Frequently Asked Questions

Product Overview & Use Cases

What is Nucleus and how does it help organizations manage vulnerabilities?

Nucleus is a unified vulnerability management platform that aggregates data from existing tools, providing a centralized command center for vulnerability analysis, triage, and remediation. It automates workflows, prioritizes risks using real-world intelligence, and helps organizations align with compliance frameworks. This enables teams to efficiently discover, prioritize, and remediate vulnerabilities across business units. Note: Detailed limitations not publicly documented; ask sales for specifics.

What specific business challenges does Nucleus address?

Nucleus addresses challenges such as fragmented vulnerability data, inefficient manual remediation workflows, difficulty in prioritizing vulnerabilities, and complex compliance requirements. For example, organizations previously relying on open-source tools and custom scripts faced costly maintenance and unreliable integrations. Nucleus streamlines these processes, enabling visibility across business units and reducing operational overhead. Note: Best fit for organizations seeking centralized vulnerability management; teams requiring highly customized workflows may need additional evaluation.

Who can benefit from using Nucleus?

Nucleus is designed for security analysts, development and IT teams, CISOs, GRC and compliance teams, and organizations in regulated industries such as healthcare, finance, government, and large enterprises managing complex infrastructures. Managed Security Service Providers (MSSPs) and public sector entities also benefit from its multi-tenant architecture and compliance automation. Note: Smaller organizations with limited vulnerability management needs may find some features unnecessary.

Features & Capabilities

What are the key features of the Nucleus platform?

Key features include vulnerability aggregation from multiple tools, risk-based prioritization using asset context and threat intelligence, automation of remediation workflows, compliance framework support (NIST, FedRAMP, CISA), POA&M automation for public sector, asset management, threat intelligence enrichment, and integrations with over 200 tools. Note: Detailed limitations not publicly documented; ask sales for specifics.

What integrations does Nucleus support?

Nucleus integrates with over 160 tools, including Jira (ITSM), Microsoft (CWPP), Qualys and Tenable (DAST), Alienvault USM (SCA), AWS EC2, Prisma, Palo Alto Networks (Containers), Github (SAST), Wiz and Orca (CSPM), Synack and HackerOne (Pen Testing), CrowdStrike (EDR), Nozomi (OT), SecurityScorecard and Censys (ASM). For a complete list, visit the integrations page. Note: Some integrations may require additional configuration or licensing.

Does Nucleus offer an API for custom integrations and reporting?

Yes, Nucleus provides an API that enables users to interact with the Nucleus Database for custom dashboards, real-time reporting, and integration with third-party tools such as SIEM and SOAR. API documentation is available at api-docs.nucleussec.com. Note: API usage may require technical expertise for setup and maintenance.

Performance & Implementation

How quickly can Nucleus be implemented, and what resources are available for onboarding?

Nucleus integrates with over 200 tools out of the box, enabling onboarding in hours instead of weeks. Prebuilt connectors and reusable templates simplify deployment. Customers have access to step-by-step guides, video tutorials, a dedicated support portal, and Customer Success Managers for implementation and ongoing support. Note: Some complex environments may require additional customization.

What performance improvements and outcomes have customers reported?

Customers have reported measurable outcomes such as reducing critical vulnerabilities by up to 86%. For example, a global airline reduced 86% of its critical vulnerabilities, and an international power company achieved a 100% reduction in widely exploitable vulnerabilities in weeks using Nucleus's threat intelligence integration. Note: Performance results may vary based on organizational size and complexity.

Security & Compliance

What security certifications and compliance standards does Nucleus meet?

Nucleus is SOC2 compliant and holds FedRAMP Moderate Authorization, ensuring adherence to rigorous security requirements for cloud services used by the U.S. Federal Government. The platform also supports compliance with frameworks such as NIST, FedRAMP, CISA, and PCI DSS Requirement 6. Note: Compliance with additional frameworks may require further configuration.

How does Nucleus protect customer data?

Nucleus employs industry-standard administrative, physical, and technical safeguards to protect the security, confidentiality, and integrity of customer data. The platform prevents unauthorized access, use, modification, or disclosure, and warrants compliance with applicable laws under its Master Service Agreement. Note: Customers should review the MSA for detailed terms.

Customer Success & Proof

Can you share specific customer success stories using Nucleus?

Yes. Notable examples include:

Note: Results may vary based on organizational context and implementation.

What feedback have customers provided regarding ease of use?

Customers have highlighted Nucleus's intuitive interface, easy onboarding, and automation features. For example, a Manager of Security Architecture in Healthcare stated, "Nucleus Security has been an exceptional partner from the beginning…After purchasing, they offered one of the best onboarding/implementations I’ve worked with, and the product is easy to use." Another review noted, "There are no words to describe how much easier it is to manage vulnerabilities using Nucleus." Note: Some advanced features may require additional training for optimal use.

Technical Documentation & Support

What technical documentation and support resources are available?

Prospects and customers can access API documentation (api-docs.nucleussec.com), FlexConnect Framework setup guides (FlexConnect Documentation), a comprehensive help and support portal (help.nucleussec.com), and quickstart guides for onboarding (Quickstart section). Note: Some resources may require registration or login.

Industry Coverage & Customer Base

Which industries are represented in Nucleus case studies?

Industries include banking and financial services, airlines, healthcare, cybersecurity services, education, energy and utilities, retail and consumer goods, public sector, and technology. For example, case studies feature Bank of Hope, a Tier-1 airline, UCSB, NRECA, and Orange Cyberdefense. Note: Industry-specific requirements may vary; consult sales for tailored solutions.

Who are some of Nucleus's customers?

Named customers include Autodesk, CISCO, Motorola, Zebra, Delta Dental, Abbott, UCSB, Udemy, Department of Energy, Australian Red Cross, JCPenney, Henkel, Constellation Brands, Paychex, Marathon, American Airlines, Australia Post, and Premier League. For a comprehensive list, visit the platform page. Note: Customer adoption may vary by region and industry.

CUSTOMER STORY

International Power Company Vastly Reduces Widely Exploitable Vulnerabilities in Weeks

International Power Company Customer Story

Customer Profile

  • Leading International provider of gas, electricity and telecommunications
  • 4,500 Employees
  • $10 Billion in Revenue
  • Struggled to gain visibility into vulnerabilities across business units
  • Interview: Enterprise Cybersecurity Leader

Executive Summary

  • A leading international provider of gas, electricity and telecommunications, with 4,500 employees and $10 billion in revenue, was seeking a tool to gain visibility into vulnerabilities across business units.
  • Cybersecurity acts as an advisory function there to discover threats, articulate risk, and help the business units make decisions based on risk appetite.
  • We needed a way to demonstrate to the business that we are continually improving our security posture.
  • In weeks, they saw a 100% reduction in widely exploitable vulnerabilities as identified by Mandiant’s embedded threat intelligence.

Business Challenge

“ It is tough for anyone to believe they are secure when they have 29,400 critical/high vulnerabilities (CVSS) in your environment.”

– Cybersecurity Leader

A leading international provider of gas, electricity, and telecommunications looked to Nucleus Security for vulnerability management after struggling to maintain visibility into software vulnerabilities using an open-source tool combined with customized scripts.   

Cybersecurity acts as an advisory function there to discover threats, articulate risk, and help the business units make decisions based on risk appetite. It is tough for anyone to believe they are secure when they have 29,400 critical/high vulnerabilities (CVSS) in your environment, and we needed a way to demonstrate to the business that we are continually improving our security posture. 

We needed a way to demonstrate to the business that we are continually improving our security posture.

They also were struggling with how to gain visibility and work collaboratively with internally developed applications across the different business units they provide advisory cybersecurity services for.

Technical Challenges

The time and effort associated with maintaining integrations with the homegrown open-source tool required dedicated resources and integrations would continuously break, resulting in an unreliable solution with too much overhead.  Custom development was required to get the open-source vulnerability management solution to work resulting in the need to maintain reams of custom code. The custom code broke often, becoming incredibly costly to maintainHalf a full-time resource was allocated to code maintenance alone, but even this was not enough to maintain a working vulnerability management solution. 

“Custom development was required to get the open-source vulnerability management solution to work resulting in the need to maintain reams of custom code. The custom code broke often, becoming incredibly costly to maintain.”

The business also set expectations that security operations would continue to get more efficient year over year adopting solutions that would drive efficiency and not require additional resourcesThe model of building and maintaining an open-source vulnerability management solution just wasn’t sustainable. Therefore, they began evaluating commercial solutions when they discovered Nucleus.

The Solution

Cybersecurity champions, security architects, and technology leadership knew they needed to streamline their vulnerability management program and looked to Nucleus for help. By providing access to Nucleus across the business, the cybersecurity and technology teams now were enabled with visibility into application assets and vulnerabilities in a way that was never possible before. Nucleus integrated quickly into their existing technology stack including their GitHub source code repositories, software composition management tool Dependebot and Static Application Security Testing tool CodeQL

“Helping get remediation on the right vulnerabilities is hard, but in a noticeably brief time we were able to get our widely exploitable vulnerabilities to zero with Nucleus’s seamless connectors and embedded threat intel from Mandiant.”

They then layered in business context of their assets and with embedded threat intel from Mandiant, Nucleus empowered the team to prioritize and fix vulnerabilities as opposed to being overwhelmed by them. The company’s portfolio of large applications has thousands of vulnerabilities, but with Nucleus’s threat intel context they know which ones are being exploited in the wild and worthy of their attention. 

“The threat intel integration gave our team visibility on what critical risks to prioritize that we would not have known otherwise and the fact that it’s included with our Nucleus subscription is amazing. All our stake holders are incredibly happy!”

Key Results

100% Reduction in Widely Exploitable Vulnerabilities in Weeks

In weeks, they saw a 100% reduction in widely exploitable vulnerabilities as identified by Mandiant’s embedded threat intelligence. In fact, by prioritizing 40 widely exploited vulnerabilities within Nucleus, they went from 40 to 0 in weeks which significantly reduced the organizations risk and was an easily demonstratable success to share with their leadership teams. 

Shifting Left in the Software Development Lifecycle

Initially, a top-down approach to vulnerability management brought in data with an application repository full of vulnerabilities which was completely disconnected without context from the businessGiving teams visibility into vulnerability risk earlier in the SDLC with Nucleus, helped tremendously. Through integration with developer’s native tools including Jira, the security team is now able to share vulnerabilities with the developer teams and work collaboratively to remediate critical software vulnerabilities fast.  

Enabling the Business with Visibility into Risk

Internal business units now have visibility into vulnerability management coverage and can make their own decisions-based context of their own business unit. Having the business context or if a vulnerability is weaponizable pushes decision making out. Organizations are always under pressure now they have the context to make decisions on what to prioritize.  

Expanding Coverage Beyond Software Development

With vulnerability coverage across the organization’s software application stack, they can now focus on expanding vulnerability management coverage across all their assets. They started incorporating pentest results into the Nucleus platform which allows them to easily gain visibility into identified risk and delegate remediation to the right stakeholders. They plan to expand the use of Nucleus to include broader network coverage using the integration with Qualys to quickly gain access to network assets and vulnerabilities associated with them. This will give the organization full visibility across all assets and vulnerabilities so they can easily make the right business decisions regarding organization risk and vulnerability management.

Want to See Nucleus in Action?

Watch our demo on-demand.