Skip to Content

FAQs

Find answers to common questions about Titania's products, platform capabilities, compliance solutions, and industry use cases, organised by topic to help you quickly find the information you need.


  • Platform | Nipper OmniSight

    • Which Nipper OmniSight tier fits our workflow?

      Nipper OmniSight is designed to scale from scheduled, repeatable exposure assessments to continuous threat exposure management (CTEM) for configuration change. The right choice depends on how you collect configurations today. It also depends on whether you use a CMDB or a repository and how you share findings across teams. Use our tier comparison to confirm the best match for your environment.

    • What problems does Nipper OmniSight solve that scanners miss?

      Many exposures are created by exported device configurations – not just missing patches. Nipper OmniSight analyzes routers, switches, firewalls, and related infrastructure to find misconfigurations, weak hardening, and segmentation gaps that can create reachable attack paths. This helps teams reduce exposure in the network control plane where attackers often move laterally.

    • How does attack path mapping help prioritize remediation?

      Attack path mapping shows how multiple configuration weaknesses combine into routes toward critical assets. Instead of fixing findings in isolation, network security teams can focus on the changes that break attacker access, reduce lateral movement, and protect key services. This supports defensible prioritization based on reachability and impact.

    • Do we need a CMDB to use Nipper OmniSight?

      No. The Standalone tier of Nipper OmniSight is designed to deliver value without a CMDB by assessing the configurations you provide on a scheduled cadence. If you do have a CMDB or configuration repository, the Integrated tier of Nipper OmniSight can ingest that context to improve ownership, baselines, and reporting.

    • How does Nipper OmniSight support Zero Trust segmentation?

      An exposure management platform helps you discover and prioritize the exposures most likely to lead to compromise. For network security teams, that means validating network configuration and segmentation controls, not just scanning for CVEs. This helps remediation focus on reachable, high-impact attack surface exposures.

  • Platform | Capabilities | Exposure Management

    • What is an exposure management platform?

      An exposure management platform helps you discover and prioritize the exposures most likely to lead to compromise. For network security teams, that means validating network configuration and segmentation controls, not just scanning for CVEs. This helps remediation focus on reachable, high-impact attack surface exposures.

    • How is this different from vulnerability scans?

      Vulnerability scans are essential, but they focus on software flaws. They do not show whether network devices are securely configured, whether access is restricted, or whether segmentation rules are enforced. Nipper OmniSight adds network configuration evidence and control validation so teams can prioritize remediation more accurately.

    • Can we use this without a CMDB?

      Yes. Nipper OmniSight (Standalone) is designed for scheduled assessments at scale without CMDB dependency. If you have a CMDB or configuration storage platform, Nipper OmniSight (Integrated) can ingest that context. It does this in a read-only way to improve scoping and reporting.

    • Does Titania support continuous threat exposure management?

      Yes. Nipper OmniSight (Continuous) supports continuous threat exposure management by monitoring network configuration change and highlighting exposures created by drift or unsafe updates. If you do not need CTEM-level monitoring, Nipper OmniSight (Standalone) and Nipper OmniSight (Integrated) support scheduled exposure assessments. These assessments are repeatable and support Threat Exposure Management (TEM).

    • What outcomes should a network security team expect?

      Teams can cut the amount of time spent on validating noisy findings. They can also prioritize remediation more confidently, and improve segmentation assurance for critical services. Over time, repeated assessments show risk reduction across digital and internet-facing assets. They support audit evidence and security program reporting.

  • Platform | Capabilities | Attack Path Mapping

    • What is attack path mapping?

      Attack path mapping shows the possible routes an attacker could take to reach critical assets.  

      It is based on how your network is configured today. APM connects misconfigurations, access rules, routing, and trust boundaries into end-to-end paths. This enables teams to prioritize the fixes that break attacker movement rather than chasing isolated findings.

    • How is attack path analysis different from vulnerability scanning?

      Vulnerability scanners surface individual software issues. Attack path analysis shows whether weaknesses are reachable because of routing, access rules, segmentation, and trust boundaries. Practitioners can remove a path by fixing a few high‑impact choke points, helping leaders see measurable exposure reduction.

    • How does reachability analysis help teams reduce exposure?

      Reachability analysis proves what can reach what across routing, rules, and segmentation boundaries. This helps teams see whether segmentation plans match operational reality. It also helps them find unintended access between zones. Finally, it helps them confirm that fixes reduce real risk, not just the number of findings.

    • What’s the difference between attack surface and attack path mapping?

      Attack surface mapping shows where configuration-driven exposures exist across devices and segments. It helps Security Operations to baseline and reduce exposure. 

      Attack path mapping shows how exposures link into real routes to critical assets. It helps Cyber Operations prioritize actions and stop escalation. Both views can be built from the same configuration evidence.

    • Can Nipper OmniSight support attack path analysis?

      Yes. Nipper OmniSight maps attack paths using configuration‑derived reachability across routing, access rules, segmentation boundaries, and trust relationships expressed in device policy and network design. For scheduled assessments choose Nipper OmniSight (Standalone). For read‑only CMDB / configuration storage context choose Nipper OmniSight (Integrated). For drift‑aware control choose Nipper OmniSight (Continuous).

  • Platform | Capabilities | Zero Trust Segmentation

    • What is segmentation in a Zero Trust model?

      In a Zero Trust model, segmentation limits communication between network segments to only what is explicitly required. It helps stop lateral movement by enforcing least privilege access control across trust boundaries. The goal is measurable: fewer reachable paths to sensitive services and a smaller blast radius during a breach.

    • Why is network segmentation hard to maintain?

      In large environments, change requests, emergency fixes, and vendor differences create rule sprawl and inconsistent enforcement. Over time, small exceptions can become permanent paths between segments. Without validation, teams can’t tell whether the Zero Trust model still holds across firewalls, routers, and switches.

    • How is this different from policy management tools?

      Policy management tools help design, automate, and document network policy. They don’t always prove that device configurations enforce the intended trust boundaries. Configuration validation focuses on what devices will actually permit, based on their exported settings, and highlights the specific misconfigurations that create unintended access paths.

    • Can we validate segmentation without a CMDB?

      Yes. The Standalone tier of Nipper OmniSight supports scheduled, repeatable assessments without CMDB dependency. If you have a CMDB or configuration repository, the Integrated tier of Nipper OmniSight can ingest that context in a read-only way to improve scoping, reporting, and workflow alignment.

    • When do teams need the Continuous tier?

      Choose the Continuous tier of Nipper OmniSight when you need continuous threat exposure management (CTEM) for network change. It is designed for high-change or high-assurance environments where configuration change must be monitored and assessed as it happens to maintain segmentation and exposure control.

  • Platform | Capabilities | Network Configuration & Change Monitoring

    • What is network configuration management?

      Network configuration management is the practice of standardizing, tracking, and verifying device configurations so security intent is enforced consistently. For security teams, it focuses on routers, switches and firewalls that control segmentation, management access, and policy enforcement, where small changes can create outsized exposure.

    • How does this help with network change management?

      It gives you evidence to review and validate changes: what was modified, whether it deviates from baseline, and what risk it introduces. That improves approvals, reduces failed changes, and speeds investigations by linking incidents to configuration history rather than relying on screenshots or incomplete tickets.

    • What should network change monitoring include?

      At minimum: a versioned history of configuration files, differences between versions, and a way to assess whether changes break hardening or network configuration compliance requirements. If you run CTEM-style programs, Nipper OmniSight (Continuous) adds continuous monitoring for configuration change.

    • How is this different from vulnerability management?

      Vulnerability management focuses on software CVEs across endpoints, servers and applications. Network device configuration management focuses on how infrastructure is configured to enforce trust, segmentation and access. Many high-impact issues are misconfigurations and policy gaps that a scanner cannot confirm without configuration evidence.

    • Can we use this in regulated or air-gapped networks?

      Yes. Nipper solutions support configuration-led assessment workflows that work in sensitive environments where active scanning is restricted. You can run scheduled assessments, maintain repeatable evidence, and reduce audit risk without introducing disruptive traffic. Perfect for regulated, sovereign, and air-gapped deployments.

  • Platform | Capabilities | Compliance Automation

    • What is compliance automation for network devices?

      It means running repeatable, configuration-based checks on routers, switches, and firewalls, then producing evidence mapped to control requirements. Instead of manual sampling, you standardize test logic, show pass or fail per control, and provide traceability back to the configuration evidence used for assessor review.

    • How do you support compliance reporting for auditors?

      Nipper OmniSight produces structured reports that help auditors verify scope, exceptions, and remediation status. Findings map to framework controls and link to configuration evidence assessed. This reduces manual collation, supports peer review and assessor testing, and makes audit workpapers consistent across vendors, sites, device types, and assessment cycles.

    • Which frameworks and benchmarks do you support?

      Nipper OmniSight maps network configuration evidence to requirements such as PCI DSS 4.0, NIST SP 800-53, ISO 27001, and CIS. For higher-assurance needs, DISA STIG benchmark validation is available as a Premium capability. The result is control-mapped, audit-ready evidence with traceability back to device settings.

    • Which Nipper OmniSight solution tier fits our audit and security workflow?

      Nipper OmniSight (Standalone) supports scheduled, repeatable assessments at scale and produces audit-ready evidence. Nipper OmniSight (Integrated) adds read-only CMDB alignment and SIEM workflow integration to reduce orchestration effort. Choose based on whether you need asset context, workflow routing, and easier scope reconciliation for audits.

    • Does this replace our GRC tools and process?

      No. Nipper OmniSight complements GRC platforms by providing configuration-derived evidence that governance workflows can reference. Automating regulatory compliance works best when assessment evidence and remediation tracking stay aligned to your existing controls and control owners. Approvals and exception handling should follow your established sign-off process. That way, your evidence holds up for both internal assurance and external assessment reviews.

  • Platform | Explore | Compare Tiers

    • What is Nipper OmniSight used for?

      Nipper OmniSight helps teams run scheduled or continuous, configuration-based exposure assessments across network estates. It is designed to identify misconfiguration- and software vulnerability-driven exposure, enable segmentation assurance, and prioritize remediation and response using deterministic evidence derived from device configurations.

    • When should I choose Nipper OmniSight (Standalone) vs Nipper OmniSight (Integrated)?

      Choose Nipper OmniSight (Standalone) when you want scheduled, repeatable assessments and dashboards at scale without relying on a CMDB. Choose Nipper OmniSight (Integrated) when you want to align assessments to CMDB or configuration repository context (read-only) and operationalize findings through more automated orchestration and workflow integrations.

    • What makes Nipper OmniSight (Continuous) different?

      Nipper OmniSight (Continuous) is built for continuous threat exposure management (CTEM) for network configuration change. It adds change-aware monitoring and continuous validation so teams can maintain exposure and segmentation assurance between assessment cycles and across fast-changing environments.

    • Does Nipper OmniSight replace a SIEM or network monitoring platform?

      No. Nipper OmniSight complements monitoring and SIEM tooling by adding configuration-validated exposure context. This helps teams understand how configuration conditions contribute to real exposure, prioritize investigations, and support more repeatable remediation decisions.

    • How does Nipper OmniSight support Zero Trust and segmentation assurance?

      Nipper OmniSight analyzes how configurations enforce routing, segmentation intent, and trust boundaries. This helps teams identify unintended access paths and segmentation gaps and validate least privilege access (LPA) and segmentation controls on a scheduled or continuous basis, depending on tier.

  • Product | Nipper InfraSight

    • What is a network security assessment?

      A network security assessment evaluates how your network is exposed and where controls are weak. For network devices, that means validating the configurations that enforce segmentation, routing, and access. Nipper InfraSight assesses exported device configurations to identify vulnerabilities, misconfigurations, and control gaps with prioritized findings and remediation guidance.

    • Why assess configs, not only scan?

      Scans can miss weaknesses where exposure depends on rules, access paths, or device settings. Configuration analysis helps you validate what the device is configured to allow, not just what responds to a probe. Nipper InfraSight focuses on routers, switches, and firewalls. It finds misconfigurations, conflicts, and gaps that scanners and policy tools may miss.

    • How does Nipper InfraSight support vulnerability management?

      It strengthens vulnerability management by adding configuration-based findings for network devices. This helps teams prioritize fixes based on exploit risk and exposure, not CVE lists alone. Practitioners get device-level evidence and guidance; decision-makers get clearer reporting on risk reduction and remediation progress.

    • What is included in compliance assessment?

      Compliance assessment reporting depends on tier. The Compliance tier of Nipper InfraSight and the Air Gapped tier add structured reports supporting audit preparation with repeatable evidence. These reports align with controls and map to major frameworks. These include NIST SP 800-53, NIST SP 800-171, PCI DSS 4.0, and CMMC.

    • Can Nipper InfraSight work in air-gapped networks?

      Yes. The Air Gapped tier of Nipper InfraSight is designed for offline and restricted environments where cloud analysis, credentialed scanning, or active probing are restricted or prohibited. It provides the full Nipper InfraSight capability set while keeping assessment workflows aligned to strict data-handling requirements.

  • Product | Capabilities | Vulnerability Management

    • What is vulnerability management for network devices?

      It is the process of identifying, prioritizing, remediating and verifying weaknesses on routers, switches, firewalls and related infrastructure. It includes configuration flaws, weak access controls and firmware or software vulnerabilities, not just endpoint CVEs.

    • How do you prioritize vulnerability remediation?

      Prioritize by exploitability and impact: is the weakness reachable, does it bypass segmentation, and what would it expose? Risk-based vulnerability management cuts time spent chasing low-impact findings. It helps teams use limited change windows where they matter most.

    • How does Nipper InfraSight reduce false positives?

      Nipper InfraSight analyzes configuration evidence rather than relying only on pattern matching. Findings link back to the specific settings, paths and conditions that create exposure, so network and security teams can validate quickly and agree on the right fix.

    • Does this replace my VM scanner or SIEM?

      No. Network vulnerability management complements vulnerability scanners, SIEM and operational monitoring by adding configuration-level truth for the network control plane. This helps teams confirm what is actually exposed and route higher-confidence issues into existing workflows.

    • When should I use Nipper InfraSight?

      Use Nipper InfraSight when you need high-confidence, point-in-time vulnerability management for network devices based on exported configurations. Use it for targeted validation, baseline hardening, or audit support. It also helps when direct device access is limited.

    • Which Nipper InfraSight tier fits my environment?

      Choose Nipper InfraSight (Essential) for core device vulnerability detection and remediation guidance. Choose Nipper InfraSight (Compliance) when you need control-mapped, audit-aligned outputs and Premium capability sets. Choose Nipper InfraSight (Air Gapped) for fully offline operation in isolated, sovereign, OT or classified environments.

  • Product | Capabilities | Network Hardening

    • How is network hardening different from vulnerability scanning?

      Vulnerability scanning highlights software weaknesses. Network hardening verifies device configurations against a baseline so insecure services, weak access controls, unsafe protocols, and permissive rules are removed. It complements scanning by addressing configuration exposure that patching and CVE detection do not resolve.

    • What should a hardening baseline configuration include?

      Define approved services, management plane access, authentication, logging, encryption, and segmentation intent. Then map settings to vendor guidance and system hardening standards (such as CIS Benchmarks) so exceptions are explicit and reviewable.

    • What devices can be assessed for device hardening?

      Nipper InfraSight supports routers, switches and firewalls for over 180 devices. Start with the devices that enforce segmentation and remote access, then expand coverage to standardize securing network devices across the estate.

    • How do you prove security hardening was applied?

      Assess the configuration, remediate using the recommended device-specific changes, then re-assess and export evidence. This creates a clear record of baseline gaps and fixes. It supports internal assurance and audits. It also strengthens controls across the network infrastructure.

    • How do you avoid hardening breaking network operations?

      Apply a baseline that matches required services and routing. Validate changes through change control. Prioritize high-impact, low-risk fixes first. Configuration evidence reduces guesswork and helps engineering teams implement security hardening without unexpected service disruption.

    • How do teams provide device configurations for assessment?

      Export configuration files from your routers, switches and firewalls, then upload them for analysis. Use the most recent exports so results reflect the current enforced configuration.

  • Product | Capabilities | Compliance Assessment

    • Who uses Nipper InfraSight, and how does it support audits and assessments?

      Nipper InfraSight provides audit-ready evidence and context from device configuration settings through point-in-time assessments you can re-run as needed. This supports audit planning and fieldwork, while giving GRC and security teams consistent, control-mapped outputs to track remediation and reduce follow-up work.

    • When should I use Nipper InfraSight?

      Use Nipper InfraSight when you need point-in-time, device-level evidence for audit scopes, targeted validations, or internal readiness checks – especially in offline or air-gapped environments. It helps you produce control-mapped, pass / fail evidence from exported configurations, prioritize remediation, and repeat assessments to confirm fixes and detect drift.

    • Does Nipper InfraSight replace an auditor / assessor’s judgment?

      No. Nipper InfraSight provides evidence and context from configuration settings and helps teams standardize remediation tracking. Final compliance determinations remain with the audit / assessment authority (and, where applicable, regulators).

    • Which frameworks can Nipper InfraSight map evidence to for audits / assessments?

      Depending on tier, assessments can align with frameworks like NIST SP 800-53 and NIST SP 800-171 and can also align with PCI DSS and CMMC – supporting control-mapped evidence generation for both internal audit and external audits / assessments.

    • What can Nipper InfraSight automate?

      Nipper InfraSight automates point-in-time, offline control checks and evidence generation from exported configs. Teams can use the outputs as audit evidence and to prioritize and validate remediation, without requiring direct access to devices or consuming operational network bandwidth.

  • Product | Explore | Compare tiers

    • What is Nipper InfraSight used for?

      Nipper InfraSight produces point-in-time, configuration-based findings for network devices such as routers, switches, and firewalls. It helps teams harden settings, produce defensible evidence for audits, and prioritize remediation using deterministic results mapped back to configuration.

    • When should I choose Essential vs Compliance tiers?

      Choose Nipper InfraSight (Essential) for fast device reviews, baseline hardening, and practical remediation guidance. Choose Nipper InfraSight (Compliance) when you must produce structured, framework-aligned reporting (for example NIST or PCI DSS) with evidence-grade pass / fail outputs and human- and machine-readable outputs for audit workflows.

    • What makes the Air Gapped tier different?

      Nipper InfraSight (Air Gapped) delivers the full capability set for environments that must remain fully offline – such as sovereign, classified, OT, or regulated networks. It is designed for high-assurance workflows where cloud-based analysis or active probing are restricted or prohibited.

    • How does Nipper InfraSight support defensible audit evidence?

      Findings are derived directly from device configuration states and can be traced back to the settings, paths, and conditions that triggered them. This supports repeatable reviews, peer validation, and clearer narratives for audit preparation, risk assessments, and follow-up work.

    • What types of devices does Nipper InfraSight assess?

      Nipper InfraSight supports point-in-time assessments across common network infrastructure devices, including routers, switches, and firewalls. Higher tiers extend coverage and outputs, adding compliance framework mappings and device support such as Cisco Meraki, SD-WAN, and wireless access points, plus capability sets like STIG.

  • Solutions | Compliance | CORA

    • What is a Cyber Operational Readiness Assessment (CORA)?

      CORA is a DoD readiness assessment that emphasizes threat-informed risk and mission assurance over checklist scoring. It helps leaders understand high-priority cyber terrain and focuses attention on controls that reduce attack surface and improve defensive cyber operations, supported by evidence.

    • What does a CORA inspection look for in networks?

      CORA assesses the risk conditions most likely to be exploited, including access control, segmentation enforcement, and hardening of mission-relevant systems. For network teams, that often comes down to whether routers, switches, and firewalls are configured to enforce intended boundaries and align to DISA STIG requirements.

    • How does Nipper OmniSight support CORA preparation?

      The Integrated tier of Nipper OmniSight automates configuration ingestion via read-only CMDB or configuration storage synchronization and routes prioritized findings into SIEM workflows for tracking. If you need CTEM for network change, Nipper OmniSight (Continuous) provides continuous monitoring and real-time drift detection so teams can validate that CORA-relevant controls stay enforced between inspection windows.

    • Can Nipper OmniSight be used in restricted environments?

      Nipper OmniSight is commonly deployed as an on-premises virtual appliance. The Integrated tier of Nipper OmniSight supports read-only CMDB or configuration storage synchronization and SIEM workflow integration. Nipper OmniSight (Continuous) requires the access needed to monitor configuration change to support CTEM; deployment constraints depend on your network architecture and control boundaries.

    • How is this different from vulnerability scanning platforms?

      Vulnerability tools are essential for software flaws, but they often cannot prove how network controls are configured and enforced. Nipper OmniSight tracks configuration state across routers, switches, and firewalls. It helps you validate segmentation intent, STIG hardening, and control effectiveness. It also provides evidence to support CORA decisions.

  • Solutions | Compliance | NIST

    • Who must comply with NIST standards?

      Compliance is mandatory for US federal agencies and most organisations that supply them. Many other organisations also adopt NIST voluntarily as a recognized benchmark for cyber‑risk management.

    • What changed in NIST CSF 2.0?

      NIST CSF 2.0, released in 2024, introduced the “Govern” function, reflecting cybersecurity as an enterprise responsibility with executive oversight.

    • What are the consequences of non-compliance?

      Failing to meet required standards, or to provide evidence, can lead to fines, contract termination, or loss of eligibility.

    • Do Nipper solutions support other frameworks?

      Yes. Pre‑built frameworks also exist for CMMC, NIS2, CORA, NERC CIP, DISA STIGs and other major security frameworks.

    • Are Nipper solutions used by military organizations?

      Nipper solutions have been used by military and defense organizations for over a decade. They support high-assurance and mission-critical environments.

  • Solutions | Compliance | PCI DSS

    • What is PCI DSS and who must comply?

      PCI DSS is the payment card security standard for organizations that store, process, or transmit cardholder data, or can impact the security of that environment. If your network connects to payment systems, your network security controls and segmentation decisions can affect PCI DSS compliance scope.

    • What changed with PCI DSS 4.0 and 4.0.1?

      PCI DSS v4.0 introduced new and updated requirements plus a more flexible way to meet objectives using a defined or customized approach. PCI DSS v4.0.1 is a minor revision that became the active version after v3.2.1 was retired, and future-dated requirements became applicable after March 31, 2025.

    • Why does segmentation affect PCI compliance audit scope?

      If the CDE is not properly isolated, more systems become “connected-to” and fall into scope. That increases the number of devices you must harden, test, and evidence. Network security teams use segmentation controls to reduce attack paths and to keep credit card compliance effort focused.

    • How can we prepare for a PCI DSS compliance assessment?

      Start by confirming scope, documenting data flows, and validating that network security controls enforce intended boundaries. Then run a configuration-based assessment to identify device settings and access paths that will fail. Mapped reports help you close gaps and keep evidence organized for assessors.

    • Are Nipper solutions a replacement for a QSA?

      No. Qualified Security Assessors (QSAs) determine compliance outcomes. Nipper solutions support your PCI DSS compliance assessment by turning device configurations into mapped evidence, prioritized findings, and remediation guidance so you can address issues earlier and reduce audit churn.

  • Solutions | Compliance | DISA STIGs

    • What are DISA STIGs?

      Security Technical Implementation Guides (STIGs) are mandatory configuration standards. Issued by the Defense Information Systems Agency (DISA), they safeguard Department of Defense (DoD) systems and networks. Each STIG defines required security controls for specific devices, operating systems, software and network technologies.

    • Are Nipper solutions aligned with the latest STIGs?

      Yes. Nipper solutions include a pre-built assessment framework. We update it regularly to reflect the latest DISA STIG requirements. This ensures consistent, accurate device‑level evaluations across supported Nipper InfraSight and Nipper OmniSight tiers.

    • How do Nipper solutions prioritize compliance risks?

      Nipper InfraSight evaluates configuration data using a penetration tester methodology to identify non‑compliance and highlight the most impactful issues first. We categorise findings as CAT I, CAT II, or CAT III. In Nipper OmniSight, independent threat intelligence mapped to MITRE ATT&CK further enhances risk prioritization.

    • Do Nipper solutions operate fully offline and protect configuration data?

      Yes. Nipper solutions let you run all assessments locally, within your security boundary. You do not need cloud services or external connectivity. 

      We do not export telemetry, metadata, or configuration samples. This supports sovereign, classified, SCIF, tactical, and fully air-gapped environments. It meets DoD data protection and enclave security requirements.

    • Are Nipper solutions suitable for military and classified use?

      Yes. U.S. military teams have used Nipper technology for over a decade. It supports secure operations in connected, segmented, sovereign, classified, and fully air‑gapped environments. More than 100 defence, government and critical‑infrastructure organisations rely on Nipper for device‑level configuration assurance in mission‑critical networks.

  • Solutions | Compliance | CMMC

    • Who needs CMMC certification?

      Any organisation in the defense industrial base that handles Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) may need CMMC certification. The required level will be stated in the contract or solicitation. This requirement may also flow down to subcontractors.

    • What are CMMC levels 1 and 2?

      CMMC level 1 focuses on basic safeguarding for FCI and is assessed through self-assessment. CMMC Level 2 aligns with NIST SP 800-171 requirements to protect CUI. It may require a C3PAO assessment, depending on the contract.

    • What evidence is needed for a CMMC audit?

      Assessors usually expect a current system security plan (SSP), a defined scope, and data flows. They also expect policies and procedures, as well as objective evidence that controls are in place. For network controls, configuration evidence, change records, and repeatable reports help reduce follow-up questions.

    • How do Nipper solutions support CMMC compliance?

      Nipper solutions analyze router, switch, and firewall configurations against mapped CMMC compliance requirements and produce control-aligned outputs. You can prioritize remediation, re-run assessments after fixes, and create consistent evidence packs for internal and external reviews.

    • Do Nipper solutions certify that we are CMMC compliant?

      No. Nipper solutions help you prepare for CMMC audits by providing configuration-based evidence and remediation guidance. Certification decisions sit with your organisation and, where required, your C3PAO assessor and the Department of Defense.

  • Solutions | Compliance | NCSC CAF

    • What is the cyber assessment framework?

      The cyber assessment framework is the NCSC’s outcomes-based approach for assessing how well an organization manages cyber risk and resilience for essential functions. It is structured around four objectives (manage risk, protect, detect, and minimize impact) with principles, contributing outcomes and indicators of good practice.

    • What evidence is expected for CAF assessment?

      Assessors typically look for evidence that controls are designed, implemented and operating effectively for the systems supporting essential functions. For network security teams, that often means defensible proof of secure configuration, access control, segmentation, vulnerability management and monitoring processes – backed by repeatable technical findings.

    • How does Nipper OmniSight support NCSC CAF compliance?

      Nipper OmniSight turns network device configurations into auditable findings and maps relevant evidence to NCSC CAF contributing outcomes. It supports IT security assessment and cybersecurity assessment workflows by making results repeatable, comparable across runs, and easier to package for assurance reviews while keeping the focus on outcomes for essential functions.

    • Which Nipper OmniSight tier should we use?

      Use Nipper OmniSight (Standalone) for scheduled, repeatable assessments at scale. Choose Nipper OmniSight (Integrated) if you need CMDB or configuration storage context (read-only) to support governance and reporting. Use Nipper OmniSight (Continuous) when you are implementing CTEM and need real-time configuration monitoring and change detection.

    • Does using Nipper OmniSight certify or guarantee compliance?

      No. Nipper OmniSight supports cyber assurance by providing technical validation and evidence you can use in assurance reviews. Compliance decisions remain with your organization and any independent assessors. The value is faster evidence collection, clearer prioritization, and a more defensible narrative about how network controls reduce risk to essential functions.

  • Solutions | Compliance | NERC CIP

    • What is NERC CIP compliance?

      NERC CIP (nerc critical infrastructure protection) is a set of mandatory cybersecurity standards for protecting Bulk Electric System assets. It requires entities to set up and prove controls under North American Electric Reliability Council oversight. These controls include perimeter protection, access management, system security management, and configuration change management.

    • What evidence do auditors expect from NERC compliance testing?

      Evidence commonly includes documented processes plus proof that controls are implemented on in-scope systems. For network devices, that often means configuration evidence for electronic security perimeters, remote access controls, hardening baselines, and change records. Configuration-based reports help make evidence traceable and repeatable.

    • How do Nipper solutions support firewall NERC compliance?

      Nipper solutions analyze firewall settings to find rule and object issues. These issues can weaken CIP expectations. Examples include open access, weak admin access, and poor segmentation. It also supports evidence creation by linking findings to the configuration statements that caused them and provides remediation guidance.

    • Do Nipper solutions replace other NERC CIP compliance software?

      No. Nipper solutions complement GRC tools, SIEM, vulnerability scanning, and network modeling by adding deterministic, configuration-level evidence for network devices. They help you prove that controls work in how devices behave (what the setup allows). This goes beyond policy or alerts alone.

    • When should we use Nipper OmniSight (Continuous)?

      Use Nipper OmniSight (Continuous) when you need CTEM-aligned, continuous monitoring of configuration change and control integrity across fast-changing or high-assurance environments. For many programs, teams start with scheduled checks in Nipper OmniSight (Standalone). They move to the Continuous tier when governance, workflows, and scale require it.

  • Solutions | Compliance | CIS Benchmarks

    • What are CIS Benchmarks?

      CIS Benchmarks provide security baseline recommendations for hardening routers, switches, firewalls, and other network infrastructure, including vendor-specific recommendations.

    • Are Nipper solutions aligned with the latest CIS Benchmarks?

      Yes. We regularly update our pre‑built frameworks to reflect the latest CIS standards. Titania is a CIS accredited partner and holds more than 100 certifications across multiple vendors and device types. www.cisecurity.org/partner/titania

    • How do Nipper solutions prioritize compliance risks?

      Nipper solutions apply a penetration tester methodology to identify misconfigurations and non‑compliance, then use risk scoring to rank issues by criticality. Nipper OmniSight also maps findings to the latest MITRE ATT&CK intelligence.

    • Do Nipper solutions support other compliance frameworks?

      Yes. We also provide pre-built frameworks for CMMC, DISA STIGs, NIST, and others.

    • Do Nipper solutions certify that we are CMMC compliant?

      No. Nipper solutions help you prepare for CMMC audits by providing configuration-based evidence and remediation guidance. Certification decisions sit with your organisation and, where required, your C3PAO assessor and the Department of Defense.

  • Solutions | Industry | National Security

    • Are Nipper solutions suitable for military use?

      Yes, Nipper InfraSight is approved for use in various services, agencies and countries. Contact us for more details.

    • We already have vulnerability management tools. Why should we add Nipper solutions?

      Vulnerability management is well-suited to devices with relatively static configurations like servers and endpoints. But attackers are targeting network devices, which are highly configurable. Nipper solutions can spot misconfigurations in those devices, and align these to the latest tactics, techniques and procedures (TTPs) used by adversaries focused on compromising national security.

    • We use policy management for all our applications. Why should we add Nipper solutions?

      Policy management solutions check whether network devices are correctly enforcing your policies, but don’t check whether the network devices themselves are secure. A device could be correctly enforcing application connectivity policy, but if it was compromised by a weak password, all data passing between applications would be vulnerable. Nipper solutions addresses this.

    • How does AI change the threat landscape?

      AI has yet to create new attack vectors: what’s changed is the speed and scale of attacks. APTs leverage the power of AI to exploit exposures across flat networks far faster – attacking multiple points including mission-critical systems and sensitive or classified data at the same time.

    • How do Nipper solutions help with Zero Trust?

      Nipper OmniSight provides Zero Trust segmentation and least privilege access monitoring for business-critical segments, confirming whether devices are correctly enforcing your policies. By combining this with pre-emptive exposure assessment Nipper OmniSight can provide a real-time, adversary-aware picture of how resilient your network’s cyber defense truly is.

    • Why is effective segmentation so important to reduce risk?

      Segmentation is fundamental to resilience because it breaks a complex environment into clearly defined zones (e.g., classified, unclassified, maximum security etc.) with explicit, least privilege connectivity between them. This therefore means that even if attackers gain access, the breach can be contained and the attack surface reduced.

    • How do you assist with CORA compliance?

      Our dedicated CORA solution is designed to help you confirm that all Key Indicators of Risk have been addressed before you face assessment. It provides actionable reports showing all non-compliance with the latest STIGs, prioritizing KIORs so you can address the most significant issues first.

    • Do Nipper solutions need network access to operate?

      No, Nipper InfraSight and Nipper OmniSight (Standalone) all function independently of your network. They examine device configuration files, rather than live configurations, and can operate on a separate laptop. Nipper OmniSight (Continuous) does require network access to enable 24x7 monitoring of every network change.

    • Can Nipper solutions help us map our network?

      Yes, both Nipper OmniSight (Integrated) and Nipper OmniSight (Continuous) can create visual representations of your networks, based on the device configurations stored in a CMDB. Nipper OmniSight (Continuous) can also populate a CMDB if you don’t already have one.

    • We don’t have a CMDB. Can we use Nipper OmniSight?

      Yes. You can use the configuration collector in Nipper OmniSight (Continuous) to populate a CMDB. Or you can use Nipper OmniSight (Standalone), which uses the configurations you upload to provide a point-in-time assessment.

    • Can Nipper solutions help us map attack paths?

      Yes, the attack path mapping capability in Nipper OmniSight can visualize the most likely approaches attackers might take to reach classified information. This involves overlaying routing and threat data including the latest TTPs from trusted sources onto network maps created from the device configurations stored in a CMDB.

  • Solutions | Industry | Federal

    • Are Nipper solutions suitable for government use?

      Nipper solutions are widely used in government departments globally. Contact us for more details.

    • Why is effective segmentation so important to reduce risk?

      Segmentation is fundamental to government network resilience because it breaks a complex environment into clearly defined zones (e.g., user, server, management, OT, etc.) with explicit, least privilege connectivity between them. This therefore means that if government networks are breached, the chances of accessing key data are reduced.

    • How do Nipper solutions help with Zero Trust?

      Nipper OmniSight helps federal government cybersecurity teams confirm whether their network devices are correctly enforcing Zero Trust segmentation and least privilege access policies. By combining this with pre-emptive exposure assessment Nipper OmniSight can provide a real-time, adversary-aware picture of how resilient the network truly is.

    • We already have vulnerability management tools. Why should we add Nipper solutions?

      Vulnerability management is well-suited to devices with relatively static configurations like servers and endpoints. But network devices are highly configurable, so benefit from the in-depth analysis that Nipper technology can provide to spot misconfigurations and align these to the latest tactics, techniques and procedures (TTPs) used by attackers targeting government networks.

    • We use policy management for all our applications. Why should we add Nipper solutions?

      If a device is correctly enforcing application connectivity policy, policy management solutions would not flag the risk – yet if it was compromised by a weak password, any classified data passing between applications would be vulnerable. Nipper solutions address this critical risk for government agencies.

    • How does AI change the threat landscape?

      AI has yet to create new attack vectors: what’s changed is the speed and scale of attacks. APTs and ransomware groups leverage the power of AI to exploit exposures across flat networks far faster – attacking multiple points including mission-critical systems and data at the same time.

    • Can Nipper solutions help us map our network?

      Yes, both Nipper OmniSight (Integrated) and Nipper OmniSight (Continuous) can create visual representations of your networks, based on the device configurations stored in a CMDB. Nipper OmniSight (Continuous) can also populate a CMDB if you don’t already have one.

    • We don’t have a CMDB. Can we use Nipper OmniSight?

      Yes. You can use the configuration collector in Nipper OmniSight (Continuous) to populate a CMDB. Or you can use Nipper OmniSight (Standalone), which uses the configurations you upload to provide a point-in-time assessment of your cybersecurity defense.

  • Solutions | Industry | Finance

    • We already have vulnerability management tools. Why should we add Nipper solutions?

      Vulnerability management is well-suited to devices with relatively static configurations like servers and endpoints. But network devices are highly configurable, so benefit from the in-depth analysis that Nipper technology can provide to spot misconfigurations and align these to the latest tactics, techniques and procedures (TTPs) used by attackers targeting financial institutions.

    • We use policy management for all our applications. Why should we add Nipper solutions?

      Policy management solutions check whether network devices are correctly enforcing your policies, but don’t check whether the network devices themselves are secure. A device could be correctly enforcing application connectivity policy, but it was compromised by a weak password, all customer data passing between applications would be vulnerable. Nipper solutions address this.

    • How does AI change the threat landscape for bank network security?

      AI has changed the speed and scale of attacks. APTs and ransomware groups leverage it to exploit exposures across flat networks – attacking multiple points including mission-critical systems and customer data at the same time. That’s one reason why The Digital Operational Resilience Act (DORA) emphasizes the importance of network segmentation.

    • Why is effective segmentation so important to reduce risk?

      Segmentation is fundamental to resilience because it breaks a complex environment into clearly defined zones (e.g., cardholder data environment) with explicit, least privilege connectivity between them. This therefore means that if the network is breached, the breach can be contained and the attack surface reduced.

    • How do your solutions help with Zero Trust?

      Nipper OmniSight confirms whether a financial services institution’s Zero Trust segmentation and least privilege access controls are being enforced correctly at device level. By combining this with pre-emptive exposure assessment, Nipper OmniSight can provide a real-time, adversary-aware picture of how resilient the network truly is.

    • How do Nipper solutions protect legacy systems?

      Nipper solutions don’t protect banks’ legacy systems directly; they focus on the networks that are now exposing these systems to outside threats. By pinpointing vulnerabilities in those networks – from misconfigured switches, routers and firewalls to rule conflicts – our solutions help eliminate attack paths that could target critical yet unsecured systems.

  • Solutions | Industry | Telecommunications

    • We already have vulnerability management tools. Why should we add Nipper solutions?

      Vulnerability management is best suited to devices with relatively static configurations like servers and endpoints. Highly configurable network devices require the kind of in-depth analysis that Nipper solutions provide to spot misconfigurations and align these to the latest tactics, techniques and procedures (TTPs) used by attackers targeting the telecoms sector.

    • We use policy management for all our applications. Why should we add Nipper solutions?

      Policy management solutions check whether network devices are correctly enforcing your policies, but don’t check whether the network devices themselves are secure. If a device has a weak password, all critical communications passing through it would be vulnerable to attackers. Nipper solutions help prevent this.

    • How does AI change the threat landscape for the telco industry?

      AI has yet to create new attack vectors, but it has already transformed the scale and intensity of attacks. APTs use it to find and exploit exposures across flat networks far faster – simultaneously attacking multiple devices that offer access to sensitive data or mission-critical systems.

    • How do Nipper solutions help with Zero Trust?

      Nipper OmniSight confirms whether each device is correctly enforcing your Zero Trust segmentation and least privilege access policies. By combining this with pre-emptive exposure assessment Nipper OmniSight can provide a real-time, adversary-aware picture of whether your networks are resilient to APTs.

    • Can Nipper solutions help us map the telecoms network infrastructure?

      Yes, both Nipper OmniSight (Integrated) and Nipper OmniSight (Continuous) can create visual representations of your networks, based on the device configurations stored in a CMDB – invaluable for day-to-day operations as well as telecoms cybersecurity. Nipper OmniSight (Continuous) can also populate a CMDB if you don’t already have one.

  • Solutions | Industry | Manufacturing

    • How do Nipper solutions protect OT?

      Nipper solutions don’t protect the OT manufacturers rely on directly. Instead, they focus on the IT networks that underpin the OT infrastructure. By pinpointing exposures and LPA compromises on OT segments, Nipper solutions helps eliminate potential OT attack paths and reduce the attack surface.

    • How do Nipper solutions help with Zero Trust?

      Nipper OmniSight provides Zero Trust segmentation and least privilege access monitoring for business-critical segments, confirming whether devices are correctly enforcing your policies. By combining this with pre-emptive exposure assessment Nipper OmniSight can reinforce manufacturing network security with a real-time, adversary-aware picture of how resilient the network truly is.

    • How do Nipper solutions protect cyber physical systems?

      Our solutions don’t protect autonomous systems directly; they focus on the networks that support those systems and are making them accessible to outside threats. By pinpointing vulnerabilities in those networks – from misconfigured switches, routers and firewalls to rule conflicts – Nipper solutions help eliminate potential attack paths and the resulting disruption to manufacturing operations.

    • We already have vulnerability management tools. Why should we add Nipper solutions?

      Vulnerability management is well-suited to devices with relatively static configurations like servers and endpoints. But network devices are highly configurable, so benefit from the in-depth analysis that Nipper solutions can provide to spot misconfigurations and align these to the latest tactics, techniques and procedures (TTPs) used by attackers targeting manufacturing.

    • We use policy management for all our applications. Why should we add Nipper solutions?

      Policy management solutions check whether network devices are enabling applications like ERP and MRP to connect securely across your network, but don’t check whether those devices themselves are secure. So if the device had a weak password, all data passing between applications would be vulnerable. Nipper solutions identify this.

    • Can your solutions help us map our network?

      Yes, both Nipper OmniSight (Integrated) and Nipper OmniSight (Continuous) can create visual representations of your network, including air-gapped segments, based on the device configurations stored in a CMDB. Nipper OmniSight (Continuous) can also populate a CMDB if you don’t already have one.

    • We don’t have a CMDB. Can we use Nipper OmniSight?

      Yes. You can use the configuration collector in Nipper OmniSight (Continuous) to populate a CMDB. Or you can use Nipper OmniSight (Standalone), which uses the configurations you upload to provide a point-in-time assessment, but does not offer the continuous network monitoring that is increasingly viewed as integral to effective cybersecurity for manufacturing.

  • Solutions | Industry | Retail

    • We already have vulnerability management tools. Why should we add Nipper solutions?

      Vulnerability management is well-suited to devices with relatively static configurations like servers and endpoints. But network devices are highly configurable, so benefit from Nipper technology’s in-depth analysis to spot misconfigurations and align these to the latest tactics, techniques and procedures (TTPs) used by ransomware groups targeting retail.

    • We use policy management for all our applications. Why should we add Nipper solutions?

      Policy management solutions check whether retail network security policies are being correctly followed, but don’t analyze whether devices themselves are secure. A device could be correctly enforcing application connectivity policy, but if it was compromised by a weak password, all customer data passing between applications would be vulnerable. Nipper solutions address this.

    • How does AI change the threat landscape for retailers?

      AI has yet to create new attack vectors: what’s changed is the speed and scale of attacks. Ransomware groups targeting retail are applying AI to exploit exposures across flat networks far faster – attacking multiple points including customer data at the same time.

    • How do Nipper solutions help with Zero Trust?

      Nipper OmniSight provides Zero Trust segmentation and least privilege access monitoring for business-critical segments, confirming whether devices are correctly enforcing access controls for e.g. the cardholder data environment. By combining this with pre-emptive exposure assessment Nipper OmniSight can provide a real-time, adversary-aware picture of how resilient your network is.

    • Why is effective segmentation so important to reduce risk?

      Segmentation is fundamental to resilience because it breaks a complex environment into clearly defined zones (e.g., cardholder data environment, stock management.) with explicit, least privilege connectivity between them. This therefore means that even if the perimeter is breached, the attack can be contained.

    • How do Nipper solutions protect cyber physical systems used in warehousing and logistics?

      Our solutions don’t protect autonomous systems like robotics directly; they focus on the networks that support those systems and are making them accessible to outside threats. By pinpointing vulnerabilities in those networks – from misconfigured switches, routers and firewalls to rule conflicts – Nipper solutions help eliminate potential attack paths.

    • Can Nipper solutions help us map our network?

      Yes, both Nipper OmniSight (Integrated) and Nipper OmniSight (Continuous) can create visual representations of the entire retail network, based on the device configurations stored in a CMDB. Nipper OmniSight (Continuous) can also populate a CMDB if you don’t already have one.

    • We don’t have a CMDB. Can we use Nipper OmniSight?

      Yes. You can use the configuration collector in Nipper OmniSight (Continuous) to populate a CMDB with data from across the network. Or you can use Nipper OmniSight (Standalone), which uses the configurations you upload to provide a point-in-time assessment.

  • Solutions | Industry | Energy and Utilities

    • We already have vulnerability management tools. Why should we add Nipper solutions?

      Vulnerability management is well-suited to devices with relatively static configurations like servers and endpoints. But network devices are highly configurable, so benefit from Nipper solutions’ in-depth analysis to spot misconfigurations and align these to the latest tactics, techniques and procedures (TTPs) used by attackers targeting energy and utilities companies.

    • How do Nipper solutions help with Zero Trust?

      Nipper OmniSight monitors Zero Trust segmentation and LPA controls for critical segments such as grid-connected environments, confirming whether devices are correctly enforcing your policies. By combining this with pre-emptive exposure assessment, Nipper OmniSight can provide a real-time, adversary-aware view of the effectiveness of cybersecurity measures for critical infrastructure. Read more

    • Why is effective segmentation so important for reducing risk?

      Segmentation is fundamental to energy sector security because it breaks a complex environment into clearly defined zones with explicit, least privilege connectivity between them. So even if the network is breached, the breach can be contained and the attack surface reduced.

    • How do Nipper solutions protect legacy systems?

      Our solutions don’t protect legacy systems directly; they focus on the networks that are exposing these mission-critical platforms to outside threats. By pinpointing vulnerabilities in these networks, Nipper solutions help eliminate attack paths.

    • Can Nipper solutions help us map our network?

      Yes, both Nipper OmniSight (Integrated) and Nipper OmniSight (Continuous) can create visual representations of your networks, including remote energy operations, based on the device configurations stored in a CMDB. Nipper OmniSight (Continuous) can also populate a CMDB if you don’t already have one.

    • We don’t have a CMDB. Can we use Nipper OmniSight?

      Yes. You can use Nipper OmniSight (Standalone), which uses the configurations you upload to provide point-in-time assessments on an ad-hoc or scheduled basis.

  • Solutions | Use Cases | CyberOps

    • How does exposure insight reduce SOC alert fatigue?

      By confirming which alerts are real, exploitable weaknesses, cybersecurity operations teams focus on what matters, not the noise.

    • How does continuous exposure visibility support cybersecurity operations maturity?

      It shifts operations from reactive alert handling to proactive exposure reduction, enabling consistent progress across CTEM cycles.

    • How does continuous insight strengthen daily cybersecurity operations workflows?

      Teams get regularly updated views of attack paths, key exposure points, drift, and segmentation gaps. This helps them triage faster and act earlier.

    • How does exposure visibility improve lateral movement detection?

      It shows how misconfigurations and trust boundary issues create full attack paths. It gives cybersecurity operations teams early insight into where attackers can move.

    • Why is configuration visibility essential for cybersecurity operations?

      Because many exploitable pathways originate from misconfigurations rather than software flaws. Continuous visibility helps teams find these weaknesses before adversaries exploit them.

  • Solutions | Use Cases | Network Operations

    • How does Nipper OmniSight support network operations centers?

      Nipper OmniSight gives network teams configuration-level visibility across routers, switches, and firewalls. It highlights where changes introduce risk, weaken segmentation, or undermine resilience. This helps teams prevent incidents, investigate faster, and recover with confidence.

    • Does Nipper OmniSight replace existing network monitoring software?

      No. It complements monitoring by adding configuration assurance. This helps teams find root causes, not just symptoms.

    • Can it support audits without disrupting operations?

      Yes. Nipper OmniSight provides evidence-based configuration reports for internal reviews and external audits. It does this using lightweight configuration collection and offline analysis, without the disruption associated with active scanning tools. This makes it well suited for NOC-led assurance workflows.

  • Solutions | Use Cases | Security Operations

    • How does Nipper OmniSight support SOC architecture design?

      Nipper OmniSight analyzes Layer 3 routing, segmentation and CMDB labels to inform SOC architecture decisions. It shows how segments connect, where segmentation issues exist, and which paths expose critical assets to untrusted networks.

    • Can Nipper OmniSight help with SOC management and maturity?

      Yes. Nipper OmniSight supports SOC management by enabling repeatable exposure assessments, attack surface assessment, and Zero Trust posture validation. This gives security leaders consistent, evidence-based insight to measure progress, prioritize remediation, and mature cybersecurity operations in a controlled, structured way.

    • How does Nipper OmniSight support threat hunting?

      All Nipper OmniSight tiers support threat hunting for indicators of compromise. They analyze network device configurations and exposure context during scheduled assessments. They do not rely on continuous monitoring or live traffic inspection.

    • Is Nipper OmniSight a replacement for a SOC or SIEM?

      No. Nipper OmniSight complements your SOC and SIEM by adding configuration-validated exposure context – helping analysts confirm what’s exploitable and prioritize response.

    • Can mid‑sized organizations use Nipper OmniSight without a SOC?

      Yes. Nipper OmniSight (Standalone) provides SOC-like exposure visibility helping regulated mid-sized teams start Threat Exposure Management without deploying a full SOC stack.

    • How do organizations progress their security maturity with Nipper OmniSight?

      Organizations start with Nipper OmniSight (Standalone) to improve visibility and posture. Integrate it seamlessly into SIEM investments using Nipper OmniSight (Integrated). Move to continuous threat exposure management (CTEM) by fully automating workflows integrating with SIEM and CMDB under Nipper OmniSight (Continuous).

    • Is Nipper OmniSight suitable for operational technology (OT) security environments?

      Yes. Nipper OmniSight supports OT security by modelling Layer 3 attack paths between IT and OT segments. It highlights segmentation violations, unsafe connections, and exposure of critical infrastructure assets to internet-facing networks. It also covers untrusted networks, helping organizations show and support adherence to IEC 62443.

  • Solutions | Use Cases | Audits & Assessments

    • How do Nipper InfraSight and Nipper OmniSight support cybersecurity audits and assessments?

      They provide evidence and context from system settings through one-time and scheduled assessments. This supports audit prep and repeatable reviews for internal and external engagements.

    • When should an assessor use Nipper InfraSight versus Nipper OmniSight?

      Nipper InfraSight supports point‑in‑time device audits, targeted reviews, and offline or air‑gapped environments. Nipper OmniSight applies the same assessment methodology across larger estates using scheduled assessments, supporting consistency and reuse across engagements.

    • Do Nipper solutions certify or guarantee compliance?

      No. Nipper solutions support audit preparation by providing evidence and context. Compliance decisions remain with auditors and regulators.

    • Which frameworks does it support?

      Depending on the tier, assessments align with frameworks like NIST SP 800-53 and NIST SP 800-171. They also support PCI DSS and CMMC. This helps teams standardize evidence for CMMC and NIST audit workflows.

  • Resources | Knowledge Center

    • What are Titania’s knowledge bases?

      Self-serve hubs offering comprehensive product documentation, step-by-step user guides, and detailed release notes - everything needed for precise configuration analysis, result interpretation, and professional reporting.

    • How often are the knowledge bases updated?

      They are continuously refreshed with the latest features, guides, performance enhancements, and industry best practices to ensure your Nipper deployments remain optimized and ahead of evolving threats.

    • How do I search and save content?

      Use the intuitive search bar for instant, relevant results across all documents; easily bookmark favorites or download PDFs for offline access and team sharing, anytime.

    • What if I can’t find the help I need in the knowledge bases?

      Simply get in touch with our expert support team through your online customer account, in-product, or various contact options - they combine knowledge base insights with tailored guidance for your unique deployment challenges and use cases.