We mainly use it for scanning for vulnerability on our hosts, like network devices and servers; to find the vulnerabilities and do remediation. We monitor Windows and Linux workstations.
We mainly use it for scanning for vulnerability on our hosts, like network devices and servers; to find the vulnerabilities and do remediation. We monitor Windows and Linux workstations.
It helps us limit our vulnerabilities and to reduce exploitations.
Tenable also helps us focus resources on the vulnerabilities that are most likely to be exploited.
Among the most valuable features are scanning for vulnerabilities and the reporting. The reporting templates are okay. I like that I can see all the hosts with different vulnerabilities. I can export reports to Excel to adjust them and it's a convenient way to send them to my manager. We actually use the report feature to identify all the vulnerabilities on all the hosts.
We use credentialed scans. They need more permissions and more changes or settings on Windows and Linux.
Also, Agent scanning is more efficient than credential scanning but Agent scanning is more expensive than credential scanning. I prefer, mainly, the Agent scan over the credential scan, it's better. But we will continue to use the credential scan. I would like to see Tenable make some improvements to the credential scanning; more vulnerabilities, because most of the problems have occurred on Windows Server. We have some scanning issues.
We have been using Tenable for just over a year.
It's always working, no crashes.
We can add more scanners to the scan zone. We can also create different organizations in terms of scanning, so I think the scalability is good.
We use Tenable on 300 servers. In our office we have two or three people using the solution who are network security engineers. Two or three people are enough to take care of deployment and maintenance of Tenable.
We have plans to increase our usage. We want to increase our licenses up to about 1,000.
Technical support is good. I get responses quickly and they provide quick resolution. I can look at their community to find questions or the problem. The support is good.
Before Tenable, our global team used Qualys, but I myself didn't use that. The switch to Tenable was decided on by our U.S. team. It was a global strategy to move to Tenable.
The initial setup was good, not complex. We had the guides from Tenable to guide us through the setup. It took us two days, but one day should be good enough for the initial deployment.
Originally, we wanted to scan all our servers from multiple clouds and also on-premises, to scan the local network.
Tenable mainly works on vulnerability scanning and prioritizing.