Tenable Cloud Security [Private Offer Only] logo

    Tenable Cloud Security [Private Offer Only]

    Tenable Cloud Security is an integrated cloud-native application protection (CNAPP) and infrastructure security platform that automates asset discovery, risk analysis, runtime threat detection, compliance and least-privilege remediation.

    Ratings and reviews

    4.5
    52 ratings
    2 star
    1 star
    65%
    31%
    4%
    0%
    0%
    7 AWS reviews
    |
    45 external reviews
    External reviews are from G2  and PeerSpot .

    Filters

    Review type

    AWS Marketplace reviews
    External reviews
    Reviews (52)
    Computer & Network Security

    Fast, Agentless Cloud Risk Visibility with Powerful Identity & Entitlement Insights

    Reviewed on Sep 22, 2026
    Review provided by G2
    What do you like best about the product?
    What I like most about Tenable Cloud Security is how quickly it gives us a clear, unified view of risk across our cloud environments. Onboarding was fast and agentless, and within a short time we had visibility into our AWS, Azure, and GCP accounts without deploying anything on our workloads.

    The identity and entitlement analysis is the standout feature for me. It surfaces excessive permissions, unused access, and risky identity combinations that are extremely difficult to uncover manually, and it also generates least-privilege policy recommendations we can act on immediately. The attack-path and “toxic combination” views are genuinely useful for prioritization. Rather than drowning in thousands of findings, we can focus on the handful of exposures that actually lead to sensitive data or critical resources.

    I also appreciate how well it fits into the broader Tenable ecosystem alongside Vulnerability Management and Security Center, so cloud misconfigurations, workload vulnerabilities, and identity risks show up in one place with consistent context. Compliance reporting against common frameworks saves our team significant audit-prep time, and the IaC scanning helps us catch issues before they reach production. Overall, it has made our cloud security posture more measurable and has kept our remediation work much more focused.
    What do you dislike about the product?
    The biggest downside for me is the learning curve. The platform is very capable, but the interface feels dense, and it takes time to learn where everything lives and how to tune policies effectively. New team members typically need a walkthrough before they can be productive. The initial alert volume can also be high; until you tune exclusions and severity thresholds for your environment, some findings come across as noisy or simply low priority.

    Integration with the rest of the Tenable portfolio has improved, but it still doesn’t always feel completely seamless. We sometimes have to jump between consoles, and the data and terminology don’t line up perfectly between cloud and on-prem views. Dashboard and report customization is also more limited than I’d like, especially when trying to tailor executive-level views.

    Pricing is on the premium side, which can be a hurdle for smaller teams or organizations that are early in their cloud journey. Licensing can also take some effort to understand as environments grow. Finally, some documentation lags behind new features, so we occasionally rely on support to clarify expected behavior. That said, support has been responsive, and none of these issues outweigh the value the product provides.
    What problems is the product solving and how is that benefiting you?
    Tenable Cloud Security solves a problem we couldn’t address well with our previous tools: understanding real risk across multiple cloud accounts and providers from a single place. Previously, cloud misconfigurations, identity permissions, and workload vulnerabilities were tracked in separate systems—often spreadsheets or native cloud consoles—which made it difficult to understand how individual issues combined into real exposure.

    The biggest challenge it helps us tackle is identity sprawl. Over time, users, service accounts, and roles accumulated far more permissions than they actually needed. Tenable makes it clear which entitlements are excessive or unused and generates least-privilege policies we can apply. As a result, we’ve meaningfully reduced our attack surface without disrupting day-to-day workflows.

    It also improves how we prioritize remediation. The attack-path analysis connects misconfigurations, vulnerabilities, and permissions to show which issues could realistically lead to sensitive data exposure or impact critical systems. Instead of chasing every finding, our team can focus effort where it matters most, which saves time and gives leadership a clearer view of risk.

    On the compliance side, continuous checks against common frameworks reduce the manual work involved in preparing for audits and customer security reviews. IaC scanning also helps us catch misconfigurations earlier in the development process, before they reach production.

    Overall, it supports a more measurable and proactive cloud security program: fewer blind spots, faster remediation of high-impact issues, and less time spent on manual evidence gathering.
    Financial Services

    Powerful, Consistent UI and Seamless Tenable One EM Integration—Azure Setup Could Be More Flexible

    Reviewed on Sep 11, 2026
    Review provided by G2
    What do you like best about the product?
    A powerful tool that provides similar consistent UI experience to other Tenable products, actively assesses your Cloud Security Posture and integrates seamlessly with Tenable One EM.
    What do you dislike about the product?
    The only downside is that it requires to create a vendor-provided multi-tenant application with no possibility to use your own Service Principal for Azure integration
    What problems is the product solving and how is that benefiting you?
    Cloud Security Posture assessment, though, usually cloud vendors usually provide this at better pricing than Tenable, so the practicality could be questionable, unless your company uses multiple vendors and wants a centralized view of all the assets
    Soumyajit D.

    Clear, Actionable Cloud Risk with Accurate Visibility and Prioritized Findings

    Reviewed on Jul 24, 2026
    Review provided by G2
    What do you like best about the product?
    What stands out most is how it turns cloud complexity into clear, actionable risk. Modern cloud environments are dynamic and distributed across multiple providers, services, and ephemeral workloads. Tenable Cloud Security combines broad discovery with continuous checks for vulnerabilities and misconfigurations, then layers risk-based prioritization on top so teams aren’t overwhelmed by noise. That combination—accurate visibility plus prioritized, contextualized findings—makes security work practical instead of purely reactive.
    What do you dislike about the product?
    Many users report that cloud security tools, including Tenable, can generate a high volume of findings that aren’t immediately actionable. When a platform surfaces many low‑priority or context‑less alerts, teams spend time triaging instead of fixing the highest‑risk issues. This is especially true in dynamic cloud environments where ephemeral resources trigger transient findings.
    What problems is the product solving and how is that benefiting you?
    Cloud environments span AWS, Azure, GCP, containers, serverless, and IaC templates; teams often don’t have a single, up‑to‑date inventory of what exists and how resources relate.
    oscar R.

    Effective automation for security and compliance failures in the cloud

    Reviewed on Jul 21, 2026
    Review provided by G2
    What do you like best about the product?
    Automate the identification of security flaws and help prioritize their mitigation. Additionally, facilitate maintaining standards and regulations in cloud environments without requiring additional effort.
    What do you dislike about the product?
    It requires considerable technical experience, which can pose a challenge for teams with less knowledge in cloud security.
    What problems is the product solving and how is that benefiting you?
    Mainly, manage identities with excessive privileges and protect workloads, limiting users who should not have access to certain company assets.
    Ojasv P.

    Great tool for vulnerability management, but needs better reporting

    Reviewed on Nov 03, 2025
    Review provided by G2
    What do you like best about the product?
    Continuous monitoring and real-time risk assessment

    Vulnerability management and detection

    Integration with other security tools

    Automated remediation and security recommendations
    What do you dislike about the product?
    Performance or latency issues

    Lack of certain security features or tools

    Difficulty integrating with other security solutions

    Reporting and analytics limitations

    Pricing concerns
    What problems is the product solving and how is that benefiting you?
    Vulnerability management: Helps identify and address security vulnerabilities across cloud environments

    Compliance and risk management: Ensures compliance with industry standards and reduces risk exposure

    Cloud infrastructure visibility: Provides better visibility into cloud security posture across AWS, Azure, GCP, etc.
    Ajay S.

    Tenable cloud security : Powerful visibility with room to improve on usability and scale.

    Reviewed on Oct 16, 2025
    Review provided by G2
    What do you like best about the product?
    Tenable uses its risk based approach to prioritize misconfigurations and vulnerabilities based on potential exploitability and business impact. It provides unified visibility into AWS, Azure and google cloud environments. Tenable CS can scan IAC templated before deployment, catching misconfigurations. Offers visibility into overly permissive roles and identity relationships in cloud environments.
    What do you dislike about the product?
    For organizations without mature cloud or security practices, getting everything up and running can be time-consuming and need technical expertise. Some users report that the alerts findings include too many low priority items and that the system needs manual tuning to avoid being overwhelmed.
    What problems is the product solving and how is that benefiting you?
    Cloud environments are often misconfigured- either through human error or poor defaults. Tenable solves this by continuously scanning cloud resources for misconfigurations. Mapping them against best practice like CIS benchmarks, NIST and custom policies.
    Prathamesh K.

    Comprehensive Security Visibility with Tenable Cloud Security

    Reviewed on Oct 10, 2025
    Review provided by G2
    What do you like best about the product?
    Tenable Cloud Security offers excellent visibility across multi-cloud environments, making it easier to identify and prioritize risks. I particularly appreciate its ability to continuously monitor configurations and detect misconfigurations or policy violations in real-time. The integration with CI/CD pipelines is a standout feature, enabling early detection of vulnerabilities during development. Its risk-based prioritization helps focus on the most critical issues first, improving remediation efficiency. The user interface is clean and intuitive, making navigation and reporting straightforward. I also value the depth of insights provided through its dashboards and compliance reports. Support for multiple cloud platforms like AWS, Azure, and GCP makes it a flexible solution. Overall, it strengthens our cloud posture with proactive security controls.
    What do you dislike about the product?
    Tenable Cloud Security is powerful, there are areas that could be improved. The initial setup and integration with complex cloud environments can be a bit time-consuming and may require technical expertise. Some dashboards feel overwhelming with too much data and limited customization options. The alerting system could benefit from more granular control to reduce noise from low-priority issues. In certain cases, scan times for large environments can be longer than expected. I’ve also noticed that documentation, while extensive, isn’t always clear or up to date for newer features. The pricing structure might be a concern for smaller organizations. Additionally, support response times can occasionally be slower than ideal. Despite these drawbacks, the platform remains a valuable tool for cloud security management.
    What problems is the product solving and how is that benefiting you?
    Tenable Cloud Security helps address the challenge of maintaining visibility and control across complex, multi-cloud environments. It identifies misconfigurations, policy violations, and vulnerabilities in real time, helping us proactively reduce our cloud attack surface. The platform also improves compliance by mapping findings to industry standards like CIS, NIST, and ISO, which simplifies audit preparation. By integrating with CI/CD pipelines, it enables us to detect security issues earlier in the development lifecycle, reducing remediation costs and effort. Its risk-based prioritization ensures our team focuses on the most critical threats first, enhancing overall security efficiency. Ultimately, it’s helping us strengthen cloud governance, reduce risk exposure, and operate with greater confidence in the cloud.
    Gibs S.

    Reports need improvement.

    Reviewed on Oct 09, 2025
    Review provided by G2
    What do you like best about the product?
    I appreciate how straightforward the console is when it comes to managing policies and templates. Its simplicity makes the process much easier and more efficient.
    What do you dislike about the product?
    The reports, particularly the executive summary, ought to be more straightforward and practical. At present, they come across as overly technical for their intended purpose.
    What problems is the product solving and how is that benefiting you?
    Occasionally, my session ends unexpectedly, though it doesn't happen every time.
    Computer & Network Security

    Strong CSPM Tool for Multicloud Visibility and Compliance

    Reviewed on Oct 08, 2025
    Review provided by G2
    What do you like best about the product?
    This tool offers comprehensive visibility into misconfigurations, excessive permissions, and compliance risks across various cloud platforms. What I appreciate most is its graph-based IAM visualization, which makes it easy to identify risky privilege escalation paths in both AWS and Azure. Additionally, it comes with robust pre-built policies for compliance frameworks such as CIS and NIST.
    What do you dislike about the product?
    At first glance, some dashboards may appear somewhat cluttered, and the options for customization could be more adaptable. Additionally, setting up the initial cloud provider permissions can be challenging if you don't have a strong background in cloud IAM, which can be particularly difficult for teams that are new to CSPM.
    What problems is the product solving and how is that benefiting you?
    Tenable Cloud Security addresses visibility gaps within cloud environments by identifying misconfigured resources, insecure identities, and compliance violations. It allows teams to prioritize risks and take proactive steps to remediate issues, which is essential for maintaining both security and audit readiness.
    DragosCernat

    Has significantly improved proactive monitoring through automated asset discovery and seamless integration with cloud environments

    Reviewed on Oct 07, 2025
    Review from a verified AWS customer

    What is our primary use case?

    We had other solutions that we used. One solution was that we did not have something exactly similar to what Element is doing. For example, we were using Bitsight, Evelin, and also Tenable Cloud Security. However, those products are different. Element was exactly the product we needed to cover close to real-time external surface monitoring. We also used Microsoft Defender for Endpoint, but the Defender product requires substantial manual labor. We were interested in having a tool that would not require too much manual labor and would be more proactive.

    The Element team is easy to discuss with. They created modules for integrations, such as with DNS. They collect records automatically and add assets to the platform, which is very useful because we do not have to check each day for new records or remove old ones. Their integration with Azure and AWS makes it great for us. It streamlines the process and gives us assurance that all new assets will be automatically added to the platform.

    I am not entirely sure about monitoring cloud applications as I have not used it extensively for that purpose. That is why we implemented Element and have other tools, as we are not using it exactly for that scope.

    What is most valuable?

    Element is precisely what we needed for close to real-time external surface monitoring. The automatic integration capabilities, particularly with DNS, Azure, and AWS, are extremely valuable. The platform automatically collects records and adds assets, eliminating the need for daily manual checking and updating.

    The streamlined process ensures that all new assets are automatically added to the platform, reducing manual labor and making the system more proactive. The ease of communication with the Element team and their responsiveness to integration needs has been particularly beneficial.

    What needs improvement?

    Making the system smarter would be beneficial. Adding modules for integration with AWS and Azure would be helpful. Adding capabilities for the scanner to automatically pick up changes and add assets automatically would be valuable.

    When discussing a big company, it is mandatory to have tools that will assist us rather than waiting for manual input to add hosts. Adding assets manually is prone to mistakes. Humans might forget to add an asset or make errors when adding multiple assets.

    Taking the human element out of the context and making it more streamlined is the future for security. The human should be involved where expertise is needed, such as analysis and decision-making. Currently, with resource constraints, we need tools to collect and aggregate data, eliminate false positives as much as possible, and present relevant information to employees for action.

    For how long have I used the solution?

    I first tested the product in November last year, and we implemented it starting in February.

    What do I think about the stability of the solution?

    I would rate it as 10 for experience. As with any other solution in the market, they may have small bugs or false positives. However, whenever I encountered an issue, I sent an email to them and they managed to fix it. They investigated and provided full details for further investigation. In situations where there was a platform issue, they fixed it immediately and provided a complete explanation for the occurrence.

    How are customer service and support?

    Working with Element is straightforward and efficient. For comparison, while working with Bitsight is not difficult, it takes considerably longer. Bitsight is a larger company, and while they will provide the answers needed, the process is more time-consuming. With Bitsight, requesting integrations or new features involves submission and approval processes with uncertain timelines.

    With Element, if you need a feature, you can discuss it with them, and if implementation is possible, you will have that feature within a month or two, depending on complexity. Simple integrations, such as DNS integration, can be completed in approximately a week.

    What other advice do I have?

    Tenable Cloud Security is a mature and trustworthy product. I have been using it since it was available on laptops approximately 10 years ago or more. I initially used it for penetration testing, though currently I perform more manual penetration testing and use the scanner primarily to validate subnets or findings.

    I started with Nessus installed on my computer, then moved to server deployment, and finally to Tenable Cloud Security. We still maintain Tenable Cloud Security but have reduced the number of licenses. We now use it occasionally to validate specific items rather than monitoring the entire surface, for which we use Element.

    Tenable Cloud Security offers various features including discovery, web scanning, and primarily vulnerability scanning. It increases awareness of system vulnerabilities. In today's environment, information comes from multiple sources including Defender, Nessus, and various other tools within an organization. Using multiple tools is necessary to cover as much of the attack surface as possible, both internal and external.

    My review rating for the solution is 10 out of 10.