SecurityScorecard vs Tenable Vulnerability Management comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

SecurityScorecard
Average Rating
8.0
Number of Reviews
4
Ranking in other categories
IT Vendor Risk Management (5th)
Tenable Vulnerability Manag...
Average Rating
8.2
Number of Reviews
39
Ranking in other categories
Vulnerability Management (2nd), Risk-Based Vulnerability Management (2nd)
 

Mindshare comparison

As of June 2024, in the IT Vendor Risk Management category, the mindshare of SecurityScorecard is 10.6%, up from 9.0% compared to the previous year. The mindshare of Tenable Vulnerability Management is 6.1%, up from 0.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
IT Vendor Risk Management
Unique Categories:
No other categories found
Vulnerability Management
11.5%
Risk-Based Vulnerability Management
21.4%
 

Featured Reviews

Rob Hussey - PeerSpot reviewer
Oct 19, 2023
Helps identify our environment's vulnerabilities
We use SecurityScorecard for reporting.  The solution helps identify our environment's vulnerabilities.  SecurityScorecard's most valuable feature is easy reporting.  The tool needs to have the ability to mitigate vulnerabilities with alternative solutions.  I have been working with the…
SC
May 29, 2023
Though it is scalable and has an easy setup phase in place, the solution is an expensive one
I would like the solution to cover the whole cycle of mitigation since it's an area where the solution currently lacks. Nessus was created and, like, covered afterward. All the system is built around a basic unit that is mitigation, not the vulnerabilities. You don't have all the vulnerabilities where you build all the processes and all the reports that you have around it. Vulnerability is not like you have this problem. They say to you. Basically, you have a problem, but you don't have the patch. And the patch, inside of it, you have fifteen vulnerabilities, and it appears as a vulnerability. You are missing a patch, but it's not a vulnerability. All the system is built around missing mitigation. As a basic unit that everything is built around, and so this part is what you see when you do reports or when you build dashboards, and you have several databases inside that you can build reports around, but it's all beautiful, and you have a lot of reports, right, out of the box. But when you start creating something that you really need, like a new report, then you're, like, this data is in this database or downloaded database and this in another database of mitigations, and hence they cannot easily be connected, so each report can be all around this database because they have, like, two, three databases. I don't remember exactly, but they have separate databases inside, and you need to build the reports around one database, and it's not easy to connect two databases into one meaningful report. So, this is a hard part. In short, I would like to see the databases seamlessly connected while doing a report. The tool is okay, but, like I said, to cover the whole cycle and is like connecting the unconnectable things because they are built this way which I don't think they can change right now. They can add things like brand reputation monitoring because it's the system that needs to identify all the vulnerabilities and infrastructure vulnerabilities. They can take it to add code vulnerabilities, like, if it's an R&D company that creates software, they have vulnerabilities of other types, like application-level vulnerabilities in the things that they are developing. And if it's a cloud, then it needs to be covered in a good way, considering the cloud infrastructure. Also, it works on the IP level. On the cloud, you can do it around EC2 instances. You can do the same in Tenable.io but then all the part of the cloud layer that is cloud-based but not on the EC2 level. Let's say it's CloudWatch logs and all the con configurations that are at a cloud provider level. So, there can be vulnerabilities there not at the EC2 level of the machine itself. So these are also vulnerabilities, and it can be good if they are shown and covered by the system. In general, brand reputation and external CTI are needed in the solution. Somewhere outside in the open world that it was bridged, and it's there, and then maybe we can show it to you also that it was bridged. So it's now in the open world, and they don't want to be, you know, to be the open world and also on the external attack surface, but I think we saw that some module that they are doing that is in just the right direction. So, it's a good direction.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"With its automated approach, nothing is missed on the IPs your organization is related to."
"The solution helps identify our environment's vulnerabilities."
"One of its most effective features for risk identification is its enterprise-ready automation for third-party risk measurements."
"I rate the product's initial setup phase a nine on a scale of one to ten, where one is a difficult setup phase, and ten is an easy setup process."
"The solution's most valuable feature is providing a single pane of visibility on all the infrastructure and its status."
"The solution creates vulnerability tickets within the VM profile but should also include them under the Remediation tab so the fixes can be viewed in the ticketing queue."
"Tenable.io, in particular, is quite a powerful product. It looks at your traditional environment, which is pretty much anything that is on-premises, and it also goes a step ahead and covers your modern assets, which is anything that is currently sitting in the cloud. You get complete visibility of your entire environment and tech operation. The ability to give you visibility across the entire tech surface is one of the biggest advantages that Tenable.io has."
"One of the most valuable features of Tenable.io Vulnerability Management is its exportability, which allows us to conduct risk assessments efficiently."
"Technical support has been good. They respond quite quickly."
"You can customize each point in new scans."
"Tenable.io Vulnerability Management is an easy-to-use product. I"
"The price of Tenable.io Vulnerability Management is reasonable as it is ten times cheaper than other options."
 

Cons

"SecurityScorecard's technical team's response time is an area that my company expects to be made faster."
"They could improve the process with a questionnaire module for the product."
"The tool needs to have the ability to mitigate vulnerabilities with alternative solutions."
"There could be more information in regards to solving problems like hints on what specifically to look for."
"Tenable could improve visibility into assets, including automated asset tagging. You should be able to automatically tag assets based on location, function, ownership, etc. That would help us because we spend a lot of time identifying and tagging assets by hand."
"The solution’s pricing could be improved."
"I'm not satisfied with the reporting structure."
"It would be helpful if Tenable could be more clear with regard to everything the solution can and cannot do with the particular license that you have."
"Users get confused between VPR and CVSS ratings."
"The solution seems to focus too much on enterprises, and they really need a product that works for SMBs."
"I would like the solution to cover the whole cycle of mitigation since it's an area where the solution currently lacks."
"I don't recommend Tenable.io Vulnerability Management for web scanning"
 

Pricing and Cost Advice

"The pricing could be split into a lower-paid tier for smaller organizations and another higher tier for others with a more security-focused outlook. $1000 per month is more than some companies pay for their internet connections in total. UPDATE: they have a new 400$ a month tier for starters."
"Even though it's competitive, they offer flexible pricing structures."
"On a scale of one to ten, where one is low, and ten is high price, I rate the pricing an eight. So, it is a pretty expensive solution."
"I would rate the pricing a five out of ten. It is in the middle."
"Yearly payments are to be made toward the licensing cost of the product. It is neither a cheap nor an expensive product."
"The tool is reasonably priced."
"The cost is determined by the number of endpoints, which is approximately one dollar per endpoint."
"A yearly payment has to be made toward the solution's licensing costs."
"Tenable.io Vulnerability Management's pricing solution model isn't great."
"The product costs us around $137,000 annually for 4000 to 5000 assets."
report
Use our free recommendation engine to learn which IT Vendor Risk Management solutions are best for your needs.
787,779 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
14%
Financial Services Firm
13%
Educational Organization
11%
Manufacturing Company
8%
Educational Organization
25%
Computer Software Company
12%
Government
9%
Financial Services Firm
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

What do you like most about SecurityScorecard?
One of its most effective features for risk identification is its enterprise-ready automation for third-party risk measurements.
What is your experience regarding pricing and costs for SecurityScorecard?
Similar to Barracuda, SecurityScorecard's list price may appear high initially. Even though it's competitive, they offer flexible pricing structures.
What needs improvement with SecurityScorecard?
They could improve the process with a questionnaire module for the product. At present, we have to answer multiple questions for the suppliers manually. They could automate functionality to enhance...
What's the difference between Tenable Nessus and Tenable.io Vulnerability Management?
Tenable Nessus is a vulnerability assessment solution that is both easy to deploy and easy to manage. The design of the program is such that if a company should desire to handle the installation t...
 

Also Known As

No data available
Tenable.io
 

Overview

 

Sample Customers

TriNet, USAA, Zurich, Gilt Groupe, McGraw Hill Financial
Global Payments AU/NZ
Find out what your peers are saying about RSA, OneTrust, BitSight and others in IT Vendor Risk Management. Updated: June 2024.
787,779 professionals have used our research since 2012.