Try our new research platform with insights from 80,000+ expert users
AdeelAgha - PeerSpot reviewer
Team Lead - Cyber Security & Compliance at a mining and metals company with 1,001-5,000 employees
Real User
Mar 6, 2023
User-friendly, stable, and scalable
Pros and Cons
  • "A new user can easily understand the workflow, even if they are creating users for other divisions and the user is a beginner."
  • "The initial setup is complex and has room for improvement."

What is our primary use case?

We use Rapid7 InsightVM and Tenable.io Vulnerability Management for similar purposes: a vulnerability assessment. At present, Rapid7 InsightVM is running in our IT infrastructure, while Tenable.io is running in our ICS and OT security, which includes our plants, premises, systems, SCADA systems, and PLCs. We usually find more vulnerabilities in these legacy systems, such as Windows XP and Windows 7, than in Rapid7 InsightVM. However, the use cases for vulnerability assessment are the same.

What is most valuable?

The solution is more user-friendly than Rapid7 InsightVM. A new user can easily understand the workflow, even if they are creating users for other divisions and the user is a beginner. They can easily use the system to get the data they need or fulfill their requirements.

What needs improvement?

I believe that Tenable.io is currently the best vulnerability management system. Compared to other vulnerability systems such as Rapid7 InsightVM, I find Tenable.io to be one of the best. However, Tenable.io lacks a platform to exploit or test the vulnerabilities it identifies. For example, if I identify a critical vulnerability, I cannot use Tenable.io to determine the risk of exploitation. Unfortunately, Tenable.io does not have a platform to test this.

The initial setup is complex and has room for improvement.

For how long have I used the solution?

I have been using the solution for five years.

Buyer's Guide
Tenable Vulnerability Management
January 2026
Learn what your peers think about Tenable Vulnerability Management. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,082 professionals have used our research since 2012.

What do I think about the stability of the solution?

The solution is stable.

What do I think about the scalability of the solution?

The solution is scalable.

How are customer service and support?

After deploying Tenable, I spoke with the technical support a maximum of two or three times. They are very knowledgeable and know their stuff well. We always received immediate support from them.

How was the initial setup?

The initial setup can be difficult. We need to configure the case. If we are starting from the beginning, we need to set up each IP range and make sure our firewall covers it. We also need to whitelist the Tenable.io IPs. This initial setup can be challenging.

What's my experience with pricing, setup cost, and licensing?

Compared to other VM solutions, Tenable.io Vulnerability Management is expensive.

What other advice do I have?

I give the solution a nine out of ten.

If we are using the solution for the first time, we should be sure to understand what aspects of the target we are trying to use Tenable.io for, such as what kind of information assets we have, whether they are general devices or specific devices, or if they are deployed in the DMZs. This way, we can ensure that we get the desired results. Therefore, before logging in or implementing Tenable.io for the first time, new users should be sure to have a good understanding of their requirements.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Joao Manso - PeerSpot reviewer
CEO at a tech services company with 11-50 employees
Real User
Top 5
Oct 31, 2024
Efficient risk management enhances asset visibility and security
Pros and Cons
  • "It has greatly impacted us by providing asset visibility."
  • "t needs additional reporting and intelligence features, as well as enhancements in AI-driven detection, which is still in its early stages."

What is our primary use case?

I use it to scan assets to evaluate vulnerabilities, define the risk, and create a resolution process for vulnerability management.

How has it helped my organization?

It has greatly impacted us by providing asset visibility, allowing us to know which assets have higher vulnerabilities and to calculate the risk for them. 

The return on investments is adequate since we need this vulnerability management, and without Tenable, visibility was not possible. It saved us time and improved our security.

What is most valuable?

The most useful feature in managing vulnerabilities is risk management.

What needs improvement?

It needs additional reporting and intelligence features, as well as enhancements in AI-driven detection, which is still in its early stages.

For how long have I used the solution?

I have been working with Tenable Vulnerability Management for six years.

How are customer service and support?

The technical support is fast and efficient, and I am satisfied with it. I would rate their support nine out of ten.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I worked with Qualys before Tenable. I find Tenable to be better due to its broader system coverage, better efficiency on discovery, and better capabilities of analysis.

How was the initial setup?

If you have knowledge of networking and security, the initial setup is easy. If you don't, it can be difficult and you might make dangerous mistakes.

What was our ROI?

The return of investments is good enough as vulnerability management is crucial for us.

What's my experience with pricing, setup cost, and licensing?

The pricing is expensive, and the cost depends on the number of assets. However, the cost is not the most important thing due to the value it provides.

Which other solutions did I evaluate?

I evaluated Qualys before using Tenable.

What other advice do I have?

Small companies might find it difficult because of the knowledge required to drive vulnerability management successfully. If you lack that knowledge, you should contract the service.

I'd rate the solution eight out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
PeerSpot user
Buyer's Guide
Tenable Vulnerability Management
January 2026
Learn what your peers think about Tenable Vulnerability Management. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,082 professionals have used our research since 2012.
Faisal Mian - PeerSpot reviewer
CTO at a tech services company with 51-200 employees
Real User
Top 5Leaderboard
Mar 11, 2024
An easy-to-manage solution to gain visibility into all IPs
Pros and Cons
  • "It is easy to manage. Most of the information the tool provided helped to further investigate the vulnerability and its impact."
  • "The solution’s pricing could be improved."

What is our primary use case?

The product operates on a license-based model, where you purchase a license based on the number of IP addresses you intend to scan. For example, if you purchase a license for 50 IP addresses and your network has 200 users, it will only scan for those 50 IPs. You can gain visibility into all IPs within your environment, including subnets with a full license. Also, you can geographically segment your scanning targets based on the number of IPs allocated for each location.

How has it helped my organization?

The product is very friendly. It is easy to manage. Most of the information the tool provided was correct and helped to further investigate the vulnerability and its impact.

What is most valuable?

The most important feature is network scanning.

What needs improvement?

The solution’s pricing could be improved.

For how long have I used the solution?

I have been using Tenable Vulnerability Management for one year.

What do I think about the stability of the solution?

I rate the solution’s stability an eight out of ten.

What do I think about the scalability of the solution?

The solution is very scalable. It allows you to adjust according to your needs. You can add more features if you wish to purchase additional tools.

How was the initial setup?

The initial setup is very easy. To deploy, run the setup command, and then it can deploy on your Linux and Windows platforms. I did it by myself.

What's my experience with pricing, setup cost, and licensing?

The product is expensive but manageable.

What other advice do I have?

I recommend the solution. Although, it varies from person to person experience. Rapid7 users can use free tools. I'm very satisfied with the product.

Overall, I rate the solution an eight out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Security Manager at a computer software company with 11-50 employees
Real User
Aug 21, 2023
An easy-to-use, mature, stable, and scalable solution for vulnerability assessment
Pros and Cons
  • "Tenable.io Vulnerability Management is an easy-to-use product. I"
  • "The shortcoming of the solution that needs improvement is related to its capability to do vulnerability assessments on applications."

What is our primary use case?

In my company, we use Tenable.io Vulnerability Management is a good solution for vulnerability assessment on the infrastructure and not on the applications. The solution is useful for conducting vulnerability assessments on IT infrastructures. We use Tenable to discover assets on the network and the vulnerabilities in the vulnerability management cycle.

What is most valuable?

Tenable.io Vulnerability Management is an easy-to-use product. It is a good solution, as per Gartner's SIEM Magic Quadrant. The product has a lot of documentation and blogs, so you can get lots of support from its communities while also finding a lot of online materials that can help you improve the solution's uses or implement it according to your use cases.

What needs improvement?

The shortcoming of the solution that needs improvement is related to its capability to do vulnerability assessments on applications.

For how long have I used the solution?

I have been using Tenable.io Vulnerability Management for more than ten years.

What do I think about the stability of the solution?

It is a very stable and mature solution in the market since it has been around for over 15 years.

What do I think about the scalability of the solution?

The product has no scalability solution since it can manage hundreds to thousands of networks.

How are customer service and support?

The solution's technical support is good and quick to respond. If you have a problem, you can be sure that someone from the support team has a solution to your problem.

Which solution did I use previously and why did I switch?

Our company doesn't use any other products from Tenable apart from Tenable Nessus for vulnerability assessment. We also use NetSuite to manage the vulnerabilities' life cycle.

How was the initial setup?

The initial setup of Tenable.io Vulnerability Management was straightforward since it allows one to use a device, like a virtual machine, or one can use it on a public IP address if it is already deployed, making the process very quick and easy.

The solution is deployed on-premises.

The deployment process was very quick since it could be done using a virtual machine or the customer's network. You can do the deployment with the virtual machine by connecting to the management suite before launching the solution.

To do an assessment for all our customers, my company has over 200 users for the deployment and maintenance of the solution. There is a dedicated team in the company I currently work for to manage the solution. One technician is needed to do a vulnerability assessment.

What's my experience with pricing, setup cost, and licensing?

Yearly payments are to be made toward the licensing cost of the product. It is neither a cheap nor an expensive product.

What other advice do I have?

I recommended the solution to those planning to use it since it is a very good product. Though there are other good solutions like Qualys, Tenable is the best.

I rate the overall tool a nine out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
AndréAndrade - PeerSpot reviewer
Senior Cyber Security Consultant at a tech vendor with 10,001+ employees
Vendor
Jun 29, 2023
A stable vulnerability management tool with a good user interface
Pros and Cons
  • "It is a very, very user-friendly tool...The setup is easy"
  • "The only drawback of the solution is that it is expensive."

What is our primary use case?

We actually needed clarity on the vulnerabilities in our infrastructure. We used the solution to scan and make a report for us on what is vulnerable in our infrastructure and what is not, what we can improve and update, and what is good as it is.

What is most valuable?

It is a very, very user-friendly tool. To make some sense, you just need to put in your domain and click a button to scan and give you a piece of customized information about your infrastructure. It is very easy to use to schedule a scan, and it can consume a lot of CPU resources. So, you can schedule a scan between 1 AM to 3 AM, and it works very well for us.

What needs improvement?

I didn't work a lot with the solution. My experience was pretty smooth. I don't have any recommendations for improvement. Maybe it's because I don't use it a lot.

The only drawback of the solution is that it is expensive. The pricing should be kept lower.

For how long have I used the solution?

I have experience with Tenable.io Vulnerability Management. I used it six months ago. I used it for two years. I am a customer of the solution.

What do I think about the stability of the solution?

It is a very stable product.

How was the initial setup?

The setup is easy. Tenable.io Vulnerability Management is known for its ease of setup.

What's my experience with pricing, setup cost, and licensing?

Tenable.io is not known for being a cheap product. You definitely can have another product that could be cheaper than Tenable.io. If you have a real concern with your budget, maybe another platform would be of interest to you.

You can find other tools that are way cheaper, with similarities to Tenable.io. I would say it may not be the same tool, but similar.

What other advice do I have?

The solution's user interface was very good.

It's one of the best tools available for vulnerability management. I would definitely recommend the solution to those planning to use it.

I rate the overall solution a ten out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Security Analyst at a consultancy with 10,001+ employees
Real User
Apr 12, 2023
Great data exportability, stable, and scalable
Pros and Cons
  • "One of the most valuable features of Tenable.io Vulnerability Management is its exportability, which allows us to conduct risk assessments efficiently."
  • "The UI has room for improvement."

What is our primary use case?

We use the solution for our vulnerability management program.

The solution is deployed in the cloud.

How has it helped my organization?

When the logging logic is lacking certain columns, Tenable.io Vulnerability Management provides comprehensive coverage, thereby simplifying the reporting process.

What is most valuable?

One of the most valuable features of Tenable.io Vulnerability Management is its exportability, which allows us to conduct risk assessments efficiently. This feature enables us to prioritize security issues based on their level of importance, without being distracted by other irrelevant details. Additionally, the system is frequently updated to ensure it complies with industry standards.

What needs improvement?

The asset identification has room for improvement. Since we are using a cloud-based scanner, we must scan devices based on their ID. However, we are encountering many issues with reporting. Assets are often being incorrectly merged or we encounter issues related to assets. If we had an agent with a scanning system, this issue may not have occurred, but it currently exists.

The UI has room for improvement. The previous version of the UI was better.

The technical support has room for improvement.

For how long have I used the solution?

I have been using the solution for nine months.

What do I think about the stability of the solution?

The solution is generally stable, although we have experienced two instances in the past where it was down. The first outage was related to the scanner and lasted a few hours, while the second was caused by storage issues that prevented us from clearing the logs.

What do I think about the scalability of the solution?

Scalability depends on our licensing agreement and the number of scanners we use. Currently, the number of scanners and our license allows for scalability up to a certain limit. Beyond that limit, we would need to purchase additional licenses to expand.

How are customer service and support?

The technical support team responds promptly to basic issues. However, when faced with major issues or more complex problems, it can take longer to receive adequate assistance due to a high volume of entries. In such cases, we are required to submit detailed logs, which the support team will analyze before we can proceed to ask further questions.

How would you rate customer service and support?

Negative

What's my experience with pricing, setup cost, and licensing?

Our current license covers 2,500 assets. If we want to add more assets we need to buy another license for another scanner.

What other advice do I have?

I give the solution an eight out of ten.

We have around nine people using the solution.

The necessary maintenance pertains to storage. As it will be hosted on a specific cloud instance, we need to periodically manage the storage when the logs become full. This involves manually logging into the deployment platform and clearing the storage every few months.

The features of Tenable.io Vulnerability Management are impressive, the management system is well-designed, and the scanning options are thorough. Additionally, there are numerous built-in templates available. However, when utilizing the twelve-day scanner, asset identification can become challenging because of the dynamic IP addresses, which the solution struggles to properly identify the devices.

Tenable.io Vulnerability Management is a leading solution for vulnerability management and excels at aggregating information.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Integrator
PeerSpot user
Cyber Security Associate at a consultancy with 10,001+ employees
Real User
Mar 24, 2023
Reliable with good dashboards and customizable templates
Pros and Cons
  • "The initial setup is pretty straightforward."
  • "They need to have more dependable and faster support."

What is our primary use case?

I primarily use the solution in order to scan assets for our clients. 

What is most valuable?

It's very reliable and is a dependable solution. 

The product offers multiple customizable templates. They've released new templates for template scanning. It makes everything a lot easier.

The dashboards are very helpful. They are also quite customizable. 

It's stable.

The solution can scale.

The initial setup is pretty straightforward. 

What needs improvement?

They need to have more dependable and faster support.

We'd like them to add more features surrounding the filtering of vulnerabilities. My understanding is that they are working on this already.

For how long have I used the solution?

I've been using the solution for almost two years. 

What do I think about the stability of the solution?

The solution is stable. I'd rate it eight out nine out of ten. It is reliable. The solution doesn't crash or freeze. There are no bugs or glitches. 

What do I think about the scalability of the solution?

The solution can scale well. I'd rate it eight out of ten. 

We have about 13,000 to 15,000 assets. 

How are customer service and support?

Support is okay. However, we've had issues with them. I've had difficulties raising cases.  They need to be more responsive and need to get back to us faster. 

How would you rate customer service and support?

Neutral

How was the initial setup?

The initial setup is easy. I've had no issues with the setup process. 

What's my experience with pricing, setup cost, and licensing?

I'm not sure what the pricing is. I don't handle licensing.

Which other solutions did I evaluate?

Last year we evaluated it with other solutions. We were looking for a new or additional product to extend our expertise beyond Tenable. We did look into Qualys, among others. 

What other advice do I have?

I'd rate the solution nine out of ten. I'm happy with its capabilities. 

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Yusuf-Hashmi - PeerSpot reviewer
Sr. Director - Group Head - IT Security (CISO) at a manufacturing company with 1,001-5,000 employees
Real User
Mar 15, 2023
The dashboard is pretty intuitive, and it lets you do a drill-down analysis
Pros and Cons
  • "The dashboard is pretty intuitive, and it lets you do a drill-down analysis of each vulnerability. That is something that brings a lot of value to the organization."
  • "Tenable could improve visibility into assets, including automated asset tagging. You should be able to automatically tag assets based on location, function, ownership, etc. That would help us because we spend a lot of time identifying and tagging assets by hand."

What is our primary use case?

Vulnerability Management is used to discover assets and identify vulnerabilities across our IT landscape. 

What is most valuable?

The dashboard is pretty intuitive, and it lets you do a drill-down analysis of each vulnerability. That is something that brings a lot of value to the organization.

What needs improvement?

Tenable could improve visibility into assets, including automated asset tagging. You should be able to automatically tag assets based on location, function, ownership, etc. That would help us because we spend a lot of time identifying and tagging assets by hand. 

For how long have I used the solution?

I have used Vulnerability Management since February 2021.

What do I think about the stability of the solution?

There are factors within the organization that affect stability. Ultimately, your Tenable.io performance depends on your on-prem network infrastructure. 

How are customer service and support?

I haven't used Tenable.io support, but my team has, and I haven't heard any complaints thus far. 

Which solution did I use previously and why did I switch?

I used Qualys at my previous job for vulnerability validation, but I have used Tenable.io VM for quite a while now.  

How was the initial setup?

Deploying Tenable.io VM is neither straightforward nor particularly complex. We run gateways in North America and India, respectively that talk to the Tenable.io console. It's not too complex. It was in place when I joined, but I believe it took no more than two weeks to deploy.

You need to create a tenant in the Tenable Cloud SaaS and configure user access.  We have five analysts using the solution and one or two admins. 

What was our ROI?

We see a return by identifying vulnerabilities and converting them into actionable items. The solution provides a lot of visibility into your environment. 

What's my experience with pricing, setup cost, and licensing?

We pay an annual subscription, and I feel the cost is reasonable. The license covers everything, including support. 

What other advice do I have?

I rate Tenable.io Vulnerability Management nine out of 10. It's an excellent product that's scalable, stable, and intuitive. It helps you to drill down into vulnerabilities.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Tenable Vulnerability Management Report and get advice and tips from experienced pros sharing their opinions.
Updated: January 2026
Buyer's Guide
Download our free Tenable Vulnerability Management Report and get advice and tips from experienced pros sharing their opinions.