Try our new research platform with insights from 80,000+ expert users
Aaron Melendez - PeerSpot reviewer
Cybersecurity Analyst / Third-Party Risk Analyst at San Jacinto Community College
Real User
Exposure management solution used to scan networks, identify assets and offers mitigation techniques
Pros and Cons
  • "The vulnerability management itself is the most valuable feature as well as references to the mitigation techniques."
  • "The user interface could be improved by being able to change the user interface to fit your position or your job. The graphs are set in stone and you can only print reports."

What is our primary use case?

We use this solution to scan our network to try to identify all our assets. It is very good at finding all assets depending on how you program it.

What is most valuable?

The vulnerability management itself is the most valuable feature as well as references to mitigation techniques.

What needs improvement?

The user interface could be improved by being able to change the user interface to fit your position or your job. The graphs are set in stone and you can only print reports. 

For how long have I used the solution?

I have been using this solution for seven months. 

Buyer's Guide
Tenable Vulnerability Management
November 2024
Learn what your peers think about Tenable Vulnerability Management. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
824,067 professionals have used our research since 2012.

What do I think about the stability of the solution?

The stability of this solution is good. The application is always available and you can also set the scans to not take up too much bandwidth.

What do I think about the scalability of the solution?

The scalability all depends on how much you want to spend. If you have 10,000 assets you want to scan, you'd have to pay for that. It is very easy to scale up or scale down, but it's going to cost you.

How are customer service and support?

I would rate their support ten out of ten. 

How would you rate customer service and support?

Positive

How was the initial setup?

It has a steep learning curve but Tenable does offer free courses for beginners and paid courses to become a specialist. This assists with the ease of setting it up. 

What's my experience with pricing, setup cost, and licensing?

The total cost we pay for this solution is over 45K. This is for a large education organization. 

What other advice do I have?

I would advise others to take the courses provided and then to play around with the solution. This will speed up learning as this solution has a steep learning curve and can be intimidating at first.

I would rate this solution an eight out of ten due to not being able to change certain parts of the user interface. 

I would rate this solution an eight out of ten. 

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Prajot Nair - PeerSpot reviewer
Senior Manager -Cloud Security at Capgemini
Real User
Full-service solution that gives a good ROI
Pros and Cons
  • "The initial setup is straightforward so long as your infrastructure, components, and networks are in place."
  • "Tenable.io Vulnerability Management could be improved with an increased number of dashboards and MSSP integration."

What is our primary use case?

Tenable.io Vulnerability Management is used as a unified platform for vulnerability management.

What needs improvement?

Tenable.io Vulnerability Management could be improved with an increased number of dashboards and MSSP integration.

For how long have I used the solution?

I've been working with Tenable.io Vulnerability Management for five years.

What do I think about the stability of the solution?

Tenable.io Vulnerability Management is stable.

What do I think about the scalability of the solution?

Tenable.io Vulnerability Management is scalable.

How are customer service and support?

Tenable doesn't provide support beyond documentation.

How would you rate customer service and support?

Neutral

How was the initial setup?

The initial setup is straightforward so long as your infrastructure, components, and networks are in place. There are also a few teaching issues post-migration, like integration with third parties and SEO integrations.

What was our ROI?

Tenable.io Vulnerability Management gives a good ROI in the long run, though it would be better with a pay-as-you-go model.

What's my experience with pricing, setup cost, and licensing?

Tenable.io Vulnerability Management's pricing solution model isn't great. Providing a pay-as-you-go option would be an improvement.

What other advice do I have?

Tenable is a full-service product, but it still has a lot of improvements to make, so I'd recommend exploring other products before implementing it. I would give Tenable.io Vulnerability Management a rating of nine out of ten.

Which deployment model are you using for this solution?

Private Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Tenable Vulnerability Management
November 2024
Learn what your peers think about Tenable Vulnerability Management. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
824,067 professionals have used our research since 2012.
Real User
Top 5Leaderboard
Useful for penetration testing but reporting functionality needs improvement
Pros and Cons
  • "It's a recommended tool for penetration testers because it's effective for that purpose."
  • "The tool's reports are bad. They're not very customizable or flexible. During audits, we often have to exclude things that aren't relevant to our organization, but we can't do that easily with the reports. They come in HTML or PDF format, and we can't compare current results with previous ones in Excel because we never receive reports in Excel."

What needs improvement?

The tool's reports are bad. They're not very customizable or flexible. During audits, we often have to exclude things that aren't relevant to our organization, but we can't do that easily with the reports. They come in HTML or PDF format, and we can't compare current results with previous ones in Excel because we never receive reports in Excel.

For how long have I used the solution?

I have been using the product for a year, and my organization has been using it for six to seven years. 

What do I think about the stability of the solution?

Tenable Vulnerability Management is stable. 

What do I think about the scalability of the solution?

I rate the tool's scalability a seven out of ten. 

How are customer service and support?

The solution's support is okay, but it could be more customer-friendly. The people providing support have knowledge, but they could improve customer interaction.

How was the initial setup?

The tool's deployment can be challenging, especially for those unfamiliar with Kali Linux, as it operates on this platform. This might make the setup process difficult for users accustomed to other operating systems like Windows. It may take a couple of tries to get comfortable with the process. However, once you have set it up a few times, it becomes easier.

What other advice do I have?

Sometimes, we use the tool for tasks like configuration and running scans. However, it's a bit difficult to use compared to Qualys. One issue we've noticed is that it takes up a lot of space, which customers often complain about. They promised more system coverage and updates, but it isn't happening.

I rate Tenable Vulnerability Management a seven out of ten. It might be challenging if you're used to working on Windows. However, it's a recommended tool for penetration testers because it's effective for that purpose.

We use it for audit and PT. 

Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
PeerSpot user
Senior Information Security Engineer at a consultancy with 5,001-10,000 employees
Consultant
An easy-to-use solution with smooth configuration and broad scalability
Pros and Cons
  • "The solution is easy to use and configuration is smooth with no complexities."
  • "The solution creates vulnerability tickets within the VM profile but should also include them under the Remediation tab so the fixes can be viewed in the ticketing queue."

    What is our primary use case?

    Our company has 25 technicians who use the solution to scan firewalls and produce scheduled compliance reports for various environments.

    What is most valuable?

    The solution is easy to use and configuration is smooth with no complexities.

    The solution is one of the best tools in the market for vulnerability management and remediation. It functions exactly as we desire.

    What needs improvement?

    The solution creates vulnerability tickets within the VM profile but should also include them under the Remediation tab so the fixes can be viewed in the ticketing queue. 

    Qualys is a competitor product and handles vulnerability tickets in this comprehensive manner. 

    For how long have I used the solution?

    I have been using the solution for two years. 

    What do I think about the stability of the solution?

    The solution is stable and I have only experienced hangs a few times. 

    What do I think about the scalability of the solution?

    The solution is accessible from the private cloud so it is scalable to any needs. 

    How are customer service and support?

    Technical support requires constant follow up and that is an issue. Once they are made aware of an issue, it takes time for them to find a resolution. I currently have three cases and have been waiting so long for updates that I have asked for escalation.

    Support provided by Qualys is better because they work with you right away to resolve issues. 

    I rate support a two out of ten. 

    How would you rate customer service and support?

    Negative

    How was the initial setup?

    The initial setup is straightforward and not hard to understand if you have worked with other solutions. 

    We experienced an authentication issue when the NetApp scanner was trying to log in to the system and firewall, but we modified the setting and the issue was resolved. 

    What about the implementation team?

    We deployed the solution ourselves and the complexity depends on each environment. 

    For example, our company has AWS, Azure, and on-premise data center environments. Our infrastructure team builds a list of assets and then our technicians deploy the solution to conduct scans. 

    What's my experience with pricing, setup cost, and licensing?

    The annual license is a bit costly but the solution is worth it. 

    Which other solutions did I evaluate?

    We also use Qualys and like how it handles vulnerability tickets. 

    We moved to the solution because Qualys does not support Cisco Secure Firewalls and that is a requirement in our environment. 

    What other advice do I have?

    While Qualys offers dual locations for vulnerability tickets, it is not difficult to use API calls to integrate the solution with ServiceNow for assigning mitigation. 

    Many companies use third-party tools like Jira to integrate things so it is not unusual. I do believe Tenable is working on an internal solution that will be available in the future.  

    I rate the solution an eight out of ten. 

    Which deployment model are you using for this solution?

    Private Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Other
    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    Amr Abdelnaser - PeerSpot reviewer
    Senior Information Security Analyst at EastNets Holding Ltd.
    Real User
    Top 5Leaderboard
    A customizable solution that helps to scan environment
    Pros and Cons
    • "You can customize each point in new scans."
    • "I don't recommend Tenable.io Vulnerability Management for web scanning"

    What is our primary use case?

    We use the solution to scan our environment, ServicePRO. 

    What is most valuable?

    You can customize each point in new scans. 

    What needs improvement?

    I don't recommend Tenable.io Vulnerability Management for web scanning. 

    For how long have I used the solution?

    I have been working with the product for two years. 

    What do I think about the stability of the solution?

    Tenable.io Vulnerability Management is stable. 

    What do I think about the scalability of the solution?

    We have seven users for the product. 

    How are customer service and support?

    My colleagues say that the tech support team is very responsive and helpful. 

    How was the initial setup?

    Tenable.io Vulnerability Management's installation is easy. You just need to access the credentials for it. 

    What was our ROI?

    We have not seen ROI with the product's use. 

    What other advice do I have?

    I would rate the product a ten out of ten. You need to be specific with each step while using Tenable.io Vulnerability Management. 

    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    IT support at Ganesh
    Real User
    Top 20
    A tool that provides great visibility of the vulnerabilities that need to consider in improving its interface
    Pros and Cons
    • "The best feature of the solution is the amount of visibility it provides of the vulnerabilities."
    • "It's not a user-friendly tool since it has a complicated interface."

    What is our primary use case?

    We use Tenable.io Vulnerability Management for our organization's endpoint and server vulnerability management.

    What is most valuable?

    The best feature of the solution is the amount of visibility it provides of the vulnerabilities.

    What needs improvement?

    Improvements should be made to the solution to make it easy to use. It's not a user-friendly tool since it has a complicated interface. The solution needs to have a more user-friendly interface.

    For how long have I used the solution?

    I have been using Tenable.io Vulnerability Management for three years. I am using the solution's latest version.

    What do I think about the stability of the solution?

    It is a stable solution. Tenable.io is the leader in the market, having a very good database of vulnerabilities.

    The solution's stability is good. From my experience, the solution's stability is good compared to its competitors.

    What do I think about the scalability of the solution?

    It is a scalable solution.

    In my company, more than 5,000 people use the solution.

    The solution is extensively used in my company.

    How are customer service and support?

    The technical support is not good.

    How was the initial setup?

    The setup phase was good.

    The setup phase could be completed in less than five minutes.

    The deployment process was carried out through an automated process and wasn't done manually. It was done with the help of Intune.

    Based on our requirements and business, we need around three to five people to deploy and maintain the solution.

    What about the implementation team?

    No consultants were involved in the setup phase since we chose to manage the installation part directly.

    What was our ROI?

    Considering our scenario, the solution is worth it.

    What's my experience with pricing, setup cost, and licensing?

    A yearly payment has to be made toward the solution's licensing costs.

    Compared to other solutions, Tenable.io is expensive.

    What other advice do I have?

    If technical support for the solution is not considered, I recommend it to those planning to use it.

    Overall, I rate the solution a six out of ten.

    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    Executive Director at Platview Technologies
    Real User
    Satisfies the requirement for vulnerability assessments and has a comprehensive database
    Pros and Cons
    • "The ease of use in terms of scanning assets is valuable."
    • "More flexibility is required compared to other solutions."

    What is our primary use case?

    Our primary use case for this solution is to satisfy the requirement for vulnerability assessments regarding internal assets, CPI assets and web applications. We deploy the solution on private cloud.

    What is most valuable?

    The ease of use in terms of scanning assets is valuable, and it has a diverse checklist when it comes to vulnerability databases. Hence, it has a comprehensive database for exploits and vulnerabilities, which is why we continue using it.

    What needs improvement?

    The response times from the customer service and support team could be improved. Additionally, the pricing could be better.

    For how long have I used the solution?

    We have been using the solution for approximately four years.

    What do I think about the stability of the solution?

    The solution is stable.

    What do I think about the scalability of the solution?

    The solution is scalable, and we currently have 15 users utilizing it.

    How are customer service and support?

    The response times of customer service and support can be faster. I rate them a six out of ten.

    How would you rate customer service and support?

    Neutral

    Which solution did I use previously and why did I switch?

    We previously used different solutions but chose to switch because of the flexibility regarding cloud.

    How was the initial setup?

    The initial setup is straightforward, and it took a couple of hours.

    What about the implementation team?

    We implemented the solution in-house.

    What's my experience with pricing, setup cost, and licensing?

    Licensing is approximately $6,000 annually.

    What other advice do I have?

    I rate the solution an eight out of ten. The solution is good, but pricing, support and flexibility can be improved.

    Disclosure: My company has a business relationship with this vendor other than being a customer:
    PeerSpot user
    President and CEO, Founder Executive at SecuSolutions Co., Ltd.
    Real User
    Very mature and quite stable but could use a better user interface
    Pros and Cons
    • "They are on a good trajectory as a company and investing in R&D in the right ways."
    • "The solution seems to focus too much on enterprises, and they really need a product that works for SMBs."

    What is our primary use case?

    Primarily we're a partner of Tenable and what we've done is we've essentially created a middleware. We created a middleware on top of Tenable.io engine, the API, and the middleware was developed back in 2003. It has gone through about three different iterations since then. 

    Essentially, we simplify their user interface. It's been designed so that the managed service providers, the MSPs, are able to use the Tenable system with our interface on top. In a sense, what we've done is dramatically dummied down the Tenable interface through the use of our own GUI. We connect to the Tenable API in the backend, however, they're doing the heavy lifting, so to speak, and we're just presenting the information in a much more logical, easily understood manner. 

    What is most valuable?

    The API is pretty good.

    The solution works well for enterprise-level organizations.

    They're a standup product. They really are. They're one of the first in the industry which means they're a quite well-established site. It's pretty hard to improve upon. 

    The initial setup is pretty straightforward.

    They are on a good trajectory as a company and investing in R&D in the right ways.

    The stability is excellent. 

    The scalability is pretty good.

    What needs improvement?

    The solution seems to focus too much on enterprises, and they really need a product that works for SMBs. The enterprise product is too expensive for smaller companies, however, they really are looking for a product like this in the market.

    It's too technologically advanced for SMBs - Tenable is kind of a little bit like flying a 747. There's a lot of bells and whistles and switches and things like that, that quite frankly are not used or not understood largely by the average user. If they don't begin to cater to smaller organizations, they'll likely lose market share.

    They could use a better user interface that could be developed a lot better than it is. It really could be more intuitive.

    For how long have I used the solution?

    I've used Tenable for 20 years or so. 18 to be exact. It's been a good amount of time. I have a lot of experience with the company.

    What do I think about the stability of the solution?

    The stability is excellent. There are no bugs or glitches. It doesn't crash or freeze. It's one of the reasons we chose it. It's reliable and the performance is excellent.

    What do I think about the scalability of the solution?

    Aside from their licensing, which needs some serious reworking, when you get the licensing in order the scaling is not that bad. It's pretty much on-par in terms of what others are doing. However, getting the provisioning of the licensing and all of that stuff through their partners, namely Ingram Micro, is nothing short of pulling teeth really. 

    How are customer service and technical support?

    I've never used technical support in the past. I've never had a need to. Therefore, I wouldn't be able to assess them. I can't say how knowledgeable or responsive they are.

    Which solution did I use previously and why did I switch?

    We've only been with Nessus. Nessus Professional came out way back in the day, in 2002, 2003, there was WebInspect which was then, bought by IBM. We used WebInspect which was another iteration of vulnerability scanning. It's kind of like Burp Suite, which is commonly used now. That was our only other experience. That was very far back, it's almost another lifetime.

    How was the initial setup?

    The initial setup is pretty straightforward. We've got staff members that are certified for decades, two decades or more, and they know their way around quite easily. It's quite easy in that regard to set up.

    What's my experience with pricing, setup cost, and licensing?

    In terms of the pricing side, I would say that they've lost a little touch on the pricing. It seems that the enterprise companies are the ones that primarily use Tenable for DIY security. However, the needs are much greater adoption in terms of the SMB space. These companies are screaming for attention. They've gotten interest from the hackers as hackers seem to be quite focused on the SMB space - which means they need protection. Most of the VA companies that are out there are servicing the enterprise and they all need the help. They've got the budget, they've got the resources, they have the CISSP certified guys on the bench taking care of their needs.

    In terms of the volume of users interacting with the solution, you're looking at tens of thousands. As a service provider, we use the solution for companies of all sizes.

    What other advice do I have?

    We're a partner for Tenable Nessus.

    The Tenable.io is what we're using currently. It suits our needs best due to the fact that it's in the cloud. The API is okay. It's not wonderful. Seems to serve a purpose.

    The biggest problem with the solution is that if you're a small company, you're not going to be able to afford it, nor are you going to be able to manage it.

    I would recommend other organizations use the product. People probably don't consider the amount of, let's say, understanding or comprehension that they need of their own network to truly be able to deploy and manage and get the results they're looking for, however. Many often underestimate all their skillsets. Tenable has a number of features and functionalities and it can be a little confusing for, let's say, a non-security savvy person. It could be a little bit of a challenge, to be honest. I'd suggest any company that considers it also does their homework first.

    I'd rate the solution at a seven out of ten. It gets the job done. It really is smooth to operate once it's set up. It is for the most part pretty easy to set and forget.

    Which deployment model are you using for this solution?

    Private Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
    PeerSpot user
    Buyer's Guide
    Download our free Tenable Vulnerability Management Report and get advice and tips from experienced pros sharing their opinions.
    Updated: November 2024
    Buyer's Guide
    Download our free Tenable Vulnerability Management Report and get advice and tips from experienced pros sharing their opinions.