My company uses Tenable as a vulnerability assessment.
We use it for scanning, for the discovery of vulnerabilities in the components or the software, or on the IT infrastructure of our client.
My company uses Tenable as a vulnerability assessment.
We use it for scanning, for the discovery of vulnerabilities in the components or the software, or on the IT infrastructure of our client.
The solution can conduct a full vulnerability assessment and also suggest mitigation of vulnerabilities and has a lot of other features.
It creates a classification of the vulnerability and the likelihood and the impact on other features.
The solution is easy to deploy and simple to use.
It's scalable.
The solution is stable.
It would be a good idea if they have a simulation of attacks or a use case for finding a new vulnerability or dealing with a zero-day attack.
Right now, it works based on dealing with a vulnerability that is already detected and reported, and it would be great if they have a combination of a vulnerability that existed and another use case to have a more proactive approach to potential new issues. Therefore, doing a simulation of attacks to find a new or zero-day issue or vulnerability would be helpful.
I've been using the solution for more than two years.
The solution is very stable and reliable. I'd rate it four or five out of five. The performance is good. There are no bugs or glitches, and it doesn't crash or freeze.
It is very scalable. I'd rate it a four or five out of five in terms of the ease of expansion.
We would use Nessus to conduct a vulnerability assessment. How many people use the solution depends on the client. Maybe five or six people from the engineering side use it in general.
We have a new client coming on, and we will require more users on the product to conduct vulnerability assessments, so we do have plans to increase usage.
I've never had any interaction with customer support. The solution works very well, and we haven't needed help.
The initial setup is very straightforward. It's not overly difficult, or complex.
I cannot recall how long the deployment process took.
Our technical team handled the deployment.
Another department handles the licensing. I can't speak to the exact costs. I do know that we pay a yearly licensing fee.
We would like to discover other solutions and do a comparison to see the better solution for our clients. We've, for example, tried to look into Cyber XM.
We are just end-users and customers.
I'm not sure which version of the solution we're using.
I'd rate the solution eight out of ten.
We are using Tenable Nessus for vulnerability management. Not exactly the management, but we perform vulnerability assessments mostly for internal networks. Additionally, we use Acunetix and it comes into play for the web application.
The most valuable feature of Tenable Nessus is vulnerability assessments. There are a lot of threats around the world and this solution is the first to come out with detection rules.
Tenable Nessus could improve the reporting by adding some dashboards. The reports are a hassle at this time. Tenable.io has more detailed reports. Having a better dashboard that can show where the vulnerabilities are and be categorized would be helpful. We then could present them to upper management for a deep overview of our network posture which they do not see.
I have been using Tenable Nessus for approximately seven years.
Tenable Nessus is stable.
Tenable Nessus is scalable, it can scale up and down.
We have five or six people using this solution occasionally. We have monthly schedules for scanning, the solution is not used daily.
The support of Tenable Nessus is responsive and helpful.
I rate the support from Tenable Nessus a five out of five.
Positive
I have previously used Acunetix and they are more focused on web applications instead of vulnerability assessments. Tenable Nessus lacks in this area, they should focus more on the web applications side.
The initial setup of Tenable Nessus is straightforward. There is helpful documentation that is provided.
I rate the setup of Tenable Nessus a five out of five.
We did the implementation of the solution in-house.
When comparing the price of Tenable Nessus to other similar solutions, such as Acunetix, Tenable Nessus is not as expensive. It is averagely priced in the market. We pay for the solution annually.
My advice to others wanting to implement this solution is they need to understand what will be scanned. For example, if they are using internal servers or something similar, and is it on the cloud, or web applications, this is something they need to know. It's a good idea to evaluate these things on their end before choosing to use the solution. This solution focuses more on the servers or the network security side. Acunetix focuses more on the web application side. This is where the buyer has to evaluate and know their use case.
I rate Tenable Nessus a nine out of ten.
The scanning capabilities are most valuable when compared to Nessus.
I think the reporting templates could be improved with Tenable Nessus.
I have been working with Tenable Nessus for the past year.
Tenable Nessus is scalable.
Technical support always replies back on Mondays and it depends on the open support cases.
The setup is straightforward. It takes about five to ten minutes to deploy and it is easy.
I would rate Tenable Nessus an eight on a scale of one to ten.
I use this solution for OS auditing, database auditing, virtualization, and following how closely it follows our CI or TISA benchmarks. We also use it for malware and ransomware risk and for carrying out assessments. We purchased this product from a local partner that has a premium partnership with Tenable. I'm a cybersecurity and compliance lead engineer.
The solution makes ransomware checking and OS auditing and implementation relatively easy. It covers most of the requirements for benchmarks for all sorts of widely available required configuration settings in the technology industry. It's also very user-friendly, easy on the eye, and saves a lot of time. It provides us with reports that perfectly satisfy compliance requirements, whatever the device or configuration settings.
There is very little to improve but cloud security tests would be something helpful to have. Tenable could also offer some penetration testing-related services, which would be beneficial.
I've been using Nessus for three years.
It's a very stable solution.
The solution is scalable. I use it for around 4,000 servers on a daily basis.
The technical support is good. They offer expensive professional support, but I generally use the website documentation to fix things. Compared with other companies, they provide very good support.
Positive
I previously used Qualys and had a bad experience. It's not very user-friendly, licensing was difficult and deployment painful. I also used Rapid7, and I think Nessus is more user-friendly than both of those products.
The initial setup was very easy and took just a few hours. It's important to plan wisely before implementing. Know how many servers you have and try to project your future requirements so that you can estimate the total number of IPs you require. If the forecast is accurate, the solution is cost-efficient. We used consultants from Singapore and they installed some agents in our on-premise servers. Maintenance is very easy.
The global situation is very unstable and the dollar price has already increased significantly in our country in the last three or four months so everything has become expensive. Licensing is very competitive in our local markets and there's a lot of haggling that goes on. The option of a three-year license would be most beneficial for us because of the huge variations in the dollar.
I rate this solution nine out of 10.
We use Tenable Nessus internally for our vulnerability scan and dynamic vulnerability assessments.
Tenable Nessus has helped us with better visibility of the current security posture of our infrastructure and helped us be proactive about remediating those findings.
The most valuable feature of Tenable Nessus is the support it provides for any new vulnerabilities quickly.
Tenable Nessus application device assessment is one of the top tools. However, in the application security assessment, there are other tools that provide better, and more accurate findings.
In a future release, I would like to see all SC reporting features included in the Professional version.
I have been using Tenable Nessus for approximately five years.
Tenable Nessus is stable.
The stability of Tenable Nessus is good.
We don't have a very big security team. It's four or five people who are using it.
We have used the support from Tenable Nessus. The support was relatively good.
The initial setup of Tenable Nessus was straightforward, we did not have any issues.
The deployment of Tenable Nessus was done in-house.
The solution is not difficult to maintain at the scale we are working on it.
We have seen a return on investment by using Tenable Nessus.
The newer tools are quite pricey. There is a case of some fine tuning that can be done in terms of licensing. The IP based licensing that is offered makes the tool very expensive. If they want the IT industry to adopt it, the price should be looked at.
For the professional the cost is reasonable. However, if you go to an HC or IO platform, then the price is high. Even though the scan engine is the same, the additional features for dashboarding and reporting should not cost more than the solution itself or the intelligence of the tool to identify those findings.
There are not any fees
In terms of the identification of vulnerabilities, this is a good tool. The engine it uses is accurate. However, it depends on which tool out of the stack you would use, and the scale of the infrastructure.
I rate Tenable Nessus a seven out of ten.
I am using it for scanning and checking vulnerabilities. I am using the Azure version of Tenable Nessus.
I like this solution because it is complete. It can scan and check many types of vulnerabilities. It can also check for compliance.
It fits very well in my environment. It is very easy to use, and there is a very good cost-benefit of this solution.
There should be a possibility to install agents on scanned machines. Tenable IO provides the capability of using local agents to check local problems, but this feature is not there in Tenable Nessus Professional. It would be nice to have something similar in Tenable Nessus Professional. We should have the capability to use local agents installed on the machines to locally check a problem.
It is stable.
It is, for sure, scalable. We have 10 or 12 people who use this solution.
We never have any kind of problem or lack of response. I would rate them a ten out of ten.
Positive
It is very easy. It is pretty straightforward.
It has a fair cost and very good cost-benefit ratio.
I would recommend it to others. It does everything that such a solution needs to do. It can check for vulnerabilities and compliance. It is also very easy to use. It is better than its competitors, such as Rapid7.
I trust Tenable solutions. I have worked with Tenable IO a few years ago, and with Tenable Nessus, I had the same feeling that I had with Tenable IO. It is a very good solution. It is more expensive than Tenable IO, but it is a complete solution.
I would rate it a nine out of ten.
Two of our customers use it for vulnerability assessment and penetration testing, and they are getting very good results.
It is easy to deploy and easy to use. Its reporting is good. From this reporting, you can see the pain point in your network, which makes it easy to fix them. It is easy to understand the reports and export them.
Technically, it is an excellent and the best solution available in Libya. My only concern is related to its pricing. They are an emerging company in Libya, and they need to put in some effort to provide us with very good prices so that customers can go with the best solution. Chinese companies are getting into the market here, and they're providing very cheap solutions.
We have been providing network and solution integration services since 2012.
It is a stable solution. It is the best one in the world. I am not considering any other solutions.
It is scalable.
Their technical support is very good. The feedback that I have received from the customers for the tickets that they opened is that they are satisfied with the service.
It is easy to deploy. It can be implemented in less than 10 days, but complex projects with ISO2007 and 001 compliance requirements can take more than a year.
From our side, there are only two engineers. One is the main engineer and the other one is the backup engineer.
It is being used by only three users. Two are from the cyber information security team and one is from the network security team.
Its price is high for Libya. The companies here in Libya don't have the awareness of and a good budget for cybersecurity services. If you want them to go for a product, you need to provide something different. This differentiation is related to the price. They should give about 40% to 45% discount per person on the current cost. From our side, we provide the demo and show it as a very good and valuable solution, but when it comes to the price, some companies don't want to own the tool. They prefer to go for it as a service. There are a few companies that are providing it as a service where they own the tool, but they provide it as a service, which is cheaper than a customer owning the product. We strongly recommended that customers own the product and use it.
I strongly recommend to customers to go for a three-year license to use it, benefit from it, and be comfortable with it. In Libya, we are facing a problem related to the timelines and delays of projects. If they go for just a one-year license and the project gets delayed by six months, they will have only six months to use it.
It is a very good and useful tool. I would rate it a nine out of ten.
We are using the product for CIS benchmarking on our systems.
Our primary use case is basically understanding whether our systems are compliant with the CIS benchmarks in terms of system hardening. What Tenable Nessus does is it can run a scan on the systems and it gives us a report in terms of what properties or settings on the systems are in compliance and what are not in compliance. Then we can review that and go back and improve the systems in terms of those settings.
What I like about it is the fact that it can figure out what changes we need to make on our systems to ensure that they're hardened properly.
The initial setup is not difficult.
Once you get past the initial implementation, the solution is very stable.
It's scalable.
So far, it has been fulfilling the requirements. From that perspective, there is not a lot that I would want to improve in the features that we are using it.
They could make their reporting a little better. Maybe they could do some more integrations with certain other tools to extend it or make the reporting better in the sense that it could probably generate some alerts or something of that sort. It could do some real-time reporting. If there are any policies that are changing or getting violated, they could probably generate some alerts, which could involve the on-call on my side so that I could take immediate action. That could probably be one thing that they could introduce.
We've used the solution for about a year now. It hasn't been that long.
Initially, we had some issues. Initially, we were not very confident about how to configure certain things. Once we had integrated and deployed the product, we needed a few support calls to fix the system properly in our environment and since then it has been smooth, I would say. The stability is now good.
The solution can scale.
We have very few users. It's basically based on the number of systems that we need to install it on in terms of scaling. That's something that probably is more than the number of users who actually access the system. It's largely used by the security team.
We do have plans to increase the usage of Tenable Nessus organically. As the number of systems that we use is dynamic in nature, it likely will keep going up and down over time.
We've dealt with technical support on and off I would say. We keep talking to the technical support at times to get some insights on any new features that are coming in or in terms of how to use a certain feature that we are probably trying to introduce or something of that sort.
We were not using any other products before this.
For the initial setup, I need to deploy an agent on my systems. It's pretty straightforward. It's not very difficult.
I'm not really sure about how long it took, however, my understanding is it didn't take too long for our system. It was maybe a few minutes per system or maybe half an hour per system. Not more than that.
We did not use a consultant or any integrator for the deployment. We did it in-house.
There were a couple of people on my team who were able to set it up for us.
I'm not aware of the licensing cost.
I'd recommend the product to others. If a company wants to use it for system analysis as part of the benchmarking of the systems or if a company wants to do security benchmarking, they can use this. They should be able to use the tool.
I'd rate the solution eight out of ten.
Our customers are using this solution. They scan their network, and they get a report about vulnerability assessment tools and solutions.
It's deployed on-prem.
It gives you an unlimited IP scan. It's a cheap solution compared to Rapid7 or Qualys. It's very user-friendly. Customers can easily scan their network.
I would like to have a management option after the network scanning.
The difference between Nessus and Rapid7 is price. Nessus is a very cheap solution compared to Rapid7 and has unlimited IP scanning facilities, but Rapid7 doesn't have this option. It has IP limitations. Rapid7 has some models based on how many IPs the customer wants to scan, and the costs depends on that amount.
The cost is around $4,300 per year. Use is unlimited. You don't pay more if you want to use it for another IP.
I would rate this solution 8 out of 10.
Tenable Nessus can be deployed on-premise and in the cloud.
Tenable Nessus is a vulnerability scanner to find vulnerabilities. The solution finds the vulnerabilities in our environment and then we send those vulnerabilities that are found out to the SMEs to be fixed.
Tenable Nessus allows us to keep up on fixing the vulnerabilities that are either being exploited in the wild or the ones that we find most critical.
The most valuable feature of Tenable Nessus is vulnerability detection.
Tenable Nessus could improve reporting and information sharing. It would be helpful if we could share the reports and have a little bit better flexibility in the reporting of the data.
In the next release, they should add some more integration with other security solutions that would be helpful.
I have used Tenable Nessus for approximately 10 years.
The stability of Tenable Nessus is very good.
Tenable Nessus is highly scalable.
We have a couple of administrators and vulnerability analysts who run scans, and read-only accounts for the SMEs who fix vulnerabilities, and an executive role for management to view the data.
We use Tenable Nessus extensively, we have scheduled jobs running all the time. We do scans on all the systems on our network, and we are always making tweaks.
I rate the support of Tenable Nessus a four out of five.
I have not used another solution previously to Tenable Nessus.
For our deployment of Tenable Nessus, there are elements of complexity. However, the complexity depends on the use case. The solution is not that difficult to implement, the complexity comes from the many things that are involved. You do not need to be an expert there are many parts that need to be set up.
We had Linux servers built and the Tenable Nessus software was installed on top of that. It was relatively simple as far as that goes.
I rate the ease of setup of Tenable Nessus a three out of five.
We did the implementation in-house.
We have two administrators and one SME that does the supporting of Tenable Nessus.
It is difficult to show or rate ROI from a security standpoint, it is similar to having car insurance. When there are vulnerabilities out there, we can quickly look because we're scanning all the time at what our vulnerabilities are. Tenable Nessus is used for keeping our infrastructure safe.
Tenable Nessus needs to be licensed. We own a license for the security center and that license is charged by the number of IP addresses that you can scan. You're allowed to have as many scanners as you want and there's no license for the number of scanners. We have a bunch of Nessus scanners out there, and as long as we're comfortable with staying under that IP address limit, that's really all we have to be concerned about.
We pay a monthly maintenance fee, which is reoccurring.
We did evaluate other solutions before choosing Tenable Nessus, such as Rapid7. We choose Tenable Nessus because it was used by more customers and it seemed at the time to be more straightforward.
Security is complicated a subject. There's a lot involved in Tenable Nessus, but the solution is easy to run and manage and we have had a lot of good success with it.
I rate Tenable Nessus a nine out of ten.

Easy to deploy and use, stable, and scalable.