Tenable.io is a great package that takes the powerful Nessus scanner and adds a web-based front end to it that provides a wealth of information about your vulnerabilities and assets. Having full access to the data in a dashboard makes searching it easy. Roles within the system allow for access and role-based controls for viewing or running scans. Their support is fast and knowledgable. IO also has Nessus Network Monitor which is a great tool for being able to find IoT or MIoT devices the scanner may have ignored (due to scan settings - another plus). Tenable also provides it's own severity ratings which don't dismiss the CVSS, but provide a more realistic view of the severity in the CVE vs real-world exploitation. Review collected by and hosted on G2.com.
The only thing I dislike may not actually be an issue with Tenable.io itself. I wish they'd add a Meraki hook for credentialed scans. Currently, we can use SMNP just fine though. Review collected by and hosted on G2.com.
Video Reviews
109 out of 110 Total Reviews for Tenable Vulnerability Management
Overall Review Sentiment for Tenable Vulnerability Management
Log in to view review sentiment.
The easy to use interface makes exploring known and discovered vulnerabilities fairly painless. The fact that the solution to exploits is listed right next to the vulnerability overview, it makes remediation a lot easier.
The number of plugins covers a wide variety of systems and possible exploits.
SAML / SCIM integration is another plus and was fairly easy to setup.
Implementation of scanning via its Nessus agents was a breeze. Review collected by and hosted on G2.com.
The plugin manager could use some work. There are often several plugins that do the same thing or just plugins that do not provide the functionality that they claim.
Additionally, some of the exploits that are not exploitable and can cause false positives. For example if I have a HTTPS exploit on a version of a router / switches firmware, but HTTPS management is turned off and only SSH management is used, then that exploit does not need to be listed as high. Review collected by and hosted on G2.com.
Tenable Vulnerability Management not only identifies issues, but also helps teams prioritize the most critical vulnerabilities, optimizing time and resources while strengthening the organization's security posture. Review collected by and hosted on G2.com.
Tenable Vulnerability Management is a robust solution, but the cost, dependency on connectivity, and challenges in larger networks can be points to consider before adoption, especially for smaller organizations or those with limited resources. Review collected by and hosted on G2.com.
Fast plugin updates for detecting new vulnerabilities in the environment. You can scan devices through an agent, with credentials or without. Useful for printers, and network equipment to see your full exposure. Review collected by and hosted on G2.com.
At times agents fail their agent update, lose their connection, then dropped from the system. Some times the remediation information is lacking leaving you unsure how to correct non-standard vulnerabilities.
Support has not been good from our account manager to those higher up. I had issues with our VAR not receiving the renewal notification and services were shut off. It took them nearly 3 weeks to figure out their backend to restore services. Review collected by and hosted on G2.com.
Pros:
Intuitive, user-friendly interface
Accurate and comprehensive asset discovery
Strong risk-based prioritization
Automated, continuous scanning
Flexible reporting and robust integration capabilities Review collected by and hosted on G2.com.
Cons:
Can be costly for smaller businesses
May require a learning curve for new users
Some users report longer scan times for larger environments Review collected by and hosted on G2.com.
Tenable Vulnerability Management makes it easy to keep vulnerabilities organised and easily reference how to remediate them. Review collected by and hosted on G2.com.
The feature rich solution does not lend itself to many short comings. Review collected by and hosted on G2.com.
Excellent coverage across various systems and networks, ease of use, intuitive dashboard, automated scanning, simplifies operations. Review collected by and hosted on G2.com.
Performance slowdowns during large-scale scans, initial setup and configuration a bit complex, the reporting feature, price. Review collected by and hosted on G2.com.

Scheduleling the scans is very helpful in that you can then have those results sent to your email. Report fatigue and email fatigue are real things but with the simplified email at a quick glance you can tell if you need to dive deeper or just review at the standard time. Review collected by and hosted on G2.com.
They could be better about some of the mitigation information, I understand that it must be a huge task but would be really helpful to have. Review collected by and hosted on G2.com.
I have been using this tool for a Long time and they were developing new features like vulnerability intelligence which helps us make a successful vulnerability management program. Integration with ServiceNow helps us in getting the results better. Review collected by and hosted on G2.com.
The support team should give a proper response. This needs to be improved. Review collected by and hosted on G2.com.

the robust cuantity of options the high speed when it comes to find vulnerabilities Review collected by and hosted on G2.com.
the price and also sometimes as little companies I can feel a bit overprices. learning curve is a bit high also Review collected by and hosted on G2.com.
What I like best is the organization in creating templates for scanning vulnerabilities and the way the reports are generated for the threats found, I used it daily to perform vulnerability assessments. Review collected by and hosted on G2.com.
I can't find anything that I dislike about the platform right now. Review collected by and hosted on G2.com.