Try our new research platform with insights from 80,000+ expert users
Olajide Olusegun - PeerSpot reviewer
Network Team Lead at Atlas Security
MSP
Top 5Leaderboard
Easy to deploy, stable, and scalable solution for vulnerability scans and assessments but can be very slow
Pros and Cons
  • "The most valuable feature is the installation of Tenable which is incredibly easy."
  • "The accuracy of the vulnerability assessment is not up to par yet, as false alarms and false positives occur often."

What is our primary use case?

We use Tenable to scan all the workstations in our government environment for vulnerabilities and outdated software. The Tenable agents installed on the PCs enable us to detect any potential security risks or applications that are not up-to-date, malicious, or suspicious. This helps us ensure that all the PCs are secure and are in good posture.

What is most valuable?

The most valuable feature is the installation of Tenable which is incredibly easy. Even those without extensive technical knowledge can do it. All we need is the license and a few clicks through the installation process which is simple. Once the program is installed on all PCs and servers, we're good to go!

What needs improvement?

The solution can be annoyingly slow.

The pricing is a bit high. 

We would like to see the inclusion of penetration testing capabilities if possible.

Tenable has been mostly used in the on-premise environment, so it would be great if they could improve the transition to the cloud.

The accuracy of the vulnerability assessment needs improvement as false alarms and false positives occur often. Applications are often flagged as critical when they are actually benign. To improve user experience, there needs to be an upgrade in the accuracy of the results and a more user-friendly interface.

Sometimes it can be difficult to adjust the policies. When the solution has been previously installed. Making changes to policies requires navigating multiple steps. This process can be time-consuming and potentially confusing. Expert knowledge may be necessary in certain cases.

For how long have I used the solution?

I have been using the solution for four years.

Buyer's Guide
Tenable Nessus
June 2025
Learn what your peers think about Tenable Nessus. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
859,579 professionals have used our research since 2012.

What do I think about the stability of the solution?

There has been an improvement over the years and the solution is now extremely stable.

What do I think about the scalability of the solution?

We can easily scale up our license to support more devices. By increasing our license, we can add more workstations.

How are customer service and support?

The technical support is outstanding. We encountered some difficulties during our initial deployment, yet they persisted in helping us all day long. Their support team is very competent.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup is straightforward. 

The deployment took us two days to install the SoC on all 100 of our workstations.

What's my experience with pricing, setup cost, and licensing?

The solution is expensive. We lost bids to competing companies due to the pricing; there are cheaper alternatives to Tenable such as Rapid7 InsightVM.

What other advice do I have?

I give the solution an eight out of ten.

We have 100 workstations that all use the solution.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer2002593 - PeerSpot reviewer
Security Compliance Officer at a tech services company with 51-200 employees
Real User
Easy to use, and provides good visibility, but the user interface could be improved
Pros and Cons
  • "The most valuable aspect of this solution is that you receive the entire report, which details the breakdown, especially in terms of critical, high, low, and mediums."
  • "To be honest, I haven't used it much to tell you that these are the things that should be improved. But I believe the UI should be enhanced somewhat. For example, there are two ways to find a report, and people are frequently confused as to which is the correct method for locating a full report. Sometimes they go in the opposite direction, so this is an area that may be improved."

What is our primary use case?

Every month, I had this Windows Gold image scan. I would obtain some IP addresses, create some rules, and then run them. 

Then there were the automatic automated jobs that I and my colleagues would arrange to execute. 

They would run at night so they wouldn't interrupt the systems. 

Enter some IP addresses for workstations and servers. Some were in a highly secure zone, while others were in a separate subnet, we enter those IP addresses in and run them, scheduling them to run biweekly or weekly.

What is most valuable?

The most valuable aspect of this solution is that you receive the entire report, which details the breakdown, especially in terms of critical, high, low, and mediums. It also informs you exactly what was wrong with it. Then I believe it copies the CVS's score as well.

What needs improvement?

To be honest, I haven't used it much to tell you that these are the things that should be improved. But I believe the UI should be enhanced somewhat.

For example, there are two ways to find a report, and people are frequently confused as to which is the correct method for locating a full report. Sometimes they go in the opposite direction, so this is an area that may be improved.

For how long have I used the solution?

I have been using Tenable Nessus for quite some time.

What do I think about the stability of the solution?

Tenable Nessus is pretty stable.

What do I think about the scalability of the solution?

Tenable Nessus is a scalable product.

How are customer service and support?

I did not deal with technical support at all.

Which solution did I use previously and why did I switch?

I used Nessus from JSON for a Gold image and vulnerability scans in my previous role.

I'm also seeking the same type of tenant for internal vulnerability scans like Qualys. 

We now use Qualys, but we haven't fully utilized its features, but I'm searching for something specialized for our internal vulnerability scan program.

How was the initial setup?

I did not set it up myself, to begin with.

What other advice do I have?

It is a good tool. It's not difficult to understand. It shouldn't be an issue as long as you know what you're doing.

I would rate Tenable Nessus a seven out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Tenable Nessus
June 2025
Learn what your peers think about Tenable Nessus. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
859,579 professionals have used our research since 2012.
Works at a university with 1,001-5,000 employees
Real User
Easy to deploy, simple to use, and offers great vulnerability assessments
Pros and Cons
  • "It's scalable."
  • "It would be a good idea if they have a simulation of attacks or a use case for finding a new vulnerability or dealing with a zero-day attack."

What is our primary use case?

My company uses Tenable as a vulnerability assessment.

We use it for scanning, for the discovery of vulnerabilities in the components or the software, or on the IT infrastructure of our client.

What is most valuable?

The solution can conduct a full vulnerability assessment and also suggest mitigation of vulnerabilities and has a lot of other features. 

It creates a classification of the vulnerability and the likelihood and the impact on other features.

The solution is easy to deploy and simple to use.

It's scalable. 

The solution is stable. 

What needs improvement?

It would be a good idea if they have a simulation of attacks or a use case for finding a new vulnerability or dealing with a zero-day attack.

Right now, it works based on dealing with a vulnerability that is already detected and reported, and it would be great if they have a combination of a vulnerability that existed and another use case to have a more proactive approach to potential new issues. Therefore, doing a simulation of attacks to find a new or zero-day issue or vulnerability would be helpful.

For how long have I used the solution?

I've been using the solution for more than two years. 

What do I think about the stability of the solution?

The solution is very stable and reliable. I'd rate it four or five out of five. The performance is good. There are no bugs or glitches, and it doesn't crash or freeze. 

What do I think about the scalability of the solution?

It is very scalable. I'd rate it a four or five out of five in terms of the ease of expansion. 

We would use Nessus to conduct a vulnerability assessment. How many people use the solution depends on the client. Maybe five or six people from the engineering side use it in general.

We have a new client coming on, and we will require more users on the product to conduct vulnerability assessments, so we do have plans to increase usage.

How are customer service and support?

I've never had any interaction with customer support. The solution works very well, and we haven't needed help.

How was the initial setup?

The initial setup is very straightforward. It's not overly difficult, or complex.

I cannot recall how long the deployment process took. 

What about the implementation team?

Our technical team handled the deployment. 

What's my experience with pricing, setup cost, and licensing?

Another department handles the licensing. I can't speak to the exact costs. I do know that we pay a yearly licensing fee. 

Which other solutions did I evaluate?

We would like to discover other solutions and do a comparison to see the better solution for our clients. We've, for example, tried to look into Cyber XM.

What other advice do I have?

We are just end-users and customers. 

I'm not sure which version of the solution we're using. 

I'd rate the solution eight out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Security Analyst at PJM Interconnection
Real User
Useful vulnerability detection, highly scalable, and good support
Pros and Cons
  • "The most valuable feature of Tenable Nessus is vulnerability detection."
  • "Tenable Nessus could improve reporting and information sharing. It would be helpful if we could share the reports and have a little bit better flexibility in the reporting of the data."

What is our primary use case?

Tenable Nessus can be deployed on-premise and in the cloud.

Tenable Nessus is a vulnerability scanner to find vulnerabilities. The solution finds the vulnerabilities in our environment and then we send those vulnerabilities that are found out to the SMEs to be fixed.

How has it helped my organization?

Tenable Nessus allows us to keep up on fixing the vulnerabilities that are either being exploited in the wild or the ones that we find most critical.

What is most valuable?

The most valuable feature of Tenable Nessus is vulnerability detection.

What needs improvement?

Tenable Nessus could improve reporting and information sharing. It would be helpful if we could share the reports and have a little bit better flexibility in the reporting of the data.

In the next release, they should add some more integration with other security solutions that would be helpful.

For how long have I used the solution?

I have used Tenable Nessus for approximately 10 years.

What do I think about the stability of the solution?

The stability of Tenable Nessus is very good.

What do I think about the scalability of the solution?

Tenable Nessus is highly scalable.

We have a couple of administrators and vulnerability analysts who run scans, and read-only accounts for the SMEs who fix vulnerabilities, and an executive role for management to view the data.

We use Tenable Nessus extensively, we have scheduled jobs running all the time. We do scans on all the systems on our network, and we are always making tweaks.

How are customer service and support?

I rate the support of Tenable Nessus a four out of five.

Which solution did I use previously and why did I switch?

I have not used another solution previously to Tenable Nessus.

How was the initial setup?

For our deployment of Tenable Nessus, there are elements of complexity. However, the complexity depends on the use case. The solution is not that difficult to implement, the complexity comes from the many things that are involved. You do not need to be an expert there are many parts that need to be set up.

We had Linux servers built and the Tenable Nessus software was installed on top of that. It was relatively simple as far as that goes.

I rate the ease of setup of Tenable Nessus a three out of five.

What about the implementation team?

We did the implementation in-house.

We have two administrators and one SME that does the supporting of Tenable Nessus.

What was our ROI?

It is difficult to show or rate ROI from a security standpoint, it is similar to having car insurance. When there are vulnerabilities out there, we can quickly look because we're scanning all the time at what our vulnerabilities are. Tenable Nessus is used for keeping our infrastructure safe.

What's my experience with pricing, setup cost, and licensing?

Tenable Nessus needs to be licensed. We own a license for the security center and that license is charged by the number of IP addresses that you can scan. You're allowed to have as many scanners as you want and there's no license for the number of scanners. We have a bunch of Nessus scanners out there, and as long as we're comfortable with staying under that IP address limit, that's really all we have to be concerned about.

We pay a monthly maintenance fee, which is reoccurring.

Which other solutions did I evaluate?

We did evaluate other solutions before choosing Tenable Nessus, such as Rapid7. We choose Tenable Nessus because it was used by more customers and it seemed at the time to be more straightforward.

What other advice do I have?

Security is complicated a subject. There's a lot involved in Tenable Nessus, but the solution is easy to run and manage and we have had a lot of good success with it.

I rate Tenable Nessus a nine out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1266162 - PeerSpot reviewer
Information Security Manager at a transportation company with 1,001-5,000 employees
Real User
Comes at a great price, does exactly what you expect it to do, and never lets you down from a stability point of view
Pros and Cons
  • "It does exactly what you expect it to do, and its pricing is great. We couldn't really ask for a better deal."
  • "The interface is a little bit clunky, and the reporting is not marvelous. There should be better integration of reporting between instances. Currently, the instance stands alone, and it produces a report. Being able to amalgamate those reports with another instance will be useful."

What is our primary use case?

We are using Nessus Pro. Our operational security team is using it at the moment. It is being used in a couple of ways. In one instance, it is being used purely to scan the internal infrastructure. In the second instance, we're using it to scan the entire network range, including all endpoints. In the third instance, we're using it to do PCI DSS compliance scanning.

What is most valuable?

It does exactly what you expect it to do, and its pricing is great. We couldn't really ask for a better deal.

What needs improvement?

The interface is a little bit clunky, and the reporting is not marvelous. There should be better integration of reporting between instances. Currently, the instance stands alone, and it produces a report. Being able to amalgamate those reports with another instance will be useful.

What do I think about the stability of the solution?

It has never let us down from a stability point of view.

What do I think about the scalability of the solution?

It is really scalable. It is great.

We have six people who are actually interacting with the tool itself, but obviously, it has been deployed against thousands of endpoints. There are three different roles of those six users.

How are customer service and support?

They are very good. Their formal support and the wider community support are excellent.

Which solution did I use previously and why did I switch?

We've used Rapid7 in the past. We switched because of the value for money and the fact that it feeds into the Tenable.io platform, which is where we ultimately want to be.

How was the initial setup?

It was straightforward and fast. It literally took a morning.

What about the implementation team?

It was done in-house. For its deployment and maintenance, there is just one person. He is an information security analyst.

What's my experience with pricing, setup cost, and licensing?

Its pricing is great and can't be improved. It is very cheap. It is less than 2,000 pounds a license, and you can't really ask for more.

It has unlimited IPs and unlimited scans. There are no particular pricing constraints. The only additional cost is the inherent cost of the people to actually review the actual scans.

What other advice do I have?

My advice to people who are looking into implementing this product would be to just go ahead and do it. Don't be frightened about it. It is great. It does exactly what you'd expect it to do. You can use it as a stepping stone to the other Tenable products.

I would rate it a nine out of 10. It is a lovely product. It just does what you need it to do, and lets you get on with your day.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Muhammad Kamran Khan - PeerSpot reviewer
Manager Information Security at NCCPL
Real User
Anyone can deploy it, even the managers, the technical teams, and the engineers
Pros and Cons
  • "With the Tenable Nessus enterprise edition, you have unlimited licenses to scan the device."
  • "The reporting feature needs to be improved."

What is our primary use case?

We are using it to find out the vulnerabilities in our critical servers and to patch them.

We are using the latest version.

What is most valuable?

Tenable Nessus is good. It's the best vulnerability solution in the industry. Most organizations are using it.

What needs improvement?

In terms of what could be improved, I would say that the reporting feature needs to be improved.

Additionally, although it has the features, the enterprise edition is very limited. They need to add multiple reporting features in the enterprise edition.

For how long have I used the solution?

I have been using Tenable Nessus for the last two years.

What do I think about the stability of the solution?

It is a stable product.

What do I think about the scalability of the solution?

Tenable Nessus is a vulnerability product. We have two to three users who are running it, but in terms of the end devices, because it's intended for vulnerabilities scanning and you have to scan your end devices, we have around hundred devices who are scanning with it.

It is a scalable solution.

How are customer service and support?

We contacted support for some scenarios, like upgrades, new security patches, and for some customized reports.

We were satisfied with the speed of the answers. It is good support.

How was the initial setup?

The initial setup is very easy.

Anyone can deploy it, even the managers, the technical teams, the engineers.

I think it took five minutes.

What about the implementation team?

We installed with the help of a consultant. You can do it one time and then you will learn it very easily.

What's my experience with pricing, setup cost, and licensing?

We have an annual subscription.

Which other solutions did I evaluate?

We also evaluated the Rapid7 Nexpose product, but it has a limitation that it supports 128 users then you have to buy another 128, but with  the Tenable Nessus enterprise edition, you have unlimited licenses to scan the device.

What other advice do I have?

I would recommend Tenable Nessus.

On a scale of one to ten, I would rate it an eight.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Network Security Delivery Manager at alascom
Real User
Useful report, responsive technical support, and installation straightforward
Pros and Cons
  • "I have found the vulnerability assessment and the reports to be useful."
  • "The solution could improve by having better integration with different vendors' IPS solutions. The ACLs and IPS policies signatures should be enabled based on the results of Tenable Nessus automatically, we currently have to do it manually which is very time-consuming. It has done a good job integrating with Fortinet but we would like it to be better integrated with other solutions that we have."

What is our primary use case?

We use Tenable Nessus for vulnerability assessments.

What is most valuable?

I have found the vulnerability assessment and the reports to be useful.

What needs improvement?

The solution could improve by having better integration with different vendors' IPS solutions. The ACLs and IPS policies signatures should be enabled based on the results of Tenable Nessus automatically, we currently have to do it manually which is very time-consuming. It has done a good job integrating with Fortinet but we would like it to be better integrated with other solutions that we have. Additionally, After Tenable Nessus was able to recognize the vulnerability it would be great to have it virtually batch the systems if you are not able to update the different systems.

For how long have I used the solution?

I have been using Tenable Nessus within the last 12 months.

What do I think about the stability of the solution?

While doing the scans we have not had any issues, the solution is stable.

What do I think about the scalability of the solution?

Tenable Nessus is scalable.

How are customer service and technical support?

The technical support was responsive and helpful. We were trying different integrations and needed some assistance.

Which solution did I use previously and why did I switch?

We used Qualys previously. 

How was the initial setup?

The initial setup is very easy and straightforward. The VM can be done very quickly and the whole process takes approximately 30 minutes. The installation is quicker than others solutions, such as Qualys.

What's my experience with pricing, setup cost, and licensing?

The price of the solution is reasonable.

What other advice do I have?

I rate Tenable Nessus an eight out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1541385 - PeerSpot reviewer
Cybersecurity Manager at a manufacturing company with 10,001+ employees
Real User
Excellent at identifying vulnerabilities and accessing information related to that
Pros and Cons
  • "Ease of reviewing scores, identifying vulnerabilities, and getting information on them."
  • "Scans aren't done properly and some devices aren't pinged."

What is most valuable?

The valuable feature for me is being able to ping the computers to do the automated scan and to come back and be able to see everything. That's definitely a huge plus, but then there's also the ease of reviewing the scores, identifying vulnerabilities, and getting the information on the vulnerabilities; the ability to review all that within one tool has been phenomenal. When we're reviewing those Nessus scores, the solution works well.

What needs improvement?

I think there's still some things that need to be ironed out to ensure that we can have a one-stop shop to do both ACAS, SCAP automated assessments in. We've been trying to do that and they say you can, the capability is integrated into the system. But in most instances, especially when you're dealing with some systems that are standalone or a network that we built ourselves, we find that some devices aren't pinged and the scans aren't done properly. That also comes down to the hardening of the systems where the password or the privileges weren't taken, so therefore it didn't do the scan properly. 

For how long have I used the solution?

I've been using this solution for the past six or seven years. 

What do I think about the stability of the solution?

The solution is stable. We haven't run into any issues other than some passwords that don't take, but that's the way we set up the system. If it's set up properly and configured appropriately, there won't be any issues.

What do I think about the scalability of the solution?

We could definitely make the adjustment to scale it left, right, up and down, depending on what we're using it for and we haven't run into any issues on that. It's pretty flexible.

How was the initial setup?

The setup itself is pretty straightforward. Because these are standalone systems, there are some additional steps that the IT team needs to do, but they pretty much have it down to where they could install the tools pretty easily and have it running reasonably quickly. 

What other advice do I have?

I would recommend making sure that the solution meets your needs for automated scans and the SCAP. If you're looking for a one-stop shop, I think it's a great tool for that. I would recommend some form of training if you don't have experience with this kind of solution. There's a bit of a learning curve involved in terms of configuring and using Nessus. 

I rate this solution an eight out of 10. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Tenable Nessus Report and get advice and tips from experienced pros sharing their opinions.
Updated: June 2025
Product Categories
Vulnerability Management
Buyer's Guide
Download our free Tenable Nessus Report and get advice and tips from experienced pros sharing their opinions.