Try our new research platform with insights from 80,000+ expert users
Former Employee of Orange Business Services as Head of Security Engineering at a comms service provider with 5,001-10,000 employees
Real User
A simple to use stable solution providing good security but needs improvement in user-management
Pros and Cons
  • "Security is the key number because it can start to scan with a few clicks instead of credits, which is a bit complicated. So simplicity is the first advantage. Then the generated reports are well done and easy to present to management. The quality of the scan is quite good in detecting the severity. The solution has simplicity. Also, it has frequent updates so that is also a valuable feature."
  • "In Nessus Professional, the main drawback was that we could have a single-user login password. So it could be better in terms of security."

What is our primary use case?

The tool was used mainly to do network and security scans in some designated areas. It was part of maintaining the ISO 27k certification for some countries, like Turkey, Egypt, and India. Another usage was that we had regular and yearly scans planned as part of policies on some other network areas that would do network management in the central region and Internet-shared network.

What is most valuable?

Security is the key number because it can start to scan with a few clicks compared to Qualys, which is a bit complicated. So simplicity is the first advantage. Then the generated reports are well done and easy to present to management. The quality of the scan is quite good in detecting the severity. The solution has simplicity. Also, it has frequent updates so that is also a valuable feature.

What needs improvement?

We've got several versions of Tenable, and the one we use is the professional. It's the only one I know because we did not explore others. It was called Nessus Professional, and it should not be confused with Nessus Enterprise, Tenable, or tenable.sc or tenable.io. In Nessus Professional, the main drawback was that we could have a single-user login password. So it could be better in terms of security. Of course, we could have as many users as we wanted, and we got about fifteen users, but we couldn't distinguish the rules in this solution. If you wanted to allow some people to do a scan of some areas and some other areas, we would have to go through an expensive version. So, with the professional edition, the management of users needed to be improved. We could have a new user-defined.

For how long have I used the solution?

I have been using the solution since 2003.It has been twenty years.


Buyer's Guide
Tenable Nessus
June 2025
Learn what your peers think about Tenable Nessus. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
861,524 professionals have used our research since 2012.

What do I think about the stability of the solution?

It is a stable solution.

What do I think about the scalability of the solution?

It is a scalable solution. Fifteen users are using the solution.

How are customer service and support?

The technical support team is good. But one drawback is that they must give more attention to small customers. We had only ten licenses in the professional mode, one of the cheapest.

So we found it easy to get attention and always found the solution.

How would you rate customer service and support?

Neutral

How was the initial setup?

The initial setup was easy.

What's my experience with pricing, setup cost, and licensing?

We paid about six thousand dollars per license.

Which other solutions did I evaluate?

I evaluated Qualys but the pricing scheme was different so did not go with that. Although Tenable was much more limited than Qualys.

What other advice do I have?

People should use it because it is straightforward and simple. I would rate it seven out of ten, for the simplicity of usage and the quality of the security assessment that is done and the reporting.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Venugopal Potumudi - PeerSpot reviewer
Senior Consultant at Tata Consultancy
Real User
A mature product that's easy to set up and offers reasonable pricing
Pros and Cons
  • "The solution can scale well."
  • "We'd like to see the solution embrace more user-friendliness."

What is our primary use case?

Tenable is for scanning the vulnerabilities on the endpoint. That's the prime use case. It can also be extended for scanning web publications, et cetera. 

What is most valuable?

Nessus is a very stable product. And it has been a pioneer and has been around for a long time. Their vulnerability dashboards are very good to use.

It is easy to set up.

The solution can scale well. 

The pricing is reasonable. 

What needs improvement?

While the pricing is quite good, any client would, of course, like it to be a bit less. 

We'd like to see the solution embrace more user-friendliness. That said, currently, we are happy with the product.

For how long have I used the solution?

I've used the solution for a while. it's been a couple of years. 

What do I think about the stability of the solution?

It is a stable, reliable product. The performance is good. There are no bugs or glitches. It doesn't crash or freeze. 

What do I think about the scalability of the solution?

I have found the product to be scalable. 

How are customer service and support?

We generally don't have a lot of requirements for tech support with Tenable. We have been using it for so long, we have received quite a good amount of training from them at this point. Therefore, we don't look for a lot of tech support.

How was the initial setup?

The setup is quite straightforward and simple. I wouldn't describe the process as overly complex. 

The deployment time depends on how the endpoints are distributed. If it is a single one within one country and one region, it is very fast. We can do it in less than three months.

What about the implementation team?

We are consultants. We can assist users with the setup process. 

What's my experience with pricing, setup cost, and licensing?

It's not an overly expensive solution. It's pretty affordable. 

Users pay an annual licensing fee. 

What other advice do I have?

I'm a consultant. 

We can deploy the solution either on-premises or on the cloud. 

I'd advise potential new users to look at what the landscape is. And based on the landscape, they should be able to fit the product. You need to first consider your strategy and build towards that. We would recommend this solution to others if it seems to fit their needs. 

I'd rate the solution nine out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Buyer's Guide
Tenable Nessus
June 2025
Learn what your peers think about Tenable Nessus. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
861,524 professionals have used our research since 2012.
OmkarZarapkar - PeerSpot reviewer
Manager II at a insurance company with 10,001+ employees
Real User
User friendly and vast scanning capabilities with built-in, pre-coded configurations
Pros and Cons
  • "The solution is easy to understand for users because instructions are included on the platform."
  • "Vulnerability recommendations are outdated and not in line with industry standards."

What is our primary use case?

Our company uses the solution for vulnerability scanning. 

What is most valuable?

The solution is easy to understand for users because instructions are included on the platform. 

Scanning capabilities are vast with built-in configurations that are pre-coded for various types of servers. 

There are very few false positives reported. 

It is easy to access and share reports. For example, consultants can extract reports, remove columns if needed, and share final copies with clients. 

What needs improvement?

Vulnerability recommendations are outdated and not in line with industry standards. 

The reporting tool should allow fancier customizations such as pivot or formula-based options. 

Cloud reviews should be a focus because AWS is taking over the market. 

For how long have I used the solution?

I have been using the solution for three years. 

What do I think about the stability of the solution?

The solution is very, very stable and is considered the leader in stability. 

What do I think about the scalability of the solution?

The solution is very scalable and we have it on every server in our organization with no issues. We only provide user-level access to our security teams. 

How are customer service and support?

Technical support is very good and responsive. 

A few months back, we utilized their assistance for configurations on a custom EMI. They were very helpful and indicated the next upgrade would include a checklist and benchmarking documents for manual completion. 

How was the initial setup?

The setup is very straightforward. 

What about the implementation team?

The implementation was handled by Tenable. There was a one-time installation cost of $500-$1,000 which was nominal for our large organization. 

Tenable either connects virtually or comes onsite to deploy the solution across your entire network.  

Routine maintenance is performed on a local machine with no server needs. This occurs about three times a year by our in-house team. 

What's my experience with pricing, setup cost, and licensing?

Our organization is huge so our license costs $30,000. We are one of the biggest financial sector groups in India, so are charged appropriately. 

Pricing is rated a seven out of ten because it is reasonable but always could be cheaper.

Which other solutions did I evaluate?

We use both the solution and Qualys which are leading tools in the industry.

Qualys is a complicated tool for users because it does not include easy-to-access instructions. It also reports more false positives. 

The solution is easier to use and includes instructions for running scans. 

Overall, the solution is a better tool than Qualys. 

What other advice do I have?

The solution is a great tool for automation and reducing your team's efforts. If you have the budget and knowledgeable staff, then I recommend you use it. 

I rate the solution an eight out of ten. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
AmardeepSingh - PeerSpot reviewer
Programmer at eClerx Services Limited
Real User
Quick new vulnerabilities support, reliable, but security assessment could improve
Pros and Cons
  • "The most valuable feature of Tenable Nessus is the support it provides for any new vulnerabilities quickly."
  • "Tenable Nessus application device assessment is one of the top tools. However, in the application security assessment, there are other tools that provide better, and more accurate findings."

What is our primary use case?

We use Tenable Nessus internally for our vulnerability scan and dynamic vulnerability assessments.

How has it helped my organization?

Tenable Nessus has helped us with better visibility of the current security posture of our infrastructure and helped us be proactive about remediating those findings.

What is most valuable?

The most valuable feature of Tenable Nessus is the support it provides for any new vulnerabilities quickly.

What needs improvement?

Tenable Nessus application device assessment is one of the top tools. However, in the application security assessment, there are other tools that provide better, and more accurate findings.

In a future release, I would like to see all SC reporting features included in the Professional version.

For how long have I used the solution?

I have been using Tenable Nessus for approximately five years.

What do I think about the stability of the solution?

Tenable Nessus is stable.

What do I think about the scalability of the solution?

The stability of Tenable Nessus is good.

We don't have a very big security team. It's four or five people who are using it.

How are customer service and support?

We have used the support from Tenable Nessus. The support was relatively good.

How was the initial setup?

The initial setup of Tenable Nessus was straightforward, we did not have any issues.

What about the implementation team?

The deployment of Tenable Nessus was done in-house.

The solution is not difficult to maintain at the scale we are working on it.

What was our ROI?

We have seen a return on investment by using Tenable Nessus.

What's my experience with pricing, setup cost, and licensing?

The newer tools are quite pricey. There is a case of some fine tuning that can be done in terms of licensing. The IP based licensing that is offered makes the tool very expensive. If they want the IT industry to adopt it, the price should be looked at.

For the professional the cost is reasonable. However, if you go to an HC or IO platform, then the price is high. Even though the scan engine is the same, the additional features for dashboarding and reporting should not cost more than the solution itself or the intelligence of the tool to identify those findings.

There are not any fees

What other advice do I have?

In terms of the identification of vulnerabilities, this is a good tool. The engine it uses is accurate. However, it depends on which tool out of the stack you would use, and the scale of the infrastructure.

I rate Tenable Nessus a seven out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
TomasStasek - PeerSpot reviewer
IT Director at Teleperformance
Real User
User-friendly environment, simple to manage, and reliable
Pros and Cons
  • "The most valuable feature of Tenable Nessus is the GUI and user-friendliness. Additionally, the environment is easy to work with."
  • "The scalability of Tenable Nessus is good. However, it could be more flexible."

What is our primary use case?

We use Tenable Nessus to schedule test scans and work with the finding.

We have integrated Tenable Nessus with Splunk.

What is most valuable?

The most valuable feature of Tenable Nessus is the GUI and user-friendliness. Additionally, the environment is easy to work with.

For how long have I used the solution?

I have been using Tenable Nessus for approximately one year.

What do I think about the stability of the solution?

Tenable Nessus is a stable solution.

I rate the stability of Tenable Nessus a ten out of ten.

What do I think about the scalability of the solution?

The scalability of Tenable Nessus is good. However, it could be more flexible.

We have over 400 people using the solution. We plan to increase our usage, but it depends on the progress of the business.

I rate the scalability of Tenable Nessus an eight out of ten.

How are customer service and support?

The support we have for Tenable Nessus is internal. The IT teams for Tenable Nessus are in the Czech Republic for us.

Which solution did I use previously and why did I switch?

I have previously used Tenable IO.

What's my experience with pricing, setup cost, and licensing?

The price of Tenable Nessus is too expensive for each service center.

What other advice do I have?

I recommend Tenable Nessus because it's a good solution, works properly, is not complicated to administrate, is simple to manage, and is stable.

I rate Tenable Nessus a nine out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Gabriel Clement - PeerSpot reviewer
Lead IT Security and Remediation at ARM Holdings Company
Real User
Top 10
Reasonably priced, reliable, and flexible
Pros and Cons
  • "It gives a holistic view of your entire environment."
  • "They should try to create an all-in-one solution."

What is our primary use case?

I primarily use the solution for network scanning. I can use it when I want to see network scanning involved with the network devices and servers. 

What is most valuable?

I love everything about Nessus. I may be biased in my rating, biased in the sense that I love using Nessus.

The usability is okay. The pricing is okay. The costs are reasonable.

The level they give you is good. It depends on the kind of scan that you want to do. There are different options there. If I want to do a PCI scan, that is available. If I want to do a scan that involves checking to see if the system patching is up to date, that is available. If I want to scan against trending vulnerabilities, I can do that, too. They have so many different options. You can streamline it to what you want, and you do your scan. 

Nessus is flexible. It gives a holistic view of your entire environment. I would go for a Nessus any day, anytime.

They have a good reporting system. I love the reporting system. The references they made in terms of recommendations are great. They can give a recommendation on how to get a particular issue fixed. 

The setup is straightforward. 

It is stable and reliable.

We can scale the product. 

What needs improvement?

They should try to create an all-in-one solution. When I say all in one, I mean something that would be cheap, where I can scan a lot in terms of web applications. Right now, this is available. However, it's a bit expensive. If users want to start scanning applications, networking devices, et cetera, they should also try and work on the pricing for those and have everything together. The web application module should be included in Tenable itself.

For how long have I used the solution?

I've used the solution over the past 13 years. I've worked with it for a long time.

What do I think about the stability of the solution?

The stability is fine. There are no bugs or glitches, and it doesn't crash or freeze. 

What do I think about the scalability of the solution?

The solution can scale as needed. 

How are customer service and support?

I've not escalated anything to technical support. 

Which solution did I use previously and why did I switch?

I'm aware of other solutions. 

What makes Nessus outstanding is the different options. There are so many scanning options. They give you the room to be flexible. You can scan your server how you want. Other options may just allow for a general scan of my system. With Nessus, I can streamline and customize my scan. 

How was the initial setup?

It is an easy solution to set up. The deployment is not lengthy. Within two hours, I had it up and running. 

There is no crazy maintenance needed. Sometimes when there are new updates, it just alerts you the moment you log into your appliance. It just alerts you and gives you room to do the updates. Sometimes it may just set automatically, and it picks the updates. When you log in, it asks for you to reinitialize your system, and you're good to go.

What's my experience with pricing, setup cost, and licensing?

The price is not bad. We are comfortable with the cost of the solution right now and with what we are paying for what we get in return. 

We just pay for the license and do not deal with any other additional fees. 

What other advice do I have?

We're using the latest version of the solution. 

When you are doing a spot check, and something rescues you a lot from disaster, you really appreciate that service. The product has really worked for me.

I highly recommend the solution.

I'd suggest new users run a POC and exhaust all the functionality and test other solutions as well. At the end of the day, compare them. Don't forget to consider budgets. Ensure that it matches what your company needs and the budget that they have for that particular solution. 

Make sure that functionality is taken into account. Some people only look at the budget and go for something cheaper and then do not have the functionality they require. 

I'd rate the solution nine out of ten. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Cyber Security Expert at Birlasoft IndiaLtd.
Real User
Provides network and device scanning and allows us to pull reports that identify vulnerabilities
Pros and Cons
  • "The vulnerability scanner is the most valuable feature."
  • "I would like to see more on the automation side."

What is our primary use case?

We use this solution for network and device scanning. Massive scanners have been integrated with the security center. We scan devices and pull the report from the security center. We publish the report to respective stakeholders, and we maintain the reports for our records. The reports show vulnerabilities, plugin text, and plugin outputs. We analyze the report and try to close the vulnerabilities identified in the scan.

The solution is deployed on-premises.

There are about 10 people using this solution in my organization. They were part of the security team and were doing the scanning and remediation. I led the team and dealt with any challenges.

My organization is a service provider. We provide security services to clients.

What is most valuable?

The vulnerability scanner is the most valuable feature. It's an important feature for us. We use the plugin output for that. It shows us the exact version of Nessus and what is needed for remediation. Based on that, we decide what should be remediated first to get the best result for security.

The agent scanner is a valuable feature. We also do credential scans, which gives the equivalent report. In the log project situation, we receive very good support from Nessus. They have built one policy for the log project itself. With the help of that policy and the plugins specified for the log project, the scans were faster for that project.

If we run a scan, it will usually check all of the plugins, which is a time-consuming process. We received help, and we had one plugin for the log project. That was for checking the log project only because we were already done with the complete scan.

What needs improvement?

I would like to see more on the automation side. There should be proper tools and support for automation in Tenable itself.

For how long have I used the solution?

I have used this solution for more than four years.

What do I think about the stability of the solution?

It's a stable solution, but we noticed that the agent wasn't being updated. This means we have to update it manually and run a few commands to get the service running. If the solution isn't updated with the latest version, it will go offline.

How are customer service and support?

We receive very good technical support from the team in India. We're very happy with them. I'm also in touch with some people from Tenable India. They helped me understand the requirements and the solution's latest features.

I would rate technical support as four out of five because they could always improve.

How was the initial setup?

Initial setup was easy. That's why I proposed the solution to my current organization. 

The deployment process completely depends on approvals and how we're getting the procurement of hardware and the licenses. It depends on the organization.

What's my experience with pricing, setup cost, and licensing?

The solution is worth the cost. It's a good investment. 

Which other solutions did I evaluate?

I have also evaluated Qualys. There were some missing features, so we weren't able to detect vulnerabilities related to specific software, like Adobe and Java.

I have also used Tenable.sc.

What other advice do I have?

I would rate this solution as eight out of ten. 

For those who want to use this solution, my advice is to go to Tenable's website and read about the solution so you can properly understand its features. There are demo videos too. That will help you make a decision about whether you want to use the tool or not.

I would definitely recommend this solution to others who want to use it.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Md. Shahriar Hussain - PeerSpot reviewer
Information Security Analyst at Banglalink
Real User
Top 5Leaderboard
Very easy to carry out ransomware checking, OS auditing and implementation
Pros and Cons
  • "Makes ransomware checking and OS auditing and implementation relatively easy."
  • "Lacks some penetration testing-related services."

What is our primary use case?

I use this solution for OS auditing, database auditing, virtualization, and following how closely it follows our CI or TISA benchmarks. We also use it for malware and ransomware risk and for carrying out assessments. We purchased this product from a local partner that has a premium partnership with Tenable. I'm a cybersecurity and compliance lead engineer.

What is most valuable?

The solution makes ransomware checking and OS auditing and implementation relatively easy. It covers most of the requirements for benchmarks for all sorts of widely available required configuration settings in the technology industry. It's also very user-friendly, easy on the eye, and saves a lot of time. It provides us with reports that perfectly satisfy compliance requirements, whatever the device or configuration settings. 

What needs improvement?

There is very little to improve but cloud security tests would be something helpful to have. Tenable could also offer some penetration testing-related services, which would be beneficial.

For how long have I used the solution?

I've been using Nessus for three years. 

What do I think about the stability of the solution?

It's a very stable solution. 

What do I think about the scalability of the solution?

The solution is scalable. I use it for around 4,000 servers on a daily basis.

How are customer service and support?

The technical support is good. They offer expensive professional support, but I generally use the website documentation to fix things. Compared with other companies, they provide very good support. 

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I previously used Qualys and had a bad experience. It's not very user-friendly, licensing was difficult and deployment painful. I also used Rapid7, and I think Nessus is more user-friendly than both of those products. 

How was the initial setup?

The initial setup was very easy and took just a few hours. It's important to plan wisely before implementing. Know how many servers you have and try to project your future requirements so that you can estimate the total number of IPs you require. If the forecast is accurate, the solution is cost-efficient. We used consultants from Singapore and they installed some agents in our on-premise servers. Maintenance is very easy.

What's my experience with pricing, setup cost, and licensing?

The global situation is very unstable and the dollar price has already increased significantly in our country in the last three or four months so everything has become expensive. Licensing is very competitive in our local markets and there's a lot of haggling that goes on. The option of a three-year license would be most beneficial for us because of the huge variations in the dollar. 

What other advice do I have?

I rate this solution nine out of 10. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Tenable Nessus Report and get advice and tips from experienced pros sharing their opinions.
Updated: June 2025
Product Categories
Vulnerability Management
Buyer's Guide
Download our free Tenable Nessus Report and get advice and tips from experienced pros sharing their opinions.