Try our new research platform with insights from 80,000+ expert users
Assistant Director for Computing and Network infrastructure at SRCE
Real User
Top 10
Helps to conduct monthly scans and open tickets for developers to address identified vulnerabilities
Pros and Cons
  • "We have around 500 virtual machines. Therefore, we conduct monthly scans and open tickets for our developers to address identified vulnerabilities. These scans cover the servers, other network equipment, and appliances in our infrastructure."
  • "One significant drawback we encounter is the tool's tendency to flag patched packages incorrectly. For instance, if a package is patched by Debian maintainers but not updated to a major or minor version, Nessus may still flag it as vulnerable based on its database. This discrepancy leads to false alarms and requires our developers, system admins, and DevOps teams to address them."

What is our primary use case?

We have around 500 virtual machines. Therefore, we conduct monthly scans and open tickets for our developers to address identified vulnerabilities. These scans cover the servers, other network equipment, and appliances in our infrastructure. 

What needs improvement?

One significant drawback we encounter is the tool's tendency to flag patched packages incorrectly. For instance, if a package is patched by Debian maintainers but not updated to a major or minor version, Nessus may still flag it as vulnerable based on its database. This discrepancy leads to false alarms and requires our developers, system admins, and DevOps teams to address them. 

It would be beneficial if it could handle minor additions to versions similar to how Debian manages its patches. This feature would allow it to differentiate between patched and non-patched versions.

For how long have I used the solution?

I have been using the product for ten years. 

What do I think about the stability of the solution?

Tenable Nessus is very stable. We encountered some issues with scanning certain network equipment but resolved them by adjusting the parameters. Our main focus is scanning our servers; we haven't experienced any significant problems with that process.

Buyer's Guide
Tenable Nessus
August 2025
Learn what your peers think about Tenable Nessus. Get advice and tips from experienced pros sharing their opinions. Updated: August 2025.
866,483 professionals have used our research since 2012.

What do I think about the scalability of the solution?

My company has three users. 

How are customer service and support?

We haven't contacted Tenable Nessus for assistance or questions because we haven't encountered any serious issues, and we are generally satisfied with the product.

Which solution did I use previously and why did I switch?

We chose Tenable Nessus because we primarily rely on open-source products as a publicly funded institution. About ten years ago, we conducted research to determine the best option, and at that time, it stood out as the preferred choice.

How was the initial setup?

Tenable Nessus' deployment is straightforward. 

What's my experience with pricing, setup cost, and licensing?

The product is free. 

What other advice do I have?

I rate the overall product a nine out of ten. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer2075424 - PeerSpot reviewer
Head of IT security at a financial services firm with 10,001+ employees
Real User
Helps with vulnerability management trafficking across an entire group
Pros and Cons
  • "I am impressed with the tool's vulnerability scanning."
  • "The tool needs to upgrade asset tracking."

What is our primary use case?

We use the solution for vulnerability management trafficking across an entire group. 

What is most valuable?

I am impressed with the tool's vulnerability scanning. 

What needs improvement?

The tool needs to upgrade asset tracking. 

For how long have I used the solution?

I am using the tool for two years. 

What do I think about the stability of the solution?

The solution is extremely stable. I would rate the tool's stability a nine out of ten. 

What do I think about the scalability of the solution?

I didn't encounter any issues with scalability and I would rate it a nine out of ten. We have around 3000 user endpoints that are being monitored. My company has around 20 users for the tool.

How are customer service and support?

Our local partner helps with the support. 

How was the initial setup?

I would rate the tool's setup a seven out of ten. It is not an easy setup but with proper support, the process is doable. 

What was our ROI?

The solution gives us ROI since it offers visibility and helps to tighten controls in our network. 

What's my experience with pricing, setup cost, and licensing?

I would like to see better discounts. 

What other advice do I have?

I would rate the solution a nine out of ten. It is one of the best tools to use if compliance is your priority. 

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Tenable Nessus
August 2025
Learn what your peers think about Tenable Nessus. Get advice and tips from experienced pros sharing their opinions. Updated: August 2025.
866,483 professionals have used our research since 2012.
Olajide Olusegun - PeerSpot reviewer
Network Team Lead at Atlas Security
MSP
Top 5Leaderboard
Easy to deploy, stable, and scalable solution for vulnerability scans and assessments but can be very slow
Pros and Cons
  • "The most valuable feature is the installation of Tenable which is incredibly easy."
  • "The accuracy of the vulnerability assessment is not up to par yet, as false alarms and false positives occur often."

What is our primary use case?

We use Tenable to scan all the workstations in our government environment for vulnerabilities and outdated software. The Tenable agents installed on the PCs enable us to detect any potential security risks or applications that are not up-to-date, malicious, or suspicious. This helps us ensure that all the PCs are secure and are in good posture.

What is most valuable?

The most valuable feature is the installation of Tenable which is incredibly easy. Even those without extensive technical knowledge can do it. All we need is the license and a few clicks through the installation process which is simple. Once the program is installed on all PCs and servers, we're good to go!

What needs improvement?

The solution can be annoyingly slow.

The pricing is a bit high. 

We would like to see the inclusion of penetration testing capabilities if possible.

Tenable has been mostly used in the on-premise environment, so it would be great if they could improve the transition to the cloud.

The accuracy of the vulnerability assessment needs improvement as false alarms and false positives occur often. Applications are often flagged as critical when they are actually benign. To improve user experience, there needs to be an upgrade in the accuracy of the results and a more user-friendly interface.

Sometimes it can be difficult to adjust the policies. When the solution has been previously installed. Making changes to policies requires navigating multiple steps. This process can be time-consuming and potentially confusing. Expert knowledge may be necessary in certain cases.

For how long have I used the solution?

I have been using the solution for four years.

What do I think about the stability of the solution?

There has been an improvement over the years and the solution is now extremely stable.

What do I think about the scalability of the solution?

We can easily scale up our license to support more devices. By increasing our license, we can add more workstations.

How are customer service and support?

The technical support is outstanding. We encountered some difficulties during our initial deployment, yet they persisted in helping us all day long. Their support team is very competent.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup is straightforward. 

The deployment took us two days to install the SoC on all 100 of our workstations.

What's my experience with pricing, setup cost, and licensing?

The solution is expensive. We lost bids to competing companies due to the pricing; there are cheaper alternatives to Tenable such as Rapid7 InsightVM.

What other advice do I have?

I give the solution an eight out of ten.

We have 100 workstations that all use the solution.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer2002593 - PeerSpot reviewer
Security Compliance Officer at a tech services company with 51-200 employees
Real User
Easy to use, and provides good visibility, but the user interface could be improved
Pros and Cons
  • "The most valuable aspect of this solution is that you receive the entire report, which details the breakdown, especially in terms of critical, high, low, and mediums."
  • "To be honest, I haven't used it much to tell you that these are the things that should be improved. But I believe the UI should be enhanced somewhat. For example, there are two ways to find a report, and people are frequently confused as to which is the correct method for locating a full report. Sometimes they go in the opposite direction, so this is an area that may be improved."

What is our primary use case?

Every month, I had this Windows Gold image scan. I would obtain some IP addresses, create some rules, and then run them. 

Then there were the automatic automated jobs that I and my colleagues would arrange to execute. 

They would run at night so they wouldn't interrupt the systems. 

Enter some IP addresses for workstations and servers. Some were in a highly secure zone, while others were in a separate subnet, we enter those IP addresses in and run them, scheduling them to run biweekly or weekly.

What is most valuable?

The most valuable aspect of this solution is that you receive the entire report, which details the breakdown, especially in terms of critical, high, low, and mediums. It also informs you exactly what was wrong with it. Then I believe it copies the CVS's score as well.

What needs improvement?

To be honest, I haven't used it much to tell you that these are the things that should be improved. But I believe the UI should be enhanced somewhat.

For example, there are two ways to find a report, and people are frequently confused as to which is the correct method for locating a full report. Sometimes they go in the opposite direction, so this is an area that may be improved.

For how long have I used the solution?

I have been using Tenable Nessus for quite some time.

What do I think about the stability of the solution?

Tenable Nessus is pretty stable.

What do I think about the scalability of the solution?

Tenable Nessus is a scalable product.

How are customer service and support?

I did not deal with technical support at all.

Which solution did I use previously and why did I switch?

I used Nessus from JSON for a Gold image and vulnerability scans in my previous role.

I'm also seeking the same type of tenant for internal vulnerability scans like Qualys. 

We now use Qualys, but we haven't fully utilized its features, but I'm searching for something specialized for our internal vulnerability scan program.

How was the initial setup?

I did not set it up myself, to begin with.

What other advice do I have?

It is a good tool. It's not difficult to understand. It shouldn't be an issue as long as you know what you're doing.

I would rate Tenable Nessus a seven out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Works at a university with 1,001-5,000 employees
Real User
Easy to deploy, simple to use, and offers great vulnerability assessments
Pros and Cons
  • "It's scalable."
  • "It would be a good idea if they have a simulation of attacks or a use case for finding a new vulnerability or dealing with a zero-day attack."

What is our primary use case?

My company uses Tenable as a vulnerability assessment.

We use it for scanning, for the discovery of vulnerabilities in the components or the software, or on the IT infrastructure of our client.

What is most valuable?

The solution can conduct a full vulnerability assessment and also suggest mitigation of vulnerabilities and has a lot of other features. 

It creates a classification of the vulnerability and the likelihood and the impact on other features.

The solution is easy to deploy and simple to use.

It's scalable. 

The solution is stable. 

What needs improvement?

It would be a good idea if they have a simulation of attacks or a use case for finding a new vulnerability or dealing with a zero-day attack.

Right now, it works based on dealing with a vulnerability that is already detected and reported, and it would be great if they have a combination of a vulnerability that existed and another use case to have a more proactive approach to potential new issues. Therefore, doing a simulation of attacks to find a new or zero-day issue or vulnerability would be helpful.

For how long have I used the solution?

I've been using the solution for more than two years. 

What do I think about the stability of the solution?

The solution is very stable and reliable. I'd rate it four or five out of five. The performance is good. There are no bugs or glitches, and it doesn't crash or freeze. 

What do I think about the scalability of the solution?

It is very scalable. I'd rate it a four or five out of five in terms of the ease of expansion. 

We would use Nessus to conduct a vulnerability assessment. How many people use the solution depends on the client. Maybe five or six people from the engineering side use it in general.

We have a new client coming on, and we will require more users on the product to conduct vulnerability assessments, so we do have plans to increase usage.

How are customer service and support?

I've never had any interaction with customer support. The solution works very well, and we haven't needed help.

How was the initial setup?

The initial setup is very straightforward. It's not overly difficult, or complex.

I cannot recall how long the deployment process took. 

What about the implementation team?

Our technical team handled the deployment. 

What's my experience with pricing, setup cost, and licensing?

Another department handles the licensing. I can't speak to the exact costs. I do know that we pay a yearly licensing fee. 

Which other solutions did I evaluate?

We would like to discover other solutions and do a comparison to see the better solution for our clients. We've, for example, tried to look into Cyber XM.

What other advice do I have?

We are just end-users and customers. 

I'm not sure which version of the solution we're using. 

I'd rate the solution eight out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Md. Shahriar Hussain - PeerSpot reviewer
Information Security Analyst at Banglalink
Real User
Top 5Leaderboard
Very easy to carry out ransomware checking, OS auditing and implementation
Pros and Cons
  • "Makes ransomware checking and OS auditing and implementation relatively easy."
  • "Lacks some penetration testing-related services."

What is our primary use case?

I use this solution for OS auditing, database auditing, virtualization, and following how closely it follows our CI or TISA benchmarks. We also use it for malware and ransomware risk and for carrying out assessments. We purchased this product from a local partner that has a premium partnership with Tenable. I'm a cybersecurity and compliance lead engineer.

What is most valuable?

The solution makes ransomware checking and OS auditing and implementation relatively easy. It covers most of the requirements for benchmarks for all sorts of widely available required configuration settings in the technology industry. It's also very user-friendly, easy on the eye, and saves a lot of time. It provides us with reports that perfectly satisfy compliance requirements, whatever the device or configuration settings. 

What needs improvement?

There is very little to improve but cloud security tests would be something helpful to have. Tenable could also offer some penetration testing-related services, which would be beneficial.

For how long have I used the solution?

I've been using Nessus for three years. 

What do I think about the stability of the solution?

It's a very stable solution. 

What do I think about the scalability of the solution?

The solution is scalable. I use it for around 4,000 servers on a daily basis.

How are customer service and support?

The technical support is good. They offer expensive professional support, but I generally use the website documentation to fix things. Compared with other companies, they provide very good support. 

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I previously used Qualys and had a bad experience. It's not very user-friendly, licensing was difficult and deployment painful. I also used Rapid7, and I think Nessus is more user-friendly than both of those products. 

How was the initial setup?

The initial setup was very easy and took just a few hours. It's important to plan wisely before implementing. Know how many servers you have and try to project your future requirements so that you can estimate the total number of IPs you require. If the forecast is accurate, the solution is cost-efficient. We used consultants from Singapore and they installed some agents in our on-premise servers. Maintenance is very easy.

What's my experience with pricing, setup cost, and licensing?

The global situation is very unstable and the dollar price has already increased significantly in our country in the last three or four months so everything has become expensive. Licensing is very competitive in our local markets and there's a lot of haggling that goes on. The option of a three-year license would be most beneficial for us because of the huge variations in the dollar. 

What other advice do I have?

I rate this solution nine out of 10. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Wessam Altoumi - PeerSpot reviewer
Chief Commercial Officer at Yamamah Information Technology & Communication Systems LLC
Real User
Good reporting, good support, and easy to deploy and use
Pros and Cons
  • "It is easy to deploy and easy to use. Its reporting is good. From this reporting, you can see the pain point in your network, which makes it easy to fix them. It is easy to understand the reports and export them."
  • "Technically, it is an excellent and the best solution available in Libya. My only concern is related to its pricing. They are an emerging company in Libya, and they need to put in some effort to provide us with very good prices so that customers can go with the best solution. Chinese companies are getting into the market here, and they're providing very cheap solutions."

What is our primary use case?

Two of our customers use it for vulnerability assessment and penetration testing, and they are getting very good results.

What is most valuable?

It is easy to deploy and easy to use. Its reporting is good. From this reporting, you can see the pain point in your network, which makes it easy to fix them. It is easy to understand the reports and export them.

What needs improvement?

Technically, it is an excellent and the best solution available in Libya. My only concern is related to its pricing. They are an emerging company in Libya, and they need to put in some effort to provide us with very good prices so that customers can go with the best solution. Chinese companies are getting into the market here, and they're providing very cheap solutions.

For how long have I used the solution?

We have been providing network and solution integration services since 2012.

What do I think about the stability of the solution?

It is a stable solution. It is the best one in the world. I am not considering any other solutions.

What do I think about the scalability of the solution?

It is scalable.

How are customer service and support?

Their technical support is very good. The feedback that I have received from the customers for the tickets that they opened is that they are satisfied with the service.

How was the initial setup?

It is easy to deploy. It can be implemented in less than 10 days, but complex projects with ISO2007 and 001 compliance requirements can take more than a year.

What about the implementation team?

From our side, there are only two engineers. One is the main engineer and the other one is the backup engineer. 

It is being used by only three users. Two are from the cyber information security team and one is from the network security team.

What's my experience with pricing, setup cost, and licensing?

Its price is high for Libya. The companies here in Libya don't have the awareness of and a good budget for cybersecurity services. If you want them to go for a product, you need to provide something different. This differentiation is related to the price. They should give about 40% to 45% discount per person on the current cost. From our side, we provide the demo and show it as a very good and valuable solution, but when it comes to the price, some companies don't want to own the tool. They prefer to go for it as a service. There are a few companies that are providing it as a service where they own the tool, but they provide it as a service, which is cheaper than a customer owning the product. We strongly recommended that customers own the product and use it. 

I strongly recommend to customers to go for a three-year license to use it, benefit from it, and be comfortable with it. In Libya, we are facing a problem related to the timelines and delays of projects. If they go for just a one-year license and the project gets delayed by six months, they will have only six months to use it.

What other advice do I have?

It is a very good and useful tool. I would rate it a nine out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
NikhilGupta1 - PeerSpot reviewer
Senior Manager - SRE at Zenoti
Real User
Reliable, easy to set up, and helps with compliance
Pros and Cons
  • "Once you get past the initial implementation, the solution is very stable."
  • "They could make their reporting a little better."

What is our primary use case?

We are using the product for CIS benchmarking on our systems.

Our primary use case is basically understanding whether our systems are compliant with the CIS benchmarks in terms of system hardening. What Tenable Nessus does is it can run a scan on the systems and it gives us a report in terms of what properties or settings on the systems are in compliance and what are not in compliance. Then we can review that and go back and improve the systems in terms of those settings.

What is most valuable?

What I like about it is the fact that it can figure out what changes we need to make on our systems to ensure that they're hardened properly.

The initial setup is not difficult. 

Once you get past the initial implementation, the solution is very stable. 

It's scalable. 

What needs improvement?

So far, it has been fulfilling the requirements. From that perspective, there is not a lot that I would want to improve in the features that we are using it.

They could make their reporting a little better. Maybe they could do some more integrations with certain other tools to extend it or make the reporting better in the sense that it could probably generate some alerts or something of that sort. It could do some real-time reporting. If there are any policies that are changing or getting violated, they could probably generate some alerts, which could involve the on-call on my side so that I could take immediate action. That could probably be one thing that they could introduce.

For how long have I used the solution?

We've used the solution for about a year now. It hasn't been that long. 

What do I think about the stability of the solution?

Initially, we had some issues. Initially, we were not very confident about how to configure certain things. Once we had integrated and deployed the product, we needed a few support calls to fix the system properly in our environment and since then it has been smooth, I would say. The stability is now good.

What do I think about the scalability of the solution?

The solution can scale. 

We have very few users. It's basically based on the number of systems that we need to install it on in terms of scaling. That's something that probably is more than the number of users who actually access the system. It's largely used by the security team.

We do have plans to increase the usage of Tenable Nessus organically. As the number of systems that we use is dynamic in nature, it likely will keep going up and down over time.

How are customer service and support?

We've dealt with technical support on and off I would say. We keep talking to the technical support at times to get some insights on any new features that are coming in or in terms of how to use a certain feature that we are probably trying to introduce or something of that sort.

Which solution did I use previously and why did I switch?

We were not using any other products before this.

How was the initial setup?

For the initial setup, I need to deploy an agent on my systems. It's pretty straightforward. It's not very difficult.

I'm not really sure about how long it took, however, my understanding is it didn't take too long for our system. It was maybe a few minutes per system or maybe half an hour per system. Not more than that.

What about the implementation team?

We did not use a consultant or any integrator for the deployment. We did it in-house. 

There were a couple of people on my team who were able to set it up for us.

What's my experience with pricing, setup cost, and licensing?

I'm not aware of the licensing cost.

What other advice do I have?

I'd recommend the product to others. If a company wants to use it for system analysis as part of the benchmarking of the systems or if a company wants to do security benchmarking, they can use this. They should be able to use the tool.

I'd rate the solution eight out of ten. 

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Tenable Nessus Report and get advice and tips from experienced pros sharing their opinions.
Updated: August 2025
Product Categories
Vulnerability Management
Buyer's Guide
Download our free Tenable Nessus Report and get advice and tips from experienced pros sharing their opinions.