What is our primary use case?
I primarily use the solution for network scanning. I can use it when I want to see network scanning involved with the network devices and servers.
What is most valuable?
I love everything about Nessus. I may be biased in my rating, biased in the sense that I love using Nessus.
The usability is okay. The pricing is okay. The costs are reasonable.
The level they give you is good. It depends on the kind of scan that you want to do. There are different options there. If I want to do a PCI scan, that is available. If I want to do a scan that involves checking to see if the system patching is up to date, that is available. If I want to scan against trending vulnerabilities, I can do that, too. They have so many different options. You can streamline it to what you want, and you do your scan.
Nessus is flexible. It gives a holistic view of your entire environment. I would go for a Nessus any day, anytime.
They have a good reporting system. I love the reporting system. The references they made in terms of recommendations are great. They can give a recommendation on how to get a particular issue fixed.
The setup is straightforward.
It is stable and reliable.
We can scale the product.
What needs improvement?
They should try to create an all-in-one solution. When I say all in one, I mean something that would be cheap, where I can scan a lot in terms of web applications. Right now, this is available. However, it's a bit expensive. If users want to start scanning applications, networking devices, et cetera, they should also try and work on the pricing for those and have everything together. The web application module should be included in Tenable itself.
For how long have I used the solution?
I've used the solution over the past 13 years. I've worked with it for a long time.
What do I think about the stability of the solution?
The stability is fine. There are no bugs or glitches, and it doesn't crash or freeze.
What do I think about the scalability of the solution?
The solution can scale as needed.
How are customer service and support?
I've not escalated anything to technical support.
Which solution did I use previously and why did I switch?
I'm aware of other solutions.
What makes Nessus outstanding is the different options. There are so many scanning options. They give you the room to be flexible. You can scan your server how you want. Other options may just allow for a general scan of my system. With Nessus, I can streamline and customize my scan.
How was the initial setup?
It is an easy solution to set up. The deployment is not lengthy. Within two hours, I had it up and running.
There is no crazy maintenance needed. Sometimes when there are new updates, it just alerts you the moment you log into your appliance. It just alerts you and gives you room to do the updates. Sometimes it may just set automatically, and it picks the updates. When you log in, it asks for you to reinitialize your system, and you're good to go.
What's my experience with pricing, setup cost, and licensing?
The price is not bad. We are comfortable with the cost of the solution right now and with what we are paying for what we get in return.
We just pay for the license and do not deal with any other additional fees.
What other advice do I have?
We're using the latest version of the solution.
When you are doing a spot check, and something rescues you a lot from disaster, you really appreciate that service. The product has really worked for me.
I highly recommend the solution.
I'd suggest new users run a POC and exhaust all the functionality and test other solutions as well. At the end of the day, compare them. Don't forget to consider budgets. Ensure that it matches what your company needs and the budget that they have for that particular solution.
Make sure that functionality is taken into account. Some people only look at the budget and go for something cheaper and then do not have the functionality they require.
I'd rate the solution nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.