Tenable Company Profile (2026): Cybersecurity
Tenable: The Pioneer of Vulnerability Management Powering Modern Exposure Management
From Nessus — built by a 17-year-old in 1998 — to the Tenable One Exposure Management Platform, Tenable has defined device vulnerability management for six consecutive years with 29% IDC market share, now serving 44,000 customers including 65% of the Fortune 500.
Executive Summary
Tenable, Inc. is the exposure management company that invented accessible vulnerability assessment. Co-founded in September 2002 by NSA veterans Ron Gula, Jack Huffard, and Nessus creator Renaud Deraison, Tenable commercialized the world's most deployed vulnerability scanner into an enterprise platform. In 2026, Tenable operates as a public company (NASDAQ: TENB) headquartered in Columbia, Maryland, with approximately $900M in FY2024 revenue. Its strategy has shifted from standalone vulnerability management to Tenable One, an Exposure Management Platform integrating six products including Tenable Lumin, Tenable.io, Cloud Security, and Attack Surface Management. The transition is working: 40% of new business in Q3 2025 came from exposure solutions, with 437 new enterprise platform customers added in that quarter alone.
Company Overview
Tenable is a pure-play cybersecurity vendor focused on helping organizations understand and reduce cyber exposure across the modern attack surface — IT, cloud, OT, identities, and external assets. The company went public in July 2018 and trades as TENB on NASDAQ.
As of 2025, Tenable serves over 44,000 customers worldwide, including approximately 65% of the Fortune 500 and 65% of the Global 2000. The company has been named the #1 vendor in Device Vulnerability Management by IDC for six consecutive years, holding approximately 29% market share. With more than 1,800 employees globally, Tenable maintains a channel-first model with operations in North America, EMEA, and APAC.
Core differentiation lies in coverage breadth (over 82,000 CVEs, 177,000+ plugins), accuracy via Nessus research heritage, and its move beyond CVSS to risk-based prioritization through Vulnerability Priority Ratings (VPR) and Exposure Scores within Tenable One.
Company History
Tenable's origins trace to Nessus, created in 1998 by Renaud Deraison at age 17 as an open-source remote security scanner while he was a teenager in France. Nessus quickly became the de facto standard for vulnerability scanning.
In September 2002, Ron Gula — a former NSA staffer in the 1990s who developed network intrusion sensors — along with his wife Jack Huffard, who led operations and go-to-market, and Deraison founded Tenable Network Security in Columbia, Maryland. Their thesis: commercialize Nessus with enterprise support, compliance, and reporting.
Key milestones include: 2005 launch of SecurityCenter (now Tenable Security Center) for continuous monitoring; 2006 Nessus closed-source to proprietary with free edition to fund R&D; 2012 Tenable.io precursor with cloud architecture; 2018 IPO raising $250M+ at $23/share; 2019-2023 acquisitions of Indegy (OT), Alsid (AD security), Cymptom (attack path), Bit Discovery (EASM), Ermetic (CNAPP - $265M in 2023); 2022 launch of Tenable One Exposure Management Platform; 2023 introduction of Tenable Cloud Security as integrated CNAPP; 2024-2025 expansion of exposure portfolio with AI-driven ExposureAI capabilities.
Leadership
- Ron Gula – Co-Founder, Former CEO & President (2002-2016): Former NSA 1990s cyber operator; architected early intrusion detection systems; led company from inception to $100M+ ARR before stepping back; now investor and cybersecurity advisor.
- Jack Huffard – Co-Founder: Managed early operations, finance, and GTM. Instrumental in scaling Tenable from services startup to product-led security company; also former spouse of Ron Gula and a key driver of federal market entry.
- Renaud Deraison – Co-Founder & Former CTO: Created Nessus in 1998 at age 17; served as long-time CTO and Chief Research Officer, maintaining Nessus engine and plugin architecture that powers entire portfolio today.
- Steve Vintz – Co-CEO & CFO (Interim Co-CEO since 2024): Joined 2014, led IPO and financial scaling; oversees fiscal discipline while driving platform bundling and profitable growth strategy.
- Mark Thurmond – Co-CEO & COO (Interim Co-CEO since 2024): Former COO responsible for global sales, customer success, and operations; focused on enterprise platform adoption and 40% new business mix from Tenable One.
- Amit Yoran – Former Chairman & CEO (2016-2024, deceased Aug 2024): Transformed company from scanner vendor to cloud-native exposure management leader; championed Tenable One vision.
Products & Services
Tenable's portfolio has consolidated from point products into a unified exposure management platform while maintaining best-of-breed standalone scanners for researchers and SMBs.
Nessus Family – The World's Most Deployed Vulnerability Scanner
Nessus Professional, Nessus Essentials (free, 16 IPs), and Nessus Expert remain the industry baseline for vulnerability assessment. Over 2M+ downloads, 82,000+ CVEs covered, with continuous plugin updates from Tenable Research. The foundation of all enterprise products.
Tenable.io / Tenable Vulnerability Management
Cloud-native SaaS vulnerability management — asset discovery, continuous scanning, risk-based prioritization via VPR, and compliance auditing. Core of mid-market adoption and legacy cloud transition from Security Center.
Tenable Security Center
On-premises/legacy version of continuous network monitoring for federal, highly regulated, and air-gapped environments. Deep integration with SIEMs and ITSM.
Tenable One Exposure Management Platform
Flagship platform launched 2022, built on six integrated products: Tenable Lumin (risk analytics and board reporting), Tenable Vulnerability Management (io), Tenable Cloud Security, Tenable Attack Surface Management (from Bit Discovery), Tenable Identity Exposure (from Alsid – Active Directory), and Tenable OT Security (from Indegy). Provides unified Exposure View, Attack Path Analysis, and benchmarked Security Score.
Tenable Cloud Security – CNAPP
Cloud Native Application Protection Platform created from Ermetic acquisition ($265M, 2023) plus prior cloud assets. Offers CSPM, CIEM, Cloud Workload Protection, Kubernetes security, IaC scanning, and Just-in-Time access. Competes directly with Wiz and Palo Alto Prisma Cloud.
Tenable Identity, OT & External Attack Surface
Tenable Identity Exposure secures Active Directory and Entra ID misconfigurations — a leading cause of ransomware. Tenable OT Security covers IT/OT converged environments. Tenable ASM discovers unknown internet-facing assets. Together they extend visibility beyond traditional IT devices.
Business Model & Platform Strategy
Tenable operates a subscription SaaS model (90%+ recurring) with tiered packaging from single-scanner Nessus licenses to enterprise-wide Tenable One Exposure Management bundles. Pricing is asset-based (IP/FQDN/container identity) with add-ons for cloud, AD, OT, and EASM.
The strategic pivot since 2022 is consolidation: moving customers from single-product Nessus/Security Center or Tenable.io to Tenable One platform deals. This increases net dollar retention, expands ARPU, and positions Tenable as a platform vs point solution — critical against Wiz, CrowdStrike Exposure Management, and Palo Alto. In Q3 2025, exposure solutions drove 40% of new business, and platform customer count is growing 437 enterprise logos per quarter.
Go-to-market remains channel-heavy (MSSPs, VARs, Big Four), with 50%+ revenue via partners, plus federal (DHS CDM program), and OEM integrations embedded in ServiceNow, Splunk, and Microsoft Defender workflows.
AI strategy is pragmatic: ExposureAI provides generative summaries, prioritized remediation guidance, and natural language search across exposure data, rather than autonomous remediation. All AI features run on Tenable's curated vulnerability dataset rather than external LLM training data.
Financial Performance
| Period | Revenue | Growth / Comment |
|---|---|---|
| FY2024 (Full Year) | ~$900M | +13% YoY; transition year to exposure platform |
| Q1 2024 | $216M | +14% YoY; calculated current billings $208.5M |
| Q3 2025 | $252.4M | +11.2% YoY; beat consensus; 116% NDR; 40% new biz from exposure |
| Scale Metrics (2025) | 44K customers | 65% Fortune 500, 65% Global 2000; 29% IDC share – #1 for 6 years |
| Platform Momentum | 437 new enterprise platform customers (Q3'25) | Tenable One & Cloud Security driving new logo + expansion |
Tenable is profitable on non-GAAP basis with strong free cash flow, balancing growth investment in Tenable One and Cloud Security while maintaining efficient GTM. The acquisition of Ermetic added near-term dilution but accelerated CNAPP relevance.
Competitive Landscape
Tenable competes across three layers: traditional vulnerability management (Qualys, Rapid7 InsightVM), modern cloud security / CNAPP (Wiz, Palo Alto Prisma Cloud, CrowdStrike, Sysdig, Orca Security), and emerging exposure management platforms (CrowdStrike Falcon Exposure Management, ServiceNow VR, Microsoft Defender Vulnerability Management).
Qualys remains the closest legacy rival in VMDR; Rapid7 competes on InsightVM + AppSec. In cloud, Wiz is the high-growth disruptor with agentless speed, while Tenable counters with breadth across cloud, identity, and OT in a single exposure view. Its moat is research depth (Nessus heritage), federal trust, and data normalization across 6 domains — competitors often specialize in one.
Risk: Wiz and native hyperscaler tools (Microsoft Defender) commoditize basic cloud vuln scanning; Tenable must prove premium value of unified exposure analytics.
Key Takeaways
- From Teen Project to Market Leader: Renaud Deraison's Nessus built at age 17 in 1998 became the kernel that Ron Gula and Jack Huffard commercialized in 2002, now the most deployed scanner and the data engine for Tenable One.
- Exposure Management is the Real Pivot: Tenable One unifies 6 products (Lumin, Vulnerability Management, Cloud Security, ASM, Identity Exposure, OT) into a single risk-based platform, shifting narrative from CVE counts to business-aligned exposure scores.
- Financially Executing Despite Transition: Q1'24 $216M (+14%), FY24 ~$900M (+13%), and Q3'25 $252.4M (+11.2% beat) show durable double-digit growth while 40% of new business now comes from exposure solutions.
- Dominant in Core Category: IDC ranks Tenable #1 in Device Vulnerability Management for 6 straight years with ~29% share — rare consistency in a crowded security market, underpinning 44K customers and 65% Fortune 500 penetration.
- CNAPP Bet is Critical: Tenable Cloud Security, built on the $265M Ermetic acquisition, positions Tenable in CNAPP against Wiz/Palo Alto; success depends on converting legacy VM customers to full cloud-to-identity exposure coverage.
- Channel and Federal Moat with Platform Upsell: Columbia MD roots, NSA lineage, and strong federal presence (CDM) plus 437 new enterprise platform customers in Q3'25 indicate land-and-expand is working beyond traditional scanner renewal cycles.
References
- Tenable, Inc. Company History – Tenable Network Security founded Sept 2002; founders Ron Gula, Jack Huffard, Renaud Deraison
- Nessus History – Renaud Deraison created Nessus 1998 age 17; Wikipedia & Tenable Research
- Ron Gula Background – NSA 1990s, network intrusion systems architect – Tenable Founding Story
- Tenable Corporate – HQ Columbia, MD; NASDAQ: TENB; 44K customers; 65% Fortune 500
- Tenable One Exposure Management Platform – Built on 6 products including Lumin, io, Cloud Security, ASM – Tenable.com 2022 launch
- Tenable Cloud Security – CNAPP overview – Ermetic acquisition Sept 2023 $265M
- Tenable Financials – Q1 2024 $216M +14% YoY – Tenable Investor Relations
- Tenable Financials – FY2024 ~13% growth ~$900M – Earnings transcript 2024
- Tenable Financials – Q3 2025 $252.4M +11.2% beat; 40% new biz from exposure solutions; 437 new enterprise platform customers – Earnings Release Oct 2025
- IDC Device Vulnerability Management – #1 for 6 years – 29% market share – IDC MarketScape 2024