Senior Systems Administrator at Government Scientific Source, Inc.
Real User
Enabled us to fix holes in our network, but having vulnerabilities fixed by the solution would be better
Pros and Cons
  • "The most valuable feature is how it scanned and detected through its database to let us know exactly what fixes we needed to put in place for the vulnerabilities. It detects and it also gives you the way to fix it."
  • "There is room, overall, for improvement in the way it groups the workstations and the way it detects, when the vulnerability is scanned. Even when we would run a new scan, if it was an already existing vulnerability, it wouldn't put a new date on it."

What is our primary use case?

It is used for vulnerability management. We used Nessus to scan our machines to see how they were vulnerable, for patches or security. The CVE numbers is what we looked at, the security vulnerability, and tried to figure out what we were vulnerable to.

We monitored Windows Servers, Windows workstations, Linux servers, firewalls, switches, VMware equipment, and Cisco UCS hardware through the application.

How has it helped my organization?

We were a lot less vulnerable after implementing the changes that the application recommended.

The solution helped limit our company's cyber exposure by pointing out every single vulnerability we had and showing us how to fix them. By following the application's directions, we were less vulnerable to attackers. By implementing what the application told us to implement, we were able to fix the holes in our network and prevent any attackers from coming in.

What is most valuable?

The most valuable feature is how it scanned and detected through its database to let us know exactly what fixes we needed to put in place for the vulnerabilities. It detects and it also gives you the way to fix it.

The product's VPR did a great job in prioritizing and giving the highs versus the mediums; it did a great job providing the different ratings and priorities.  

What needs improvement?

The Nessus predictive prioritization feature is very nice, the way it displays. The interface could look better, but it has everything it needs. It could do a better grouping of the workstations and run a better schedule. But it was sufficient in what it provided.

There is room, overall, for improvement in the way it groups the workstations and the way it detects, when the vulnerability is scanned. Even when we would run a new scan, if it was an already existing vulnerability, it wouldn't put a new date on it.

Buyer's Guide
Tenable Nessus
April 2024
Learn what your peers think about Tenable Nessus. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
769,334 professionals have used our research since 2012.

For how long have I used the solution?

I used Nessus for about three years.

What do I think about the stability of the solution?

It was very stable. We didn't have any outages or downtime during its use.

What do I think about the scalability of the solution?

The scalability was very good. We were able to deploy it into multiple remote sites using the scanners. You can deploy separate scanner VMs into remote locations where you don't have access. They have Tenable.io in the cloud, which allows you to do all that.

I used it in a very large environment. Just in my sector, we had about 5,000 workstations along with about 150 servers. So it was a pretty sizable environment. The company was using it for a much bigger purpose. It had between about 50,000 and 100,000 workstations and about 10,000 servers.

In my environment we had about seven users logging into it. The company as a whole had about 150 users. They were security engineers, security administrators, system administrators, and system engineers. For maintenance of Nessus, there was only a team of about 15 people.

How are customer service and support?

I rarely had to call technical support. There was one time when we were troubleshooting a VMware scan. They got on and were helpful, but they weren't able to provide a solution quickly enough. I would give them a three out of five.

How was the initial setup?

I found the setup to be simple. The interface was very intuitive. It was simple yet functional.

What was our ROI?

Without Nessus, we would have had a lot more vulnerabilities which would have opened the doors to potential attacks. And attacks would have cost the company a lot more money.

What other advice do I have?

Know that it's only a detection tool and that it has limitations as a detection tool, but the deployment can be pretty scalable.

The solution didn't reduce the number of critical and high vulnerabilities we needed to patch first. It tells you what the critical vulnerabilities are that you need to patch, but it didn't reduce anything. It doesn't patch it for you.

I would give Nessus a seven out of ten, as it doesn't automatically resolve the vulnerabilities. There are tools out there that give you an option: "Hey, do you want me to patch that vulnerability?" You just hit "yes" and it automatically does it. Nessus doesn't do that. And, as I said, the grouping could be a little bit better.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Security Engineer at a media company with 10,001+ employees
Real User
Helpful support, reliable, and effective real-time monitoring
Pros and Cons
  • "The most valuable feature of Tenable Nessus is real-time monitoring."
  • "Tenable Nessus could improve by having more steady updates which will reduce the vulnerabilities."

What is our primary use case?

We are using Tenable Nessus real-time monitoring.

What is most valuable?

The most valuable feature of Tenable Nessus is real-time monitoring.

What needs improvement?

Tenable Nessus could improve by having more steady updates which will reduce the vulnerabilities.

For how long have I used the solution?

I have been using Tenable Nessus for approximately 10 years.

What do I think about the stability of the solution?

Tenable Nessus is a stable solution, we are fairly satisfied.

What do I think about the scalability of the solution?

I rate the scalability of Tenable Nessus an eight out of ten.

Most of the people using this solution at this time are managers.

How are customer service and support?

The technical support has been very useful. They are helpful.

I rate the technical support from Tenable Nessus a four out of five.

How was the initial setup?

The initial setup has been straightforward. However, we are trying to roll out our agents and find all of our devices which we have experienced some challenges. The whole process has taken us approximately three months.

What about the implementation team?

We are doing the implementation in-house.

What other advice do I have?

I would advise others that if this solution fits your use case then I would try it out. Different environments require different solutions.

I rate Tenable Nessus an eight out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Tenable Nessus
April 2024
Learn what your peers think about Tenable Nessus. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
769,334 professionals have used our research since 2012.
Senior Partner
Real User
Overall great solution, plenty of features, and free options
Pros and Cons
  • "Overall Zoom is a good solution."
  • "I have found it is sometimes difficult to control the Zoom meeting sessions. For example, it is difficult to know who is talking and when trying to mute everyone but the speaker you end up muting everyone. When using multiple screens it is laborious to find the control buttons, such as to start a session. Additionally, when a recording is done I have found it difficult to find them, there should be an easier way to retrieve them."

What is our primary use case?

I use Zoom for virtual meetings. 

What is most valuable?

Overall Zoom is a good solution.

What needs improvement?

I have found it is sometimes difficult to control the Zoom meeting sessions. For example, it is difficult to know who is talking and when trying to mute everyone but the speaker you end up muting everyone. When using multiple screens it is laborious to find the control buttons, such as to start a session. Additionally, when a recording is done I have found it difficult to find them, there should be an easier way to retrieve them.

In a future release, the recordings should be able to be enhanced. I am not fully sure if it is the speed of the network or what the challenge is but we record our Zoom meetings and then I edit them to make them into a presentation. There are times when people are grainy, or their sound is not the best. Zoom should have an optimization option for those wanting to do recordings to allow them to receive the best experience. Alternatively, they could give tips on the best configuration settings for the highest recording output quality. For example, Is the user using the most current version of Zoom, or have they blocked out the background noise.

For how long have I used the solution?

I have been using Zoom for approximately 10 years.

Which solution did I use previously and why did I switch?

I have used Teams, ON24, and Citrix.

What's my experience with pricing, setup cost, and licensing?

The solution has free options.

What other advice do I have?

Zoom is a great solution. I did appreciate during the pandemic they offered it for free for a certain amount of callers. I thought that gesture was really great. 

I rate Zoom a ten out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Senior Cyber Security Expert at a security firm with 11-50 employees
Real User
Easy to install, reliable, helpful support, and has a good assessment tool
Pros and Cons
  • "Tenable Nessus is one of the best vulnerability assessment tools, that I know."
  • "They need more flexible pricing."

What is our primary use case?

We use this solution for information gathering and as an assessment tool.

What is most valuable?

Tenable Nessus is one of the best vulnerability assessment tools, that I know.

What needs improvement?

The price could be improved. They need more flexible pricing.

If they had a very creative idea, maybe they could add a special feature. Even extending functions, or exploring new areas. If they were able to integrate it with the existing solution, that would be fine.

I would like to see more integrations, more ideas or services, and functions offered.

It's about wider functionality and not a question of integration. It's more a question of, creativity. If they have other ideas such as what could be added to the vulnerability management. 

For how long have I used the solution?

I have been using Tenable Nessus for five years.

What do I think about the stability of the solution?

Tenable Nessus is a stable product.

What do I think about the scalability of the solution?

It's a scalable solution.

Nessus we either use Nessus for projects for ourselves in many situations, and they also deliver Nessus as a solution for at least five clients. We also have approximately 10 users in our organization.

How are customer service and technical support?

My experience with technical support is very positive.

How was the initial setup?

The installation was easy.

It took approximately six hours to install and deploy.

We need two for the deployment and maintenance, we have two or three people.

What's my experience with pricing, setup cost, and licensing?

In general, it is extremely expensive. If they have a higher price, that's fine, but if there were one or two solutions where you can buy something for a cheaper price then that would make sense for many users.

I understand why it's expensive, but it would be good to have a limited solution with cheaper prices.

There are different solutions for purchasing Nessus, which is not possible with Datadog.

What other advice do I have?

I would recommend this solution to others.

I would rate Tenable Nessus a nine out of ten because it has many dimensions.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Senior Manager at a security firm with 201-500 employees
Real User
Quickly scans and detects new vulnerabilities
Pros and Cons
  • "Tenable Nessus is cheap and flexible."
  • "The professional version is not very scalable."

What is our primary use case?

We use Tenable Nessus to provide service to our bank.

I use it to provide our main service related to our big management.

Other than providing information security to our clients, it is our information security provider, service provider — we manage it. Using Nessus, we are able to scan and locate any potential vulnerabilities that our clients may have and point them out to them.

I am not sure how many users we have using this solution, but we have more than 100,000 assets distributed between roughly 40 clients.

What is most valuable?

Tenable Nessus is cheap and flexible.

What needs improvement?

Currently, they don't have all of the features that I am looking for. I am looking for a technology that installs agents into the machines to perform complicated scanning. That's a good feature that I'm looking for.

Our issues are not all due to Tenable Nessus; we have more than one console that we administrate.

For how long have I used the solution?

I have been using this solution for 10 to 15 years.

I use this solution on a regular basis at my current company. I used it at my previous company as well.

What do I think about the stability of the solution?

This solution is quite stable.

What do I think about the scalability of the solution?

The professional version is not very scalable. It's not really scalable considering the number of assets and clients that I have.

Many of our clients would like to switch to a better solution.

How are customer service and technical support?

The technical support is great. We have called them a few times and they have always helped us.

How was the initial setup?

The initial setup was pretty straightforward. Within a week we had set up all of the infrastructure and were ready to deploy.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Olajide Olusegun - PeerSpot reviewer
Network Team Lead at Atlas Security
MSP
Top 5Leaderboard
Easy to deploy, stable, and scalable solution for vulnerability scans and assessments but can be very slow
Pros and Cons
  • "The most valuable feature is the installation of Tenable which is incredibly easy."
  • "The accuracy of the vulnerability assessment is not up to par yet, as false alarms and false positives occur often."

What is our primary use case?

We use Tenable to scan all the workstations in our government environment for vulnerabilities and outdated software. The Tenable agents installed on the PCs enable us to detect any potential security risks or applications that are not up-to-date, malicious, or suspicious. This helps us ensure that all the PCs are secure and are in good posture.

What is most valuable?

The most valuable feature is the installation of Tenable which is incredibly easy. Even those without extensive technical knowledge can do it. All we need is the license and a few clicks through the installation process which is simple. Once the program is installed on all PCs and servers, we're good to go!

What needs improvement?

The solution can be annoyingly slow.

The pricing is a bit high. 

We would like to see the inclusion of penetration testing capabilities if possible.

Tenable has been mostly used in the on-premise environment, so it would be great if they could improve the transition to the cloud.

The accuracy of the vulnerability assessment needs improvement as false alarms and false positives occur often. Applications are often flagged as critical when they are actually benign. To improve user experience, there needs to be an upgrade in the accuracy of the results and a more user-friendly interface.

Sometimes it can be difficult to adjust the policies. When the solution has been previously installed. Making changes to policies requires navigating multiple steps. This process can be time-consuming and potentially confusing. Expert knowledge may be necessary in certain cases.

For how long have I used the solution?

I have been using the solution for four years.

What do I think about the stability of the solution?

There has been an improvement over the years and the solution is now extremely stable.

What do I think about the scalability of the solution?

We can easily scale up our license to support more devices. By increasing our license, we can add more workstations.

How are customer service and support?

The technical support is outstanding. We encountered some difficulties during our initial deployment, yet they persisted in helping us all day long. Their support team is very competent.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup is straightforward. 

The deployment took us two days to install the SoC on all 100 of our workstations.

What's my experience with pricing, setup cost, and licensing?

The solution is expensive. We lost bids to competing companies due to the pricing; there are cheaper alternatives to Tenable such as Rapid7 InsightVM.

What other advice do I have?

I give the solution an eight out of ten.

We have 100 workstations that all use the solution.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Deputy Manager at a consultancy with 501-1,000 employees
Real User
Geared for use in small environments
Pros and Cons
  • "Tenable Nessus is an absolutely stable and fantastic product."
  • "Tenable Nessus is not feasible for a large company."

What needs improvement?

While Nessus produces good software, I would like it to allow me to better utilize my homepage. The report structures should be more gradual and effective. Also, other components, such as certain vulnerabilities and Malware detection, should better reflect on the console or dashboard. Nessus does not make this available as there is no centralized dashboard. So too, I require a cloud-based Tenable product, not the one available, which is on-premises.

We have already entered an agreement with Nessus for Tenable.io., following contact I established with South Boston.

Once a person takes part in the demo offered by Tenable.io, we are talking about, more or less, VAS software. The VAS feature is absolutely nice. We have already addressed the coming roadmap with Nessus and it will not include these features. Consequently, perhaps Tenable.io will be the next step. Users such as ourselves will definitely be looking at a different application.

For how long have I used the solution?

I have been using the solution for the past four years. 

What do I think about the stability of the solution?

Tenable Nessus is an absolutely stable and fantastic product. As a customer I would give it a 90 percent out of 100 rating.  This is because we have been really satisfied with its use over the past four years. The company and market standards are growing and the margin standard is going up.

Tenable Nessus is competitively slower than Tenable.io.

What other advice do I have?

We are currently trying to procure Tenable.io from Nessus.

I would definitely recommend Tenable Nessus to those who are operating in small environments, with like-sized infrastructure.

When it comes to a big company we should look towards OpenView. Tenable Nessus is not feasible for a large company. For a team comprising 1,000 people, it would be too unstable. Instead, Tenable.io. would be the appropriate choice since it contains a completely different infra.

I rate Tenable Nessus as an eight out of ten. 

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
SamiAyyash - PeerSpot reviewer
Threat Intelligence Engineer at a tech services company with 11-50 employees
Reseller
Top 10
It's easy to set up and integrate
Pros and Cons
  • "Nessus is effortless to integrate."
  • "The reporting could be improved. The reporting in Rapid7 is much better."

What is our primary use case?

We use Nessus for vulnerability assessment. Three or four engineers at my company are using it currently.

What is most valuable?

Nessus is effortless to integrate.

What needs improvement?

The reporting could be improved. The reporting in Rapid7 is much better.

What do I think about the stability of the solution?

Nessus performs well.

What do I think about the scalability of the solution?

Nessus is scalable.

How are customer service and support?

I'm happy with Tenable's technical support. 

How was the initial setup?

Nessus is easy to set up, and it only takes about two hours to deploy. 

What other advice do I have?

I rate Tenable Nessus nine out of 10. Nessus isn't suitable for everyone. It depends on the case. If you need reporting for the COs and stuff, Rapid7 is better. However, if you are implementing it as part of an ongoing VA or retention operation, you should probably use Tenable.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
PeerSpot user
Buyer's Guide
Download our free Tenable Nessus Report and get advice and tips from experienced pros sharing their opinions.
Updated: April 2024
Product Categories
Vulnerability Management
Buyer's Guide
Download our free Tenable Nessus Report and get advice and tips from experienced pros sharing their opinions.