What is our primary use case?
Tenable Nessus can be deployed on-premise and in the cloud.
Tenable Nessus is a vulnerability scanner to find vulnerabilities. The solution finds the vulnerabilities in our environment and then we send those vulnerabilities that are found out to the SMEs to be fixed.
How has it helped my organization?
Tenable Nessus allows us to keep up on fixing the vulnerabilities that are either being exploited in the wild or the ones that we find most critical.
What is most valuable?
The most valuable feature of Tenable Nessus is vulnerability detection.
What needs improvement?
Tenable Nessus could improve reporting and information sharing. It would be helpful if we could share the reports and have a little bit better flexibility in the reporting of the data.
In the next release, they should add some more integration with other security solutions that would be helpful.
For how long have I used the solution?
I have used Tenable Nessus for approximately 10 years.
What do I think about the stability of the solution?
The stability of Tenable Nessus is very good.
What do I think about the scalability of the solution?
Tenable Nessus is highly scalable.
We have a couple of administrators and vulnerability analysts who run scans, and read-only accounts for the SMEs who fix vulnerabilities, and an executive role for management to view the data.
We use Tenable Nessus extensively, we have scheduled jobs running all the time. We do scans on all the systems on our network, and we are always making tweaks.
How are customer service and support?
I rate the support of Tenable Nessus a four out of five.
Which solution did I use previously and why did I switch?
I have not used another solution previously to Tenable Nessus.
How was the initial setup?
For our deployment of Tenable Nessus, there are elements of complexity. However, the complexity depends on the use case. The solution is not that difficult to implement, the complexity comes from the many things that are involved. You do not need to be an expert there are many parts that need to be set up.
We had Linux servers built and the Tenable Nessus software was installed on top of that. It was relatively simple as far as that goes.
I rate the ease of setup of Tenable Nessus a three out of five.
What about the implementation team?
We did the implementation in-house.
We have two administrators and one SME that does the supporting of Tenable Nessus.
What was our ROI?
It is difficult to show or rate ROI from a security standpoint, it is similar to having car insurance. When there are vulnerabilities out there, we can quickly look because we're scanning all the time at what our vulnerabilities are. Tenable Nessus is used for keeping our infrastructure safe.
What's my experience with pricing, setup cost, and licensing?
Tenable Nessus needs to be licensed. We own a license for the security center and that license is charged by the number of IP addresses that you can scan. You're allowed to have as many scanners as you want and there's no license for the number of scanners. We have a bunch of Nessus scanners out there, and as long as we're comfortable with staying under that IP address limit, that's really all we have to be concerned about.
We pay a monthly maintenance fee, which is reoccurring.
Which other solutions did I evaluate?
We did evaluate other solutions before choosing Tenable Nessus, such as Rapid7. We choose Tenable Nessus because it was used by more customers and it seemed at the time to be more straightforward.
What other advice do I have?
Security is complicated a subject. There's a lot involved in Tenable Nessus, but the solution is easy to run and manage and we have had a lot of good success with it.
I rate Tenable Nessus a nine out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Easy to deploy and use, stable, and scalable.