No more typing reviews! Try our Samantha, our new voice AI agent.
IT Manager at State of Texas
Real User
Oct 31, 2022
Reliable with good vulnerability management but needs better reporting
Pros and Cons
  • "The initial setup is not complex."
  • "It's a great product, and it brings more value with every improvement in the quarter."
  • "The one drawback that we have found is the reports."
  • "The one drawback that we have found is the reports. We are still getting reports from Tenable.sc since the maturity levels on the reports are lacking."

What is our primary use case?

We can scan manual stuff through Tenable.io. 

We have a great view to create desktops also in Tenable.io.

What is most valuable?

Regarding vulnerability management, the web application scanning is okay. The assist agents are bringing more value to the product by getting the vulnerabilities addressed early with real-time response. This is better, rather than waiting for the scans to run or something like that.

The initial setup is not complex. 

It's a stable product. 

We can scale the solution.

What needs improvement?

The one drawback that we have found is the reports. We are still getting reports from Tenable.sc since the maturity levels on the reports are lacking. They need to improve the reporting in this solution. We just aren't seeing that many features or options.

For how long have I used the solution?

I've used the solution for the past three years. 

Buyer's Guide
Tenable Vulnerability Management
August 2026
Learn what your peers think about Tenable Vulnerability Management. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
913,806 professionals have used our research since 2012.

What do I think about the stability of the solution?

The stability is good. I don't really have any complaints. It doesn't crash or freeze. There are no bugs or glitches. 

What do I think about the scalability of the solution?

The scalability is good. I can't complain about its capabilities. 

We have four people who use it in our team. There may be others using it. However, they wouldn't use it in the same way.

We may increase usage in the future. 

How are customer service and support?

Technical support is good. We have 24/7 support from them. There are some of sales managers who are the bridge between us and support sometimes. 

How was the initial setup?

It's pretty simple to set up the solution. It's not overly complex. 

What's my experience with pricing, setup cost, and licensing?

I don't have the exact cost numbers on tip of my tongue. However, I have some reports that are generated for us every fiscal year. I'm seeing probably around $120,000 spent. That said, I'm not sure of the exact cost for four or five people in our organization.

I'd rate the affordability of the product at a 3.5 out of five. 

What other advice do I have?

It's a great product, and it brings more value with every improvement in the quarter. It's a mature product. Of course, the reporting could be better.

I'd rate the solution seven out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer2293332 - PeerSpot reviewer
IT Manager at a financial services firm with 1,001-5,000 employees
MSP
Oct 20, 2023
An exceptionally stable and scalable solution that helps users find vulnerabilities
Pros and Cons
  • "It is a stable solution. Stability-wise, I rate the solution a ten out of ten."
  • "The reporting was never great in Tenable Vulnerability Management, so, in my company, we imported all the data into Ivanti RiskSense to start using it for reporting."

What is our primary use case?

I was the manager of the vulnerability patching team in my company, and we would use it to go through everything, discover our network, find what vulnerabilities existed, and then use that for a work plan and assignments to decide who would fix what vulnerabilities.

How has it helped my organization?

In my company, with the help of Tenable Vulnerability Management, we could find all the things that we didn't know existed. It would be too resource-intensive to manually go into every device and figure out in which version of a solution the vulnerability exists, which is something that Tenable Vulnerability Management does for you.

What is most valuable?

The solution's most valuable feature is the product's vulnerability database, as it knows what to scan.

What needs improvement?

There is no good work assignment system in the product. Specifically, if an SQL patch needs to be applied, then that needs to go to the SQL team, but Tenable wants to assign the ticket to an individual and not a team.

The reporting was never great in Tenable Vulnerability Management, so, in my company, we imported all the data into Ivanti RiskSense to start using it for reporting.

For how long have I used the solution?

I have been using Tenable Vulnerability Management for three to four years. I don't remember the version of the solution.

What do I think about the stability of the solution?

It is a stable solution. Stability-wise, I rate the solution a ten out of ten.

What do I think about the scalability of the solution?

Scalability-wise, I rate the solution a ten out of ten.

How are customer service and support?

I rate the technical support a seven out of ten.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

I have experience with another solution in the past, but I don't remember its name.

How was the initial setup?

The product's initial setup was very straightforward.

The solution is deployed on an on-premises model and the cloud. With the endpoint in the product, everything was reported back to the cloud offered by Tenable.

What was our ROI?

I saw a return on investment from using the solution since I feel that finding the vulnerabilities is always much cheaper than dealing with a situation after your system gets hacked. In short, I would put it as insurance is cheaper than the fire.

Which other solutions did I evaluate?

In our company, we went through every other tool in the market and came down to Rapid7 and Tenable since they were the only two good options.

What other advice do I have?

Network scans are very resource-intensive and can cause outages in some instances, which is a political and not a technical issue to solve.

I rate the overall tool a ten out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Tenable Vulnerability Management
August 2026
Learn what your peers think about Tenable Vulnerability Management. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
913,806 professionals have used our research since 2012.
AdeelAgha - PeerSpot reviewer
Team Lead - Cyber Security & Compliance at Al Tuwairqi Group
Real User
Mar 6, 2023
User-friendly, stable, and scalable
Pros and Cons
  • "A new user can easily understand the workflow, even if they are creating users for other divisions and the user is a beginner."
  • "The initial setup is complex and has room for improvement."

What is our primary use case?

We use Rapid7 InsightVM and Tenable.io Vulnerability Management for similar purposes: a vulnerability assessment. At present, Rapid7 InsightVM is running in our IT infrastructure, while Tenable.io is running in our ICS and OT security, which includes our plants, premises, systems, SCADA systems, and PLCs. We usually find more vulnerabilities in these legacy systems, such as Windows XP and Windows 7, than in Rapid7 InsightVM. However, the use cases for vulnerability assessment are the same.

What is most valuable?

The solution is more user-friendly than Rapid7 InsightVM. A new user can easily understand the workflow, even if they are creating users for other divisions and the user is a beginner. They can easily use the system to get the data they need or fulfill their requirements.

What needs improvement?

I believe that Tenable.io is currently the best vulnerability management system. Compared to other vulnerability systems such as Rapid7 InsightVM, I find Tenable.io to be one of the best. However, Tenable.io lacks a platform to exploit or test the vulnerabilities it identifies. For example, if I identify a critical vulnerability, I cannot use Tenable.io to determine the risk of exploitation. Unfortunately, Tenable.io does not have a platform to test this.

The initial setup is complex and has room for improvement.

For how long have I used the solution?

I have been using the solution for five years.

What do I think about the stability of the solution?

The solution is stable.

What do I think about the scalability of the solution?

The solution is scalable.

How are customer service and support?

After deploying Tenable, I spoke with the technical support a maximum of two or three times. They are very knowledgeable and know their stuff well. We always received immediate support from them.

How was the initial setup?

The initial setup can be difficult. We need to configure the case. If we are starting from the beginning, we need to set up each IP range and make sure our firewall covers it. We also need to whitelist the Tenable.io IPs. This initial setup can be challenging.

What's my experience with pricing, setup cost, and licensing?

Compared to other VM solutions, Tenable.io Vulnerability Management is expensive.

What other advice do I have?

I give the solution a nine out of ten.

If we are using the solution for the first time, we should be sure to understand what aspects of the target we are trying to use Tenable.io for, such as what kind of information assets we have, whether they are general devices or specific devices, or if they are deployed in the DMZs. This way, we can ensure that we get the desired results. Therefore, before logging in or implementing Tenable.io for the first time, new users should be sure to have a good understanding of their requirements.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Aaron Melendez - PeerSpot reviewer
Cybersecurity Analyst / Third-Party Risk Analyst at San Jacinto Community College
Real User
Dec 7, 2022
Exposure management solution used to scan networks, identify assets and offers mitigation techniques
Pros and Cons
  • "The vulnerability management itself is the most valuable feature as well as references to the mitigation techniques."
  • "The user interface could be improved by being able to change the user interface to fit your position or your job. The graphs are set in stone and you can only print reports."

What is our primary use case?

We use this solution to scan our network to try to identify all our assets. It is very good at finding all assets depending on how you program it.

What is most valuable?

The vulnerability management itself is the most valuable feature as well as references to mitigation techniques.

What needs improvement?

The user interface could be improved by being able to change the user interface to fit your position or your job. The graphs are set in stone and you can only print reports. 

For how long have I used the solution?

I have been using this solution for seven months. 

What do I think about the stability of the solution?

The stability of this solution is good. The application is always available and you can also set the scans to not take up too much bandwidth.

What do I think about the scalability of the solution?

The scalability all depends on how much you want to spend. If you have 10,000 assets you want to scan, you'd have to pay for that. It is very easy to scale up or scale down, but it's going to cost you.

How are customer service and support?

I would rate their support ten out of ten. 

How would you rate customer service and support?

Positive

How was the initial setup?

It has a steep learning curve but Tenable does offer free courses for beginners and paid courses to become a specialist. This assists with the ease of setting it up. 

What's my experience with pricing, setup cost, and licensing?

The total cost we pay for this solution is over 45K. This is for a large education organization. 

What other advice do I have?

I would advise others to take the courses provided and then to play around with the solution. This will speed up learning as this solution has a steep learning curve and can be intimidating at first.

I would rate this solution an eight out of ten due to not being able to change certain parts of the user interface. 

I would rate this solution an eight out of ten. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Faisal Mian - PeerSpot reviewer
CTO at ABM Info. tech
Real User
Mar 11, 2024
An easy-to-manage solution to gain visibility into all IPs
Pros and Cons
  • "It is easy to manage. Most of the information the tool provided helped to further investigate the vulnerability and its impact."
  • "The solution’s pricing could be improved."

What is our primary use case?

The product operates on a license-based model, where you purchase a license based on the number of IP addresses you intend to scan. For example, if you purchase a license for 50 IP addresses and your network has 200 users, it will only scan for those 50 IPs. You can gain visibility into all IPs within your environment, including subnets with a full license. Also, you can geographically segment your scanning targets based on the number of IPs allocated for each location.

How has it helped my organization?

The product is very friendly. It is easy to manage. Most of the information the tool provided was correct and helped to further investigate the vulnerability and its impact.

What is most valuable?

The most important feature is network scanning.

What needs improvement?

The solution’s pricing could be improved.

For how long have I used the solution?

I have been using Tenable Vulnerability Management for one year.

What do I think about the stability of the solution?

I rate the solution’s stability an eight out of ten.

What do I think about the scalability of the solution?

The solution is very scalable. It allows you to adjust according to your needs. You can add more features if you wish to purchase additional tools.

How was the initial setup?

The initial setup is very easy. To deploy, run the setup command, and then it can deploy on your Linux and Windows platforms. I did it by myself.

What's my experience with pricing, setup cost, and licensing?

The product is expensive but manageable.

What other advice do I have?

I recommend the solution. Although, it varies from person to person experience. Rapid7 users can use free tools. I'm very satisfied with the product.

Overall, I rate the solution an eight out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer2298213 - PeerSpot reviewer
Information Security Manager at a international affairs institute with 10,001+ employees
Real User
Oct 31, 2023
An easy-to-use and stable solution that helps organizations to find vulnerabilities in their systems
Pros and Cons
  • "The product is easy to use."
  • "The solution must be promoted more in the market."

What is our primary use case?

We use the tool to find loopholes in the system.

What is most valuable?

The product fulfills our needs. It gives reports and finds vulnerabilities in our system. The product is easy to use. It is easy to integrate the tool with other products.

What needs improvement?

The solution must be promoted more in the market. It will make the customers more aware of the product.

For how long have I used the solution?

My organization has been using the solution for a month.

What do I think about the stability of the solution?

The tool is stable.

What do I think about the scalability of the solution?

Around 20 people use the product in our organization. We have one to three administrators. We are most likely to increase the usage of the product in the future.

How was the initial setup?

It was easy to deploy the solution.

What's my experience with pricing, setup cost, and licensing?

The tool is reasonably priced. There are no additional costs associated with the product.

What other advice do I have?

I have known the product for some time. So, I implemented it. Overall, I rate the solution an eight out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
AndréAndrade - PeerSpot reviewer
Senior Cyber Security Consultant at ATOS
Vendor
Jun 29, 2023
A stable vulnerability management tool with a good user interface
Pros and Cons
  • "It is a very, very user-friendly tool...The setup is easy"
  • "The only drawback of the solution is that it is expensive."

What is our primary use case?

We actually needed clarity on the vulnerabilities in our infrastructure. We used the solution to scan and make a report for us on what is vulnerable in our infrastructure and what is not, what we can improve and update, and what is good as it is.

What is most valuable?

It is a very, very user-friendly tool. To make some sense, you just need to put in your domain and click a button to scan and give you a piece of customized information about your infrastructure. It is very easy to use to schedule a scan, and it can consume a lot of CPU resources. So, you can schedule a scan between 1 AM to 3 AM, and it works very well for us.

What needs improvement?

I didn't work a lot with the solution. My experience was pretty smooth. I don't have any recommendations for improvement. Maybe it's because I don't use it a lot.

The only drawback of the solution is that it is expensive. The pricing should be kept lower.

For how long have I used the solution?

I have experience with Tenable.io Vulnerability Management. I used it six months ago. I used it for two years. I am a customer of the solution.

What do I think about the stability of the solution?

It is a very stable product.

How was the initial setup?

The setup is easy. Tenable.io Vulnerability Management is known for its ease of setup.

What's my experience with pricing, setup cost, and licensing?

Tenable.io is not known for being a cheap product. You definitely can have another product that could be cheaper than Tenable.io. If you have a real concern with your budget, maybe another platform would be of interest to you.

You can find other tools that are way cheaper, with similarities to Tenable.io. I would say it may not be the same tool, but similar.

What other advice do I have?

The solution's user interface was very good.

It's one of the best tools available for vulnerability management. I would definitely recommend the solution to those planning to use it.

I rate the overall solution a ten out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Yusuf-Hashmi - PeerSpot reviewer
Sr. Director - Group Head - IT Security (CISO) at Jubilant Organosys Ltd., India, Leading Chemical M
Real User
Mar 15, 2023
The dashboard is pretty intuitive, and it lets you do a drill-down analysis
Pros and Cons
  • "The dashboard is pretty intuitive, and it lets you do a drill-down analysis of each vulnerability. That is something that brings a lot of value to the organization."
  • "Tenable could improve visibility into assets, including automated asset tagging. You should be able to automatically tag assets based on location, function, ownership, etc. That would help us because we spend a lot of time identifying and tagging assets by hand."

What is our primary use case?

Vulnerability Management is used to discover assets and identify vulnerabilities across our IT landscape. 

What is most valuable?

The dashboard is pretty intuitive, and it lets you do a drill-down analysis of each vulnerability. That is something that brings a lot of value to the organization.

What needs improvement?

Tenable could improve visibility into assets, including automated asset tagging. You should be able to automatically tag assets based on location, function, ownership, etc. That would help us because we spend a lot of time identifying and tagging assets by hand. 

For how long have I used the solution?

I have used Vulnerability Management since February 2021.

What do I think about the stability of the solution?

There are factors within the organization that affect stability. Ultimately, your Tenable.io performance depends on your on-prem network infrastructure. 

How are customer service and support?

I haven't used Tenable.io support, but my team has, and I haven't heard any complaints thus far. 

Which solution did I use previously and why did I switch?

I used Qualys at my previous job for vulnerability validation, but I have used Tenable.io VM for quite a while now.  

How was the initial setup?

Deploying Tenable.io VM is neither straightforward nor particularly complex. We run gateways in North America and India, respectively that talk to the Tenable.io console. It's not too complex. It was in place when I joined, but I believe it took no more than two weeks to deploy.

You need to create a tenant in the Tenable Cloud SaaS and configure user access.  We have five analysts using the solution and one or two admins. 

What was our ROI?

We see a return by identifying vulnerabilities and converting them into actionable items. The solution provides a lot of visibility into your environment. 

What's my experience with pricing, setup cost, and licensing?

We pay an annual subscription, and I feel the cost is reasonable. The license covers everything, including support. 

What other advice do I have?

I rate Tenable.io Vulnerability Management nine out of 10. It's an excellent product that's scalable, stable, and intuitive. It helps you to drill down into vulnerabilities.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
ZafarUddin - PeerSpot reviewer
Technical Lead Information Security at Australian OpCo Pty Ltd.
Real User
Mar 9, 2023
Easy to deploy, simple to maintain, and very user-friendly
Pros and Cons
  • "The interface is fine."
  • "The solution is a bit slow."

What is our primary use case?

Before, they did not have an agent-based solution. Last year, they developed one. For example, before, when users were roaming or working from home, we wouldn't be able to scan previously. Now, we can cover anyone, even off-site. 

What is most valuable?

The most valuable feature is the configuration audit. 

The interface is fine. 

We haven't had issues with support.

The solution is easy to deploy and maintain. 

The solution can scale well.

The entire product is very easy to use. 

What needs improvement?

The solution is a bit slow. It should be faster. They could improve the performance. 

For how long have I used the solution?

We primarily use the solution for vulnerability management and confidential information detection, for example, credit card information. We also use it for configuration management. 

What do I think about the scalability of the solution?

The scalability is great. I'd rate it nine out of ten. A company can expand it if they would like to. 

How are customer service and support?

Technical support is okay. The issue is they don't have a team based in India. Sometimes, it's hard to get support on time. However, they are pretty helpful. 

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We are also using Tenable.sc, version 6.0.

How was the initial setup?

The initial setup is pretty straightforward. I'd rate the process eight out of ten overall. It is not overly complex. 

We can implement the solution in one week in one region. 

In terms of maintenance, we only really need one person. That's enough.

What's my experience with pricing, setup cost, and licensing?

I do not manage the licensing or pricing. My team handles this aspect.

Which other solutions did I evaluate?

We did test multiple other solutions.

What other advice do I have?

I'm an end-user.

This is an agent-based solution. There isn't a specific version we use.

The solution is very user-friendly if you compare it to other tools. I'd rate it eight out of ten. 

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Venugopal Potumudi - PeerSpot reviewer
Senior Consultant at Tata Consultancy
Real User
Nov 15, 2022
Reliable with good scanning and good performance
Pros and Cons
  • "It is quite straightforward to set up."
  • "The product offers good performance, with no bugs or glitches, and it doesn't crash or freeze."
  • "We'd like to see a bit more user-friendliness. They need to work on that aspect of the solution."

What is our primary use case?

The solution is mainly for vulnerability scanning management. It's more like an extension of the Nessus.

What is most valuable?

I like the ten points of scanning. 

The performance is good.

It is quite straightforward to set up.

The solution is stable, and it is quite scalable. 

What needs improvement?

We'd like to see a bit more user-friendliness. They need to work on that aspect of the solution.

For how long have I used the solution?

We've recently adopted the solution and have been dealing with it for just over a year or so.

What do I think about the stability of the solution?

The product offers good performance. There are no bugs or glitches. It doesn't crash or freeze. 

What do I think about the scalability of the solution?

This is a scalable solution. It's easy to expand. 

I'm not sure how many users there are, however, my understanding is there are more than ten people.

How are customer service and support?

We've never had any real difficulties, and therefore we haven't really dealt with support.

How was the initial setup?

The solution is easy to set up. It's straightforward. It's not overly complex. 

It's based on landscape dependencies. However, it's easily deployed. It can take a few weeks to set up. If you are deploying across the globe, it might take longer. 

What was our ROI?

I don't work in an area that would keep track of ROI. I can't say we have been following that.

What's my experience with pricing, setup cost, and licensing?

We pay for an annual license.

If there are extra fees, it depends on what use cases you want to deploy. If you want to use simple vulnerability management and you want to extend it to application scanning, then pricing modules will be different.

What other advice do I have?

I'd recommend the solution to others. 

I would rate the solution nine out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Buyer's Guide
Download our free Tenable Vulnerability Management Report and get advice and tips from experienced pros sharing their opinions.
Updated: August 2026
Buyer's Guide
Download our free Tenable Vulnerability Management Report and get advice and tips from experienced pros sharing their opinions.