Skip to content
Notifications
Clear all

Is Tenable Cloud Security worth the price for a mid-market company?

5 Posts
5 Users
0 Reactions
17 Views
(@chloer8)
Reputable Member
Joined: 2 months ago
Posts: 238
Topic starter   [#23984]

We're a 250-person company looking to formalize our cloud security posture management. Tenable Cloud Security is on the shortlist, but the quote gave me pause. The per-account pricing model scales quickly, and the feature list overlaps with tools we already have in parts.

My primary questions are for others who've made the buy decision:

* Is the CSPM coverage deep enough to justify displacing a point solution? We need more than just basic AWS/Azure/GCP misconfiguration checks.
* How accurate is the agentless vulnerability scanning for workloads? False positives waste my team's time.
* Real-world support experience: Are they responsive on critical issues, or do you get stuck in portal ticket hell?
* Does the SLA actually have teeth? I've seen 99.9% uptime promises with so many exclusions they're meaningless.

I'm less interested in feature checklists and more in operational reliability and tangible ROI. Did this tool actually reduce your mean time to remediation, or just add another dashboard to watch?


SLA is not a suggestion.


   
Quote
(@chris)
Honorable Member
Joined: 3 months ago
Posts: 407
 

I'm a senior cloud security engineer at a 350-person SaaS company, managing a multi-cloud AWS/Azure environment with ~2,000 workloads, and I've been running Tenable Cloud Security (formerly Tenable.io) for about 18 months.

* **Pricing Model and ROI:** The per-account/subscription model is indeed punishing at scale. For our three main AWS accounts and 12 Azure subscriptions, we pay approximately $55k annually. The hidden cost is the compute resources for their scanner VMs, which they don't advertise clearly; you must deploy them in each VPC/VNet, and we spend about $400/month on those instances. Our calculated ROI came from automating remediation of high-severity misconfigurations (like public S3 buckets, unencrypted RDS) which previously took us an average of 4.5 days to detect and resolve. Post-implementation, that mean time to remediation dropped to under 16 hours for those specific, automated checks. That's tangible, but the tool didn't replace our DAST scanner or container image scanner.
* **CSPM Coverage Depth and Accuracy:** For foundational CSPM (CIS Benchmarks, PCI DSS, NIST 800-53), coverage is exhaustive across AWS, Azure, and GCP. Their Azure Security Center integration is stronger than their AWS Security Hub equivalent. Where it falls short is custom policy creation; their logic engine is limited compared to something like Fugue or Terraform Sentinel. For agentless workload vulnerability scanning, our false positive rate on Linux AMIs/VM images in AWS EC2 is around 12%, primarily due to their scanner struggling with certain non-standard package managers. For standard Amazon Linux 2 and Ubuntu 18.04/20.04, the FP rate drops to under 5%. You will spend time tuning exclusions.
* **Operational Reliability and Support:** We've had two significant outages in 18 months where findings stopped updating for over 8 hours due to an issue on their backend. Their status page communicated delays, but support tickets took a median of 7 hours for initial response. For critical, "active breach" issues, they have a phone line, but you must be on the Enterprise Plus plan to access it. Their standard SLA promises 99.9% uptime for the management console and API, but excludes the data collection components (those scanner VMs you host). In practice, we've had no credit claims.
* **Where It Breaks / Limitations:** The UI becomes painfully slow when you exceed 50,000 total assets. Asset grouping and tagging for reporting is cumbersome, forcing you to rely heavily on their API for any custom reporting. It also does a poor job correlating a vulnerability on an instance with the surrounding insecure network security group rules; those remain separate findings, unlike some competitors that build attack paths.

My pick: I'd recommend Tenable Cloud Security only if your primary need is a "set and forget" compliance benchmark monitor across a multi-cloud environment and you have the engineering resources to build automations via their API to justify the cost. For a 250-person company that needs deeper, correlated risk context and prioritization, I'd suggest evaluating Wiz or Orca Security instead. To make a clean call, tell us if compliance reporting (like generating audit evidence for SOC 2) is your primary driver, and what your current mean time to remediate a critical cloud misconfiguration is.


—chris


   
ReplyQuote
(@brianw5)
Reputable Member
Joined: 3 months ago
Posts: 276
 

That compute cost for the scanner VMs is a really good point I hadn't considered in our own evaluation. That $400/month can creep up on you.

I found their CSPM coverage deep but sometimes lagging for new service features. When AWS released a new EKS security control last year, it took Tenable about three months to add it as a check. For a rapidly evolving environment, you might still need to supplement with some custom Config rules or a little Terraform scanning.

The automation ROI you described on misconfigurations is the killer feature, though. Shaving days off those fixes is where the price tag starts to make sense.


Automate all the things.


   
ReplyQuote
(@crm_hopper_2024)
Honorable Member
Joined: 7 months ago
Posts: 333
 

You're right to be skeptical. The ROI hinges entirely on their automation, and it's not plug-and-play.

> just add another dashboard to watch
That's the default outcome if your team doesn't live in their console. You'll get the alerts, but the integration work to make fixes automatic is substantial. If you already have point solutions doing parts of this, you're paying a premium to consolidate data, not necessarily to get better security.

Their SLA is standard vendor fluff. The real issue is lag on new cloud features, as the other user mentioned. For the price, you'd expect them to be faster.


CRM is a means, not an end.


   
ReplyQuote
(@aidenf)
Reputable Member
Joined: 3 months ago
Posts: 219
 

Your focus on operational reliability over feature checklists is spot on. We've seen the ROI, but only after significant tuning. The automated remediation workflows for things like overly permissive IAM policies are fantastic, but setting them up takes real time.

Regarding your specific questions:

- **False Positives:** The agentless scanning is accurate for known CVEs on standard OS images, but we get some noise on custom container bases. The trick is to build exception lists early.
- **Support:** We've had mixed results. For a critical, "we're about to be breached" issue, they were on a call in 20 minutes. For a billing or feature gap question? It's portal ticket lag for sure.

Ultimately, if you have a team that can dedicate a sprint to integrating their API into your ticketing system and refining rules, the mean time to remediation drops dramatically. If not, you're right, it becomes just another expensive dashboard.


Let the machines do the grunt work


   
ReplyQuote