing, so when a company is building a software, they could see their current security status while they are building the application.
One of the areas where improvement is needed is in the visibility and reporting for large enterprises.
We push the boundaries with digital twins; I understand XM Cyber uses a similar concept of graph databases to map environments.
They could improve support because when we need to create a super case and escalate to resolve with technical support, they resolve our ticket in approximately two weeks.
The part that can be improved is the mobile exposure and the IBM i specific equipment.
The pricing is much more affordable than traditional penetration tests.
It's a bit cheaper than manual penetration testing because manual testing typically allows you to scan only a few subnets.
While cheaper than XM Cyber and human pen testers, it's more expensive than vulnerability managers.
We have a large, complicated estate, and in the licensing discussions, we were keen not to have the cost balloon because of the complication, the number of PCs and servers that we have.
When a new vulnerability, such as a zero-day exploit, is identified, they review your previous scans to determine if you might be vulnerable to it, and they proactively notify you.
The detailed reports not only list the vulnerabilities that matter, but they also include direct links to patches.
The NodeZero Platform's real attack capabilities help in identifying vulnerabilities on our on-prem systems because it provides actual vulnerabilities by attacking our systems.
Our loss exposure amount has reduced significantly, leading to two big wins: our loss exposure amount has gone down, and we have direct savings from focusing our team's time on what's important, allowing them to work on other business benefits and generate value for the company.
By far, the best feature of XM Cyber is being able to map out the way vulnerabilities can be exploited based on what they call the choke points in the network where the path that a bad actor would take comes closest to assets within our environment that are most vulnerable but also most valuable.
XM Cyber allows us to quantify the risk, and we are able to track remediation, so we can quantify the risk at an executive level and also to a technical IT team.
| Product | Mindshare (%) |
|---|---|
| The NodeZero Platform by Horizon3.ai | 1.5% |
| XM Cyber | 1.0% |
| Other | 97.5% |


| Company Size | Count |
|---|---|
| Small Business | 10 |
| Midsize Enterprise | 2 |
| Large Enterprise | 6 |
NodeZero by Horizon3.ai is an offensive security platform that enables users to adopt an attacker’s perspective, reveal vulnerabilities, and verify defense effectiveness with evidence-backed insights.
NodeZero provides autonomous pentesting, showing how attackers exploit misconfigurations, credentials, and exposures into attack paths. It helps focus on real risks rather than hypothetical ones, integrating seamlessly into existing IT and security workflows to streamline processes. The platform drives risk-based vulnerability management and CTEM by validating vulnerabilities and measuring resilience.
What standout features improve your security?NodeZero assists in automated penetration testing and vulnerability management in industries like finance and healthcare. It enhances security processes by complementing or replacing existing solutions, enabling efficient testing, feedback, and control validation.
XM Cyber is a leading hybrid cloud security company that’s changing the way innovative organizations approach cyber risk. Our attack path management platform continuously uncovers hidden attack paths to your critical assets across cloud and on-prem environments, so you can cut them off at key junctures and eradicate risk with a fraction of the effort. This overcomes the big disconnect that security teams experience when they’re presented with endless alerts, yet can’t see which exposures impact risk the most, how they come together to be exploited by an attacker, or how to efficiently eliminate them. This approach is a complete game-changer, which is why some of the world’s largest, most complex organizations choose XM Cyber to help eradicate risk. Founded by top executives from the Israeli cyber intelligence community, XM Cyber has offices in North America, Europe, and Israel.
We monitor all Vulnerability Management reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.