We use Tenable to scan all of our environments and plugins for vulnerabilities. Tenable helps us discover network vulnerabilities to threats and piracy.
Chief Information Security Officer at MIDBANK
It helps us discover network vulnerabilities to threats and piracy
Pros and Cons
- "We use Tenable to scan all of our environments and plugins for vulnerabilities, and Tenable helps us discover network vulnerabilities to threats and piracy."
- "Tenable's reporting engine needs improvement. It needs to be more efficient and add more features."
What is our primary use case?
What needs improvement?
Tenable's reporting engine needs improvement. It needs to be more efficient and add more features.
For how long have I used the solution?
I've been using Tenable for one year.
What do I think about the scalability of the solution?
Tenable is scalable.
Buyer's Guide
Tenable Security Center
August 2026
Learn what your peers think about Tenable Security Center. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
911,952 professionals have used our research since 2012.
How are customer service and support?
Tenable technical support needs improvement.
How was the initial setup?
Setting up Tenable SC was straightforward, and it took two months to deploy.
What about the implementation team?
A third-party vendor implemented Tenable for us.
What other advice do I have?
I rate Tenable SC nine out of 10. It needs some improvements in the reporting engine and training. For example, I need the ability to easily check what happened on Tenable specific dates.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT security consultant at Netready LATAM
Simple setup, useful analysis, and helpful support
Pros and Cons
- "The most valuable features in Tenable SC are scanning and analysis."
- "Tenable SC can improve by making it easier to create complicated reports and have more effectiveness in the remediation area for comparison between the scans."
What is our primary use case?
I am using Tenable SC for vulnerability management and for the dashboards.
What is most valuable?
The most valuable features in Tenable SC are scanning and analysis.
What needs improvement?
Tenable SC can improve by making it easier to create complicated reports and have more effectiveness in the remediation area for comparison between the scans.
For how long have I used the solution?
I have used Tenable SC within the past 12 months.
What do I think about the stability of the solution?
Tenable SC is stable.
How are customer service and support?
Tenable SC support has been very helpful.
How was the initial setup?
The setup of Tenable SC is easy.
What other advice do I have?
I rate Tenable SC an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Buyer's Guide
Tenable Security Center
August 2026
Learn what your peers think about Tenable Security Center. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
911,952 professionals have used our research since 2012.
Technical Implementation Manager at a manufacturing company with 1,001-5,000 employees
Very scalable product
Pros and Cons
- "I find Tenable SC to be a very scalable product."
- "I think the vendor training provided for Tenable.sc could be a lower price. It's quite expensive for the training."
What is our primary use case?
Our primary use case for Tenable SC is its vulnerability scanning capability.
What needs improvement?
I think the vendor training provided for Tenable SC could be a lower price. It's quite expensive for the training.
For how long have I used the solution?
I have been working with Tenable SC for 4 years.
What do I think about the stability of the solution?
The stability of the Tenable SC product is satisfactory.
What do I think about the scalability of the solution?
I find Tenable SC to be a very scalable product.
How was the initial setup?
The initial setup of Tenable SC is not unmanageable.
What's my experience with pricing, setup cost, and licensing?
With regards to the setup of Tenable SC, I would advise others to spend time using the module, get familiar with the product, and in addition read the manual that is provided.
Which other solutions did I evaluate?
We primarily use Tenable SC for vulnerability scanning and did not evaluate other options. This meets our needs.
What other advice do I have?
I would say there are approximately 30 users in our organization using the Tenable SC product.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Infrastructure Engineer at a healthcare company with 1-10 employees
Dashboard features made it easy to track remediation progress, but exporting things out for reports was a little tough
Pros and Cons
- "I found the dashboard features very useful, as they made it easy to track remediation progress and allowed me to publish dashboards to remediation teams and track the progress on the dashboards."
- "The reporting side can be improved. The dashboards are nice, but exporting things out for reports for management was a little tough."
What is our primary use case?
In my previous company, we were using both Tenable IO and Tenable SC. We had the on-prem and the cloud versions. IO was a cloud version, and SC was on-prem.
In my new company, they do use Tenable, but I'm not part of that team. They have the latest version.
What is most valuable?
I found the dashboard features very useful. It made it easy to track remediation progress. I could publish dashboards to remediation teams and track the progress on the dashboards.
What needs improvement?
The reporting side can be improved. The dashboards are nice, but exporting things out for reports for management was a little tough.
We had the on-prem version and the cloud version, and I wasn't a big fan of having different consoles. It would have been nice to be able to have all those features in the cloud version because on-prem is a little tough to manage.
For how long have I used the solution?
I've been using it for about two years. I switched positions about six months ago, and at the moment, I am not using it.
What do I think about the stability of the solution?
I find it stable.
How was the initial setup?
It was pretty straightforward.
What about the implementation team?
We had a consultant from Tenable with us.
What other advice do I have?
I would rate it a seven out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Information Security Analyst at a tech services company with 51-200 employees
Good reporting, alerting, and filtering capabilities and good integration with multiple vendors
Pros and Cons
- "Tenable SC is good for reporting and alerting. The filtering feature is also very valuable. Its integration with multiple vendors is quite good. It can be integrated with SIEM solutions and PAM solutions such as Thycotic, which is very helpful."
- "It is a much better solution than other competitors and provides almost everything that is required in terms of vulnerability management."
- "There is not much room for improvement. However, there should be a guide that describes the step-by-step procedures for doing tasks. Otherwise, training is required from a senior guy to a junior guy."
What is our primary use case?
We had a requirement to connect multiple branches into one console. We installed Nessus at multiple locations and then connected Nessus. We did the service scan and got the report on the central site with Tenable SC.
How has it helped my organization?
Previously, we were using Nessus, which required a lot of manual work in terms of reporting. We do a lot of customization, and Tenable SC has been very helpful. Reporting is just a click away in Tenable SC, whereas it used to take a long time to create a similar report and customize it in Nessus.
What is most valuable?
Tenable SC is good for reporting and alerting. The filtering feature is also very valuable.
Its integration with multiple vendors is quite good. It can be integrated with SIEM solutions and PAM solutions such as Thycotic, which is very helpful.
What needs improvement?
There is not much room for improvement. However, there should be a guide that describes the step-by-step procedures for doing tasks. Otherwise, training is required from a senior guy to a junior guy.
What do I think about the scalability of the solution?
Our usage is the same. Currently, no increment is required in terms of the license.
How are customer service and technical support?
They are good.
Which solution did I use previously and why did I switch?
We used to use Rapid7, but there were too many false positives. So, we switched to Nessus, but in Nessus, we faced the challenge of reporting. Nessus required a lot of manual work in terms of reporting. Tenable SC has been quite helpful for reporting.
How was the initial setup?
It is not straightforward. When you do integrations, it turns into a complex solution, but this complexity is required. If security is a priority, then complexity will be there for enterprise security.
It didn't take a long time. In one month, we were able to configure and run the reports. Everything was done within a month. We were in desperate need of such a solution, and this solution came. We already knew about integrations from the white papers and documents available on the Tenable website. They were very helpful. So, doing integration was not an issue. We did it without much effort.
What about the implementation team?
I was heading this project as a project manager.
What other advice do I have?
It is a much better solution than other competitors. It provides almost everything that is required in terms of vulnerability management. If you are looking for overall enterprise security in terms of integrations and vulnerability management, you should go for Tenable SC or Tenable SCCV.
I would rate Tenable SC a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Information Security Analyst at a retailer with 1,001-5,000 employees
Intuitive with excellent technical support and good stability
Pros and Cons
- "Their overall cost of service is pretty good."
- "Technical support is excellent. They are extremely responsive and very helpful."
- "The biggest issue I have with the solution is when I'm using the scanning it picks up the original DNS of that device. That means, before we image it and actually change the DNS to something within our company structure, it'll just be random numbers and letters and Tenable will stick to that DNS for a long time."
What is our primary use case?
Essentially we use the solution to monitor hard devices on a network with it. That includes laptops, desktops, tablets, et cetera. I'm just using that to make sure that all of our patching is up to date.
What is most valuable?
The UI, the user interface, is really, really good. It's really simple. I started with no prior experience in vulnerability management and picked it up in less than a day, pretty quickly. It's very intuitive.
Their overall cost of service is pretty good.
I've worked with my CS manager and with them a lot, and I'd say every case I've opened, they've reached out to me within two hours. They're pretty prompt in their responses and overall the company is really easy to get ahold of.
Scaling the solution is very easy.
The stability of the product is pretty good.
What needs improvement?
The biggest issue I have with the solution is when I'm using the scanning it picks up the original DNS of that device. That means, before we image it and actually change the DNS to something within our company structure, it'll just be random numbers and letters and Tenable will stick to that DNS for a long time. I'll be searching for a gallery or a laptop and I can't find it due to the fact that the DNS when it was scanned went in as something non-sensical, like M P X 23 Z. That's the biggest issue I have with it. it's some sort of strange glitch.
For how long have I used the solution?
While I started using the solution in January of last year, the company itself has been on the solution for about three years or so.
What do I think about the stability of the solution?
The stability of the solution has been quite good. I haven't experienced any real problems so far. It's been a rather smooth proess.
What do I think about the scalability of the solution?
Scaling the solution would be pretty simple. The process would require us to reach out to Tenable to get more licenses, however, that's a pretty simple process. Overall, it's pretty easy. Essentially it'd just be adding a list of all the new IPs into any asset groups that they would be involved in. I don't think it would take much longer than a week.
How are customer service and technical support?
Technical support is excellent. They are extremely responsive and very helpful. We are quite satisfied with the level of support we've received from them.
I would give them a ten out of ten. They are very prompt and very knowledgeable. They are great at answering questions and walking you through anything step-by-step.
How was the initial setup?
When I started, the company was actually in the process of revamping the solution.
It was a two-day process and the company walked us through the entire thing. I had a Tenable engineer on-call with me for eight hours. It was a long process, however, it was easy as they were walking me through it, step-by-step.
What about the implementation team?
When we did a recent re-vamp, Tenable was on hand to walk us through the entire process. We had a very positive experience with them.
What's my experience with pricing, setup cost, and licensing?
I don't handle the billing and therefore don't have an exact idea of how much the solution costs.
Which other solutions did I evaluate?
We just renewed the solution and didn't look into any other product on the market before we did.
What other advice do I have?
We are just customers and end-users of the product.
If a company does decide to implement the solution, I'd advise working with Tenable engineers during the process, and even afterward, in order to ensure everything is set up appropriately.
I'd rate the solution at an eight out of ten We've had a largely very positive experience with the solution so far.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Presales Engineer at a tech services company with 11-50 employees
Easy to install, very customizable with a lot of templates available; great technical support
Pros and Cons
- "Very customizable with a lot of templates."
- "This solution is very customizable compared to everything else I've seen on the market, so you can easily customize it to suit your needs."
- "Current web page needs improvement, slows down processes."
- "I think the company should redo their web page because the way things are now there are a lot of things you can't do."
What is our primary use case?
I'm a pre-sales engineer and we are resellers of Tenable.
What is most valuable?
This solution is very customizable compared to everything else I've seen on the market, so you can easily customize it to suit your needs. There are a lot of templates you can use and you can install it pretty quickly so in one hour you can have your scanner up and running.
What needs improvement?
I think the company should redo their web page because the way things are now there are a lot of things you can't do. For example, if you want to filter something on the solution and have it filter down to all of your widgets, you can't do it, you have to go from one widget to the other. It takes some time if you have a big customer dashboard that's using some data. I think that the integration with a solution like Jira could be a little bit better for when you create tickets based on your vulnerability.
I know they are working on additional features related to the integration with the patch management like Qualys has, which is really amazing. This is the future and I know they're working on it.
For how long have I used the solution?
I've been using this solution for the past six or seven years.
What do I think about the stability of the solution?
Usually the solution is stable but it can be a little bit tricky which I think depends on the kind of BME and the sizing used. I'd say it was 80%, 85% stable.
What do I think about the scalability of the solution?
The solution is very scalable, it's one of the most scalable solutions that I've used so far, compared to Rapid7 and Qualys, it's very scalable. You can use it pretty much with anything, even if you start with 1000 IPs and scale up from 1000 to 10,000.
How are customer service and technical support?
Technical support is very efficient and they escalate the tickets when you have a big issue. When you open a ticket, they respond within the hour and they're pretty quick to find the issue. If you have a bigger issue, you can set up a Zoom call with them and that's very helpful.
Which solution did I use previously and why did I switch?
I've used Rapid7 in the past and I've also used Qualys a little as well. I work with customers, so I go with whatever they want to use.
How was the initial setup?
The initial setup is very straightforward and quick.
What other advice do I have?
I would definitely recommend the solution but I would tell people that it requires dedicated staff. You need to have someone looking at what's going on when you scan and you need somebody to go through all the results, otherwise it just sits there.
I would rate this solution an eight out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
IT Consultant - Microsoft Design and Implementation at a tech services company with 1,001-5,000 employees
Has good scans and good stability
Pros and Cons
- "The scans are the most valuable aspect of this solution."
- "The reporting needs a lot of work on the template."
- "There should be an easier way to build your own type of reports because the data is there but it is quite painful to get what I want from it."
What is our primary use case?
Our primary use case is for vulnerability assessment of our internal network.
What is most valuable?
The scans are the most valuable aspect of this solution. The reporting isn't so good but I use scans the most. The reporting needs a lot of work on the template.
What needs improvement?
There should be an easier way to build your own type of reports because the data is there but it is quite painful to get what I want from it. I prefer Tenable SC to other solutions.
For how long have I used the solution?
We have been using Tenable SC for a little more than two years.
What do I think about the stability of the solution?
Stability and scalability are good. The administrators use it. We have three regular users.
How are customer service and technical support?
We have contacted their customer support and they were fine.
How was the initial setup?
We didn't have any issues with the initial setup.
What's my experience with pricing, setup cost, and licensing?
We pay around 60,000 on a yearly basis.
What other advice do I have?
Nessus is for a single company and tenable SC is for when you've got multiple repositories. SC is the same as Nessus, except it's got central logging. It's the same thing. For large widespread companies, you use SC, if you're a small to medium-sized company, you use Nessus.
I would rate it an eight out of ten. Not a ten because of the reporting. It needs improvement.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Tech consultant at select softwares
Provides clear and precise vulnerability details with few false positives compared to other solutions
Pros and Cons
- "This solution has a much lower rate of false positives compared to competing products."
- "The vulnerability scan does not work correctly until the access privileges are set by the system administrator."
What is our primary use case?
I use this solution to perform vulnerability assessments and then patch my systems using third-party tools.
The vulnerability scan is pretty fast and once you give it the right access privileges on the target system, you get very clear and precise details of the vulnerabilities.
How has it helped my organization?
This solution has a much lower rate of false positives compared to competing products.
It can operate in hybrid mode, too. The greatest strength of the product comes up when the agent is deployed on the endpoint to be scanned. Thereafter, even if the agent is out of the office network, it can still be scanned and will also send back data to the parent console.
What is most valuable?
The dashboard and the templates used to delvelop reports are awesome.
It is easy to run, scan, and categorize an asset as and when needed. The same asset can be present in two or more groups based on the identification.
This solution can now be deployed in cloud setups.
This solution provides a good reporting system and with a reasonably good level of third-party integration. McAfee has leveraged this capability beautifully in its Policy Orchestrator.
What needs improvement?
We need to give more customer demos and also highlight the strengths of the product that have been developed over a twenty-year period.
The vulnerability scan does not work correctly until the access privileges are set by the system administrator.
For how long have I used the solution?
I have been using this solution for a few years.
What do I think about the stability of the solution?
This system is stable under normal configurational mode. It is important to understand how many hosts it will handle and size the system accordingly.
What do I think about the scalability of the solution?
This is a very highly scalable system.
How are customer service and technical support?
I have not contacted technical support so far, as there was no issue to escalate.
Which solution did I use previously and why did I switch?
We did not use another solution prior to this one.
How was the initial setup?
I have worked on a few demos and they have been pretty straightforward to setup.
What about the implementation team?
I perform the deployment of this solution.
What was our ROI?
Yet to be calculated.
What's my experience with pricing, setup cost, and licensing?
Costing is pretty reasonable compared to the competition.
Which other solutions did I evaluate?
We evaluated Rapid7 and Qualys before choosing this solution.
Disclosure: My company has a business relationship with this vendor other than being a customer. I work for a software dealership and we have had good responses from customers on the product and its capabilities
IT Security Specialist at a consultancy with 1,001-5,000 employees
Automatic scanning distribution and the ability to write custom audit files are distinguishing features
Pros and Cons
- "One of the most valuable features is their distributed scan model for allotting engines to work together as a pool and handle multiple scans at once, across multiple environments. Automatic scanning distribution is a distinguishing feature of their toolset."
- "It increases the trust in the information from the tool, cuts down on accusations of false-positives, helps people do their job better, helps us to understand our cyber-exposure, and helps us focus resources on the vulnerabilities that are most likely to be exploited."
- "It's good at creating information, it's good creating dashboards, it's good at creating reports, but if you want to take that reporting metadata and put it into another tool, that is a little bit lacking."
- "Their tier-one, initial tech support is pretty bad."
What is our primary use case?
Vulnerability assessment and compliance auditing are our primary use cases. That includes baseline configuration scanning. We use it to protect everything in the enterprise environment: servers, workstations, pretty much all operating systems, networking gear. We are doing cloud and we are doing some IOT. We are not using their web application scanning tool.
How has it helped my organization?
The ability to view the plug-ins, the way that the plug-in library works, is really good. It's not an individual list of 80 million different CVEs. We can actually just say, "Hey, here's a plug-in," and it really helps us to boil things down. Instead of having a million CVEs, here's the specific plug-ins that are actually tying the CVE families together. That helps our platform owners, if there is an issue, to see what it is and understand better how to fix it.
Also, the fact that they display the very specific plug-in output in their details area helps our platform owners know, if there's an issue, specifically what was checked and what versions it was on at the time of the test. That's just huge. It increases the trust in the information from the tool. It cuts down on accusations of false-positives and it helps people do their job better.
It helps us to understand our cyber-exposure. At the end of the day, if you don't know what you have, then you cannot defend against it. Understanding what services, what technologies, and all those components will also give us an idea about how to predict what kinds of attacks are the things that we need to guard against in the future.
It also helps us focus resources on the vulnerabilities that are most likely to be exploited. Looking at what actually has an exploit available along with consideration of other things such as network proximity times and information about the threat - either VPR or CVSS - pulling all that together does allow us to identify pretty quickly what are the high-priority targets that we should work on.
What is most valuable?
One of the most valuable features is their distributed scan model for allotting engines to work together as a pool and handle multiple scans at once, across multiple environments. Automatic scanning distribution is a distinguishing feature of their toolset.
Also, the ability to trend data back as far back as we have disk space for, is helpful.
Finally, the ability to write custom audit files is a really helpful and useful feature. That's something that not a lot of assessment companies have gotten right. There's room for improvement, but literally being able to take the text file, open it up, and adjust the changes, write your own regex and write your own checks, is huge.
What needs improvement?
It's good at creating information, it's good creating dashboards, it's good at creating reports, but if you want to take that reporting metadata and put it into another tool, that is a little bit lacking. It does great for things for the API. For instance, if we say, "What vulnerabilities do we have?" or "How many things have we scanned?" those things are great. But if we want to know more trending stuff over time, it can create a chart, but that's in a format which is really difficult to get into another program. Integration into other reporting platforms, or providing more specific scanning program metadata, would be an opportunity.
It does have a fully-bolstered API which is available online that you can look at, but it is more aimed at getting more vulnerability information out instead of reporting information out.
For how long have I used the solution?
We've been using it for about two years.
What do I think about the stability of the solution?
We've had more problems with the underlying stuff that is running the operating system, as opposed to actually running Tenable. Tenable SecurityCenter has been pretty stable. We've only had one or two smaller technical issues. There have been other issues, but they've not been Tenable's fault.
What do I think about the scalability of the solution?
It does have an upper limit. You can go on their website and see what their upper IP limit is.
We have seen that more and more teams want to get access to the data and get access to their vulnerability information, and it really has helped us grow our program.
How are customer service and technical support?
Their tier-one, initial tech support is pretty bad. Their premium support is excellent. Whether premium support comes at an extra fee depends on how your negotiations go.
Which solution did I use previously and why did I switch?
We migrated from Nexpose. We switched because Nexpose is not a scalable product for an enterprise. Also, in most instances, SecurityCenter is less false-positive prone and the detection seems to be better in most instances.
How was the initial setup?
The initial setup was very straightforward. In fact, for some of our teams, we've actually done - "capture the flag" is a bad word for it - but effectively that type of an activity, and they pretty much go from naked box to Tenable scanning instances within a couple of hours. It's very easy to set up.
I can safely say that it can be deployed with one person. And it doesn't require a lot of maintenance. It depends on how much you use it for, but it's mostly just set-it-and-forget-it. Then there is just the mechanical stuff of patching the box and applying system updates, but it actually does a pretty good job most of the time.
What was our ROI?
We've seen return on investment through visibility, scan stability, ensuring that we're able to assess our environment. Also, ensuring that we are able to have good confidence in the data, and that we're able to do out-of-the-box reporting and various other dashboards that really help us drive our program and help sell our case.
Which other solutions did I evaluate?
We evaluated Qualys. It depends on whether you want to do on-prem or in the cloud. Qualys really is a black box. You literally put this thing on your network, you can't touch it, and if you want to do something like troubleshoot, it is just not very friendly from an "if things go wrong" perspective.
What other advice do I have?
Make sure that your sizing is done correctly, in terms of the hardware size. When you do buy Tenable, a lot of times you'll use Professional Services to help you implement the tool. Whatever advice Tenable has, listen to it very specifically and also talk to them specifically about what your goals are. Instead of talking tactics, talk about goals. What's going to happen is that they may say "Hey, we're going to do things slightly differently than how you used to do it," but in a lot of instances, they're going to be right.
In terms of features that we're looking forward to, VPR is one that we're going to start using more. And they also recently had a SAML integration for single sign-on. That was a new feature in 5.9.
Overall, Tenable is easily a nine out of ten. It's not a ten because there is no perfect tool out there, and Tenable SecurityCenter does have its limitations.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Buyer's Guide
Download our free Tenable Security Center Report and get advice and tips from experienced pros
sharing their opinions.
Updated: August 2026
Product Categories
Risk-Based Vulnerability Management Vulnerability Management Cloud Security Posture Management (CSPM)Popular Comparisons
Cloudflare
SentinelOne Singularity Cloud Security
Microsoft Defender for Cloud
Darktrace
Checkmarx One
Prisma Cloud by Palo Alto Networks
Check Point Cloud Firewall (formerly CloudGuard Network Security)
Qualys Exposure Management
TrendAI Vision One – Cloud Security
Orca Security
CrowdStrike Falcon Cloud Security
Buyer's Guide
Download our free Tenable Security Center Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Can you recommend API for Tenable Connector into ServiceNow
- Vulnerability Management and Risk Management Integration
- Which one to buy out of the following products: Tenable SC, Tenable.io, Tenable.ep or Tenable.ad?
- What are the differences between Tenable.sc and Tenable.io?
- When evaluating Cloud Security Remediation, what aspect do you think is the most important to look for?
- Why is Risk-Based Vulnerability Management important for companies?


















