We use Tenable Nessus as a vulnerability management tool. It helps identify vulnerabilities in our system, how to address them, and what mitigation steps are required. We can assign high, medium, or low priority levels and schedule scans to run at specific times. The tool generates vulnerability assessment reports, valuable in our organization's environment for continuous security assessment.
Nessus (BYOL)
Tenable, Inc.External reviews
External reviews are not included in the AWS star rating for the product.
Tenable is a must for Vulnerability Scanning
Nessus is a great tool for vulnerability scanning and remediation guidance
Tenable Nessus
One of the best vulnerability scanners on the market
Nessus Professional has the best price/coverage ratio of the industry
Most of the scanners have licenses per IP, so if you have wide ip ranges, licenses fee would be astronomious.
You will need to accomodate the limited reporting and vulnerability management feature of the proffessional version.
Great Tool
Smooth Experience
Identifies and addresses vulnerabilities but the dashboard needs improvement
What is our primary use case?
How has it helped my organization?
We can onboard our organization's access and run scans as needed. We can also share the scan results every year and perform many other tasks with Tenable.
What is most valuable?
It’s a strong vulnerability assessment tool for management and serviceability. It is a reliable product that helps us identify vulnerabilities in our system effectively. I use it to scan our environment with SSM and generate vulnerability assessment reports.
What needs improvement?
The dashboard could be improved.
For how long have I used the solution?
I have been using Tenable Nessus for two years.
What do I think about the scalability of the solution?
Our team has 10-15 people using this solution. It’s a good tool for vulnerability assessment, and we can identify vulnerabilities in our organization. At this time, we can effectively use it within our organization.
I rate the solution’s scalability a nine out of ten.
What's my experience with pricing, setup cost, and licensing?
It is expensive.
I rate the product’s pricing an eight out of ten, where one is cheap, and ten is expensive.
What other advice do I have?
Overall, I rate the solution a seven out of ten.
Discovers all the assets and identifies existing vulnerabilities
What is our primary use case?
We do infrastructure audits in the state, and we have a lot of organizations and customers for which we do security assessments.
How has it helped my organization?
Nessus assists you to complete the job in a shorter period of time. It discovers all the assets and identifies existing vulnerabilities in the environment.
You can then direct your team to create a report on the discovered vulnerabilities. Basically, you can use Tenable to shorten the activity and get faster results.
What needs improvement?
Tenable Nessus could include a broader range of IT assets. Nowadays, IT is not limited to laptops and desktops. It can be any environment in the organization, such as iOS or Android mobile phones.
Apart from that, organizations use APIs and specific tools. We would like Tenable to cover every aspect of IT infrastructure, not just generic systems like laptops, desktops, switches, or servers. It should include every kind of device, like Raspberry Pi. This small chunk of devices acts as sensors in several organizations.
We would like to be able to scan every device in the network, and the solution should present vulnerabilities within their system.
For how long have I used the solution?
I've been working with it for ten years.
What do I think about the stability of the solution?
Tenable is a stable solution. I would rate the stability a ten out of ten.
What do I think about the scalability of the solution?
Tenable's scalability is good. I would rate the scalability a seven out of ten.
How are customer service and support?
We have no issues with support.
Which solution did I use previously and why did I switch?
We had used some open-source solutions previously.
We made a switch to Tenable Nessus because of the vulnerability coverage. It has a huge scope.
How was the initial setup?
Nessus is quite easy. It is quite easy to deploy, quite easy for my team to use this software for vulnerability scanning. So it is very easy.
I would rate my experience with the initial setup a nine out of ten, with ten being easy.
It took one to two hours.
What about the implementation team?
We do this in-house. We, ourselves, deployed this solution.
Sometimes we take assistance from the OEM or the reseller, but generally, we make it an in-house activity.
What was our ROI?
There is a ROI in terms of cost savings, time savings and more.
What's my experience with pricing, setup cost, and licensing?
We have one user license at present. The price is okay. I would give it a seven out of ten, where one is cheap and ten is expensive.
What other advice do I have?
I would recommend it to others. It's a good solution. Overall, I would rate it an eight out of ten. In every aspect, it is good.
Automates scanning process, enhancing the ability to monitor the security landscape continuously
How has it helped my organization?
The platform is essential for vulnerability management tasks and integrates with various data management applications.
What needs improvement?
The product could have unique features similar to Qualys.
For how long have I used the solution?
We have been using Tenable Nessus for about a year to a year and a half. We are using the latest version to ensure access to all the latest features.
Which solution did I use previously and why did I switch?
While Tenable offers a robust solution, the main competitor, Qualys, has some unique features. However, Tenable has a larger market share, indicating that it has undergone extensive testing and development based on customer feedback.
How was the initial setup?
The complexity of deploying Nessus largely depends on the customer's operational environment. If the environment has diverse systems, implementation may be more complex, while a more uniform system allows for easier setup.
The timeline for implementation could range from one week to several months based on these factors.
What's my experience with pricing, setup cost, and licensing?
The product pricing is dynamic and varies based on the specific needs of each project and customer.
Discounts can be offered based on competition and project requirements, making it a relative cost depending on the context.
What other advice do I have?
The solution automates vulnerability checks, which is crucial for our customers who cannot dedicate a team to monitor security issues constantly. It notifies us of vulnerabilities as they arise, allowing us to respond quickly without manual intervention.
It automates the scanning process, allowing us to schedule regular scans, generate reports, and receive notifications about critical vulnerabilities via email. It enhances our ability to monitor the security landscape continuously.
Overall, I rate it a nine out of ten.