Tüm satıcılar

Vendor lineage

Tenable

Built on a scanner a seventeen-year-old wrote, and then closed the source to fund the company.

In April 1998, aged seventeen, Renaud Deraison released the first version of Nessus. In September 2002 he folded it into a company founded with Ron Gula and Jack Huffard, in Columbia, Maryland. Most sources date the incorporation to 16 September 2002; one gives 4 October, and both are recorded here rather than one being chosen.

Ron Gula had worked at the National Security Agency in the 1990s and written the Dragon intrusion detection system, and the company he founded before this one was sold to Enterasys Networks - which appears elsewhere on this timeline as the enterprise remnant of Cabletron. Marcus Ranum, one of the people who built the first commercial firewalls, joined as chief security officer in 2004.

The decision that defines the company came in October 2005. With the release of Nessus 3 the scanner became proprietary, and the stated reasons were both of them honest: to generate income, and to stop giving competitors a free product to resell. The community forked the last open version, and that fork became OpenVAS, which still exists.

That is worth sitting with rather than judging quickly. A free tool written by a teenager became the default vulnerability scanner in the industry, and the only way to fund the engineering it then needed was to stop it being free. Both the closing and the fork were reasonable responses to the same fact.

Tenable was bootstrapped for a decade. Its first institutional money was a $50M Series A from Accel in September 2012 - ten years in, which is not how the funding narrative usually goes. It went public in 2018, and by 2023 was reporting around $799M in revenue and roughly 44,000 customers including a majority of the Fortune 500.

The product argument has since moved from scanning to prioritisation, because the finding that changed the category was that nobody can patch everything. Risk scoring, and CISA's catalogue of vulnerabilities known to be exploited, replaced completeness with triage - and every vendor in this segment made the same move at roughly the same time.

Founding stories

1998

Nessus

France · Founders: Renaud Deraison

Released in April by a seventeen-year-old, as free software, because the commercial scanners of the day were expensive and the author wanted one. It became the default vulnerability scanner of the internet before there was a company attached to it.

2002

Tenable Network Security

Columbia, Maryland · Founders: Renaud Deraison, Ron Gula, Jack Huffard

Founded on 16 September. Gula had worked at the National Security Agency and written the Dragon intrusion detection system; the combination put a widely deployed scanner and operational detection experience in the same company.

The timeline

  1. Nessus 1.0

    Free, open source, and quickly the standard scanner in the field.

  2. Company founded

    16 September, in Maryland, around the scanner and Gula's detection work.

  3. Nessus 3 closes the source

    In October the scanner became proprietary. The stated reason was funding the engineering; the effect was that a tool the community had helped build stopped being theirs.

  4. First institutional money

    A $50M Series A from Accel, ten years after founding - unusually late, and a sign the business had been funding itself.

  5. NASDAQ listing

    Listed as TENB.

  6. Scale and losses

    Revenue of $799M against an operating loss of $52M with around 2,000 staff - the ordinary shape of a subscription business still buying growth.

Flagship products and solutions

  • NessusThe scanner, still sold directly - Professional for practitioners, Expert adding web application and external attack surface coverage. It remains the reference implementation most engineers have used.
  • Tenable Vulnerability ManagementThe cloud platform built around the scanner, priced per asset, aimed at continuous assessment rather than periodic scans.
  • Tenable Security CenterThe on-premises deployment, for organisations that cannot or will not send scan data to a vendor's cloud - which remains a real requirement in defence and regulated sectors.
  • Tenable OneThe exposure management platform: asset inventory, identity exposure and cloud posture folded into one view alongside vulnerability findings.
  • Tenable OT SecurityIndustrial and operational technology, where passive discovery matters because active scanning can disrupt equipment that was never designed to be probed.

Key innovations

  • Plugin coverage as the actual productA scanner is only as good as its checks, and maintaining tens of thousands of them across every operating system, appliance and library is unglamorous, continuous work. Buyers still decide on this rather than on the platform branding above it.
  • Closing the source to fund the engineeringThe 2005 decision is the company's defining one and cuts both ways. It funded two decades of that maintenance; it also converted community contribution into a commercial asset, and the open-source forks that followed never matched the coverage.
  • Passive discovery for networks you must not disturbWatching traffic to infer what is on a network, rather than probing it, is the only safe approach in industrial environments - and the technique that let vulnerability management reach beyond IT.
  • Prioritisation as the answer to volumeOnce a scan returns fifty thousand findings, the scan is no longer the hard part. Scoring which findings are actually reachable and actually exploited is where the category moved.

Main markets

Enterprise and government, with a strong position in United States federal and defence work that follows from the on-premises option and the founders' background. Priced from a few thousand a year for small estates to six figures for large ones.

It competes directly with Qualys and Rapid7, both on this timeline, and increasingly with cloud-native posture vendors approaching the same problem from the other end.

Analyst standing

  • Consistently placed among the leaders in vulnerability and exposure assessment evaluations, with Nessus itself functioning as the informal benchmark competitors are measured against.
  • The category-wide observation is worth recording: all three of the established vendors are repositioning around exposure management, and none has completed the transition - so purchases are still decided on scanner coverage, scan architecture and risk scoring rather than on the platform branding.