Try our new research platform with insights from 80,000+ expert users

Pentera vs Tenable Vulnerability Management comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 9, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Pentera
Average Rating
7.8
Reviews Sentiment
7.2
Number of Reviews
9
Ranking in other categories
Penetration Testing Services (2nd), Breach and Attack Simulation (BAS) (2nd)
Tenable Vulnerability Manag...
Average Rating
8.0
Reviews Sentiment
7.0
Number of Reviews
43
Ranking in other categories
Vulnerability Management (6th), Risk-Based Vulnerability Management (2nd)
 

Mindshare comparison

Pentera and Tenable Vulnerability Management aren’t in the same category and serve different purposes. Pentera is designed for Breach and Attack Simulation (BAS) and holds a mindshare of 29.3%, up 28.3% compared to last year.
Tenable Vulnerability Management, on the other hand, focuses on Vulnerability Management, holds 5.4% mindshare, down 9.6% since last year.
Breach and Attack Simulation (BAS)
Vulnerability Management
 

Featured Reviews

Jon Medvenics - PeerSpot reviewer
Useful in vulnerability management and can automate pen tests
One of the big issues we have is that the tool has an additional license for compromised credentials. Suppose compromised credentials for any of your domains appear in leaks, dumps, or are being sold. In that case, they try to aggregate that data and highlight that, for example, ten users appeared in recent dumps as compromised credentials. However, they don't provide much information about where those compromises came from or their source information, probably to protect their sources. Also, if you have credentials and want to check if they're still valid or can still be used, and you confirm they can't be used (maybe they're from a leak or a twenty-year-old database), there's no way for you to flag that these credentials aren't a problem anymore. The solution has a sort of flat report. It's annoying to go through lots of legwork only to see the same names or credentials still there, and you can't do anything about it in their portal. We've given them feedback, but I think it's probably on their long list of feature requests to address. For me, that would be a greater user configuration of the tests performed on a granular level. As I mentioned with Cymulate, they show you every line of code they will run and what tool is being used, step by step. Pentera is more closed in that regard. If Pentera released a feature that allows you to alter the attack path or change the command, that would be incredibly useful. Pentera might use one or a few different methods to do something, but if none of those work, it will just say everything is fine and secure. If Pentera could adapt or change based on what it finds in the environment, that would be very valuable. As a customer, we understand our environments better than an automated tool, so providing context to help the tool get better results would be valuable.
Mani Bommisetty - PeerSpot reviewer
Streamlines vulnerability management with excellent reporting and potential AI integration
Tenable is user-friendly and excels in reporting. It allows me to easily fetch and schedule reports. The software's discovery feature aids in strengthening our security posture. The single-sensor installation process on various operating systems is smooth, unlike Rapid7, which requires different versions for separate systems. Furthermore, Tenable enables vulnerability management through potential AI integration that consolidates efforts and resolves multiple vulnerabilities simultaneously.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The platform's most valuable features are credential management and vulnerability management."
"The vulnerability scanner, exploit achievements, and remediation actions are all great."
"What I like the most about Pentera is its solution-oriented approach."
"Pentera has many authentic features."
"The tool showed us that our ransomware protection wasn’t working on some machines."
"The most valuable feature of Pentera is that you can do continuous vulnerability assessment, which is automated."
"The product is easy to use."
"The solution is SaaS-based. From a cloud perspective, it has Pentera Surface and Pentera Core. The Core is the on-prem deployed solution, while the Surface is the cloud-hosted solution that scans your public infrastructure. From the Surface perspective, the most valuable feature so far has been the attack surface mapping."
"The best feature of the solution is the amount of visibility it provides of the vulnerabilities."
"Tenable.io, in particular, is quite a powerful product. It looks at your traditional environment, which is pretty much anything that is on-premises, and it also goes a step ahead and covers your modern assets, which is anything that is currently sitting in the cloud. You get complete visibility of your entire environment and tech operation. The ability to give you visibility across the entire tech surface is one of the biggest advantages that Tenable.io has."
"The solution can integrate with third parties and meets standard compliance."
"Tenable is user-friendly and excels in reporting."
"The ease of use in terms of scanning assets is valuable."
"Tenable is user-friendly and excels in reporting."
"Tenable Vulnerability Management is the backbone of our vulnerability management and has affected my organization positively."
"The price of Tenable.io Vulnerability Management is reasonable as it is ten times cheaper than other options."
 

Cons

"The licensing and IP management need improvement."
"The price could be improved."
"Maybe scalability. I know that the Pentera right now is high level in order to scan big deals over 500 IPs and not less, and not less. That can be more granular. This will be useful."
"Pentera's general dashboards could be improved and made more specific in terms of vulnerabilities that I'm discovering."
"One area for product improvement could be the inclusion of a dashboard to cover multiple branches and subsidiaries, allowing for centralized monitoring."
"The vulnerability scanner, exploit achievements, and remediation actions are all great."
"There is room for improvement in virtualization compatibility."
"The licensing and IP management need improvement. When the IP is imported into a system, we cannot withdraw or revoke the license."
"t needs additional reporting and intelligence features, as well as enhancements in AI-driven detection, which is still in its early stages."
"The reporting was never great in Tenable Vulnerability Management, so, in my company, we imported all the data into Ivanti RiskSense to start using it for reporting."
"They've been able to think about everything in terms of where the world is going and the type of assets that you've got. They've everything sorted out in that aspect, but you have to pay for most of the other components that they've got to give you complete visibility across your tech surface. If it already had those capabilities in-built, without having to add them on to take advantage of them, it would be a very compelling value proposition."
"Users get confused between VPR and CVSS ratings."
"Tenable could improve visibility into assets, including automated asset tagging. You should be able to automatically tag assets based on location, function, ownership, etc. That would help us because we spend a lot of time identifying and tagging assets by hand."
"An area of improvement for this solution is being able to customize the dashboard. For example, the dashboard does not allow us to view a previous months vulnerability results alongside current results to make comparisons."
"The stability has room for improvement."
"More flexibility is required compared to other solutions."
 

Pricing and Cost Advice

"It's not that expensive, but it could be more cost-effective."
"The product's cost is reasonable. I rate the pricing a three out of ten."
"The tool is relatively cheap."
"We have to pay a yearly licensing cost for Pentera."
"Compared to other VM solutions, Tenable.io Vulnerability Management is expensive."
"A yearly payment has to be made toward the solution's licensing costs."
"The product costs us around $137,000 annually for 4000 to 5000 assets."
"The tool is reasonably priced."
"On a scale of one to ten, where one is low, and ten is high price, I rate the pricing an eight. So, it is a pretty expensive solution."
"Tenable.io Vulnerability Management's pricing solution model isn't great."
"I would rate the pricing a five out of ten. It is in the middle."
"Yearly payments are to be made toward the licensing cost of the product. It is neither a cheap nor an expensive product."
report
Use our free recommendation engine to learn which Breach and Attack Simulation (BAS) solutions are best for your needs.
860,592 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
14%
Computer Software Company
13%
Manufacturing Company
10%
Educational Organization
6%
Computer Software Company
13%
Financial Services Firm
12%
Educational Organization
10%
Government
9%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Pentera?
What I like the most about Pentera is its solution-oriented approach.
What needs improvement with Pentera?
The licensing and IP management need improvement. When the IP is imported into a system, we cannot withdraw or revoke the license.
What is your primary use case for Pentera?
I am using the OpenIntra solution for pentesting and managing candidates in my environment. I also use this solution for house customers.
What's the difference between Tenable Nessus and Tenable.io Vulnerability Management?
Tenable Nessus is a vulnerability assessment solution that is both easy to deploy and easy to manage. The design of the program is such that if a company should desire to handle the installation t...
What needs improvement with Tenable.io Vulnerability Management?
I would suggest HP WebInspect as a better option than Tenable.io. My current client doesn't have access to it. However, from my experience, HPE WebInspect provides more extensive reports and detail...
 

Also Known As

No data available
Tenable.io
 

Overview

 

Sample Customers

Blackstone Group Caterpillar Apria Healthcare Taylor Vinters Sandler Capital Management Drawbridge BNP Paribas British Red Cross
Global Payments AU/NZ
Find out what your peers are saying about Pentera vs. Tenable Vulnerability Management and other solutions. Updated: January 2025.
860,592 professionals have used our research since 2012.