We use the tool to find loopholes in the system.
Information Security Manager at a international affairs institute with 10,001+ employees
An easy-to-use and stable solution that helps organizations to find vulnerabilities in their systems
Pros and Cons
- "The product is easy to use."
- "The solution must be promoted more in the market."
What is our primary use case?
What is most valuable?
The product fulfills our needs. It gives reports and finds vulnerabilities in our system. The product is easy to use. It is easy to integrate the tool with other products.
What needs improvement?
The solution must be promoted more in the market. It will make the customers more aware of the product.
For how long have I used the solution?
My organization has been using the solution for a month.
Buyer's Guide
Tenable Vulnerability Management
November 2024
Learn what your peers think about Tenable Vulnerability Management. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
824,067 professionals have used our research since 2012.
What do I think about the stability of the solution?
The tool is stable.
What do I think about the scalability of the solution?
Around 20 people use the product in our organization. We have one to three administrators. We are most likely to increase the usage of the product in the future.
How was the initial setup?
It was easy to deploy the solution.
What's my experience with pricing, setup cost, and licensing?
The tool is reasonably priced. There are no additional costs associated with the product.
What other advice do I have?
I have known the product for some time. So, I implemented it. Overall, I rate the solution an eight out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Security engineer at a construction company with 1,001-5,000 employees
Has a valuable remediation feature, but it could be easier to set up on the cloud
Pros and Cons
- "It helps us create remediation projects and assign the console’s responsibility to specific engineers."
- "The product could be easier to set up on the cloud."
What is our primary use case?
We use the software to manage vulnerabilities in our environment.
What is most valuable?
The product’s most valuable feature is remediation. It shows a list of vulnerabilities per server once you scan on cloud or on-premise instances. It helps us create remediation projects and assign the console’s responsibility to specific engineers. We can set up a follow-up date depending on the organization's requirements.
What needs improvement?
The product could be easier to set up on the cloud.
For how long have I used the solution?
We have been using Tenable Vulnerability Management for three years.
What do I think about the stability of the solution?
I rate the platform's stability an eight out of ten. Once, a few of our subsidiaries complained that channel usage in the environment was consuming bandwidth.
What do I think about the scalability of the solution?
We have five admins using Tenable Vulnerability Management in our organization. I rate the product’s scalability a seven out of ten. It has many features, and it is complicated to train someone on how to use Tenable. You have to schedule a session every day for almost two weeks for it.
How are customer service and support?
It was challenging to contact the technical support team earlier. However, we have found the right contact and can reach out to them easily.'
Which solution did I use previously and why did I switch?
I have used open-source applications before.
How was the initial setup?
The product is complicated to set up on AWS. However, it is easy to implement on-premises. It involves discovering IP addresses and schedule scanning. It requires acquiring some knowledge about the process to familiarize yourself with the AWS environment. We have to complete the setup for the whole environment. The deployment for a vast environment involves migrating a lot of data from on-premise to the cloud.
What about the implementation team?
We execute the implementation for most of the tools in-house. We take help from third-party vendors for the rest of it.
What other advice do I have?
I rate Tenable Vulnerability Management a nine out of ten. I advise you to choose Tenable.iO as it is a cloud-based solution.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Tenable Vulnerability Management
November 2024
Learn what your peers think about Tenable Vulnerability Management. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
824,067 professionals have used our research since 2012.
Cyber Security Analyst at Platview Technologies
A stable and easy-to-use solution that scans vulnerabilities in assets and provides suggestions for remediation
Pros and Cons
- "The solution is very simple to use."
- "The solution must provide penetration testing."
What is our primary use case?
The solution scans vulnerabilities in assets like workstations, network devices, desktops, or laptops. The product indicates vulnerabilities based on severity levels. There are high, critical, medium, low, and informational levels of severity.
What is most valuable?
The product can scan assets and web applications. It provides remediation for each vulnerability it scans. We get to know the actions we have to take to remediate the vulnerabilities. The solution is very simple to use. It also has cloud scanners. We can integrate Tenable and Nessus Scanner. It is easier to use.
What needs improvement?
The solution must provide penetration testing.
For how long have I used the solution?
I have been using the solution since 2022.
What do I think about the stability of the solution?
The tool is very stable.
What do I think about the scalability of the solution?
The tool is scalable.
How are customer service and support?
We don't have many issues.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup is very easy.
What other advice do I have?
The tool is easy to use and deploy. It's easy for customers to go through the documentation, see how it works, and scan their assets. Everything is straightforward, including the creation of users and enabling 2FA. Overall, I rate the tool a nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company has a business relationship with this vendor other than being a customer: Customer/Partner
A stable and user-friendly solution that is easy to setup
Pros and Cons
- "The solution is quite friendly."
- "Users get confused between VPR and CVSS ratings."
What is most valuable?
The solution is quite friendly.
What needs improvement?
Users get confused between VPR and CVSS ratings.
What do I think about the stability of the solution?
I would rate the tool's stability an eight out of ten.
What do I think about the scalability of the solution?
I would rate the solution's scalability an eight out of ten. We have around 1000 users for the product. We plan to increase the tool's usage in the future.
Which solution did I use previously and why did I switch?
I have used Nessus before Tenable. We switched to Tenable since it covered the problem for us.
How was the initial setup?
The product's setup is very easy and the deployment took six months to complete.
What about the implementation team?
We relied on a third-party vendor to complete the tool's deployment.
What other advice do I have?
The tool is easy to use and user-friendly and I would rate it an eight out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Owner at Sunlit Technologies
An easy initial setup with responsive technical support and good stability
Pros and Cons
- "The vulnerability scanning is the most important aspect of the solution for us."
- "The pricing of the solution could be more reasonable."
What is our primary use case?
We primarily use the solution for vulnerability scanning.
What is most valuable?
The vulnerability scanning is the most important aspect of the solution for us.
The initial setup is easy. It's pretty straightforward.
The stability is very good. We have appreciated the performance it offers.
Technical support is responsive. They help if you have issues.
What needs improvement?
The pricing of the solution could be more reasonable.
For how long have I used the solution?
We've been working with the solution for many years. We have clients that have been using this solution for the last year.
What do I think about the stability of the solution?
The stability has been very good overall. It's reliable. There aren't bugs or glitches. It doesn't crash or freeze. It's good.
What do I think about the scalability of the solution?
The solution is very highly scalable, and I don't have any complaints about that. If a company needs to expand it, it can do so fairly easily.
We typically deal with medium to large-sized organizations. Typically, there are thousands of users.
How are customer service and technical support?
Technical support is okay. We don't have any complaints about their level of service. They are knowledgeable and responsive and we are able to get the information that we need when we need it.
How was the initial setup?
The initial setup is not complex. It's pretty straightforward. A company that wants to implement it themselves shouldn't have any issues.
We sold Tenable.io Vulnerability Management, and the implementation has always gone smoothly. It's pretty seamless overall.
The entire deployment process takes anywhere from a week to ten days. It's not too long.
You only need two to three people to handle the implementation process.
What's my experience with pricing, setup cost, and licensing?
The pricing is a bit high. It could be better.
Which other solutions did I evaluate?
It is my understanding that our clients did not evaluate other options before this product was suggested to them last year.
The two main competitors on the market are likely Qualys and Rapid7. I'm not familiar with the key differences of each solution, however.
What other advice do I have?
We are a reseller. We work with a lot of different Tenable.io products.
My only recommendation to other companies would be to put up a plan and follow the plan, point by point. Keep tracking of the result and make adjustments, if necessary. It's important to go in with a bit of a roadmap to follow. It will help ensure results.
In general, I would rate the solution at an eight out of ten. We've been pretty happy with the solution overall.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
Intake Specialist at Maxtec
A powerful product that provides visibility across the entire tech surface and helps you to focus on the vulnerabilities that pose immediate risks
Pros and Cons
- "Tenable.io, in particular, is quite a powerful product. It looks at your traditional environment, which is pretty much anything that is on-premises, and it also goes a step ahead and covers your modern assets, which is anything that is currently sitting in the cloud. You get complete visibility of your entire environment and tech operation. The ability to give you visibility across the entire tech surface is one of the biggest advantages that Tenable.io has."
- "They've been able to think about everything in terms of where the world is going and the type of assets that you've got. They've everything sorted out in that aspect, but you have to pay for most of the other components that they've got to give you complete visibility across your tech surface. If it already had those capabilities in-built, without having to add them on to take advantage of them, it would be a very compelling value proposition."
What is our primary use case?
I work for a company called Maxtec, and we are a distributor. One of the solutions that we used to distribute, not anymore, is Tenable. I've worked as the product manager for Tenable, and it is one of the products on which I've worked quite extensively. We stopped its distribution last year, and I stopped working with it at the beginning of 2022. We were using its latest version.
How has it helped my organization?
One of the biggest cutting-edge technologies that they were able to introduce is predictive prioritization. It has helped a lot of IT teams enormously that were heavily under the weight of vulnerabilities that they needed to remediate. Just in 2019, over 19,000 vulnerabilities were discovered, and about 10,000 of those vulnerabilities were rated between high and critical. The way predictive prioritization works is that it adds a lot of context and granularity, and it helps you understand which vulnerabilities actually pose an immediate risk to your environment. It eliminates the pressure that the IT teams were under in terms of remediation because now, they don't have to focus on 10,000 vulnerabilities. They can only focus on 3% of vulnerabilities that pose an immediate risk to their environment. That, for me, has been a cutting-edge technology and a game-changer in helping a lot of IT teams in focusing more on the risk that they need to address, at least within the next 30 days.
What is most valuable?
Tenable.io, in particular, is quite a powerful product. It looks at your traditional environment, which is pretty much anything that is on-premises, and it also goes a step ahead and covers your modern assets, which is anything that is currently sitting in the cloud. You get complete visibility of your entire environment and tech operation. The ability to give you visibility across the entire tech surface is one of the biggest advantages that Tenable.io has.
The use of agents comes in very handy when a lot of the workforce is working from home, such as during COVID-19. Some of the traditional tools would not be able to monitor any of those devices that people would be working with, such as laptops, because they are remote. You can only audit their machines if they are on the business premises, but with Tenable.io agents, you can maintain that level of continuous monitoring, even if they are not on-premises at the time of the scan. The agents run the scans locally on the machine.
Tenable.io is a cloud-managed solution, but the scanners are sitting on-premises. They've also got some public cloud scanners that are sitting all over the world. They've got something called frictionless assessments, which is quite an interesting approach for vulnerability scanning of anything that is sitting in your AWS. You don't have to deploy the scanners. They've got sensors in there that are able to give you continuous monitoring without deploying scanners, doing any configurations, or inputting any credentials.
What needs improvement?
They've been able to think about everything in terms of where the world is going and the type of assets that you've got. They've everything sorted out in that aspect, but you have to pay for most of the other components that they've got to give you complete visibility across your tech surface. If it already had those capabilities in-built, without having to add them on to take advantage of them, it would be a very compelling value proposition.
Their support needs to be improved in terms of turnaround time.
What do I think about the stability of the solution?
It is stable.
What do I think about the scalability of the solution?
It is a cloud solution. Therefore, it is highly scalable. There is no limit to how many assets and devices you can handle.
In terms of verticals, in the public sector, we've seen a huge uptake. That could be because of compliance reasons. We've also seen it being used quite extensively within the banking and financial verticals. Those are the biggest users of the product. There has also been an uptake in other verticals but just not as big or as vast as the public sector and the finance and banking sector.
How are customer service and support?
One area that they could improve is technical support. Oftentimes, it's not as good as it should be. The turnaround time could be improved quite significantly.
How was the initial setup?
It is pretty easy and straightforward. For the cloud, you don't have to do anything on the management console. That is already set up for you. The only thing that you need to configure is your scanners that are sitting on-premise. For that, you just need a linking key that you obtain from Tenable.io so that there is directional communication between the cloud, your cloud instance, and various scanners that are sitting on-premises. It would be the same process if you want to install an agent, for example, on a machine. It would apply the same way. The only difference is that instead of choosing a scanner, you'd choose an agent.
What other advice do I have?
For future users of Tenable.io, I would recommend using a layered approach. Tenable.io has an open API. So, it can be integrated with SIEM solutions. You can look at integrating it with privileged access management or any SIEM solution so that you've got all the data being pumped into a centralized location, and you are able to read the data alongside other security events coming from the SIEM and privileged access management solutions.
Companies that are currently using Tenable.io can definitely start looking at integrating some of their security solutions for a much more robust security approach.
I would rate it a solid eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
Security Specialist at a security firm with 51-200 employees
I like the Cloud Scanning feature the most, but they can improve in the area of role management and compliance reporting
Pros and Cons
- "It is pretty stable. I would rate it nine or maybe ten."
- "They should include better customization of the dashboard, and integration tools."
What is our primary use case?
We use Tenable.io for vulnerability scanning.
What is most valuable?
I like the Cloud Scanning feature the most.
What needs improvement?
They can improve in the area of role management and compliance reporting.
They should include better customization of the dashboard and integration tools.
For how long have I used the solution?
We have been partners with Tenable.io for four years.
What do I think about the stability of the solution?
It is pretty stable. I would rate it nine or maybe ten out of ten. I didn't realize that the solution will be dropped in availability.
What do I think about the scalability of the solution?
It is a scalable solution. I would like to rate it a six out of ten.
How are customer service and support?
Many times, I get some answers that are not suitable information for my query. Thus, I need to escalate our vendors and our contacts internally. When some task is escalated and some security engineer supports them, it becomes quite helpful. After all, we are a part of it. I am working with Tenable.io. So in general when I have some problems, it is a pretty big problem for me. And I need someone else for support. It is not a general problem that some customers can figure out.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
Two years ago, I was training for Rapid7. Since then, I have had no time to implement another solution. So we are just implementing Tenable.io right now. Also, we have some big Tenable.io projects. So, we are just working around Tenable.io. But I have some expectations to work in the future with another vendor for vulnerability management.
What's my experience with pricing, setup cost, and licensing?
I don't have any comparative options from another vendor. I just work at the retail level. I know it has a pretty high cost for some features. It's a security vendor, and the security solutions are pretty high-priced. I think Tenable.io is available at the mid-range of prices, maybe the mid-high range.
What other advice do I have?
I work with Tenable.io and implement this solution for many customers. I would rate it eight out of ten.
The solution needs either two engineers or one security specialist to maintain it.
Which deployment model are you using for this solution?
Private Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company has a business relationship with this vendor other than being a customer:
Team Lead, Cyber Security at Uridium Technologies
Provides seamlessness, a perfect UI, and identity management for office operations
Pros and Cons
- "The solution provides seamlessness, a perfect UI, and identity management for office operations. We are most vulnerable to users. Therefore, it is crucial to implement the right solution to ensure proper user access and resource management."
What is our primary use case?
We use the Tenable Vulnerability Management solution for internal web applications, asset management, and remediation. It helps us transfer and leverage the remediation of websites, effectively addressing vulnerabilities.
How has it helped my organization?
We need to deploy this on internal assets. It resides within the internal infrastructure and communication.
It encompasses everything at some point. From development to deployment, it receives the necessary attention.
What is most valuable?
The solution provides seamlessness, a perfect UI, and identity management for office operations. We are most vulnerable to users. Therefore, it is crucial to implement the right solution to ensure proper user access and resource management.
For how long have I used the solution?
I have been using Tenable Vulnerability Management for 4 years.
What do I think about the scalability of the solution?
200 users are using this solution.
Which solution did I use previously and why did I switch?
We have used Qualys. It is tricky and expensive.
How was the initial setup?
The initial setup is seamless and takes three days to complete. Two people are required for the deployment but one person can do as well.
What other advice do I have?
This process is seamless because checks are scheduled at different intervals, typically every ten minutes. Once a log is generated, we attend to it immediately. Also, the maintenance is straightforward.
Overall, I rate the solution an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Last updated: May 12, 2024
Flag as inappropriateBuyer's Guide
Download our free Tenable Vulnerability Management Report and get advice and tips from experienced pros
sharing their opinions.
Updated: November 2024
Popular Comparisons
Tenable Nessus
Tenable Security Center
Orca Security
Claroty Platform
Microsoft Defender Vulnerability Management
Rapid7 Metasploit
The NodeZero Platform
Amazon Inspector
Buyer's Guide
Download our free Tenable Vulnerability Management Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Can you recommend API for Tenable Connector into ServiceNow
- What's the difference between Tenable Nessus and Tenable.io Vulnerability Management?
- Which one to buy out of the following products: Tenable SC, Tenable.io, Tenable.ep or Tenable.ad?
- What are the differences between Tenable.sc and Tenable.io?
- How inadvisable is it to use a single vulnerability analysis tool?
- What are the benefits of continuous scanning for vulnerability management?
- When evaluating Vulnerability Management, what aspect do you think is the most important to look for?
- What is a more effective approach to cyber defense: risk-based vulnerability management or vulnerability assessment?
- What are the main KPIs that need to be implemented to have better posture in vulnerability projects?
- Which is the best vulnerability scanner tool?