An easy-to-use, mature, stable, and scalable solution for vulnerability assessment
What is our primary use case?
In my company, we use Tenable.io Vulnerability Management is a good solution for vulnerability assessment on the infrastructure and not on the applications. The solution is useful for conducting vulnerability assessments on IT infrastructures. We use Tenable to discover assets on the network and the vulnerabilities in the vulnerability management cycle.
What is most valuable?
Tenable.io Vulnerability Management is an easy-to-use product. It is a good solution, as per Gartner's SIEM Magic Quadrant. The product has a lot of documentation and blogs, so you can get lots of support from its communities while also finding a lot of online materials that can help you improve the solution's uses or implement it according to your use cases.
What needs improvement?
The shortcoming of the solution that needs improvement is related to its capability to do vulnerability assessments on applications.
For how long have I used the solution?
I have been using Tenable.io Vulnerability Management for more than ten years.
What do I think about the stability of the solution?
It is a very stable and mature solution in the market since it has been around for over 15 years.
What do I think about the scalability of the solution?
The product has no scalability solution since it can manage hundreds to thousands of networks.
How are customer service and support?
The solution's technical support is good and quick to respond. If you have a problem, you can be sure that someone from the support team has a solution to your problem.
Which solution did I use previously and why did I switch?
Our company doesn't use any other products from Tenable apart from Tenable Nessus for vulnerability assessment. We also use NetSuite to manage the vulnerabilities' life cycle.
How was the initial setup?
The initial setup of Tenable.io Vulnerability Management was straightforward since it allows one to use a device, like a virtual machine, or one can use it on a public IP address if it is already deployed, making the process very quick and easy.
The solution is deployed on-premises.
The deployment process was very quick since it could be done using a virtual machine or the customer's network. You can do the deployment with the virtual machine by connecting to the management suite before launching the solution.
To do an assessment for all our customers, my company has over 200 users for the deployment and maintenance of the solution. There is a dedicated team in the company I currently work for to manage the solution. One technician is needed to do a vulnerability assessment.
What's my experience with pricing, setup cost, and licensing?
Yearly payments are to be made toward the licensing cost of the product. It is neither a cheap nor an expensive product.
What other advice do I have?
I recommended the solution to those planning to use it since it is a very good product. Though there are other good solutions like Qualys, Tenable is the best.
I rate the overall tool a nine out of ten.
Tenable IO
What do you like best about the product?
more visibility of the entire environment vulnerability with a good followup console.
What do you dislike about the product?
we have to schedule the scanning, they can do auto scan for the new vulnerability.
What problems is the product solving and how is that benefiting you?
vulnerability management gives the important tracking system to solve the findings
A stable and user-friendly solution that is easy to setup
What is most valuable?
The solution is quite friendly.
What needs improvement?
Users get confused between VPR and CVSS ratings.
What do I think about the stability of the solution?
I would rate the tool's stability an eight out of ten.
What do I think about the scalability of the solution?
I would rate the solution's scalability an eight out of ten. We have around 1000 users for the product. We plan to increase the tool's usage in the future.
Which solution did I use previously and why did I switch?
I have used Nessus before Tenable. We switched to Tenable since it covered the problem for us.
How was the initial setup?
The product's setup is very easy and the deployment took six months to complete.
What about the implementation team?
We relied on a third-party vendor to complete the tool's deployment.
What other advice do I have?
The tool is easy to use and user-friendly and I would rate it an eight out of ten.
Tenable Is The Industry Standard for Vulnerability Management Scanning
What do you like best about the product?
Tenable can scan all endpoints, including servers, workstations, network appliances, web applications, any OS.
What do you dislike about the product?
Sometimes scanning profiles aren't updated as frequently as I would like.
What problems is the product solving and how is that benefiting you?
Overview of assets and their security posture
Tenable.io: The Vulnerability Evaluator
What do you like best about the product?
The customization possibilities Tenable holds are the outstanding feature that made it stand out. It is neither easy for all the users to be okay with the default layout nor able to include everything the user requires in the same. Tenable.io is the final solution to it!
What do you dislike about the product?
I would have loved it more if the reporting mechanism in Tenable.io had been a bit more conclusive. I felt some of the details included were of no use at all. This could be avoided and made more professional.
What problems is the product solving and how is that benefiting you?
Most importantly, Risk-Based Vulnerability Management. It helps in getting more and more informations on all risks and also provides the best workarounds or patches for these issues.
Vulnerability Assesment Tool for Cloud Asset
What do you like best about the product?
Tenable Provides the best VA scans and the reporting structure with severity is good
What do you dislike about the product?
the Scan sometimes are too heavy that it slows down the network performance
What problems is the product solving and how is that benefiting you?
Performing the Vulnerability assesment for Infrastructure
Tenable.io
What do you like best about the product?
The scan engine seems to be good since it was based on the Nessus platform.
What do you dislike about the product?
The User Interface/Web Interface needs some work. There are a bunch of 'little things' that are annoying to an end user. Overall good but need some investment here.
What problems is the product solving and how is that benefiting you?
Vulnerability managment.
Vulnerability Management and Prioritization
What do you like best about the product?
Tenable.io makes it effortless to spin up a vulnerability management, prioritization and reporting platform for your network. The dashboards are decent out of the box and the ability to dig into the data of interest is incredibly valuable. The combined view of all of their solutions makes the job of a security team much easier.
What do you dislike about the product?
Since it is a SaaS platform, the level of customization is not as high as with the on-prem counterpart of Tenable.sc. For instance, custom trending charts are not available in the way they were as part of Tenable.sc.
What problems is the product solving and how is that benefiting you?
Tenable.io helps us identify and prioritize vulnerabilities within our internal network, external perimeter and our cloud infrastructure. Teams are able to manage their own assets and we use the data at the engineer and executive level.
An excellent product backup up by great support
What do you like best about the product?
Tenable.IO has great reporting and dashboard capabilities making it easy to understand risk and prioritise remediation.
What do you dislike about the product?
Whilst not an issue specific to Tenable.IO, better results can be achieved using agents than active scanning.
What problems is the product solving and how is that benefiting you?
Tenable.IO helps us understand the risks and prioritise vulnerability management
Tenable.io - Reliable and Current
What do you like best about the product?
Tenable.io just works and does what it needs to do. You can deploy internal scanners or use their cloud-hosted scanners for your external perimeter. Tenable stays on top of current events and updates and creates new plugins to detect the latest vulnerabilities.
What do you dislike about the product?
They are continually working on expanding their functionality, so they are tweaking their console. Adding functionality like more reporting, dashboards, and remediation scans. We stay current on their suggested best practices, unfortunately, too many other users did not update to newer and improved functionality and they provided old and new methods of tagging\grouping too long - confusing for new users to know what to use - I believe this is being cleaned up now.
What problems is the product solving and how is that benefiting you?
Scanning, reporting, and checking on remediation progress. Easy to set up schedules and just let Tenable do its thing. It is still best to review in the console, but you can also schedule reports.