Essentially we use the solution to monitor hard devices on a network with it. That includes laptops, desktops, tablets, et cetera. I'm just using that to make sure that all of our patching is up to date.
Information Security Analyst at a retailer with 1,001-5,000 employees
Intuitive with excellent technical support and good stability
Pros and Cons
- "Their overall cost of service is pretty good."
- "The biggest issue I have with the solution is when I'm using the scanning it picks up the original DNS of that device. That means, before we image it and actually change the DNS to something within our company structure, it'll just be random numbers and letters and Tenable will stick to that DNS for a long time."
What is our primary use case?
What is most valuable?
The UI, the user interface, is really, really good. It's really simple. I started with no prior experience in vulnerability management and picked it up in less than a day, pretty quickly. It's very intuitive.
Their overall cost of service is pretty good.
I've worked with my CS manager and with them a lot, and I'd say every case I've opened, they've reached out to me within two hours. They're pretty prompt in their responses and overall the company is really easy to get ahold of.
Scaling the solution is very easy.
The stability of the product is pretty good.
What needs improvement?
The biggest issue I have with the solution is when I'm using the scanning it picks up the original DNS of that device. That means, before we image it and actually change the DNS to something within our company structure, it'll just be random numbers and letters and Tenable will stick to that DNS for a long time. I'll be searching for a gallery or a laptop and I can't find it due to the fact that the DNS when it was scanned went in as something non-sensical, like M P X 23 Z. That's the biggest issue I have with it. it's some sort of strange glitch.
For how long have I used the solution?
While I started using the solution in January of last year, the company itself has been on the solution for about three years or so.
Buyer's Guide
Tenable Security Center
November 2024
Learn what your peers think about Tenable Security Center. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
824,067 professionals have used our research since 2012.
What do I think about the stability of the solution?
The stability of the solution has been quite good. I haven't experienced any real problems so far. It's been a rather smooth proess.
What do I think about the scalability of the solution?
Scaling the solution would be pretty simple. The process would require us to reach out to Tenable to get more licenses, however, that's a pretty simple process. Overall, it's pretty easy. Essentially it'd just be adding a list of all the new IPs into any asset groups that they would be involved in. I don't think it would take much longer than a week.
How are customer service and support?
Technical support is excellent. They are extremely responsive and very helpful. We are quite satisfied with the level of support we've received from them.
I would give them a ten out of ten. They are very prompt and very knowledgeable. They are great at answering questions and walking you through anything step-by-step.
How was the initial setup?
When I started, the company was actually in the process of revamping the solution.
It was a two-day process and the company walked us through the entire thing. I had a Tenable engineer on-call with me for eight hours. It was a long process, however, it was easy as they were walking me through it, step-by-step.
What about the implementation team?
When we did a recent re-vamp, Tenable was on hand to walk us through the entire process. We had a very positive experience with them.
What's my experience with pricing, setup cost, and licensing?
I don't handle the billing and therefore don't have an exact idea of how much the solution costs.
Which other solutions did I evaluate?
We just renewed the solution and didn't look into any other product on the market before we did.
What other advice do I have?
We are just customers and end-users of the product.
If a company does decide to implement the solution, I'd advise working with Tenable engineers during the process, and even afterward, in order to ensure everything is set up appropriately.
I'd rate the solution at an eight out of ten We've had a largely very positive experience with the solution so far.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Technical Consultant at a tech consulting company with 51-200 employees
Great Predictive Prioritization and Risk-based VM with good reliability
Pros and Cons
- "Support is knowledgeable."
- "Support could be faster."
What is our primary use case?
We primarily use the solution for vulnerability scanning across the network .
A few months back, I conducted a Deployment on Tenable SecurityCenter for a Reputed Private Bank. Also I had to teach the Usage and features and then show them how the scan things work and how results can help analyze and report. also helped developing some use case like Scheduling scan and email that to specific users for mitigation, Generating Alert for particular level of vulnerability etc.
How has it helped my organization?
Tenable has come a long way than we found earlier, Asset Criticality Report and Predictive Prioritization helps us finding the most critical loophols in minutes, Security Engineers can now focus more on Remediation. Less of false positive eases our vulnerability program and saved time.
What is most valuable?
In Tenable SecurityCenter, the Risk-based approach for Prioritizing vulnerability is something that is unique to any vulnerability management platform. Compared to Qualys and Rapid7, Tenable VPR is a special thing that those products don't have. The security over the CVSS and V1 and V2 with the VPR feature help an organization reveal the exact risk of any asset. There might be thousands of vulnerabilities, however, the most impactful vulnerabilities are listed and prioritized in the VPR.
As tenable SecurityCenter is powered by popular Nessus technology, It is really easy to set up.
The solution is stable and considered as the most solid vulnerability management platform in the industry.
Tenable.sc provides a wide range of dashboards which makes it easy to grasp the vulnerability profile of the organization. These dashboards allow us to view vulnerabilities in different categories in a simple to understand format. The upgrade to Tenable.sc+ has improved on this as well. Regularity of plugin updates are also exceptional. The speed at which tenable has pushed plugin updates and overall platform updates is great. Also the automatic update capability makes maintenance very simplified. Easy to use User interface. For someone who is not familiar with Tenable.sc, the interface is not difficult to follow along and the documentation makes it very simple for anyone
The solution has a very nice Asset discovery feature that gives you gives you unified visibility of your entire attack surface, As It leverages Nessus Sensors, a mix of active scanners, agents, passive network monitoring, and CMDB integrations to maximize scan coverage across your infrastructure to reduce vulnerability blind spots. This mix of data sensor types helps you track and assess both known and unknown assets and their vulnerabilities
What needs improvement?
The solution is a bit on the expensive site. In a country like Bangladesh, most of the customers don't have a budget that could afford Tenable SecurityCenter. They'd rather go for Qualys and Nexpose, which cost less. The licensing policy is something they can improve.
Support could be faster.
For how long have I used the solution?
I've used the solution for last 5 years now.
What do I think about the stability of the solution?
The solution is verry stable. That said, some customers complain about the results and how they are shown. Compared to Nessus, if a customer gets used to using Nessus, and then comes into Tenable SecurityCenter, then the compliance results are an area where they might find a difference. In Nessus, the compliance results are shown in past and failed. In Tenable.sc, it's shown in medium and high. This could be more clear.
What do I think about the scalability of the solution?
Tenable can be scaled easily, just to add additional IP's on the licensing and that's it.
How are customer service and support?
I haven't really dealt much with technical support. In the initial stage, however, when I started deploying Tenable SecurityCenter, I faced a bit of a challenge implementing the Nessus Network Monitor. I figured it out, and now I don't have issues.
Support is top-notch, however, in terms of response times, they are slow, and they need to be faster.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I have also worked with Qualys for a long time.
In our country, People are yet not comfortable adopting SaaS/cloud based solutions also,there are some government jurisdictions that require data to be within the country and an on-prem solution is always needed for the organization. Other solutions, Qualys and Rapid7, are mainly cloud designed. Tenable SecurityCenter is the only solution that can be fully on-prem for small to mid Enterprises.
Also, Tenable is better for compliance requirements in terms of regulations around vulnerability management. it has reporting on compliance with pre-defined checks, metrics and proactive alerts on violations for industry standards like CERT, NIST, DISA STIG, DHS CDM, FISMA, PCI DSS etc. and regulatory mandates. while it comes to other solutions i dint find the compliance feature as good as Tenable
How was the initial setup?
The initial setup is simple. It's not complex at all.
You can go with the installer for Tenable SecurityCenter, which has an installer file for Linux and Unix platforms only. talking about the Nessus scanners, It can be deployed anywhere, including on Windows machines or Linux. There is not much of a challenge to it.
The time it takes to deploy varies. For example, what is the implementation size? How many IPs, and what are the sites? Those things change the timing. If it's a stand-alone setup, it can take around one to two hours to deploy. If you are also talking about onboarding the IPs, and scanning all those IPs, it can take a working day to complete.
What's my experience with pricing, setup cost, and licensing?
The legecy container security is already in it's EOL, if it gets added to Tenable Security Center, users can take full toll of on prem container scanning.
Its cost depends on the Number of Assets. The licensing is per year.
Which other solutions did I evaluate?
i had also worked and evaluated Qualys.
What other advice do I have?
We sell Tenable.
I'm using something around version five. I have installed the demo version of it in my Docker.
The product really stands out in comparison to the competition. However, the price tag is a bit on the higher.
I would advise new users to scan all assets and grab the results and set up all security postures and do stats for mitigating those attacks which are critical. For the first time, I would recommend they go for the critical and high vulnerabilities first in order to mitigate effectively very early on.
I'd rate the solution nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Distributor
Last updated: May 8, 2024
Flag as inappropriateBuyer's Guide
Tenable Security Center
November 2024
Learn what your peers think about Tenable Security Center. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
824,067 professionals have used our research since 2012.
Sr. Engineer at Techsa Services
Helps with vulnerability assessment and vulnerability management
Pros and Cons
- "The tool gives us fewer false positives. Compared to its competitors, the solution’s reports are more accurate."
- "We experienced some difficulties with the solution’s support."
What is our primary use case?
The tool helps with vulnerability assessment and vulnerability management.
What is most valuable?
The tool gives us fewer false positives. Compared to its competitors, the solution’s reports are more accurate.
What needs improvement?
We experienced some difficulties with the solution’s support.
For how long have I used the solution?
I have been working with the solution for two years. I use the tool’s latest version.
What do I think about the stability of the solution?
I would rate the tool’s stability a nine out of ten.
What do I think about the scalability of the solution?
I would rate the tool’s scalability a ten out of ten. You can place sensors for the scanners and easily scale up.
How was the initial setup?
I would rate the tool’s setup an eight out of ten. The tool’s deployment is very straightforward and it took only one day to deploy the solution. The solution’s deployment is simple and efficient.
What other advice do I have?
I would rate the tool an eight out of ten. The tool has community support. From my experience of using the solution, I would recommend it to anyone looking to use it.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Technical Implementation Manager at a manufacturing company with 1,001-5,000 employees
Very scalable product
Pros and Cons
- "I find Tenable SC to be a very scalable product."
- "I think the vendor training provided for Tenable.sc could be a lower price. It's quite expensive for the training."
What is our primary use case?
Our primary use case for Tenable SC is its vulnerability scanning capability.
What needs improvement?
I think the vendor training provided for Tenable SC could be a lower price. It's quite expensive for the training.
For how long have I used the solution?
I have been working with Tenable SC for 4 years.
What do I think about the stability of the solution?
The stability of the Tenable SC product is satisfactory.
What do I think about the scalability of the solution?
I find Tenable SC to be a very scalable product.
How was the initial setup?
The initial setup of Tenable SC is not unmanageable.
What's my experience with pricing, setup cost, and licensing?
With regards to the setup of Tenable SC, I would advise others to spend time using the module, get familiar with the product, and in addition read the manual that is provided.
Which other solutions did I evaluate?
We primarily use Tenable SC for vulnerability scanning and did not evaluate other options. This meets our needs.
What other advice do I have?
I would say there are approximately 30 users in our organization using the Tenable SC product.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Tech consultant at select softwares
Provides clear and precise vulnerability details with few false positives compared to other solutions
Pros and Cons
- "This solution has a much lower rate of false positives compared to competing products."
- "The vulnerability scan does not work correctly until the access privileges are set by the system administrator."
What is our primary use case?
I use this solution to perform vulnerability assessments and then patch my systems using third-party tools.
The vulnerability scan is pretty fast and once you give it the right access privileges on the target system, you get very clear and precise details of the vulnerabilities.
How has it helped my organization?
This solution has a much lower rate of false positives compared to competing products.
It can operate in hybrid mode, too. The greatest strength of the product comes up when the agent is deployed on the endpoint to be scanned. Thereafter, even if the agent is out of the office network, it can still be scanned and will also send back data to the parent console.
What is most valuable?
The dashboard and the templates used to delvelop reports are awesome.
It is easy to run, scan, and categorize an asset as and when needed. The same asset can be present in two or more groups based on the identification.
This solution can now be deployed in cloud setups.
This solution provides a good reporting system and with a reasonably good level of third-party integration. McAfee has leveraged this capability beautifully in its Policy Orchestrator.
What needs improvement?
We need to give more customer demos and also highlight the strengths of the product that have been developed over a twenty-year period.
The vulnerability scan does not work correctly until the access privileges are set by the system administrator.
For how long have I used the solution?
I have been using this solution for a few years.
What do I think about the stability of the solution?
This system is stable under normal configurational mode. It is important to understand how many hosts it will handle and size the system accordingly.
What do I think about the scalability of the solution?
This is a very highly scalable system.
How are customer service and technical support?
I have not contacted technical support so far, as there was no issue to escalate.
Which solution did I use previously and why did I switch?
We did not use another solution prior to this one.
How was the initial setup?
I have worked on a few demos and they have been pretty straightforward to setup.
What about the implementation team?
I perform the deployment of this solution.
What was our ROI?
Yet to be calculated.
What's my experience with pricing, setup cost, and licensing?
Costing is pretty reasonable compared to the competition.
Which other solutions did I evaluate?
We evaluated Rapid7 and Qualys before choosing this solution.
Disclosure: My company has a business relationship with this vendor other than being a customer: I work for a software dealership and we have had good responses from customers on the product and its capabilities
Cyber Security Expert at Birlasoft IndiaLtd.
Excellent credential scan and vulnerability features
Pros and Cons
- "Tenable's most valuable features are the credential scan, vulnerability reports, and vulnerability ratings (VPR)."
- "Tenable has some problems with agents going offline during scanning and lag between agents and the security center."
What is our primary use case?
I primarily use Tenable for scanning and reporting.
What is most valuable?
Tenable's most valuable features are the credential scan, vulnerability reports, and vulnerability ratings (VPR).
What needs improvement?
Tenable has some problems with agents going offline during scanning and lag between agents and the security center. In the next release, Tenable should include automated patching and integration with SSCM so missing patches can be pushed from there.
What do I think about the stability of the solution?
Tenable is stable.
How are customer service and support?
I'm satisfied with Tenable's technical support.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup was easy.
What's my experience with pricing, setup cost, and licensing?
Tenable is open-source.
What other advice do I have?
I would rate Tenable eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Infrastructure Engineer at a healthcare company with 1-10 employees
Dashboard features made it easy to track remediation progress, but exporting things out for reports was a little tough
Pros and Cons
- "I found the dashboard features very useful. It made it easy to track remediation progress. I could publish dashboards to remediation teams and track the progress on the dashboards."
- "The reporting side can be improved. The dashboards are nice, but exporting things out for reports for management was a little tough."
What is our primary use case?
In my previous company, we were using both Tenable IO and Tenable SC. We had the on-prem and the cloud versions. IO was a cloud version, and SC was on-prem.
In my new company, they do use Tenable, but I'm not part of that team. They have the latest version.
What is most valuable?
I found the dashboard features very useful. It made it easy to track remediation progress. I could publish dashboards to remediation teams and track the progress on the dashboards.
What needs improvement?
The reporting side can be improved. The dashboards are nice, but exporting things out for reports for management was a little tough.
We had the on-prem version and the cloud version, and I wasn't a big fan of having different consoles. It would have been nice to be able to have all those features in the cloud version because on-prem is a little tough to manage.
For how long have I used the solution?
I've been using it for about two years. I switched positions about six months ago, and at the moment, I am not using it.
What do I think about the stability of the solution?
I find it stable.
How was the initial setup?
It was pretty straightforward.
What about the implementation team?
We had a consultant from Tenable with us.
What other advice do I have?
I would rate it a seven out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Security Administrator at TOPNET
Excellent availability model with fewer false positives than competitors
Pros and Cons
- "Tenable.sc's best features are the availability model, accident management, and scoring."
- "Tenable.sc's user interface could be improved."
What is our primary use case?
I primarily use Tenable.sc to search availability and for our workstation server and data center.
What is most valuable?
Tenable.sc's best features are the availability model, accident management, and scoring. It also gives fewer false positives than its competitors.
What needs improvement?
Tenable.sc's user interface could be improved.
For how long have I used the solution?
I've been using Tenable.sc for about two months.
What do I think about the stability of the solution?
Tenable.sc is very stable.
What do I think about the scalability of the solution?
Tenable.sc is scalable.
How are customer service and support?
Tenable's technical support is good.
How was the initial setup?
The initial setup was easy as we use the cloud version.
What's my experience with pricing, setup cost, and licensing?
Tenable.sc is more expensive than its competitors.
What other advice do I have?
I would give Tenable.sc a rating of eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Download our free Tenable Security Center Report and get advice and tips from experienced pros
sharing their opinions.
Updated: November 2024
Product Categories
Risk-Based Vulnerability Management Vulnerability Management Cloud Security Posture Management (CSPM)Popular Comparisons
Qualys VMDR
Rapid7 InsightVM
Tenable Vulnerability Management
Microsoft Defender Vulnerability Management
Cisco Vulnerability Management (formerly Kenna.VM)
SecureWorks Taegis VDR
Buyer's Guide
Download our free Tenable Security Center Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Can you recommend API for Tenable Connector into ServiceNow
- Vulnerability Management and Risk Management Integration
- Which one to buy out of the following products: Tenable SC, Tenable.io, Tenable.ep or Tenable.ad?
- What are the differences between Tenable.sc and Tenable.io?
- When evaluating Cloud Security Remediation, what aspect do you think is the most important to look for?
- Why is Risk-Based Vulnerability Management important for companies?