Try our new research platform with insights from 80,000+ expert users
reviewer1229910 - PeerSpot reviewer
Security Architect at a logistics company with 10,001+ employees
Real User
The vulnerability priority rating has been accurate and helps us prioritize effectively, based on risk
Pros and Cons
  • "The most valuable feature is the breadth of vulnerabilities that it finds. It's able to find across a lot of different platforms and operating systems. It's also able to combine local testing with network-based testing."
  • "There is room for improvement in finishing the transition to the cloud. We'd like to see them keep on improving the Tenable.io product, so that we can migrate to it entirely, instead of having to keep the Tenable.sc on-prem product."

What is our primary use case?

We use it for internal and external vulnerability scans.

How has it helped my organization?

Instead of just looking at high, medium or low risk for vulnerabilities, and having to remediate all of them, we can remediate in a more effective manner. We have limited resources for remediation work and we want to spend our time on the most critical issues.

It helps us focus resources on the vulnerabilities that are most likely to be exploited. It gives a higher VPR number where the things are more likely to be exploited, instead of just using the pure severity rating as a way to prioritize and decide to remediate.

What is most valuable?

The most valuable feature is the breadth of vulnerabilities that it finds. It's able to find across a lot of different platforms and operating systems. It's also able to combine local testing with network-based testing.

When it comes to vulnerability prioritization, Tenable's predictive features are off to a great start. It's definitely giving us more data to help prioritize, instead of just relying on straight CVSS. The vulnerability priority rating has been accurate and is helping us prioritize effectively, based on risk or based on the likelihood of being exploited. Based on what they say, and comparing it to what we are seeing with malware exploits, their predictions are lining up with what we are seeing being exploited.

What needs improvement?

There is room for improvement in finishing the transition to the cloud. We'd like to see them keep on improving the Tenable.io product, so that we can migrate to it entirely, instead of having to keep the Tenable.sc on-prem product.

There is also room for improvement in some of the reporting and the role-based access. They have a pretty defined roadmap. They know where the gaps are, but it's a totally different product and so there's a lot of work that they have to do to get it to match.

Buyer's Guide
Tenable Nessus
June 2025
Learn what your peers think about Tenable Nessus. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
861,524 professionals have used our research since 2012.

For how long have I used the solution?

I have been using Nessus for three years at my current company. 

We monitor Windows, Linux, Mac, workstations, servers, and cloud resources.

What do I think about the stability of the solution?

It's very stable. We haven't had any issues. There has been no database corruption or anything like that. All we've had to do to the main Security Center is give it more disk space to save more data. That's it.

What do I think about the scalability of the solution?

The scalability is okay. We would definitely run into issues if we wanted to save a longer history of the data. It would be terabytes and terabytes of data. But in terms of at least keeping all the data for all the assets that we have, it's good. We're good enough with the retention. It meets our requirements.

The issues would be storage and being able to search across it. If we needed to save five years of scan history, it would be operationally difficult to use all the data that would be saved. But it's not problematic to look at the current data or trends for the past six months. Stuff like that is fine.

We're at about 20,000 hosts and it's pretty stable. I don't think we're going to do a big increase.

How are customer service and support?

Tenable's technical support is good, except for things that involve some of the custom development work that we've done using their API. Early on, that was problematic, but they've gotten better and released more API documentation and sample code, and that was fine.

It was nothing that was wrong with the product itself, but tech support is more designed for normal user interactions with the product, not doing development against the API. The problem with my code was because some documentation wasn't clear or there wasn't a sample for how to do this. That's where it was a little bit tougher. The normal, user function stuff was totally fine. It was really the developer-focused side.

Which solution did I use previously and why did I switch?

We were on Rapid7. We switched because of scalability and performance.

We were looking for a solution that could handle and scan our volume of assets. It wasn't working with our previous solution. Nessus has scalability. Being able to scan in time and actually being able to report on that data were things we couldn't do with our old solution.

Also, the level of visibility that Tenable provides is much better than Rapid7 because we're able to actually see all of the data that was collected and we're able to scan for vulnerabilities and config issues and pull all the data together. We were having real trouble with that before.

How was the initial setup?

The initial setup was straightforward. We were easily able to set up scan policies, asset groups, scan schedules, and start collecting data very quickly.

It wasn't complicated to define what we wanted to scan. It wasn't complicated to set up the credentialed scans, or to set up the different credentials for the different policies and different types of machines. Everything that that goes into building a scan policy was straightforward and we were able to get all of our assets scanned pretty quickly. Within 45 days of buying, we had good data and had done multiple scans already with all of our assets.

Our implementation strategy was that we wanted to set up credentialed scans for all of our machines as quickly as possible. We were working towards that and trying to get the coverage in Tenable as soon as possible.

What about the implementation team?

We did it ourselves.

What was our ROI?

We are fulfilling our goals and able to deliver on the requirements that we have. It's hard for security to be a real ROI. We need to do vulnerability scanning, we need to know where the issues are and we need to be able to fix them. It is doing that.

What's my experience with pricing, setup cost, and licensing?

Our licensing is on a yearly basis but we did a three-year deal. It is a fixed cost to cover a certain number of hosts or assets. There are no additional costs to the standard licensing fees.

What other advice do I have?

Leverage authenticated scans if you can. That reduces the number of false positives compared to just network-based scanning. Leverage the Tenable Agents if you can, as well, because that will help reduce the scan time and make it easier to get data from machines that are all over your network.

The solution isn't really helping to reduce our exposure over time because there are always new vulnerabilities coming out. It's helping us keep track of what's out there better.

The next part is going to be convincing external auditors that VPR is a reasonable way to actually prioritize, in terms of whatever our policy statements say for what we fix and how quickly; to get that to line up. A lot of people are still in the, "You must patch criticals with this number of days, highs with this number of days." We want to be able to turn that into a more risk-based approach but haven't really been able to do that.

The users of the solution in our organization are really just the people on our security team, so the number is under ten people. They're really just using it to look at the vulnerabilities, analyze the vulnerabilities, and figure out where our risks are and what should get patched. For deployment and maintenance of the solution we have a quarter of an FTE.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Mona Nyachhyon - PeerSpot reviewer
Director at Monal Tech Pvt.Ltd.
Reseller
Beneficial website scanning, reliable, and scales well
Pros and Cons
  • "The most valuable feature of Tenable Nessus is website scanning."
  • "The solution could improve security updates."

What is our primary use case?

Our clients use Tenable Nessus to find vulnerabilities in websites and infrastructure.

What is most valuable?

The most valuable feature of Tenable Nessus is website scanning.

What needs improvement?

The solution could improve security updates.

For how long have I used the solution?

I have been using Tenable Nessus for approximately three years.

What do I think about the stability of the solution?

The solution is stable.

I rate the stability of Tenable Nessus a seven out of ten.

What do I think about the scalability of the solution?

I am the only one using this solution.

I rate the scalability of Tenable Nessus a seven out of ten.

How are customer service and support?

I rate the support of Tenable Nessus a six out of ten.

How would you rate customer service and support?

Neutral

How was the initial setup?

The setup is easy. We use the deployment manual and followed the steps.

I rate the initial setup of Tenable Nessus a nine out of ten.

What's my experience with pricing, setup cost, and licensing?

The price is high for the solution. There are free tools with similar functionality available. The solution cost approximately $3,500.

I rate the price of Tenable Nessus a six out of ten.

What other advice do I have?

I would recommend this solution to others.

I rate Tenable Nessus a seven out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Tenable Nessus
June 2025
Learn what your peers think about Tenable Nessus. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
861,524 professionals have used our research since 2012.
Yashas P - PeerSpot reviewer
Cybersecurity engineer at Cyberjeet
Real User
Top 20
A cost-effective and user-friendly vulnerability scanning solution, but it lacks application-level support for mobile devices
Pros and Cons
  • "I like the fact that it was not expensive. I like that it's user-friendly."
  • "It would be better if they had application-level support for mobile devices. They don't have anything to scan mobile devices. Tenable Nessus doesn't have a mobile application vulnerability assessment. I also have issues with the false positive rates. The product has limited features."

What is our primary use case?

I evaluated, set up, and implemented Tenable Nessus for a client. They had four firewalls, about 500 endpoints, two servers, and one database server.

What is most valuable?

I like the fact that it was not expensive. I like that it's user-friendly.

What needs improvement?

It would be better if they had application-level support for mobile devices. They don't have anything to scan mobile devices. Tenable Nessus doesn't have a mobile application vulnerability assessment. I also have issues with the false positive rates. The product has limited features.

For how long have I used the solution?

I have been using Tenable Nessus for about six months.

What do I think about the stability of the solution?

On a scale from one to ten, I would give stability a seven.

How was the initial setup?

The initial setup is straightforward. We can deploy this solution within a week.

On a scale from one to ten, I would give the initial setup a seven.

What about the implementation team?

We implemented this solution. 

What's my experience with pricing, setup cost, and licensing?

Tenable Nessus is affordable. 

On a scale from one to ten, I would give pricing a ten.

What other advice do I have?

I would tell potential users that Tenable Nessus is suitable for device security.

On a scale from one to ten, I would give Tenable Nessus a seven.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer.
PeerSpot user
SamiAyyash - PeerSpot reviewer
Threat Intelligence Engineer at a tech services company with 11-50 employees
Reseller
It's easy to set up and integrate
Pros and Cons
  • "Nessus is effortless to integrate."
  • "The reporting could be improved. The reporting in Rapid7 is much better."

What is our primary use case?

We use Nessus for vulnerability assessment. Three or four engineers at my company are using it currently.

What is most valuable?

Nessus is effortless to integrate.

What needs improvement?

The reporting could be improved. The reporting in Rapid7 is much better.

What do I think about the stability of the solution?

Nessus performs well.

What do I think about the scalability of the solution?

Nessus is scalable.

How are customer service and support?

I'm happy with Tenable's technical support. 

How was the initial setup?

Nessus is easy to set up, and it only takes about two hours to deploy. 

What other advice do I have?

I rate Tenable Nessus nine out of 10. Nessus isn't suitable for everyone. It depends on the case. If you need reporting for the COs and stuff, Rapid7 is better. However, if you are implementing it as part of an ongoing VA or retention operation, you should probably use Tenable.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
PeerSpot user
Ali Al-Mahrooqi - PeerSpot reviewer
Manager at a financial services firm with 201-500 employees
Real User
Affordable, stable, and easy to set up vulnerability scanner with a responsive technical support
Pros and Cons
  • "Easy to set up vulnerability scanner with good stability and a responsive technical support team."
  • "The inventory management function in this solution needs improvement."

What is our primary use case?

We're using Tenable Nessus to manage vulnerabilities.

What is most valuable?

What I like most about Tenable Nessus is its vulnerability scanning feature.

What needs improvement?

A room for improvement which I see in Tenable Nessus is the inventory management function.

For how long have I used the solution?

I've been working with Tenable Nessus for two years now.

What do I think about the stability of the solution?

I'm satisfied with the stability of Tenable Nessus.

What do I think about the scalability of the solution?

We have not tried to scale up Tenable Nessus. The number of users we have when we started using it is still the same.

How are customer service and support?

Technical support for this solution was good. They were responsive.

How was the initial setup?

The initial setup for this solution was easy.

What about the implementation team?

We implemented Tenable Nessus through a vendor team, and the process took one month to complete. They were good.

What's my experience with pricing, setup cost, and licensing?

This solution is affordable. We pay a standard fee. We pay for the license yearly.

What other advice do I have?

I work with different products, e.g. firewalls, PAM technology, antivirus, WAF, and proxy. I'm handling information security in the government, not as a consultant. I deal with government procedures.

We deployed this solution on hardware, on VM.

We have 10 users of Tenable Nessus, and they are a mix of engineers and managers.

I'm scoring Tenable Nessus a ten out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1768575 - PeerSpot reviewer
Independ consultant
Consultant
Highly scalable and reliable
Pros and Cons
  • "The stability is very good."
  • "The reports should be improved in Tenable Nessus. For example, when you are auditing compliance with CIS standards. It provides very poor reports."

What needs improvement?

The reports should be improved in Tenable Nessus. For example, when you are auditing compliance with CIS standards. It provides very poor reports.

For how long have I used the solution?

I have been using Tenable Nessus for approximately one year.

What do I think about the stability of the solution?

The stability is very good.

What do I think about the scalability of the solution?

Tenable Nessus has been scalable.

What other advice do I have?

My advice to others is for them to focus on the cloud solution, and do as much as possible in the cloud.

I rate Tenable Nessus an eight out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Assistant Engineer at Harel Mallac Technologies Ltd
Real User
User-friendly, easy to use, and good performance
Pros and Cons
  • "Tenable Nessus has a good performance, is very user-friendly, and is easy to use."
  • "The solution should be able to support more devices."

What is most valuable?

Tenable Nessus has a good performance, is very user-friendly, and is easy to use.

What needs improvement?

The solution should be able to support more devices.

For how long have I used the solution?

I have been using Tenable Nessus for approximately one year.

What do I think about the scalability of the solution?

I have one customer that is using this solution.

How was the initial setup?

The installation of Tenable Nessus is straightforward, and it can take a couple of hours.

What about the implementation team?

I am able to do the deployment myself.

What's my experience with pricing, setup cost, and licensing?

There is an annual license required to use this solution.

What other advice do I have?

I would recommend this solution to others.

I rate Tenable Nessus a nine out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
reviewer1687830 - PeerSpot reviewer
Information Technology Security Specialist at a tech services company with 201-500 employees
Real User
A remote security scanning tool that's pretty good to optimize
Pros and Cons
  • "I have experience with it on my attack stations, and it's pretty good to optimize. Personally, I think Nessus is quite a good product."
  • "Some things in the user interface could be better. The user interface could allow more adjustments to plugins. The price could also be better."

What is our primary use case?

I'm using Tenable Nessus for my personal projects and vulnerability assessment, but I can't discuss what I do at work with you.

What is most valuable?

I have experience with it on my attack stations, and it's pretty good to optimize. Personally, I think Nessus is quite a good product.

What needs improvement?

Some things in the user interface could be better. The user interface could allow more adjustments to plugins. The price could also be better.

For how long have I used the solution?

I have been using Tenable Nessus as a worker in America for about 15 years now.

How are customer service and support?

Technical support could be more knowledgeable. Their support right now goes from awkward to funny. Sorry to say that, but Tenable Nessus support isn't working as it should. They act fast, but their solutions don't always work. I've been in several situations at work where I had to find my own solutions.

How was the initial setup?

The initial setup and installation are pretty straightforward. Let's say 15 minutes to compile the plugin. It would take about half an hour to an hour to set up and deploy.

What's my experience with pricing, setup cost, and licensing?

One problem with Tenable is its pricing policy. Optimal results can be achieved with Greenbone Solutions which has much more friendly pricing policies.

What other advice do I have?

On a scale from one to ten, I would give Tenable Nessus an eight.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Tenable Nessus Report and get advice and tips from experienced pros sharing their opinions.
Updated: June 2025
Product Categories
Vulnerability Management
Buyer's Guide
Download our free Tenable Nessus Report and get advice and tips from experienced pros sharing their opinions.