Best Attack Surface Management Software for Small Business

How Many Attack Surface Management Software Products Does G2 Track?

Total Products under this Category: 170

Category Stats (Aug 2026)

  • Average Rating: 4.6/5 The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: UpGuard Breach Risk (+0.92%) - Among all products in this category, UpGuard Breach Risk recorded the largest rating increase compared to last month

Last updated: August 12, 2026

How Does G2 Rank Attack Surface Management Software Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 5,400+ Authentic Reviews
  • 170+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Attack Surface Management Software

G2 Grid® for  Attack Surface Management Software plotting products by satisfaction and market presence

Highlighted products: Wiz, Intruder, RiskProfiler - External Threat Exposure Management, Scrut Automation, Cyble, CTM360, SentinelOne Singularity Cloud Security, and Pentera.

Underlying data: [Grid® JSON](https://www.g2.com/categories/attack-surface-management/grids.json?focus%5B%5D=wiz-wiz&focus%5B%5D=intruder&focus%5B%5D=riskprofiler-external-threat-exposure-management&focus%5B%5D=scrut-automation&focus%5B%5D=cyble&focus%5B%5D=ctm360-ctm360&focus%5B%5D=sentinelone-singularity-cloud-security&focus%5B%5D=pentera&segment=small-business)

Sponsored

Intruder

Intruder's continuous exposure management platform helps security, IT, and engineering teams stop breaches before they start. By unifying AI penetration testing, attack surface monitoring, cloud security, and vulnerability management in one intuitive platform, Intruder gives stretched teams an always-on security source of truth. Our approach focuses on continuous automated scanning using expertise and agentic solutions to ensure that the findings we deliver are accurate, prioritized by real-world risk, and ready to act on. Founded in 2015 by Chris Wallis, a former ethical hacker turned corporate blue teamer, Intruder is now protecting over 3,000 companies worldwide. Intruder has been awarded multiple accolades, was selected for GCHQ’s Cyber Accelerator, included on Deloitte’s Tech Fast 50 2023 list as the fastest-growing cybersecurity company in the UK and was named in G2’s 2026 Best Software Awards.

Visit website

Wiz

Wiz transforms cloud security for customers – including more than 50% of the Fortune 100 – by enabling a new operating model. With Wiz, organizations can democratize security across the development lifecycle, empowering them to build fast and securely. Its Cloud Native Application Protection Platform (CNAPP) consolidates CSPM, KSPM, CWPP, Vulnerability management, IaC scanning, CIEM, DSPM into a single platform. Wiz drives visibility, risk prioritization, and business agility. Protecting Your Cloud Environments Requires a Unified, Cloud Native Platform. Wiz connects to every cloud environment, scans every layer, and covers every aspect of your cloud security - including elements that normally require installing agents. Its comprehensive approach has all of these cloud security solutions built in. Hundreds of organizations worldwide, including 50 percent of the Fortune 100, to rapidly identify and remove critical risks in cloud environments. Its customers include Salesforce, Slack, Mars, BMW, Avery Dennison, Priceline, Cushman & Wakefield, DocuSign, Plaid, and Agoda, among others. Wiz is backed by Sequoia, Index Ventures, Insight Partners, Salesforce, Blackstone, Advent, Greenoaks, Lightspeed and Aglaé. Visit https://www.wiz.io for more information.

Average Rating: 4.7/5.0

Total Reviews: 840

How Do G2 Users Rate Wiz?

  • Vulnerability Intelligence: 9.0/10 (Category avg: 9.0/10)
  • Continuous Monitoring: 9.0/10 (Category avg: 9.2/10)
  • Compliance Monitoring: 8.8/10 (Category avg: 8.6/10)
  • Ease of Admin: 9.0/10 (Category avg: 9.0/10)

Who Is the Company Behind Wiz?

  • Seller: Wiz
  • Company Website:
  • Year Founded: 2020
  • HQ Location: New York, US
  • Twitter: @wiz_io
    24,733 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    3,383 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: CISO, Security Engineer
  • Top Industries: Financial Services, Computer Software
  • Company Size: 53% Large, 39% Medium

What Do G2 Reviewers Say About Wiz?

AI-generated summary from verified user reviews

Pros
  • Users commend the capable APIs and user-friendly UI, providing valuable insights and continuous improvements in security features.
  • Users value the unmatched security features of Wiz, providing comprehensive visibility and proactive threat management capabilities.
  • Users find Wiz's product suite extremely easy to use, benefiting from seamless integration and a user-friendly interface.
  • Users appreciate the visibility Wiz offers, enhancing security posture and prioritizing critical vulnerabilities effectively.
  • Users praise the easy setup of Wiz, enabling quick deployment and seamless integration across modules for enhanced security.
Cons
  • Users experience a steep learning curve with Wiz, making it challenging for newcomers to fully utilize the platform.
  • Users find the feature limitations of Wiz, such as complex reporting and management, hinder user-friendliness and efficiency.
  • Users highlight the need for improvement in performance and reporting capabilities to enhance overall usability of Wiz.
  • Users note several improvements needed, particularly in dashboard reporting and the complexity of the pricing model.
  • Users find the complexity of the interface overwhelming initially, requiring time to adapt and learn effectively.

What Are Recent G2 Reviews of Wiz?

Intruder

Intruder's continuous exposure management platform helps security, IT, and engineering teams stop breaches before they start. By unifying AI penetration testing, attack surface monitoring, cloud security, and vulnerability management in one intuitive platform, Intruder gives stretched teams an always-on security source of truth. Our approach focuses on continuous automated scanning using expertise and agentic solutions to ensure that the findings we deliver are accurate, prioritized by real-world risk, and ready to act on. Founded in 2015 by Chris Wallis, a former ethical hacker turned corporate blue teamer, Intruder is now protecting over 3,000 companies worldwide. Intruder has been awarded multiple accolades, was selected for GCHQ’s Cyber Accelerator, included on Deloitte’s Tech Fast 50 2023 list as the fastest-growing cybersecurity company in the UK and was named in G2’s 2026 Best Software Awards.

Average Rating: 4.8/5.0

Total Reviews: 209

How Do G2 Users Rate Intruder?

  • Vulnerability Intelligence: 9.5/10 (Category avg: 9.0/10)
  • Continuous Monitoring: 9.6/10 (Category avg: 9.2/10)
  • Compliance Monitoring: 9.3/10 (Category avg: 8.6/10)
  • Ease of Admin: 9.5/10 (Category avg: 9.0/10)

Who Is the Company Behind Intruder?

  • Seller: Intruder
  • Company Website:
  • Year Founded: 2015
  • HQ Location: London
  • Twitter: @intruder_io
    979 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    84 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: CTO, Director
  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 57% Small, 36% Medium

What Do G2 Reviewers Say About Intruder?

AI-generated summary from verified user reviews

Pros
  • Users find the ease of use of Intruder perfect for configuring and scanning cloud resources efficiently.
  • Users appreciate the easy configuration of vulnerability detection, making it simple to secure cloud resources efficiently.
  • Users value the exceptional customer support from Intruder, highlighting quick responses and friendliness during their experience.
  • Users value Intruder's easy-to-use interface and seamless integration, enhancing their cybersecurity management experience significantly.
  • Users value the easy configuration of Intruder, allowing timely identification of vulnerabilities across cloud resources.
Cons
  • Users find the service to be expensive, suggesting improvements in pricing models for better value.
  • Users report slow scanning as Intruder misses some vulnerabilities and lacks integration with comprehensive testing tools.
  • Users struggle with the licensing model of Intruder, finding it complex and not immediately intuitive.
  • Users experience false positives from Intruder, leading to confusion between critical and lower-risk vulnerabilities.
  • Users find the limited features of Intruder frustrating, especially regarding reporting flexibility and license understanding.

What Are Recent G2 Reviews of Intruder?

What Are G2 Users Discussing About Intruder?

RiskProfiler - External Threat Exposure Management

RiskProfiler is an advanced cybersecurity platform purpose-built for Continuous Threat Exposure Management (CTEM). It unifies external, cloud, vendor, and brand risk intelligence into a single ecosystem—providing organizations with real-time visibility, contextual threat insights, and actionable remediation guidance. Through its integrated suite, External Attack Surface Managemnet, Third_party Risk Management, Cloud Attack Surface Management, and Brand Risk Protection; the platform continuously discovers, classifies, and evaluates external-facing assets and risks across the internet, multi-cloud environments, and third-party ecosystems. Powered by AI-enabled risk questionnaires, RiskProfiler automates the exchange, validation, and scoring of security assessments, dramatically accelerating third-party due diligence and compliance validation. The platform’s context-enriched graph engine correlates vulnerabilities, exposures, and configurations with real-world threat data, revealing how attackers might exploit an organization’s digital footprint. Its newly enhanced Cyber Threat Intelligence (CTI) module provides live insights into industry-specific attack trends, threat actor profiles, and evolving TTPs, directly embedded within the dashboard. By analyzing CVEs, IOCs, and exploit patterns, it maps these to relevant assets and potential attack paths, enabling focused, prioritized mitigation. From identifying exposed cloud resources across AWS, Azure, and Google Cloud to uncovering brand impersonation, phishing campaigns, or logo abuse, RiskProfiler delivers unified visibility and continuous monitoring that extends beyond the perimeter. It helps organizations anticipate, contextualize, and neutralize threats before they turn into breaches, transforming exposure management into a truly intelligent, predictive defense capability.

Average Rating: 4.9/5.0

Total Reviews: 118

How Do G2 Users Rate RiskProfiler - External Threat Exposure Management?

  • Vulnerability Intelligence: 10.0/10 (Category avg: 9.0/10)
  • Continuous Monitoring: 9.9/10 (Category avg: 9.2/10)
  • Compliance Monitoring: 9.9/10 (Category avg: 8.6/10)
  • Ease of Admin: 9.7/10 (Category avg: 9.0/10)

Who Is the Company Behind RiskProfiler - External Threat Exposure Management?

  • Seller: Riskprofiler
  • Company Website:
  • Year Founded: 2019
  • HQ Location: Rock Hill , US
  • Twitter: @riskprofilerio
    209 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    32 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Software Engineer, Security Consultant
  • Top Industries: Information Technology and Services, Design
  • Company Size: 66% Medium, 33% Small

What Do G2 Reviewers Say About RiskProfiler - External Threat Exposure Management?

AI-generated summary from verified user reviews

Pros
  • Users value the effective risk management capabilities of RiskProfiler, facilitating informed decisions and quick responses to threats.
  • Users appreciate the seamless onboarding and integration of RiskProfiler, enhancing visibility and monitoring of external threats.
  • Users commend the fast and efficient customer support of RiskProfiler, enhancing their overall experience and response time.
  • Users value the ease of use of RiskProfiler, particularly the seamless integration and user-friendly dashboard.
  • Users value the easy setup of RiskProfiler, appreciating its intuitive dashboard and quick implementation process.
Cons
  • Users face a steep learning curve with RiskProfiler, requiring time for training and customization to navigate effectively.
  • Users find the complexity of RiskProfiler overwhelming, necessitating significant time for training and adjustment.
  • Users find a difficult learning curve for RiskProfiler, requiring significant training and time to navigate effectively.
  • Users find the learning difficulty of RiskProfiler challenging, necessitating extra training and time for effective use.
  • Users find the complex setup of RiskProfiler challenging, particularly for non-specialist teams trying to integrate it.

What Are Recent G2 Reviews of RiskProfiler - External Threat Exposure Management?

Scrut Automation

Scrut Automation is a leading compliance automation platform designed for fast-growing businesses looking to streamline security, risk, and compliance without disrupting operations. It centralizes compliance functions, automates evidence collection, and simplifies audits, helping security teams reduce compliance efforts. Scrut supports 70+ out-of-the-box frameworks, including SOC 2, ISO 27001, GDPR, HIPAA, and PCI-DSS, with the flexibility to add custom frameworks for unique regulatory needs. With 150+ integrations, Scrut seamlessly integrates into your security and IT ecosystem, automating compliance, eliminating manual work, and improving risk visibility. Join 2500+ industry leaders who trust Scrut for simplified compliance and risk management. Schedule a demo today.

Average Rating: 4.9/5.0

Total Reviews: 1,311

How Do G2 Users Rate Scrut Automation?

  • Vulnerability Intelligence: 9.5/10 (Category avg: 9.0/10)
  • Continuous Monitoring: 9.5/10 (Category avg: 9.2/10)
  • Compliance Monitoring: 9.5/10 (Category avg: 8.6/10)
  • Ease of Admin: 9.6/10 (Category avg: 9.0/10)

Who Is the Company Behind Scrut Automation?

  • Seller: Scrut Automation
  • Company Website:
  • Year Founded: 2022
  • HQ Location: Palo Alto, US
  • Twitter: @scrutsocial
    120 Twitter followers
  • LinkedIn® Page: in.linkedin.com
    233 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: CTO, CEO
  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 50% Small, 48% Medium

What Do G2 Reviewers Say About Scrut Automation?

AI-generated summary from verified user reviews

Pros
  • Users find Scrut Automation's ease of use invaluable for tracking tasks and maintaining team access effectively.
  • Users commend the outstanding customer support of Scrut Automation, highlighting teamwork and effective guidance throughout the process.
  • Users appreciate the exceptional support and guidance from Scrut's team, significantly enhancing their compliance experience.
  • Users value the exceptional compliance management by Scrut Automation, finding it efficient and cost-effective for SOC 2 processes.
  • Users value the supportive compliance assistance from Scrut Automation, enhancing clarity and ease during audits.
Cons
  • Users feel that Scrut Automation requires significant improvements in UI clarity and documentation quality for better usability.
  • Users note the missing features in Scrut Automation, particularly in auto-answering questionnaires and report customization.
  • Users face technical issues with complex modules and occasional login problems, impacting the overall user experience.
  • Users find the learning curve steep, making navigation and understanding challenging for newcomers to Scrut Automation.
  • Users express concerns over lack of clarity in test results and policy processes, complicating their experience with Scrut Automation.

What Are Recent G2 Reviews of Scrut Automation?

What Are G2 Users Discussing About Scrut Automation?

Cyble

Cyble is an AI-native cybersecurity solution designed to help organizations enhance their digital security posture through real-time intelligence, detection, and response capabilities. By leveraging advanced agentic AI and processing vast amounts of data, Cyble empowers businesses to navigate the complexities of the cyber threat landscape effectively. Its unique approach involves collecting and enriching signals from various sources, including the dark web, deep web, and surface web, providing unparalleled visibility into emerging threats and adversarial activities. Targeting a wide range of industries, Cyble's platform is particularly beneficial for security teams, risk management professionals, and organizations that prioritize safeguarding their digital assets. The comprehensive suite of solutions offered by Cyble includes Threat Intelligence, Dark Web & Deep Web Monitoring, Attack Surface Management (ASM), and Brand Intelligence, among others. These tools are designed to address specific use cases such as identifying vulnerabilities, monitoring brand reputation, and managing third-party risks, making it an essential resource for organizations aiming to bolster their cybersecurity measures. Cyble's key features are centered around its unified platform, which integrates multiple cybersecurity functions into a single interface. This integration allows for seamless communication between different security components, enabling teams to anticipate, identify, and neutralize threats with remarkable speed and precision. For instance, the Digital Forensics & Incident Response (DFIR) capabilities equip organizations with the tools needed to investigate and respond to incidents effectively, while the DDoS Protection and Cloud Security Posture Management (CSPM) features ensure that businesses can maintain operational integrity even under attack. Moreover, Cyble stands out in its category by combining vast data intelligence with cutting-edge AI automation. This proactive defense strategy not only helps organizations react to cyber threats but also empowers them to stay ahead of potential risks. By enhancing visibility into the threat landscape and providing actionable insights, Cyble enables enterprises to protect their assets, safeguard brand trust, and operate with confidence in an increasingly complex digital environment. The result is a robust cybersecurity framework that supports organizations in navigating the ever-evolving challenges of the cyber world.

Average Rating: 4.8/5.0

Total Reviews: 144

How Do G2 Users Rate Cyble?

  • Vulnerability Intelligence: 9.5/10 (Category avg: 9.0/10)
  • Continuous Monitoring: 9.5/10 (Category avg: 9.2/10)
  • Compliance Monitoring: 9.1/10 (Category avg: 8.6/10)
  • Ease of Admin: 9.6/10 (Category avg: 9.0/10)

Who Is the Company Behind Cyble?

  • Seller: Cyble
  • Company Website:
  • Year Founded: 2019
  • HQ Location: Alpharetta, US
  • Twitter: @cybleglobal
    16,252 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    233 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer & Network Security
  • Company Size: 39% Large, 17% Medium

What Do G2 Reviewers Say About Cyble?

AI-generated summary from verified user reviews

Pros
  • Users value the intuitive and user-friendly interface of Cyble, making threat intelligence management seamless and efficient.
  • Users value the comprehensive threat protection of Cyble, facilitating efficient threat intel and seamless integrations.
  • Users appreciate the state-of-the-art equipment and comprehensive threat monitoring tools offered by Cyble for effective risk management.
  • Users appreciate the real-time insights provided by Cyble, enhancing threat detection and proactive cybersecurity measures.
  • Users value Cyble's real-time threat detection capabilities, which enhance digital risk protection and streamline security efforts.
Cons
  • Users experience inefficient alerts from Cyble, leading to frustration and difficulty distinguishing real threats from false positives.
  • Users express frustration over limited customization options in Cyble, impacting efficiency and user experience.
  • Users are frustrated with Cyble's slow and inadequate customer support, especially during urgent situations needing immediate assistance.
  • Users experience poor support management with Cyble, facing slow response times during critical situations.
  • Users face significant challenges due to false positives, which overwhelm and distract from real threats in Cyble.

What Are Recent G2 Reviews of Cyble?

CTM360

CTM360 is a consolidated external security platform that integrates External Attack Surface Management, Digital Risk Protection, Cyber Threat Intelligence, Brand Protection & Anti-phishing, Surface, Deep, & Dark Web Monitoring, Security Ratings, Third-party risk Management, and fully managed unlimited Takedowns. As a pioneer and innovator in preemptive security, CTM360 operates as an external CTEM technology platform outside an organization’s perimeter. Seamless and turn-key, CTM360 requires no configurations, installations or inputs from the end-user, with all data pre-populated and specific to your organization. All aspects are managed by CTM360.

Average Rating: 4.6/5.0

Total Reviews: 166

How Do G2 Users Rate CTM360?

  • Vulnerability Intelligence: 9.0/10 (Category avg: 9.0/10)
  • Continuous Monitoring: 9.1/10 (Category avg: 9.2/10)
  • Compliance Monitoring: 8.8/10 (Category avg: 8.6/10)
  • Ease of Admin: 9.7/10 (Category avg: 9.0/10)

Who Is the Company Behind CTM360?

  • Seller: CTM360
  • Company Website:
  • Year Founded: 2014
  • HQ Location: Manama, BH
  • Twitter: @teamCTM360
    999 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    133 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Banking, Financial Services
  • Company Size: 38% Medium, 37% Large

What Do G2 Reviewers Say About CTM360?

AI-generated summary from verified user reviews

Pros
  • Users commend the top-notch customer support of CTM360, highlighting responsiveness and professionalism in every interaction.
  • Users appreciate the ease of use of CTM360, praising its straightforward setup and user-friendly interface.
  • Users highlight the exceptional quality and commitment of CTM360, praising its comprehensive features and proactive support.
  • Users commend CTM360 for its effective monitoring of assets and risks, enabling proactive security measures and informed decisions.
  • Users value the high detection efficiency of CTM360, experiencing minimal false positives and quick risk identification.
Cons
  • Users note the limited features of the CTM360 app compared to the web portal, affecting overall usability.
  • Users face integration issues with existing tools like ArcticHub, hindering automated security feed capabilities.
  • Users feel the lack of features in CTM360 limits its utility compared to the web and other tools.
  • Users highlighted the lack of integration with their existing security systems, limiting automated security feeds and usability.
  • Users highlight the lack of integrations with existing security tools, limiting the effectiveness of CTM360's capabilities.

What Are Recent G2 Reviews of CTM360?

SentinelOne Singularity Cloud Security

Singularity Cloud Security is SentinelOne’s comprehensive, cloud-native application protection platform (CNAPP). It combines the best of agentless insights with AI-powered threat protection, to secure and protect your multi-cloud infrastructure, services, and containers from build time to runtime. SentinelOne’s CNAPP applies an attacker’s mindset to help security practitioners better prioritize their remediation tasks with evidence-backed Verified Exploit Paths™. The efficient and scalable runtime protection, proven over 5 years and trusted by many of the world’s leading cloud enterprises, harnesses local, autonomous AI engines to detect and thwart runtime threats in real-time. CNAPP data and workload telemetry is recorded to SentinelOne’s unified security lake, for easy access and investigation.

Average Rating: 4.9/5.0

Total Reviews: 122

How Do G2 Users Rate SentinelOne Singularity Cloud Security?

  • Vulnerability Intelligence: 9.7/10 (Category avg: 9.0/10)
  • Continuous Monitoring: 9.9/10 (Category avg: 9.2/10)
  • Compliance Monitoring: 9.8/10 (Category avg: 8.6/10)
  • Ease of Admin: 9.7/10 (Category avg: 9.0/10)

Who Is the Company Behind SentinelOne Singularity Cloud Security?

  • Seller: SentinelOne
  • Company Website:
  • Year Founded: 2013
  • HQ Location: Mountain View, CA
  • Twitter: @SentinelOne
    57,863 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    3,426 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Financial Services
  • Company Size: 59% Medium, 30% Large

What Do G2 Reviewers Say About SentinelOne Singularity Cloud Security?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the real-time alert system of SentinelOne Singularity, enhancing proactive threat management and security.
  • Users find the user-friendly interface of SentinelOne Singularity Cloud Security makes managing security straightforward for everyone.
  • Users value the automated vulnerability detection in PingSafe, enhancing proactive cloud security management effortlessly.
  • Users appreciate the real-time alert system of PingSafe, enhancing proactive cloud security management effectively.
  • Users commend SentinelOne Singularity Cloud Security for its ease of use and strong visibility across cloud environments.
Cons
  • Users feel that SentinelOne Singularity Cloud Security has a complex setup that can be challenging for less technical users.
  • Users experience ineffective alerts that require tuning, leading to confusion and potential oversight in security management.
  • Users find the complex setup of SentinelOne Singularity Cloud Security challenging, requiring time for effective configuration and tuning.
  • Users find difficult configuration of SentinelOne Singularity Cloud Security requires time and experience for optimal setup and tuning.
  • Users find the UI to be clunky, making the platform's complexity and learning curve more challenging.

What Are Recent G2 Reviews of SentinelOne Singularity Cloud Security?

Pentera

Pentera is the category leader for Automated Security Validation, allowing every organization to test with ease the integrity of all cybersecurity layers, unfolding true, current security exposures at any moment, at any scale. Thousands of security professionals and service providers around the world use Pentera to guide remediation and close security gaps before they are exploited. Its customers include Casey's General Stores, Emeria, LuLu International Exchange, IP Telecom PT, BrewDog, City National Bank, Schmitz Cargobull, and MBC Group. Pentera is backed by leading investors such as K1 Investment Management, Insight Partners, Blackstone, Evolution Equity Partners, and AWZ. Visit https://pentera.io for more information.

Average Rating: 4.5/5.0

Total Reviews: 171

How Do G2 Users Rate Pentera?

  • Vulnerability Intelligence: 8.3/10 (Category avg: 9.0/10)
  • Continuous Monitoring: 7.9/10 (Category avg: 9.2/10)
  • Compliance Monitoring: 7.8/10 (Category avg: 8.6/10)
  • Ease of Admin: 8.6/10 (Category avg: 9.0/10)

Who Is the Company Behind Pentera?

  • Seller: Pentera
  • Company Website:
  • Year Founded: 2015
  • HQ Location: Boston, MA
  • Twitter: @penterasec
    3,291 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    483 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Banking, Government Administration
  • Company Size: 52% Large, 36% Medium

What Do G2 Reviewers Say About Pentera?

AI-generated summary from verified user reviews

Pros
  • Users value the automation features of Pentera, enhancing ease of use and enabling efficient continuous operation.
  • Users recognize the powerful automation and detailed remediation suggestions of Pentera for effective vulnerability detection.
  • Users value Pentera's effective vulnerability scanning and remediation suggestions, enhancing their overall security posture and testing efficacy.
  • Users value the responsive customer support of Pentera, enhancing their overall vulnerability scanning experience.
  • Users appreciate the efficiency of Pentera, notably for its quick implementation and time-saving automation.
Cons
  • Users find the reporting inadequate, particularly for enterprise-level assessments, necessitating significant improvements.
  • Users experience a lack of essential features, including limited TTP updates and inadequate user permissions management.
  • Users find the reporting in Pentera lacking, especially for enterprise-level needs and multilingual support.
  • Users find Pentera demands a high amount of system resources, which can hinder overall performance and efficiency.
  • Users report technical issues, particularly with module compatibility and unexpected upgrade failures, though support is responsive.

What Are Recent G2 Reviews of Pentera?

AI-Native Continuous Offensive Security Platform

RidgeBot by Ridge Security is a leading agentic AI-driven offensive security platform, supporting continuous threat management programs. It enables CISOs to minimize cyber risks by continuously validating the cybersecurity posture and controls protecting attack surfaces against increasingly sophisticated and frequent attacks. RidgeBot automatically tests an organization’s entire IP-based environment, including network infrastructure, applications, websites, IoT, and OT, using ethical hacking techniques to pinpoint the most critical vulnerabilities. It's dynamic AI-powered decision-making supports DevSecOps, compliance, incident response verification, and custom attack simulations. RidgeBot maintains a library of over 36,000 plugins to launch complex penetration tests and attack simulations, with detailed reporting of results and remediation recommendations.

Average Rating: 4.5/5.0

Total Reviews: 98

How Do G2 Users Rate AI-Native Continuous Offensive Security Platform?

  • Vulnerability Intelligence: 8.9/10 (Category avg: 9.0/10)
  • Continuous Monitoring: 8.6/10 (Category avg: 9.2/10)
  • Compliance Monitoring: 8.5/10 (Category avg: 8.6/10)
  • Ease of Admin: 9.1/10 (Category avg: 9.0/10)

Who Is the Company Behind AI-Native Continuous Offensive Security Platform?

  • Seller: Ridge Security Technology
  • Company Website:
  • Year Founded: 2020
  • HQ Location: Santa Clara, California
  • Twitter: @RidgeSecurityAI
    1,291 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    47 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer & Network Security
  • Company Size: 51% Small, 45% Medium

What Do G2 Reviewers Say About AI-Native Continuous Offensive Security Platform?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the ease of use of RidgeBot, enabling quick setup and straightforward penetration testing automation.
  • Users value the automation capabilities of RidgeBot, significantly enhancing efficiency in penetration testing and vulnerability validation.
  • Users value the high efficiency of RidgeBot's pentesting, enabling quick, automated vulnerability validation and seamless integration.
  • Users commend RidgeBot for its effective vulnerability identification, providing reliable, automated testing and integration for security efficiency.
  • Users praise RidgeBot for its efficiency in automating vulnerability testing and streamlining security processes seamlessly.
Cons
  • Users find the complex setup of RidgeBot challenging, particularly for new admins requiring better documentation and support.
  • Users find RidgeBot's setup overly complex, particularly when working with customized or legacy systems.
  • Users find the missing features in RidgeBot, such as limited reporting and API testing, hinder optimal usage.
  • Users find poor customer support frustrating, often lacking resources for resolving issues independently.
  • Users find the poor documentation of RidgeBot challenging, especially for new admins during setup and onboarding.

What Are Recent G2 Reviews of AI-Native Continuous Offensive Security Platform?

Tenable Nessus

Built for security practitioners, by security professionals, Nessus products by Tenable are the de-facto industry standard for vulnerability assessment. Nessus performs point-in-time assessments to help security professionals quickly and easily identify and fix vulnerabilities, including software flaws, missing patches, malware, and misconfigurations - across a variety of operating systems, devices, and applications. With features such as pre-built policies and templates, customizable reporting, group “snooze” functionality, and real-time updates, Nessus is designed to make vulnerability assessment simple, easy, and intuitive. The result: less time and effort to assess, prioritize, and remediate issues.

Average Rating: 4.5/5.0

Total Reviews: 291

How Do G2 Users Rate Tenable Nessus?

  • Vulnerability Intelligence: 10.0/10 (Category avg: 9.0/10)
  • Continuous Monitoring: 9.2/10 (Category avg: 9.2/10)
  • Compliance Monitoring: 8.6/10 (Category avg: 8.6/10)
  • Ease of Admin: 8.9/10 (Category avg: 9.0/10)

Who Is the Company Behind Tenable Nessus?

  • Seller: Tenable
  • Company Website:
  • HQ Location: Columbia, MD
  • Twitter: @TenableSecurity
    87,752 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    2,350 employees on LinkedIn®
  • Ownership: NASDAQ: TENB

Who Uses This Product?

  • Who Uses This: Security Engineer, Network Engineer
  • Top Industries: Information Technology and Services, Computer & Network Security
  • Company Size: 40% Medium, 34% Large

What Do G2 Reviewers Say About Tenable Nessus?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the vulnerability identification capabilities of Tenable Nessus, highlighting its accuracy and comprehensive coverage for security management.
  • Users value the advanced vulnerability detection capabilities of Tenable Nessus, enhancing their security risk management effectively.
  • Users value the ease of use of Tenable Nessus, appreciating its simple setup and user-friendly interface.
  • Users value the automated scanning capabilities of Tenable Nessus, benefiting from its comprehensive and up-to-date vulnerability checks.
  • Users commend the comprehensive scanning capabilities of Tenable Nessus, alongside its robust reporting and automation features.
Cons
  • Users note the slow scanning process, especially in large environments, significantly impacting resource usage and production times.
  • Users find the cost of running and maintaining Tenable Nessus to be extensively high and burdensome.
  • Users find limited features in Tenable Nessus, including restrictions on hosts, scans, and mobile application testing.
  • Users find the complexity of Tenable Nessus challenging, especially with advanced features requiring significant technical knowledge.
  • Users report that Nessus generates false positives, resulting in extra workload and hindering effective security management.

What Are Recent G2 Reviews of Tenable Nessus?

What Are G2 Users Discussing About Tenable Nessus?

Halo Security

Halo Security is an External Attack Surface Management (EASM) platform that helps organizations discover, monitor, and secure their external digital footprint against cyber threats. The solution enables security teams to view their infrastructure from an attacker's perspective, providing continuous visibility into vulnerabilities, exposed assets, and potential security risks across web applications, cloud resources, and third-party services. Halo Security was founded in 2013 and is headquartered in the United States. With a team of experienced security professionals, the company has assisted thousands of organizations in strengthening their security posture. Their fully US-based operations have earned the trust of organizations across various industries seeking to protect their digital assets from evolving cyber threats. The platform combines automated discovery with expert analysis to deliver comprehensive attack surface monitoring, vulnerability detection, and technology identification. Key features include continuous asset discovery that automatically identifies unknown digital resources, real-time alerts for newly discovered vulnerabilities delivered via integrations with dozens of tools, technology fingerprinting to detect potential vulnerabilities in third-party services, and subdomain takeover protection that identifies dangerous DNS misconfigurations before attackers can exploit them. Halo Security empowers organizations to eliminate blind spots in their attack surface, prioritize remediation efforts based on real risk, and secure their external-facing assets against increasingly sophisticated cyber threats. The solution solves critical challenges for security teams by providing visibility into forgotten or unknown assets, detecting vulnerabilities in third-party platforms, and alerting teams to changes that introduce security risks. Whether managing a growing digital footprint or meeting compliance requirements, Halo Security provides the visibility and tools needed to maintain a strong security posture in today's complex threat landscape.

Average Rating: 4.5/5.0

Total Reviews: 56

How Do G2 Users Rate Halo Security?

  • Vulnerability Intelligence: 8.5/10 (Category avg: 9.0/10)
  • Continuous Monitoring: 9.4/10 (Category avg: 9.2/10)
  • Compliance Monitoring: 9.3/10 (Category avg: 8.6/10)
  • Ease of Admin: 8.4/10 (Category avg: 9.0/10)

Who Is the Company Behind Halo Security?

  • Seller: Halo Security
  • Company Website:
  • Year Founded: 2013
  • HQ Location: Miami Beach, US
  • Twitter: @halohackers
    84 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    34 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Retail
  • Company Size: 54% Medium, 23% Large

What Do G2 Reviewers Say About Halo Security?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the ease of use of Halo Security, enjoying a seamless experience and efficient setup process.
  • Users value the real-time notifications from Halo Security, enabling proactive risk management and enhanced security awareness.
  • Users value the easy integrations of Halo Security, which enhance workflow and streamline security management effortlessly.
  • Users commend Halo Security for its comprehensive features and effective attack surface scanning capability, delivering essential insights for security.
  • Users value Halo Security for its comprehensive attack surface scanning, enhancing overall security and adaptability for businesses.
Cons
  • Users find that difficult navigation within the Halo Security portal can be quite frustrating at times.
  • Users find the API unintuitive, noting that setting up multiple scan targets involves too many steps and inefficiencies.
  • Users find the complex setup of Halo Security cumbersome, making it less efficient to configure multiple scan targets.
  • Users feel the complex UI of Halo Security makes navigation difficult and needs significant improvement for better usability.
  • Users find the dashboard navigation uncomfortable due to the new design that transforms dashboards into reports.

What Are Recent G2 Reviews of Halo Security?

CloudSEK

CloudSEK is a contextual AI company that predicts Cyber Threats. We combine the power of Cyber Crime monitoring, Brand Monitoring, Attack Surface monitoring, and Supply Chain intelligence to give context to our customers’ digital risks.

Average Rating: 4.8/5.0

Total Reviews: 137

How Do G2 Users Rate CloudSEK?

  • Vulnerability Intelligence: 9.0/10 (Category avg: 9.0/10)
  • Continuous Monitoring: 9.6/10 (Category avg: 9.2/10)
  • Compliance Monitoring: 9.4/10 (Category avg: 8.6/10)
  • Ease of Admin: 9.6/10 (Category avg: 9.0/10)

Who Is the Company Behind CloudSEK?

  • Seller: CloudSEK
  • Year Founded: 2015
  • HQ Location: Singapore, SG
  • Twitter: @cloudsek
    2,417 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    234 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Security Analyst, Analyst
  • Top Industries: Financial Services, Airlines/Aviation
  • Company Size: 53% Large, 31% Medium

What Do G2 Reviewers Say About CloudSEK?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the ease of use with CloudSEK, enjoying smooth integration and an intuitive dashboard for monitoring.
  • Users value the continuous monitoring and real-time alerts provided by CloudSEK, enhancing their security efforts.
  • Users value the active and helpful customer support from CloudSEK, which enhances their experience and resolves issues promptly.
  • Users commend CloudSEK for its robust threat intelligence features, improving cybersecurity with real-time monitoring and insights.
  • Users recognize the real-time visibility into external threats provided by CloudSEK, enhancing proactive risk management.
Cons
  • Users encounter numerous false positives in alerts, complicating threat prioritization and overall effectiveness of CloudSEK.
  • Users face challenges with inefficient alerts from CloudSEK, as many are false positives requiring extra validation.
  • Users experience dashboard issues, including clutter and limited customization, impacting alert management and overall usability.
  • Users face challenges with the inefficient alert system, leading to false positives and difficulties in threat prioritization.
  • Users find the complex UI of CloudSEK overwhelming, requiring time and skill to navigate effectively.

What Are Recent G2 Reviews of CloudSEK?

Detectify

Detectify sets a new standard for advanced application security testing, challenging traditional DAST by providing evolving coverage of each and every exposed asset across the changing attack surface. AppSec teams trust Detectify to expose how attackers will exploit their Internet-facing applications. The Detectify platform automates continuous real-world, payload-based attacks fuelled by its global community of elite ethical hackers into its own expert-built engines, exposing critical weaknesses before it's too late. The Detectify solution includes: - Automated discovery of known and unknown digital assets via domain & cloud connectors - Continuous coverage (24/7) of every corner of the attack surface with dynamic testing. Not just predefined targets - 100% payload-based testing fuelled by elite ethical hackers for a high signal-to-noise ratio - Distributed coverage across an unmatched array of relevant technologies - Actionable remediation tips for software development teams - Team functionality to easily share reports - Powerful integrations platform to prioritize and triage vulnerability findings onward to development teams -Advanced API functionality -Capabilities to set custom attack surface security policies

Average Rating: 4.5/5.0

Total Reviews: 49

How Do G2 Users Rate Detectify?

  • Vulnerability Intelligence: 9.0/10 (Category avg: 9.0/10)
  • Continuous Monitoring: 10.0/10 (Category avg: 9.2/10)
  • Compliance Monitoring: 9.4/10 (Category avg: 8.6/10)
  • Ease of Admin: 8.7/10 (Category avg: 9.0/10)

Who Is the Company Behind Detectify?

  • Seller: Detectify
  • Year Founded: 2013
  • HQ Location: Stockholm, Sweden
  • Twitter: @detectify
    11,256 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    94 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 47% Small, 35% Medium

What Do G2 Reviewers Say About Detectify?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the automation capabilities of Detectify, enjoying seamless integration and tailored security testing processes.
  • Users value the easy automation and integration features of Detectify that enhance security testing efficiently.
  • Users value the customizability of Detectify, enabling easy integration and tailored security testing to fit diverse needs.
  • Users appreciate the easy integration and comprehensive features of Detectify for efficient security testing.
  • Users appreciate Detectify for its effective dynamic application security testing, ensuring comprehensive security without complex setups.
Cons
  • Users find the initial complexity of setting up Detectify to be a challenging aspect of the product.
  • Users find the complex queries in Detectify challenging, impacting clarity on spidering results and app assessment.
  • Users find the complex setup of Detectify to be a challenging start, impacting its usability for newcomers.
  • Users find Detectify to be expensive when testing multiple sites, impacting its affordability for small operations.
  • Users find inaccuracy in outcomes from Detectify's spidering, lacking clarity on app assessment completeness.

What Are Recent G2 Reviews of Detectify?

What Are G2 Users Discussing About Detectify?

Saner CVEM

Prevention-first Vulnerability and Exposure Management for unified visibility, prioritization, compliance, and remediation Saner Continuous Vulnerability and Exposure Management unifies asset exposure, posture anomaly detection, vulnerability assessment, compliance management, risk prioritization, patching, and endpoint actions in one dashboard. Saner CVEM is built to help teams continuously detect, assess, prioritize, and remediate vulnerabilities and other security risks from a unified console Why Choose Saner CVEM? • Unified dashboard with interactive views across visibility, detection, prioritization, and remediation for a single source of truth • Complete asset visibility across endpoint and non-endpoint devices, operating system applications, third-party applications, and lifecycle changes • Continuous risk discovery with rapid scans, daily-updated risk intelligence, and posture anomaly detection that helps surface outliers and misconfigurations faster • Context-driven prioritization with SSVC categories such as Act, Attend, Track, and Track* so teams can focus on the risks that deserve action first. • Continuous compliance management with built-in templates, customizable profiles, daily checks, and deviation tracking across common frameworks. • Integrated patching and remediation with vulnerability-to-patch mapping, automated deployment workflows, and endpoint actions from the same ecosystem. • Machine-learning-assisted analysis to identify deeper risk patterns, detect unusual posture, and support smarter remediation decisions. • Customizable, audit-ready reporting for security, IT, and compliance teams that need clearer evidence and easier tracking. • Flexible deployment on cloud or on-premises, with remediation support across Windows, Linux, macOS, and AIX environments.

Average Rating: 4.5/5.0

Total Reviews: 72

How Do G2 Users Rate Saner CVEM?

  • Vulnerability Intelligence: 9.5/10 (Category avg: 9.0/10)
  • Continuous Monitoring: 9.0/10 (Category avg: 9.2/10)
  • Compliance Monitoring: 9.0/10 (Category avg: 8.6/10)
  • Ease of Admin: 9.0/10 (Category avg: 9.0/10)

Who Is the Company Behind Saner CVEM?

  • Seller: SecPod
  • Company Website:
  • Year Founded: 2008
  • HQ Location: Redwood City, California
  • Twitter: @secpod
    542 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    168 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer & Network Security
  • Company Size: 41% Small, 38% Medium

What Do G2 Reviewers Say About Saner CVEM?

AI-generated summary from verified user reviews

Pros
  • Users value the effective automation of security patches with Saner CVEM, enhancing compliance for remote systems.
  • Users appreciate the automated endpoint security and compliance tracking of Saner CVEM, simplifying patch management for remote systems.
  • Users appreciate the ease of use of Saner CVEM, benefiting from its intuitive interface and efficient functionalities.
  • Users appreciate the responsive customer support of Saner CVEM, enhancing their overall security management experience.
  • Users value the automated compliance management of Saner CVEM, ensuring timely security updates across hybrid workforces.
Cons
  • Users face integration issues with Saner CVEM, especially requiring custom solutions and troubleshooting during data synchronization.
  • Users experience limited features in multi-tenant support, integration, and dashboard usability, affecting overall efficiency.
  • Users experience slow performance during initial dashboard loading and while handling large data sets, affecting efficiency.
  • Users experience slow scanning with initial dashboard loads and large data sets, impacting daily checks and efficiency.
  • Users find the limited cloud integration challenging, requiring workarounds and custom scripts for effective use.

What Are Recent G2 Reviews of Saner CVEM?

What Are G2 Users Discussing About Saner CVEM?

Check Point Exposure Management

Exposure Management is changing how organizations react to cyber risk. Attackers exploit exposed assets, leaked credentials, and misconfigurations within hours, while security teams are left sorting through dashboards, alerts, and disconnected tools. For a limited time only, we are providing an Agentic Exposure Validation Scan at no cost. It delivers proven, evidence-backed findings your team can act on immediately. Request scan here - https://checkpoint.cyberint.com/limited-time-offer-aev-scan Check Point Exposure Management closes that gap by combining billions of external intelligence signals into a Unified Intelligence Fabric. The platform continuously identifies, validates, prioritizes, and safely remediates the exposures attackers are most likely to exploit. With Cyber Asset Attack Surface Management (CAASM), security teams gain a real-time inventory across cloud, SaaS, on-premises infrastructure, endpoints, and identities through 150+ agentless integrations. Unlike traditional vulnerability management, Check Point prioritizes exposures based on real-world exploitability, active threat intelligence, business context, and existing security controls, eliminating duplicate alerts and reducing remediation noise. It does so while maintaining business continuity. Safe-by-design remediation then validates every action before enforcement, enabling capabilities such as virtual patching, IPS activation, configuration hardening, and policy enforcement without disrupting business operations. Organizations using the platform achieve a 93% true positive rate, 12-hour average takedown MTTR, and 504 safe remediations per organization every month. Built around Gartner's Continuous Threat Exposure Management (CTEM) framework, Check Point helps organizations move from visibility to measurable risk reduction. Gartner predicts organizations adopting CTEM with mobilization will experience 50% fewer successful cyberattacks by 2028. Ready to see Exposure Management in action? Get a 15-minute demo: https://l.cyberint.com/exposure-management-demo

Average Rating: 4.6/5.0

Total Reviews: 173

How Do G2 Users Rate Check Point Exposure Management?

  • Vulnerability Intelligence: 8.7/10 (Category avg: 9.0/10)
  • Continuous Monitoring: 8.7/10 (Category avg: 9.2/10)
  • Compliance Monitoring: 8.3/10 (Category avg: 8.6/10)
  • Ease of Admin: 9.1/10 (Category avg: 9.0/10)

Who Is the Company Behind Check Point Exposure Management?

Who Uses This Product?

  • Who Uses This: Cyber Security Analyst, Security Threat Analyst
  • Top Industries: Banking, Financial Services
  • Company Size: 68% Large, 20% Medium

What Do G2 Reviewers Say About Check Point Exposure Management?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the ease of use of Cyberint, enjoying its intuitive interface and seamless integration into workflows.
  • Users value the comprehensive threat intelligence of Check Point Exposure Management, enhancing proactive threat detection and response capabilities.
  • Users find Cyberint's threat detection valuable for enhancing situational awareness and proactive threat response in sensitive environments.
  • Users commend the comprehensive threat intelligence of Check Point Exposure Management, enhancing detection and response to potential cyber threats.
  • Users commend the responsive and proactive support from Cyberint, enhancing their ability to manage complex threats effectively.
Cons
  • Users experience inefficient alerts due to occasional false positives, requiring extra time for verification and impacting productivity.
  • Users experience false positives in alerts, necessitating extra analyst time for validation and slowing response efforts.
  • Users experience inefficient alert systems, finding the volume of alerts overwhelming and slow threat intel response frustrating.
  • Users often face integration issues, particularly with centralizing alerts and security tool compatibility.
  • Users note the limited features of Check Point Exposure Management, particularly regarding alert tuning and third-party integrations.

What Are Recent G2 Reviews of Check Point Exposure Management?

What Are G2 Users Discussing About Check Point Exposure Management?