No more typing reviews! Try our Samantha, our new voice AI agent.
Real User
Apr 23, 2024
Useful for penetration testing but reporting functionality needs improvement
Pros and Cons
  • "It's a recommended tool for penetration testers because it's effective for that purpose."
  • "The tool's reports are bad. They're not very customizable or flexible. During audits, we often have to exclude things that aren't relevant to our organization, but we can't do that easily with the reports. They come in HTML or PDF format, and we can't compare current results with previous ones in Excel because we never receive reports in Excel."

What needs improvement?

The tool's reports are bad. They're not very customizable or flexible. During audits, we often have to exclude things that aren't relevant to our organization, but we can't do that easily with the reports. They come in HTML or PDF format, and we can't compare current results with previous ones in Excel because we never receive reports in Excel.

For how long have I used the solution?

I have been using the product for a year, and my organization has been using it for six to seven years. 

What do I think about the stability of the solution?

Tenable Vulnerability Management is stable. 

What do I think about the scalability of the solution?

I rate the tool's scalability a seven out of ten. 

Buyer's Guide
Tenable Vulnerability Management
August 2026
Learn what your peers think about Tenable Vulnerability Management. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
913,924 professionals have used our research since 2012.

How are customer service and support?

The solution's support is okay, but it could be more customer-friendly. The people providing support have knowledge, but they could improve customer interaction.

How was the initial setup?

The tool's deployment can be challenging, especially for those unfamiliar with Kali Linux, as it operates on this platform. This might make the setup process difficult for users accustomed to other operating systems like Windows. It may take a couple of tries to get comfortable with the process. However, once you have set it up a few times, it becomes easier.

What other advice do I have?

Sometimes, we use the tool for tasks like configuration and running scans. However, it's a bit difficult to use compared to Qualys. One issue we've noticed is that it takes up a lot of space, which customers often complain about. They promised more system coverage and updates, but it isn't happening.

I rate Tenable Vulnerability Management a seven out of ten. It might be challenging if you're used to working on Windows. However, it's a recommended tool for penetration testers because it's effective for that purpose.

We use it for audit and PT. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Security engineer at a construction company with 1,001-5,000 employees
Real User
Oct 27, 2023
Has a valuable remediation feature, but it could be easier to set up on the cloud
Pros and Cons
  • "It helps us create remediation projects and assign the console’s responsibility to specific engineers."
  • "The product could be easier to set up on the cloud."

What is our primary use case?

We use the software to manage vulnerabilities in our environment.

What is most valuable?

The product’s most valuable feature is remediation. It shows a list of vulnerabilities per server once you scan on cloud or on-premise instances. It helps us create remediation projects and assign the console’s responsibility to specific engineers. We can set up a follow-up date depending on the organization's requirements.

What needs improvement?

The product could be easier to set up on the cloud.

For how long have I used the solution?

We have been using Tenable Vulnerability Management for three years.

What do I think about the stability of the solution?

I rate the platform's stability an eight out of ten. Once, a few of our subsidiaries complained that channel usage in the environment was consuming bandwidth.

What do I think about the scalability of the solution?

We have five admins using Tenable Vulnerability Management in our organization. I rate the product’s scalability a seven out of ten. It has many features, and it is complicated to train someone on how to use Tenable. You have to schedule a session every day for almost two weeks for it.

How are customer service and support?

It was challenging to contact the technical support team earlier. However, we have found the right contact and can reach out to them easily.'

Which solution did I use previously and why did I switch?

I have used open-source applications before.

How was the initial setup?

The product is complicated to set up on AWS. However, it is easy to implement on-premises. It involves discovering IP addresses and schedule scanning. It requires acquiring some knowledge about the process to familiarize yourself with the AWS environment. We have to complete the setup for the whole environment. The deployment for a vast environment involves migrating a lot of data from on-premise to the cloud.

What about the implementation team?

We execute the implementation for most of the tools in-house. We take help from third-party vendors for the rest of it.

What other advice do I have?

I rate Tenable Vulnerability Management a nine out of ten. I advise you to choose Tenable.iO as it is a cloud-based solution.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Tenable Vulnerability Management
August 2026
Learn what your peers think about Tenable Vulnerability Management. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
913,924 professionals have used our research since 2012.
Security Manager at Yarix S.r.l.
Real User
Aug 21, 2023
An easy-to-use, mature, stable, and scalable solution for vulnerability assessment
Pros and Cons
  • "Tenable.io Vulnerability Management is an easy-to-use product. I"
  • "The shortcoming of the solution that needs improvement is related to its capability to do vulnerability assessments on applications."

What is our primary use case?

In my company, we use Tenable.io Vulnerability Management is a good solution for vulnerability assessment on the infrastructure and not on the applications. The solution is useful for conducting vulnerability assessments on IT infrastructures. We use Tenable to discover assets on the network and the vulnerabilities in the vulnerability management cycle.

What is most valuable?

Tenable.io Vulnerability Management is an easy-to-use product. It is a good solution, as per Gartner's SIEM Magic Quadrant. The product has a lot of documentation and blogs, so you can get lots of support from its communities while also finding a lot of online materials that can help you improve the solution's uses or implement it according to your use cases.

What needs improvement?

The shortcoming of the solution that needs improvement is related to its capability to do vulnerability assessments on applications.

For how long have I used the solution?

I have been using Tenable.io Vulnerability Management for more than ten years.

What do I think about the stability of the solution?

It is a very stable and mature solution in the market since it has been around for over 15 years.

What do I think about the scalability of the solution?

The product has no scalability solution since it can manage hundreds to thousands of networks.

How are customer service and support?

The solution's technical support is good and quick to respond. If you have a problem, you can be sure that someone from the support team has a solution to your problem.

Which solution did I use previously and why did I switch?

Our company doesn't use any other products from Tenable apart from Tenable Nessus for vulnerability assessment. We also use NetSuite to manage the vulnerabilities' life cycle.

How was the initial setup?

The initial setup of Tenable.io Vulnerability Management was straightforward since it allows one to use a device, like a virtual machine, or one can use it on a public IP address if it is already deployed, making the process very quick and easy.

The solution is deployed on-premises.

The deployment process was very quick since it could be done using a virtual machine or the customer's network. You can do the deployment with the virtual machine by connecting to the management suite before launching the solution.

To do an assessment for all our customers, my company has over 200 users for the deployment and maintenance of the solution. There is a dedicated team in the company I currently work for to manage the solution. One technician is needed to do a vulnerability assessment.

What's my experience with pricing, setup cost, and licensing?

Yearly payments are to be made toward the licensing cost of the product. It is neither a cheap nor an expensive product.

What other advice do I have?

I recommended the solution to those planning to use it since it is a very good product. Though there are other good solutions like Qualys, Tenable is the best.

I rate the overall tool a nine out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Director Information Security at Chup
Real User
Jul 11, 2023
A stable and user-friendly solution that is easy to setup
Pros and Cons
  • "The solution is quite friendly."
  • "Users get confused between VPR and CVSS ratings."

What is most valuable?

The solution is quite friendly. 

What needs improvement?

Users get confused between VPR and CVSS ratings. 

What do I think about the stability of the solution?

I would rate the tool's stability an eight out of ten. 

What do I think about the scalability of the solution?

I would rate the solution's scalability an eight out of ten. We have around 1000 users for the product. We plan to increase the tool's usage in the future. 

Which solution did I use previously and why did I switch?

I have used Nessus before Tenable. We switched to Tenable since it covered the problem for us. 

How was the initial setup?

The product's setup is very easy and the deployment took six months to complete. 

What about the implementation team?

We relied on a third-party vendor to complete the tool's deployment. 

What other advice do I have?

The tool is easy to use and user-friendly and I would rate it an eight out of ten. 

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Security Analyst at a consultancy with 10,001+ employees
Real User
Top 20
Apr 12, 2023
Great data exportability, stable, and scalable
Pros and Cons
  • "One of the most valuable features of Tenable.io Vulnerability Management is its exportability, which allows us to conduct risk assessments efficiently."
  • "The UI has room for improvement."

What is our primary use case?

We use the solution for our vulnerability management program.

The solution is deployed in the cloud.

How has it helped my organization?

When the logging logic is lacking certain columns, Tenable.io Vulnerability Management provides comprehensive coverage, thereby simplifying the reporting process.

What is most valuable?

One of the most valuable features of Tenable.io Vulnerability Management is its exportability, which allows us to conduct risk assessments efficiently. This feature enables us to prioritize security issues based on their level of importance, without being distracted by other irrelevant details. Additionally, the system is frequently updated to ensure it complies with industry standards.

What needs improvement?

The asset identification has room for improvement. Since we are using a cloud-based scanner, we must scan devices based on their ID. However, we are encountering many issues with reporting. Assets are often being incorrectly merged or we encounter issues related to assets. If we had an agent with a scanning system, this issue may not have occurred, but it currently exists.

The UI has room for improvement. The previous version of the UI was better.

The technical support has room for improvement.

For how long have I used the solution?

I have been using the solution for nine months.

What do I think about the stability of the solution?

The solution is generally stable, although we have experienced two instances in the past where it was down. The first outage was related to the scanner and lasted a few hours, while the second was caused by storage issues that prevented us from clearing the logs.

What do I think about the scalability of the solution?

Scalability depends on our licensing agreement and the number of scanners we use. Currently, the number of scanners and our license allows for scalability up to a certain limit. Beyond that limit, we would need to purchase additional licenses to expand.

How are customer service and support?

The technical support team responds promptly to basic issues. However, when faced with major issues or more complex problems, it can take longer to receive adequate assistance due to a high volume of entries. In such cases, we are required to submit detailed logs, which the support team will analyze before we can proceed to ask further questions.

How would you rate customer service and support?

Negative

What's my experience with pricing, setup cost, and licensing?

Our current license covers 2,500 assets. If we want to add more assets we need to buy another license for another scanner.

What other advice do I have?

I give the solution an eight out of ten.

We have around nine people using the solution.

The necessary maintenance pertains to storage. As it will be hosted on a specific cloud instance, we need to periodically manage the storage when the logs become full. This involves manually logging into the deployment platform and clearing the storage every few months.

The features of Tenable.io Vulnerability Management are impressive, the management system is well-designed, and the scanning options are thorough. Additionally, there are numerous built-in templates available. However, when utilizing the twelve-day scanner, asset identification can become challenging because of the dynamic IP addresses, which the solution struggles to properly identify the devices.

Tenable.io Vulnerability Management is a leading solution for vulnerability management and excels at aggregating information.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Integrator
PeerSpot user
Cyber Security Associate at a consultancy with 10,001+ employees
Real User
Mar 24, 2023
Reliable with good dashboards and customizable templates
Pros and Cons
  • "The initial setup is pretty straightforward."
  • "They need to have more dependable and faster support."

What is our primary use case?

I primarily use the solution in order to scan assets for our clients. 

What is most valuable?

It's very reliable and is a dependable solution. 

The product offers multiple customizable templates. They've released new templates for template scanning. It makes everything a lot easier.

The dashboards are very helpful. They are also quite customizable. 

It's stable.

The solution can scale.

The initial setup is pretty straightforward. 

What needs improvement?

They need to have more dependable and faster support.

We'd like them to add more features surrounding the filtering of vulnerabilities. My understanding is that they are working on this already.

For how long have I used the solution?

I've been using the solution for almost two years. 

What do I think about the stability of the solution?

The solution is stable. I'd rate it eight out nine out of ten. It is reliable. The solution doesn't crash or freeze. There are no bugs or glitches. 

What do I think about the scalability of the solution?

The solution can scale well. I'd rate it eight out of ten. 

We have about 13,000 to 15,000 assets. 

How are customer service and support?

Support is okay. However, we've had issues with them. I've had difficulties raising cases.  They need to be more responsive and need to get back to us faster. 

How would you rate customer service and support?

Neutral

How was the initial setup?

The initial setup is easy. I've had no issues with the setup process. 

What's my experience with pricing, setup cost, and licensing?

I'm not sure what the pricing is. I don't handle licensing.

Which other solutions did I evaluate?

Last year we evaluated it with other solutions. We were looking for a new or additional product to extend our expertise beyond Tenable. We did look into Qualys, among others. 

What other advice do I have?

I'd rate the solution nine out of ten. I'm happy with its capabilities. 

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Executive Director at Platview Technologies
Real User
Nov 25, 2022
Satisfies the requirement for vulnerability assessments and has a comprehensive database
Pros and Cons
  • "The ease of use in terms of scanning assets is valuable."
  • "The ease of use in terms of scanning assets is valuable, and it has a diverse checklist when it comes to vulnerability databases."
  • "More flexibility is required compared to other solutions."
  • "The response times from the customer service and support team could be improved."

What is our primary use case?

Our primary use case for this solution is to satisfy the requirement for vulnerability assessments regarding internal assets, CPI assets and web applications. We deploy the solution on private cloud.

What is most valuable?

The ease of use in terms of scanning assets is valuable, and it has a diverse checklist when it comes to vulnerability databases. Hence, it has a comprehensive database for exploits and vulnerabilities, which is why we continue using it.

What needs improvement?

The response times from the customer service and support team could be improved. Additionally, the pricing could be better.

For how long have I used the solution?

We have been using the solution for approximately four years.

What do I think about the stability of the solution?

The solution is stable.

What do I think about the scalability of the solution?

The solution is scalable, and we currently have 15 users utilizing it.

How are customer service and support?

The response times of customer service and support can be faster. I rate them a six out of ten.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

We previously used different solutions but chose to switch because of the flexibility regarding cloud.

How was the initial setup?

The initial setup is straightforward, and it took a couple of hours.

What about the implementation team?

We implemented the solution in-house.

What's my experience with pricing, setup cost, and licensing?

Licensing is approximately $6,000 annually.

What other advice do I have?

I rate the solution an eight out of ten. The solution is good, but pricing, support and flexibility can be improved.

Disclosure: My company has a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1248330 - PeerSpot reviewer
Security Specialist at a security firm with 51-200 employees
Real User
Nov 20, 2022
Easy to set up with lots of great features and continuous investment in developing the product
Pros and Cons
  • "The initial setup is mostly straightforward."
  • "The product has many features and continues to develop its capabilities at a rapid pace."
  • "I'd like to see them improve their support."
  • "They need a better approach to support. When I have hard questions that need answers to, I prefer to jump to L3 support instead of getting pushed to L1."

What is our primary use case?

I primarily implement the solution for clients. It's mostly used for security purposes. 

What is most valuable?

The product has many features and continues to develop its capabilities at a rapid pace. 

It's done a lot of acquisitions and has really built out its cloud functionality. They're doing a good job of building out their cloud security.

The initial setup is mostly straightforward. 

The solution is stable. 

It can scale as necessary.

What needs improvement?

I'd like to see them improve their support.

It would be great if there was more integration with other third-party products. They have a robust API, so it's possible to write a script in Python and extend or integrate with another solution, however, will be great if they had this integration automatically.

For how long have I used the solution?

I've been dealing with the solution for three or four years. 

What do I think about the stability of the solution?

The solution is stable. I haven't had any issues. There are no bugs or glitches. It doesn't crash or freeze. We use AWS infrastructure and find it to be very reliable. 

What do I think about the scalability of the solution?

The general scalability is pretty good. It's easy to add on. We haven't had an issue with expansion. 

At this point in time, I'm not sure if our clients intend to increase usage. 

How are customer service and support?

They need a better approach to support. When I have hard questions that need answers to, I prefer to jump to L3 support instead of getting pushed to L1. It's not solving my problems fast enough.

Which solution did I use previously and why did I switch?

I've deployed Tenable.sc and other Tenable products. I've also dealt with FireEye.

How was the initial setup?

I've been implementing the solution for four years. Therefore, I do not find it to be a difficult process. In general, it is easy to deploy, however, it depends on the client. If they are cooperative, it is easier. 

We need at least one person for deployment and maintenance. 

What's my experience with pricing, setup cost, and licensing?

I can't speak to the exact cost of the solution. 

There may be some features that we have to pay for that are extra. However, when someone wants to use Tenable.io only for vulnerability scanning and vulnerability management, there is no hidden cost.

Which other solutions did I evaluate?

We are partners with Tenable and therefore tend to lean towards their products more than others. 

What other advice do I have?

We're partners. I mainly implement the solution. 

I work with a variety of different versions. I use the whole Tenable portfolio.

I'd rate the solution eight out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: My company has a business relationship with this vendor other than being a customer. partner
PeerSpot user
Senior Information Security Engineer at a consultancy with 5,001-10,000 employees
Real User
Sep 25, 2022
An easy-to-use solution with smooth configuration and broad scalability
Pros and Cons
  • "The solution is easy to use and configuration is smooth with no complexities."
  • "The solution creates vulnerability tickets within the VM profile but should also include them under the Remediation tab so the fixes can be viewed in the ticketing queue."
  • "Technical support requires constant follow up and that is an issue. I rate support a two out of ten."

What is our primary use case?

Our company has 25 technicians who use the solution to scan firewalls and produce scheduled compliance reports for various environments.

What is most valuable?

The solution is easy to use and configuration is smooth with no complexities.

The solution is one of the best tools in the market for vulnerability management and remediation. It functions exactly as we desire.

What needs improvement?

The solution creates vulnerability tickets within the VM profile but should also include them under the Remediation tab so the fixes can be viewed in the ticketing queue. 

Qualys is a competitor product and handles vulnerability tickets in this comprehensive manner. 

For how long have I used the solution?

I have been using the solution for two years. 

What do I think about the stability of the solution?

The solution is stable and I have only experienced hangs a few times. 

What do I think about the scalability of the solution?

The solution is accessible from the private cloud so it is scalable to any needs. 

How are customer service and support?

Technical support requires constant follow up and that is an issue. Once they are made aware of an issue, it takes time for them to find a resolution. I currently have three cases and have been waiting so long for updates that I have asked for escalation.

Support provided by Qualys is better because they work with you right away to resolve issues. 

I rate support a two out of ten. 

How would you rate customer service and support?

Negative

How was the initial setup?

The initial setup is straightforward and not hard to understand if you have worked with other solutions. 

We experienced an authentication issue when the NetApp scanner was trying to log in to the system and firewall, but we modified the setting and the issue was resolved. 

What about the implementation team?

We deployed the solution ourselves and the complexity depends on each environment. 

For example, our company has AWS, Azure, and on-premise data center environments. Our infrastructure team builds a list of assets and then our technicians deploy the solution to conduct scans. 

What's my experience with pricing, setup cost, and licensing?

The annual license is a bit costly but the solution is worth it. 

Which other solutions did I evaluate?

We also use Qualys and like how it handles vulnerability tickets. 

We moved to the solution because Qualys does not support Cisco Secure Firewalls and that is a requirement in our environment. 

What other advice do I have?

While Qualys offers dual locations for vulnerability tickets, it is not difficult to use API calls to integrate the solution with ServiceNow for assigning mitigation. 

Many companies use third-party tools like Jira to integrate things so it is not unusual. I do believe Tenable is working on an internal solution that will be available in the future.  

I rate the solution an eight out of ten. 

Which deployment model are you using for this solution?

Private Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Prajot Nair - PeerSpot reviewer
Senior Manager -Cloud Security at Capgemini
Real User
Jul 22, 2022
Full-service solution that gives a good ROI
Pros and Cons
  • "The initial setup is straightforward so long as your infrastructure, components, and networks are in place."
  • "Tenable.io Vulnerability Management gives a good ROI in the long run, though it would be better with a pay-as-you-go model."
  • "Tenable.io Vulnerability Management could be improved with an increased number of dashboards and MSSP integration."
  • "Tenable is a full-service product, but it still has a lot of improvements to make, so I'd recommend exploring other products before implementing it."

What is our primary use case?

Tenable.io Vulnerability Management is used as a unified platform for vulnerability management.

What needs improvement?

Tenable.io Vulnerability Management could be improved with an increased number of dashboards and MSSP integration.

For how long have I used the solution?

I've been working with Tenable.io Vulnerability Management for five years.

What do I think about the stability of the solution?

Tenable.io Vulnerability Management is stable.

What do I think about the scalability of the solution?

Tenable.io Vulnerability Management is scalable.

How are customer service and support?

Tenable doesn't provide support beyond documentation.

How would you rate customer service and support?

Neutral

How was the initial setup?

The initial setup is straightforward so long as your infrastructure, components, and networks are in place. There are also a few teaching issues post-migration, like integration with third parties and SEO integrations.

What was our ROI?

Tenable.io Vulnerability Management gives a good ROI in the long run, though it would be better with a pay-as-you-go model.

What's my experience with pricing, setup cost, and licensing?

Tenable.io Vulnerability Management's pricing solution model isn't great. Providing a pay-as-you-go option would be an improvement.

What other advice do I have?

Tenable is a full-service product, but it still has a lot of improvements to make, so I'd recommend exploring other products before implementing it. I would give Tenable.io Vulnerability Management a rating of nine out of ten.

Which deployment model are you using for this solution?

Private Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Tenable Vulnerability Management Report and get advice and tips from experienced pros sharing their opinions.
Updated: August 2026
Buyer's Guide
Download our free Tenable Vulnerability Management Report and get advice and tips from experienced pros sharing their opinions.