All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
Tenable sells exposure management software to large enterprises and government agencies. Its Tenable One platform maps security weaknesses across infrastructure, cloud, identity, operational technology, third-party applications and AI. Founded in 2002 and listed on Nasdaq, Tenable has over 40,000 customers, including about 65% of the Fortune 500. Revenue in 2025 was $999.4 million, up 11%, with a $36.1 million net loss and $266.8 million of operating cash flow. Gartner named Tenable a Leader among exposure assessment platforms in 2025. In its annual report, Tenable lists Qualys, Rapid7, CrowdStrike, Palo Alto Networks and Wiz as competitors and says many organizations build their own tools in-house. A customer that consolidates all six areas on Tenable One would be slow to replace it.
| Description | Public exposure-management company built on the Nessus vulnerability scanner. The Tenable One platform unifies vulnerability, cloud, identity, OT, web-app, and AI exposure across the attack surface and prioritizes risk. | [f1] |
|---|---|---|
| Founded | 2002 | [f2] |
| HQ | Columbia, Maryland, USA | [f3] |
| Latest funding | IPO July 2018 (Nasdaq: TENB) | [f2] |
| Deployment | SaaS | [f4] |
| Compliance | ISO 27001 | [f4] |
| Product | What it does |
|---|---|
| Tenable One | Exposure-management platform unifying vulnerability, cloud, identity, OT, web-app, and AI signals across the attack surface with 300-plus integrations. |
| Nessus | Vulnerability assessment scanner, trusted by tens of thousands of organizations with 2 million downloads, that powers the Tenable One platform. |
| Tenable Cloud Security | Cloud-native application protection (CNAPP) closing cloud exposure across configurations, identities, and workloads in multi-cloud environments. |
| Tenable Identity Exposure | Agentless identity-security solution that unifies Active Directory and Entra ID, maps attack paths, and hardens identity posture. |
| Tenable OT Security | Security for converged OT/IT environments, inventorying OT, IoT, and IT assets and surfacing cyber-physical exposures. |
| Tenable AI Exposure | Discovers shadow AI usage on connected platforms, detects prompt injection and jailbreaks, and enforces AI acceptable-use policy. |
AI Defense Matrix
| Govern | Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|---|
| AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain. | ||||||
| AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices. | ||||||
| AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD. | ||||||
| AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic. | ||||||
| AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes. | ||||||
| Training Data Datasets used for training, fine-tuning, and continued learning. | ||||||
| Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history. | ||||||
| AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools. |
Tenable AI Exposure discovers how employees and agents use AI platforms, surfaces shadow AI and misconfigurations, detects attacks such as prompt injection, and enforces AI acceptable use policies. It is mapped to the AI Defense Matrix. [f5]
Cyber Defense Matrix
| Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|
| Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware. | |||||
| Applications Software, interactions, and application flows on the devices. | |||||
| Networks Connections and traffic flowing among devices and apps, plus communication paths. | |||||
| Data Content at rest, in transit, or in use across devices, apps, and networks. | |||||
| Users The people using the devices, apps, networks, and data. |
Vulnerability Management and Patch Management cover devices, Web App Scanning covers applications, OT Security covers networks, Cloud Security covers data, and Identity Exposure covers users. Tenable is mapped to the Cyber Defense Matrix. [f6]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 3/5 | Tenable defines exposure management clearly and a regulatory filing confirms a large paying base, but the pain stays category-generic and vendor-framed without an independent source quantifying the problem itself, holding this at the present-but-unproven level alongside Rapid7. [s1, s2, s9] |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. | 4/5 | Tenable documents multi-domain capabilities across vulnerability, cloud, identity, OT, and AI on the Nessus scanner, with external validation beyond its own pages from a Gartner Leader placement in exposure assessment and Tenable Research vulnerability disclosures catalogued in the national vulnerability record. [s5, s9, s10, s17] |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 4/5 | A regulatory filing shows revenue growing 11 percent to $999.4 million, and the company added 502 new enterprise customers in 2025, buyer-side signals that demand for exposure management is expanding. Tenable founded 2002 is not timing-eligible, so this reads present tense. [s3, s15, s17] |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 4/5 | Founders turned the Nessus scanner into a Nasdaq-listed company, a verifiable long-run build in the domain, and the company now runs under co-CEOs Steve Vintz and Mark Thurmond after the death of chief executive Amit Yoran, whose prior roles spanned RSA, NetWitness, and In-Q-Tel. [s7, s16] |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 5/5 | A regulatory filing independently confirms more than 40,000 customers, roughly 65 percent of the Fortune 500, and $999.4 million in revenue with no customer above 2 percent, the third-party-confirmed scale that clears the at-scale bar. [s1, s3, s15] |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 4/5 | Tenable generated $266.8 million of operating cash flow in 2025 and stayed acquisitive while growing revenue, strong output per dollar, but a GAAP operating loss keeps confirmable efficiency below the profitable Qualys 5. [s3, s15] |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 4/5 | A regulatory filing names Tenable inside the recognized vulnerability and exposure-management category beside Qualys and Rapid7, and Gartner named it a Leader in exposure assessment, but those analyst placements are vendor-announced rather than independently fetched, holding this at 4. [s2, s17] |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 3/5 | Tenable's own annual report names the scanning value as contestable by platform bundling from CrowdStrike, Palo Alto Networks, and Wiz and by in-house open-source builds, and the platform embedding through more than 100 integrations creates friction without a structural moat bundling could not eventually replicate. [s2, s8] |
Tenable sells exposure management, the work of finding and fixing the weaknesses across an organization's attack surface before an attacker reaches them. The company frames the pain as fragmented visibility across infrastructure, cloud, identity, operational technology, web applications, and AI, the seams where single-layer tools leave gaps.
The scale of the problem is now visible in an independent record rather than only in marketing. Tenable's annual report to regulators reports more than 40,000 customers, including roughly 65 percent of the Fortune 500 and half of the Global 2000, with no single customer above 2 percent of revenue. That breadth is corroboration that buyers carry budget for the work rather than needing to be taught it exists, even though the pain is stated in category-general terms. [s1, s2, s9]
Tenable runs on Nessus, the vulnerability scanner trusted by tens of thousands of organizations with two million downloads and a twenty-six-year coverage record. The Tenable One platform layers exposure data, more than 100 third-party integrations added through the Vulcan Cyber acquisition, and risk prioritization across sensors spanning IT, cloud, identity, OT, web apps, and AI, so findings across the estate roll into one risk model.
The capability is evidenced beyond the company's own pages. Tenable Research reported a critical remote buffer-overflow flaw in a third-party server that the national vulnerability record independently catalogues, work that shows the offensive-research craft behind the scanner. Cloud Security closes cloud exposure as a CNAPP, Identity Exposure unifies Active Directory and Entra ID without agents, OT Security inventories converged OT, IoT, and IT assets with Safe Active Query, and the newer AI Exposure line detects prompt injection on connected platforms. [s5, s8, s9, s10, s11, s12, s13]
Tenable competes for the exposure-management budget as a recognized leader of the category, with Gartner naming it a Leader in exposure assessment. That standing signals both its position and a crowded field of ranked rivals.
The pressure is documented in Tenable's own regulatory filing, the sharpest evidence of the contest. The filing names Qualys and Rapid7 as direct vulnerability rivals, CrowdStrike as an endpoint vendor adding vulnerability assessment, and Palo Alto Networks and Wiz folding exposure into cloud-security suites buyers already own. The same filing concedes that many organizations build their own scanning in-house from open-source code, which is how Nessus itself began, so the question over the lead is how much of it the platform embedding holds rather than the scan content. [s2, s9, s17]
Tenable reaches enterprise buyers at scale through a hired go-to-market organization, and the traction is documented outside its own marketing. Its annual report to regulators reports $999.4 million in 2025 revenue up 11 percent and more than 40,000 customers, and the full-year results add 502 new enterprise platform customers.
The distribution advantage is cross-sell into an existing base. Because the six exposure lines share the Tenable One platform, a customer that buys vulnerability management can add cloud, identity, OT, or AI coverage through an account relationship the company already holds. The traction is the standout strength of the whole-company record rather than a claim that needs the benefit of the doubt. [s1, s3, s15, s17]
Tenable was founded in September 2002 by Ron Gula, Jack Huffard, and Renaud Deraison, who folded the Nessus scanner in at founding and turned it into a Nasdaq-listed public company, the durable build the franchise still rests on.
Leadership has turned over at the top. Longtime chief executive Amit Yoran, whose career spanned RSA, NetWitness, and In-Q-Tel, died in January 2025, and the company now runs under co-CEOs Steve Vintz and Mark Thurmond. The visible signal is the durable operating record and research organization rather than a single founder-led vision. [s7, s16]
Tenable carries the assurance posture a regulated enterprise buyer expects. It runs a published Trust Center with downloadable compliance documents and holds FedRAMP-authorized cloud security, reinforced by a GSA OneGov agreement to invest further in that federal posture, which supports the government agencies named among its customers.
The posture is table-stakes assurance rather than a standalone advantage. The federal authorization and the published documentation ease procurement and remove a friction point a lightly certified replacement would still face, supporting the regulated and public-sector buyers Tenable serves across many countries. [s14, s17, s1]
| Company | Relationship | Note | Compare |
|---|---|---|---|
| Qualys | competes with | Public vulnerability and exposure-management rival named alongside Tenable in its own regulatory filing. | |
| Rapid7 | competes with | Public exposure-management and detection vendor named as a direct rival in Tenable's regulatory filing. | |
| CrowdStrike | competes with | Endpoint platform vendor adding vulnerability assessment, named as a competitor in Tenable's regulatory filing. | |
| Wiz | competes with | Cloud-native exposure and posture vendor contesting Tenable's cloud and AI surfaces. | |
| Palo Alto Networks | competes with | Platform vendor that bundles exposure and cloud security into suites large accounts already license. | N/AWe scored these companies at different scopes, so the totals measure different things. |
| Microsoft | adjacent | Large platform vendor whose bundled security suites are a standing absorption pressure on standalone exposure tools. | N/AMicrosoft is scored by product line, not as a whole company, so there is no company-wide column to compare. Open its profile to compare a specific product. |
Add analyzed competitors to compare them side by side with Tenable.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
reinforce or reposition
Tenable's durable hold is its customer base and integration depth. A regulatory filing shows the buyers are regulated enterprises and government agencies, roughly 65 percent of the Fortune 500, and their legal and security teams must approve any replacement. Tenable wires six exposure surfaces into Tenable One through more than 100 integrations, so replacement is slow. Scanning accuracy, attack-path analysis, and agentless discovery of operational technology, the industrial control-system environment, take years of engineering. What the customer buys is software it configures and runs, and the Nessus corpus is not a named non-public dataset, a limit its own filing notes when it says some organizations build their own scanning, often with open-source code.
| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 | Customers buy and operate the Tenable One platform and Nessus as software they configure, paying for scanning, correlation, and prioritization features rather than a service in which Tenable accepts accountability for the outcome. |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 | Wiring six exposure surfaces and the broader estate into Tenable One through more than 100 integrations and one risk model creates real friction to replace, short of network effects or mandated residency, since the exposure data stays re-derivable from the customer's own assets. |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 2/3 | Tenable holds FedRAMP-authorized cloud security reinforced by a GSA OneGov agreement and publishes a Trust Center with downloadable compliance documents, though a determined operator could clear the same gates. |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 | Vulnerability scanning at high accuracy, attack-path analysis across identity, agentless OT discovery, and multi-domain correlation take years of specialized engineering, work corroborated by a critical remote vulnerability Tenable Research reported in a third-party server. |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 3/3 | A regulatory filing shows the buyers are regulated enterprises and government agencies, drawn from a base reaching roughly 65 percent of the Fortune 500 with no customer above 2 percent of revenue, the population whose legal and security review sits between the vendor and replacement. |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 2/3 | Tenable One is an agentless control plane that observes, correlates, and rates the estate rather than infrastructure that customer traffic is forced through inline, a platform with application features rather than infrastructure others build on. |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 1/3 | The Nessus coverage corpus is the deepest accumulating detection catalog in vulnerability assessment, but it is not a named non-public cross-customer dataset, a limit Tenable's own filing underscores by noting some organizations build their own scanning, often with open-source code. |
Tenable sells to large, mostly regulated enterprises that buy exposure management across a mixed asset base, the buyer whose procurement and legal review gate any change. A regulatory filing puts roughly 65 percent of the Fortune 500 and half of the Global 2000 in the base, with 502 new enterprise platform customers added in 2025, so the segment is broad enterprise rather than a niche.
The portfolio widens the addressable surface within that base. Tenable One sensors span IT, cloud, identity, OT, web apps, and AI, so a customer can consolidate several exposure budget lines on one platform, and the public sector is reachable through FedRAMP-authorized cloud security and a GSA OneGov agreement. The reach is the strength and the dependence a wary buyer weighs, since the consolidation only pays where the customer standardizes on Tenable.
Tenable runs on Nessus, the vulnerability scanner trusted by tens of thousands of organizations with more than four million downloads and a decades-long coverage record. The Tenable One platform layers exposure data, more than 100 third-party integrations from the Vulcan Cyber acquisition, and risk prioritization across sensors, so findings across the estate roll into one risk model.
The capabilities span six exposure domains rather than one control point, and the engineering is evidenced outside Tenable's own pages. Tenable Research reported a critical remote buffer-overflow flaw in a third-party server that the national vulnerability record independently catalogues. Cloud Security closes cloud exposure as a CNAPP, Identity Exposure unifies Active Directory and Entra ID without agents, OT Security inventories converged OT, IoT, and IT assets through Safe Active Query, and the newer AI Exposure line detects prompt injection. The breadth and the Nessus accuracy are the differentiated work.
Go-to-market runs through a hired enterprise sales motion at scale, and the traction is documented in an independent record. A regulatory filing reports $999.4 million in 2025 revenue up 11 percent, and the full-year results add 502 new enterprise platform customers, traction visible outside marketing copy.
The distribution advantage is cross-sell into an existing base. Because the six exposure lines share the Tenable One platform, a customer that buys vulnerability management can add cloud, identity, OT, or AI coverage through an account relationship the company already holds. The newer AI line is the exception, with capability and category position documented but no named reference customer in the public record.
Tenable does not publish a public rate card for its platform lines, consistent with a vendor selling negotiated enterprise platform agreements to large accounts rather than self-serve subscriptions. The product pages route buyers to a demo request rather than a posted price, so the fetched evidence cannot state a unit of pricing for the platform.
The practical implication follows the consolidation model. The likely path for an existing customer is to add an exposure line to a Tenable One platform agreement rather than buy a separate product, a structure that favors the installed base and leaves a buyer without a transparent way to forecast cost from the public pages.
Delivery is software the customer configures and operates, much of it agentless. Nessus and the Tenable One sensors scan the estate, Identity Exposure runs agentlessly without privileged credentials, and OT Security uses Safe Active Query tuned for cyber-physical networks, so the operational burden is configuration and review rather than standing up bespoke infrastructure for each domain.
Because Tenable runs the cloud platform, findings across the six surfaces land in one inventory and risk model. That concentration is the platform efficiency the company sells and the single-vendor dependence a cautious buyer weighs, since on the Tenable One cloud platform the loop of discovery, prioritization, and reporting runs on infrastructure the customer does not control, while Nessus itself can also deploy on platforms the customer picks.
Trust rests on a long operating record, a public financial position, and a published assurance program. Tenable has run as a Nasdaq-listed public company, a regulatory filing reports $999.4 million in 2025 revenue, and the company publishes a Trust Center with downloadable compliance documents.
The assurance extends to the federal posture buyers in regulated sectors require. Tenable holds FedRAMP-authorized cloud security reinforced by a GSA OneGov agreement, so for a regulated buyer the published documentation and the install base both clear the reviews that gate enterprise security purchases, table-stakes assurance that eases procurement rather than a standalone advantage.
Tenable One is built to be the exposure control plane, and each line is one more surface on it. The homepage describes native signals, exposure intelligence, and third-party data converging to map the entire attack surface across infrastructure, cloud, identity, OT, applications, and AI, with one risk model scoring across them, deepened by more than 100 integrations from the Vulcan Cyber acquisition.
This is the consolidation play and its own counterweight. Standardizing multiple exposure domains on Tenable One concentrates the customer's risk data with one vendor, the efficiency Tenable sells and the dependence a wary buyer weighs against it.
The platform also points to a latent data advantage the public record does not yet evidence. As more customers route findings through Tenable One, the cross-customer signal of which exposures get remediated and which get exploited could in principle sharpen a prioritization model no single-customer rival could match, but nothing in the record shows Tenable operating such a cross-customer learning loop today.
The business is run by an established public-company organization rather than a startup team. Tenable was founded in 2002 by Ron Gula, Jack Huffard, and Renaud Deraison, who folded the Nessus scanner into the company at founding, and it operates as Nasdaq-listed Tenable Holdings.
Leadership turned over at the top in 2025. Longtime chief executive Amit Yoran, whose career spanned RSA, NetWitness, and In-Q-Tel, died in January 2025, and the company now runs under co-CEOs Steve Vintz and Mark Thurmond. The visible signal is the durable build and research organization rather than a single founder-led vision for any newer line.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | Tenable homepage, exposure-management framing | official | 2026-06-23 |
| f2 | Tenable, Inc. (Wikipedia), founding | research | 2026-06-14 |
| f3 | Tenable FY2025 results (GlobeNewswire), dateline | press | 2026-06-14 |
| f4 | AI Defense Matrix Catalog entry | other | 2026-06-13 |
| f5 | AI Defense Matrix Catalog mapping | other | 2026-06-23 |
| f6 | Tenable Vulnerability Management page | official | 2026-06-12 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Tenable Holdings 10-K (FY2025), customer scale and concentration “At December 31, 2025, we had over 40,000 customers, including approximately 65% of the Fortune 500 and approximately 50% of the Global 2000 and large government agencies. In 2025, 2024 and 2023, no single customer represented more than 2% of our revenue.” | regulatory | 2026-06-27 |
| s2 | Tenable Holdings 10-K (FY2025), competition and substitution “Our competitors include: vulnerability management and assessment vendors, including Qualys and Rapid7 ... including CrowdStrike ... such as Palo Alto Networks and Wiz. Many organizations also choose to build their own solutions in-house, often using open-source code.” | regulatory | 2026-06-27 |
| s3 | Tenable Holdings 10-K (FY2025), revenue, operating result, cash flow “Revenue $ 999,405 $ 900,021 $ 798,710 Loss from operations (9,168) (6,856) (52,160) Net loss (36,118) (36,301) (78,284) Net cash provided by operating activities 266,750 217,476 149,855” | regulatory | 2026-06-27 |
| s4 | NVD CVE-2025-36630, SYSTEM-privilege file overwrite in Tenable Nessus (CVSS 8.4 High) “In Tenable Nessus versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrite arbitrary local system files with log content at SYSTEM privilege.” | regulatory | 2026-06-27 |
| s5 | NVD CVE-2025-2263 (CVSS 9.8), critical flaw Tenable Research reported in Sante PACS Server “A stack-based buffer overflow exists if a long encrypted username or password is supplied by an unauthenticated remote attacker.” | regulatory | 2026-06-27 |
| s6 | Calcalist (Meir Orbach): Tenable acquires Apex Security for over $105 million “Despite having raised just $8.6 million, Apex is being acquired for more than $105 million ... Apex's Seed round was co-led by Sequoia Capital and Index Ventures, with participation from angel investors, most notably OpenAI CEO Sam Altman.” | press | 2026-06-27 |
| s7 | TechCrunch: Tenable CEO Amit Yoran dies; co-CEO transition “Before becoming Tenable's CEO in 2016, he held a number of roles, including president of RSA, founding CEO of NetWitness, and CEO of In-Q-Tel ... CFO Steve Vintz and COO Mark Thurmond appointed as co-CEOs in his place.” | press | 2026-06-27 |
| s8 | SecurityWeek: Tenable to acquire Vulcan Cyber for $150 million “Tenable has agreed to buy Vulcan for roughly $150 million, $147 million in cash and $3 million in stock. Customers will benefit from extended third-party data flows through integration with over 100 security products.” | press | 2026-06-27 |
| s9 | Tenable homepage, exposure-management framing and sensors “Native signals, exposure intelligence, and third-party data converge inside Tenable One to map the entire attack surface across your infrastructure, cloud, identity, OT, third party applications, and AI.” | official | 2026-06-27 |
| s10 | Tenable Nessus product page, adoption and tenure “Nessus is trusted by tens of thousands of organizations, with 2 million downloads worldwide. For over twenty-six years, this partnership has driven continuous innovation and optimization.” | official | 2026-06-27 |
| s11 | Tenable Identity Exposure, agentless Active Directory and Entra ID “The identity security solution is completely agentless and does not need privileged credentials, ensuring zero impact on production while delivering instant visibility without increasing your attack surface.” | official | 2026-06-27 |
| s12 | Tenable OT Security, converged OT/IT asset inventory “Build a complete inventory of OT, IoT, and IT assets. Use Safe Active Query to uncover deep device details, including firmware, backplane details, lifecycle data, and known vulnerabilities to eliminate blind spots.” | official | 2026-06-27 |
| s13 | Tenable AI Exposure, AI attack-surface coverage “Detect and stop AI-specific attacks such as prompt injection and jailbreak attempts, and contain risky or compromised AI agents before they cause damage.” | official | 2026-06-27 |
| s14 | Tenable Trust Center (SafeBase), downloadable compliance documents “Use Ask to quickly get answers to your questions without having to sift through the documents within the Trust Center.” | official | 2026-06-27 |
| s15 | Tenable FY2025 results, revenue and cash flow “full year revenue of $999.4 million, up 11% year-over-year; full year net cash provided by operating activities of $266.8 million; full year unlevered free cash flow of $277.0 million.” | press | 2026-06-27 |
| s16 | Wikipedia: Tenable, Inc., founders and listing “Founded September 16, 2002. Founders Ron Gula, Jack Huffard, Renaud Deraison. Traded as Nasdaq: TENB. Headquarters Columbia, Maryland.” | research | 2026-06-27 |
| s17 | Tenable FY2025 results, customers, analyst recognition, federal posture “Added 502 new enterprise platform customers and 5 net new six-figure customers ... Named a Leader in the 2025 Gartner Magic Quadrant for Exposure Assessment Platforms ... Announced agreement with GSA OneGov to further invest in FedRAMP-authorized cloud security capabilities.” | press | 2026-06-27 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Tenable Holdings 10-K (FY2025), customer scale and concentration “At December 31, 2025, we had over 40,000 customers, including approximately 65% of the Fortune 500 and approximately 50% of the Global 2000 and large government agencies. In 2025, 2024 and 2023, no single customer represented more than 2% of our revenue.” | regulatory | 2026-06-27 |
| s2 | Tenable Holdings 10-K (FY2025), competition and substitution “Our competitors include: vulnerability management and assessment vendors, including Qualys and Rapid7 ... including CrowdStrike ... such as Palo Alto Networks and Wiz. Many organizations also choose to build their own solutions in-house, often using open-source code.” | regulatory | 2026-06-27 |
| s3 | Tenable Holdings 10-K (FY2025), revenue, operating result, cash flow “Revenue $ 999,405 $ 900,021 $ 798,710 Loss from operations (9,168) (6,856) (52,160) Net loss (36,118) (36,301) (78,284) Net cash provided by operating activities 266,750 217,476 149,855” | regulatory | 2026-06-27 |
| s4 | NVD CVE-2025-36630, SYSTEM-privilege file overwrite in Tenable Nessus (CVSS 8.4 High) “In Tenable Nessus versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrite arbitrary local system files with log content at SYSTEM privilege.” | regulatory | 2026-06-27 |
| s5 | NVD CVE-2025-2263 (CVSS 9.8), critical flaw Tenable Research reported in Sante PACS Server “A stack-based buffer overflow exists if a long encrypted username or password is supplied by an unauthenticated remote attacker.” | regulatory | 2026-06-27 |
| s6 | Calcalist (Meir Orbach): Tenable acquires Apex Security for over $105 million “Despite having raised just $8.6 million, Apex is being acquired for more than $105 million ... Apex's Seed round was co-led by Sequoia Capital and Index Ventures, with participation from angel investors, most notably OpenAI CEO Sam Altman.” | press | 2026-06-27 |
| s7 | TechCrunch: Tenable CEO Amit Yoran dies; co-CEO transition “Before becoming Tenable's CEO in 2016, he held a number of roles, including president of RSA, founding CEO of NetWitness, and CEO of In-Q-Tel ... CFO Steve Vintz and COO Mark Thurmond appointed as co-CEOs in his place.” | press | 2026-06-27 |
| s8 | SecurityWeek: Tenable to acquire Vulcan Cyber for $150 million “Tenable has agreed to buy Vulcan for roughly $150 million, $147 million in cash and $3 million in stock. Customers will benefit from extended third-party data flows through integration with over 100 security products.” | press | 2026-06-27 |
| s9 | Tenable homepage, exposure-management framing and sensors “Native signals, exposure intelligence, and third-party data converge inside Tenable One to map the entire attack surface across your infrastructure, cloud, identity, OT, third party applications, and AI.” | official | 2026-06-27 |
| s10 | Tenable Nessus product page, adoption and tenure “Nessus is trusted by tens of thousands of organizations, with over 4 million downloads worldwide.” | official | 2026-07-10 |
| s11 | Tenable Identity Exposure, agentless Active Directory and Entra ID “The identity security solution is completely agentless and does not need privileged credentials, ensuring zero impact on production while delivering instant visibility without increasing your attack surface.” | official | 2026-06-27 |
| s12 | Tenable OT Security, converged OT/IT asset inventory “Build a complete inventory of OT, IoT, and IT assets. Use Safe Active Query to uncover deep device details, including firmware, backplane details, lifecycle data, and known vulnerabilities to eliminate blind spots.” | official | 2026-06-27 |
| s13 | Tenable AI Exposure, AI attack-surface coverage “Detect and stop AI-specific attacks such as prompt injection and jailbreak attempts, and contain risky or compromised AI agents before they cause damage.” | official | 2026-06-27 |
| s14 | Tenable Trust Center (SafeBase), downloadable compliance documents “Use Ask to quickly get answers to your questions without having to sift through the documents within the Trust Center.” | official | 2026-06-27 |
| s15 | Tenable FY2025 results, revenue and cash flow “full year revenue of $999.4 million, up 11% year-over-year; full year net cash provided by operating activities of $266.8 million; full year unlevered free cash flow of $277.0 million.” | press | 2026-06-27 |
| s16 | Wikipedia: Tenable, Inc., founders and listing “Founded September 16, 2002. Founders Ron Gula, Jack Huffard, Renaud Deraison. Traded as Nasdaq: TENB. Headquarters Columbia, Maryland.” | research | 2026-06-27 |
| s17 | Tenable FY2025 results, customers, analyst recognition, federal posture “Added 502 new enterprise platform customers and 5 net new six-figure customers ... Named a Leader in the 2025 Gartner Magic Quadrant for Exposure Assessment Platforms ... Announced agreement with GSA OneGov to further invest in FedRAMP-authorized cloud security capabilities.” | press | 2026-06-27 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.