PeerSpot user
Senior Consultant at a tech company with 1,001-5,000 employees
MSP
Reduces the amount of time spent on finding vulnerabilities.
Pros and Cons
  • "Tenable Nessus streamlines the process of scanning for our organization."
  • "This is still a maturing product. Tenable is only a scanner for one ability, while other solutions like Rapid7 have more tools for verification. We still have to manually verify to see if the vulnerability is a false positive or not."

What is our primary use case?

My primary use case of this solution is for scanning internal networks.

How has it helped my organization?

We use Tenable Nessus for scanning. We find lots of vulnerabilities and then we reduce the time spent on finding inbox vulnerabilities. Of course, Tenable streamlines the process. It has been a positive experience overall.

Tenable can scan for missing patches for the endpoints. We can scan it and then, once we can support any endpoint without patching, we inform our users.

What is most valuable?

We wanted to do a lot of Hardening and we have to make sure that all endpoints are up to the certain Hardening standard and we propose the CIS benchmark to do this. That's why we use Tenable to do scanning frequency and to ensure the quality of the endpoints.

What needs improvement?

This is still a maturing product. Tenable is only a scanner for one ability, while other solutions like Rapid7 have more tools for verification. We still have to manually verify to see if the vulnerability is a false positive or not. 

Buyer's Guide
Tenable Nessus
April 2024
Learn what your peers think about Tenable Nessus. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
769,334 professionals have used our research since 2012.

For how long have I used the solution?

Less than one year.

What do I think about the stability of the solution?

It is stable. We have not had any major issues. It performs as scheduled and scans as needed.

What do I think about the scalability of the solution?

In terms of scalability, there is an issue with cloud servers. You need the internet bandwidth to do the testing. They consume a lot of bandwidth and they use the cloud scanners for the scanning. 

How are customer service and support?

I usually use the dashboard for support. It shows the critical vulnerabilities from low to high. They are very responsive when necessary. 

How was the initial setup?

The implementation was straightforward. First, we noticed whether everything was ready, then we got a license key, set up some basic scanning using a default template, and finally, we scheduled time. 

What's my experience with pricing, setup cost, and licensing?

The price of Tenable Nessus is much more competitive versus other solutions on the market. 

Which other solutions did I evaluate?

We were manually scanning before using Tenable Nessus. We looked at Rapid7 but we are satisfied with Tenable Nessus. 

What other advice do I have?

I would suggest that people considering this solution should choose the cloud-based solution versus the on-premise version.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Cyber Security Engineer at a manufacturing company with 5,001-10,000 employees
Real User
Very user friendly with good dashboards
Pros and Cons
  • "User friendly and good dashboards."
  • "Consumes more system resources when it's running."

What is our primary use case?

I'm using Tenable for a project I'm working on. The primary use case is for web application scanning and we're also able to conduct infrastructure scanning and network scanning. I'm not using all the features. 

What is most valuable?

It's a user friendly solution and I like the dashboards. 

What needs improvement?

Unfortunately, the solution consumes more system resources when it's being run and I'd like that to be reduced. 

For how long have I used the solution?

I've been using this solution for three months. 

What do I think about the stability of the solution?

The solution is stable. 

What do I think about the scalability of the solution?

The solution is scalable.

How was the initial setup?

The initial setup was very easy, it didn't take more than 10 minutes. It does depend on internet speed so sometimes deployment might take longer. 

What other advice do I have?

I rate this solution an eight out of 10. 

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Tenable Nessus
April 2024
Learn what your peers think about Tenable Nessus. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
769,334 professionals have used our research since 2012.
CSSP Manager at a tech services company with 51-200 employees
MSP
Largely problem-free with good scanning capabilities and a good interface
Pros and Cons
  • "The automatic scanner and scheduler are pretty cool."
  • "The reporting is a bit cumbersome."

What is our primary use case?

I primarily use the solution for vulnerability scanning within our organization.

What is most valuable?

The automatic scanner and scheduler are pretty cool. 

The interface is excellent. It makes it very user friendly and easy to navigate for the most part.

It's a pretty solid product. I pretty much like almost all of it. 

The product is pretty problem-free. We don't have any real issues with it.

What needs improvement?

The reporting is a bit cumbersome. 

A lot of times you have got to, if you want to test things, go in and then back all the way out, and then try something else, and that just becomes cumbersome. 

The testing functionality could be better.

The way they had set up the scan sometimes is difficult as well. It's partly due to how it's set up where I am. It's not necessarily a Tenable thing, however, the user, how they assign users and roles, is strange. Sometimes if a coworker sets up a scan, I can't start it or stop it. That's just something that may be an issue on our set-up and not a Tenable issue.

For how long have I used the solution?

I've been using the solution for a while. I've probably been using the solution since 2015. It's been over five years at this point.

What other advice do I have?

We're just customers. We're end-users. We don't have a business relationship with the company.

We're using the solution as what I would consider a hybrid, where the security center is managed by another group. However, we have a scanner in our network that connects back to the security center and the DOD of Azure.

We're largely happy with the product. Overall, I'd rate the solution eight out of ten. If it weren't for the reporting or the scanning difficulties, I would rate it higher.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Senior Infrastructure Project Manager at a energy/utilities company with 501-1,000 employees
Real User
Has good vulnerability reporting and is stable and scalable
Pros and Cons
  • "The solution is very stable."
  • "I would like to see an improvement in the ranking of high, medium and low vulnerability."

What is our primary use case?

Our primary use case of this solution is scanning of our external websites.

What is most valuable?

The feature I find most valuable is the vulnerability reporting.

What needs improvement?

I would like to see an improvement in the ranking of high, medium and low vulnerability.

For how long have I used the solution?

I have been using Tenable Nessus for six months now.

What do I think about the stability of the solution?

The solution is very stable.

What do I think about the scalability of the solution?

Tenable Nessus is a very scalable solution. We have over 50 devices running on it currently, and over 50 locations. And we plan to increase our usage in the future. We use our existing team for maintenance, so we didn't have to increase our headcounts. One person is enough to do the maintenance.

How are customer service and technical support?

The technical support is good.

How was the initial setup?

I will say the initial setup was not straightforward, and not complex either. It's medium. Technically it's not too complicated, but if you work with a good partner, they can help. The deployment took us about three to six months.

What other advice do I have?

My advice to others would be to include post-implementation support for six months from the vendor to help with the fine-tuning. I rate this solution an eight out of ten. In the future, I would like to see better reporting for high impact vulnerabilities.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Founder & CEO at a tech services company with 1-10 employees
Real User
Top 20
Very user friendly and affordable
Pros and Cons
  • "The trial version is very good for testing whether it will suit your needs."
  • "The report for counters is too simple and would be improved by a dashboard."

What is our primary use case?

I'm currently using the Nessus essentials for testing, it's installed on my Notebook. My company has only been in operation for one month so as soon as I close with my first client, I will buy the professional version. I used the solution in my previous job. 

What is most valuable?

I have chosen Nessus because it's very simple to use and install. Depending on the number of assets you scan, Nessus is also an affordable solution. Products such as Tenable IO and RapidLab, can become expensive depending on the number of IPs. So Nessus Pro is perfect for my needs right now.

What needs improvement?

I'd like to see a dashboard for this product because the report for counters is too simple. There needs to be something better for the client.

For how long have I used the solution?

I've been using this solution for five years. 

What do I think about the stability of the solution?

This solution is stable. 

What do I think about the scalability of the solution?

The solution is definitely scalable. 

How are customer service and support?

I've never needed to contact Tenable support, I've been able to resolve any issues myself. 

How was the initial setup?

The initial setup is very easy. Deployment takes less than two hours, it's simple.

What other advice do I have?

It's important to test the solution so you know that it works for your situation. They have a trial version so it's easy to test before you purchase it. 

I rate this solution eight out of 10. 

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Information Technology Security Specialist at a tech services company with 201-500 employees
Real User
A remote security scanning tool that's pretty good to optimize
Pros and Cons
  • "I have experience with it on my attack stations, and it's pretty good to optimize. Personally, I think Nessus is quite a good product."
  • "Some things in the user interface could be better. The user interface could allow more adjustments to plugins. The price could also be better."

What is our primary use case?

I'm using Tenable Nessus for my personal projects and vulnerability assessment, but I can't discuss what I do at work with you.

What is most valuable?

I have experience with it on my attack stations, and it's pretty good to optimize. Personally, I think Nessus is quite a good product.

What needs improvement?

Some things in the user interface could be better. The user interface could allow more adjustments to plugins. The price could also be better.

For how long have I used the solution?

I have been using Tenable Nessus as a worker in America for about 15 years now.

How are customer service and support?

Technical support could be more knowledgeable. Their support right now goes from awkward to funny. Sorry to say that, but Tenable Nessus support isn't working as it should. They act fast, but their solutions don't always work. I've been in several situations at work where I had to find my own solutions.

How was the initial setup?

The initial setup and installation are pretty straightforward. Let's say 15 minutes to compile the plugin. It would take about half an hour to an hour to set up and deploy.

What's my experience with pricing, setup cost, and licensing?

One problem with Tenable is its pricing policy. Optimal results can be achieved with Greenbone Solutions which has much more friendly pricing policies.

What other advice do I have?

On a scale from one to ten, I would give Tenable Nessus an eight.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
VP - Risks, Audits & InfoSec at a tech services company with 501-1,000 employees
Real User
I like its ability to collate a dependable output, where we are able to get the same vulnerability when we test manually
Pros and Cons
  • "The features of Tenable Nessus that I have found most valuable are its reliability and its ability to collate a dependable output, where we are able to get the same vulnerability when we test manually. The output is quite reliable."
  • "In terms of what could be improved, I would say its reporting portion."

What is most valuable?

The features of Tenable Nessus that I have found most valuable are its reliability and its ability to collate a dependable output, where we are able to get the same vulnerability when we test manually. The output is quite reliable.

What needs improvement?

In terms of what could be improved, I would say its reporting portion.

Additionally, we have the on-prem version, but sometimes we want to have an on-cloud deployment as well for certain projects, although not so many. The people who used it on cloud didn't find it as good as the version they were using on-prem. Overall, the cloud version could be improved.

For how long have I used the solution?

I have been using Tenable Nessus for about three years now. We are currently using the latest version.

What do I think about the stability of the solution?

In terms of stability, recently we are seeing many updates coming in and we are finding that the updating model with its latest releases may be a little buggy. So sometimes deployment may take a couple of times and Nessus takes its own time for updating, thereby delaying the deployment time. Of late is, we are seeing updates coming in very frequently. So when we deploy it, it just updates again and again and that almost doubles the time.

What do I think about the scalability of the solution?

Tenable Nessus is scalable. That's not an issue.

How are customer service and technical support?

We did reach out to technical support. I think it was just once, but it took them a long time to respond. Maybe it was case specific, but they took a few days to get back to us and we didn't expect that. Now they've completely changed the model to email support, so we send the email and we'll have to wait until the guys answer us back.

How was the initial setup?

The initial setup on-prem and on-cloud did not have any issues. It just took a couple of hours.

What other advice do I have?

On a scale of one to ten, I would give Tenable Nessus an eight.

What happens is Nessus keeps on updating and this becomes a showstopper. We are unable to proceed with the vulnerability scans or testing if we do not update to the latest available patch. We can understand the risk if it's maybe one version earlier, meaning, we understand something was updated with XYZ patch but there should be something which gives us an option so that not all of our deployments need to have the latest patch. This would save the deployment time because of frequent updates.

I would recommend Tenable Nessus. Especially the commercial model. We operate in small and medium enterprises and for them, Nessus is becoming expensive. Because of this I may not buy Nessus this year and I might switch to Qualys, for example. Overall, Tenable Nessus is not so price pocket friendly for small and medium users.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Security Professional at a tech vendor with 10,001+ employees
Real User
An affordable product that needs to improve the reporting function
Pros and Cons
  • "I find the features that are most valuable are the policies that help us identify the vulnerabilities. These policies are then used for scanning instabilities and then identifying the particular vulnerabilities."
  • "We have had some false positives in the past, which we hope can improve in the future."

What is our primary use case?

Primarily, I use this for assessment and administration testing.

What is most valuable?

I find the features that are most valuable are the policies that help us identify the vulnerabilities. These policies are then used for scanning and identifying instabilities.

What needs improvement?

The reporting functionality needs improvement. I think it would be beneficial to have a high level explanation for a particular user. 

For how long have I used the solution?

Three to five years.

What do I think about the stability of the solution?

It is very stable, based on our past experience. We have had some false positives in the past, which we hope can improve in the future.

What do I think about the scalability of the solution?

The scalability is fine. It is tied to the licensing agreement. We currently have 20 people using this tool in our organization. It is primarily used by people in our cellular team. If we see a need to add more users in the future, we will renegotiate our licensing agreement to do so. 

How are customer service and technical support?

We have not needed to contact tech support much. We contacted them about the false positives, and they were helpful. 

Which solution did I use previously and why did I switch?

We also evaluated Netplus. 

How was the initial setup?

The installation is very straightforward and easy. We did not use a third-party installer. 

What's my experience with pricing, setup cost, and licensing?

I think the price is fairly affordable. It provides a license that is fair.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free Tenable Nessus Report and get advice and tips from experienced pros sharing their opinions.
Updated: April 2024
Product Categories
Vulnerability Management
Buyer's Guide
Download our free Tenable Nessus Report and get advice and tips from experienced pros sharing their opinions.