SecurityScorecard vs Tenable Nessus comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

SecurityScorecard
Average Rating
8.0
Number of Reviews
4
Ranking in other categories
IT Vendor Risk Management (5th)
Tenable Nessus
Average Rating
8.4
Number of Reviews
75
Ranking in other categories
Vulnerability Management (3rd)
 

Mindshare comparison

As of June 2024, in the IT Vendor Risk Management category, the mindshare of SecurityScorecard is 10.6%, up from 9.0% compared to the previous year. The mindshare of Tenable Nessus is 8.7%, up from 1.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
IT Vendor Risk Management
Unique Categories:
No other categories found
Vulnerability Management
21.2%
 

Featured Reviews

Rob Hussey - PeerSpot reviewer
Oct 19, 2023
Helps identify our environment's vulnerabilities
We use SecurityScorecard for reporting.  The solution helps identify our environment's vulnerabilities.  SecurityScorecard's most valuable feature is easy reporting.  The tool needs to have the ability to mitigate vulnerabilities with alternative solutions.  I have been working with the…
AG
Apr 11, 2023
You can customize the tool to scan exactly what you want
My favorite part about Nessus is that you can customize the tool to scan exactly what you want. Microsoft releases new patches monthly on Patch Tuesday, and a lot of companies track that date. I set up Nessus for the day after Patch Tuesday to see which devices have already pushed those updates from Microsoft, so we can stay updated. Tenable stays on top of new IT trends in vulnerability management because there's constant innovation. They keep up with the industry. In the past few years, everything has shifted to cloud-based servers. It's a long-term trend that COVID accelerated. Tenable came out with a tool for that.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"One of its most effective features for risk identification is its enterprise-ready automation for third-party risk measurements."
"With its automated approach, nothing is missed on the IPs your organization is related to."
"The solution helps identify our environment's vulnerabilities."
"I rate the product's initial setup phase a nine on a scale of one to ten, where one is a difficult setup phase, and ten is an easy setup process."
"The solution is great for scanning servers."
"It is easy to deploy and easy to use. Its reporting is good. From this reporting, you can see the pain point in your network, which makes it easy to fix them. It is easy to understand the reports and export them."
"The automatic scanner and scheduler are pretty cool."
"The features of Tenable Nessus that I have found most valuable are its reliability and its ability to collate a dependable output, where we are able to get the same vulnerability when we test manually. The output is quite reliable."
"User friendly and good dashboards."
"The stability is very good."
"The solution is very stable."
"The product's most valuable features are vulnerability and asset management. It can define the rules and validate the configuration."
 

Cons

"The tool needs to have the ability to mitigate vulnerabilities with alternative solutions."
"There could be more information in regards to solving problems like hints on what specifically to look for."
"They could improve the process with a questionnaire module for the product."
"SecurityScorecard's technical team's response time is an area that my company expects to be made faster."
"You can scale Nessus to the extent that you can afford it. You need to have a license for every device you scan. As long as you can afford the increased costs, you won't have a problem scaling it."
"They need more flexible pricing."
"It would be a good idea if they have a simulation of attacks or a use case for finding a new vulnerability or dealing with a zero-day attack."
"The reports should be improved in Tenable Nessus. For example, when you are auditing compliance with CIS standards. It provides very poor reports."
"Tenable Nessus could improve reporting and information sharing. It would be helpful if we could share the reports and have a little bit better flexibility in the reporting of the data."
"Tenable Nessus could improve the reporting by adding some dashboards. The reports are a hassle at this time. Tenable.io has more detailed reports. Having a better dashboard that can show where the vulnerabilities are and be categorized would be helpful. We then could present them to upper management for a deep overview of our network posture which they do not see."
"We use credentialed scans. They need more permissions and more changes or settings on Windows and Linux."
"Technically, it is an excellent and the best solution available in Libya. My only concern is related to its pricing. They are an emerging company in Libya, and they need to put in some effort to provide us with very good prices so that customers can go with the best solution. Chinese companies are getting into the market here, and they're providing very cheap solutions."
 

Pricing and Cost Advice

"The pricing could be split into a lower-paid tier for smaller organizations and another higher tier for others with a more security-focused outlook. $1000 per month is more than some companies pay for their internet connections in total. UPDATE: they have a new 400$ a month tier for starters."
"Even though it's competitive, they offer flexible pricing structures."
"The newer tools are quite pricey. There is a case of some fine tuning that can be done in terms of licensing. The IP based licensing that is offered makes the tool very expensive. If they want the IT industry to adopt it, the price should be looked at."
"In general, it is extremely expensive."
"We incurred a single cost for a perpetual license, although I cannot comment on the price as this is above my management level."
"Our organization is huge so our license costs $30,000."
"The solution has a single price for unlimited assets."
"I would like to see better discounts."
"I rate the product's price seven or eight on a scale of one to ten, where one is low price and ten is high price."
"It has a fair cost and very good cost-benefit ratio."
report
Use our free recommendation engine to learn which IT Vendor Risk Management solutions are best for your needs.
789,135 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
14%
Financial Services Firm
13%
Educational Organization
11%
Manufacturing Company
8%
Educational Organization
35%
Computer Software Company
11%
Government
7%
Financial Services Firm
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

What do you like most about SecurityScorecard?
One of its most effective features for risk identification is its enterprise-ready automation for third-party risk measurements.
What is your experience regarding pricing and costs for SecurityScorecard?
Similar to Barracuda, SecurityScorecard's list price may appear high initially. Even though it's competitive, they offer flexible pricing structures.
What needs improvement with SecurityScorecard?
They could improve the process with a questionnaire module for the product. At present, we have to answer multiple questions for the suppliers manually. They could automate functionality to enhance...
How would you choose between Rapid7 InsightVM and Tenable Nessus?
You have full visibility across cloud, network, virtual, and containerized infrastructures with Rapid7 Insight VM. You can easily prioritize vulnerabilities using attacker analytics. Overall, Rapid...
What's the difference between Tenable Nessus and Tenable.io Vulnerability Management?
Tenable Nessus is a vulnerability assessment solution that is both easy to deploy and easy to manage. The design of the program is such that if a company should desire to handle the installation t...
What do you like most about Tenable Nessus?
We have around 500 virtual machines. Therefore, we conduct monthly scans and open tickets for our developers to address identified vulnerabilities. These scans cover the servers, other network equi...
 

Overview

 

Sample Customers

TriNet, USAA, Zurich, Gilt Groupe, McGraw Hill Financial
Bitbrains, Tesla, Just Eat, Crosskey Banking Solutions, Covenant Health, Youngstown State University
Find out what your peers are saying about RSA, OneTrust, BitSight and others in IT Vendor Risk Management. Updated: June 2024.
789,135 professionals have used our research since 2012.