Best Risk-Based Vulnerability Management Software - Page 6

How Many Risk-Based Vulnerability Management Software Products Does G2 Track?

Total Products under this Category: 194

Category Stats (Aug 2026)

  • Average Rating: 4.48/5 (↓0.02 vs Jul 2026) The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: Ivanti Neurons for RBVM (+2.94%) - Among all products in this category, Ivanti Neurons for RBVM recorded the largest rating increase compared to last month

Last updated: August 07, 2026

How Does G2 Rank Risk-Based Vulnerability Management Software Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 4,800+ Authentic Reviews
  • 194+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Risk-Based Vulnerability Management Software

G2 Grid® for Risk-Based Vulnerability Management Software plotting products by satisfaction and market presence

Highlighted products: Arctic Wolf, Tenable Vulnerability Management, Recorded Future, RiskProfiler - External Threat Exposure Management, YesWeHack, H1 Platform, Check Point Exposure Management, and Pentera.

Underlying data: [Grid® JSON](https://www.g2.com/categories/risk-based-vulnerability-management/grids.json?focus%5B%5D=arctic-wolf&focus%5B%5D=tenable-vulnerability-management&focus%5B%5D=recorded-future&focus%5B%5D=riskprofiler-external-threat-exposure-management&focus%5B%5D=yeswehack&focus%5B%5D=h1-platform&focus%5B%5D=check-point-exposure-management&focus%5B%5D=pentera)

Sponsored

Silobreaker

Silobreaker is a technology company that builds solutions that unify data, contextual analysis, and human expertise to deliver decision-grade intelligence when and where it matters most. Continually refined for both leadership and analysts operating across business resilience, enterprise security, threat, and risk disciplines, the Silobreaker intelligence layer uses a proprietary search and entity database to automate the production of intelligence across cyber, geopolitical, and physical domains. Using Silobreaker's priority intelligence requirements (PIR)-driven workflows, agentic automation, MCP-enabled integrations, and executive-ready reporting, governments and global enterprises can anticipate threats, protect assets and people, accelerate decision-making, and steer through uncertainty with confidence.

Visit website

Senteon System Hardening

Senteon is a game-changer in the cybersecurity landscape, designed specifically to meet the needs of enterprises and MSPs/MSSPs. Our platform takes the complexity out of hardening workstations, servers, and browsers, automating the process to ensure the highest security standards in minutes. This comprehensive overview aims to provide a deep dive into what makes Senteon a critical asset for your security posture, with a focus on technology, education, and strategic partnerships. Advanced Automated Hardening Automated CIS Benchmark Compliance Senteon automatically aligns your systems with the latest CIS Benchmarks. This automation removes the manual burden of configuration, reducing human error and ensuring that your security measures are always up-to-date. Registry-Level Security Changes Unlike traditional methods that depend on Intune, Group Policy, or PowerShell, Senteon operates directly at the registry level. This ensures that security policies are applied reliably, minimizing the risk of configuration drift and maximizing effectiveness. Learning Mode for Non-Disruptive Hardening Our innovative learning mode assesses the impact of security settings before applying them. This feature allows you to implement security measures seamlessly, maintaining business continuity while enhancing your security posture. Real-Time Monitoring and Enforcement Senteon continuously monitors your endpoints, enforcing security settings in real-time. This proactive approach prevents configuration drift and keeps your systems secure without constant manual intervention. Comprehensive Compliance and Reporting Compliance Across Multiple Standards Senteon generates detailed compliance reports, aligning with various regulatory standards such as NIST 800-53, NIST 800-171, CMMC, HIPAA, PCI-DSS, SOC2, and more. These reports simplify audits, providing clear evidence of your security measures and ensuring you meet regulatory requirements with ease. Detailed Change Tracking and Audit Trails Our platform logs all security changes, offering a transparent record for audits and compliance reviews. This detailed tracking helps maintain a robust security posture and demonstrates your commitment to security and compliance. Direct Integration with Win32 APIs Senteon integrates directly with Win32 APIs, allowing for single-click deployments and consistent configuration updates. This ensures near-perfect execution and simplifies the management of security settings across all endpoints. Strategic Education and Partnerships Weekly Webinar Series with CIS In partnership with the Center for Internet Security (CIS), Senteon hosts a weekly webinar series. These sessions cover practical applications of CIS Benchmarks, security best practices, and regulatory compliance, providing valuable education to help you stay informed and prepared. Global Reach with Strategic Partnerships Senteon has a global presence, with distributors in the EU, UK, and APAC regions. Our strategic partnerships with leading organizations, including CIS, enhance our capabilities and provide additional resources for our clients. Expert Support and Training Benefit from Senteon’s expert support and training programs, designed to help you maximize your security investment. Our team is available to assist with onboarding, troubleshooting, and ongoing education, ensuring you have the knowledge and resources to maintain a strong security posture. Future-Ready Security Measures Continuous Improvement with Regular Updates Senteon is committed to continuous improvement, regularly updating our platform to incorporate the latest security best practices and benchmarks. This ensures your security measures remain current and effective against evolving threats. Professional Services for Enhanced Security Access tailored professional services to further enhance your security measures. Senteon offers compliance certification assistance, penetration testing, and customized security solutions to help you implement and manage your security policies effectively. ROI and Operational Efficiency Maximizing ROI Senteon delivers significant ROI by automating system hardening and compliance processes, reducing the time and effort required for these critical tasks. This allows your IT team to focus on higher-value projects and reduces the risk of costly security incidents. Standardized Configurations for Efficiency By standardizing configurations across all endpoints, Senteon reduces troubleshooting time and enhances overall operational efficiency. This streamlining of processes not only boosts productivity but also ensures a consistent and secure environment. Senteon is the premier solution for automated endpoint hardening, offering comprehensive security and compliance for enterprises and MSPs/MSSPs. Our platform's advanced features, robust automation capabilities, and commitment to continuous improvement make Senteon the ideal choice for organizations seeking to enhance their security posture and ensure regulatory compliance. Join the many businesses that trust Senteon to safeguard their digital assets and experience the future of cybersecurity today.

Average Rating: 4.9/5.0

Total Reviews: 9

How Do G2 Users Rate Senteon System Hardening?

  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 9.2/10)
  • Reporting: 10.0/10 (Category avg: 8.8/10)
  • Risk-Prioritization: 10.0/10 (Category avg: 8.8/10)

Who Is the Company Behind Senteon System Hardening?

  • Seller: Senteon
  • Year Founded: 2019
  • HQ Location: Marietta, US
  • LinkedIn® Page: www.linkedin.com
    28 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 89% Small, 11% Medium

What Do G2 Reviewers Say About Senteon System Hardening?

AI-generated summary from verified user reviews

Pros
  • Users value the automation capabilities of Senteon, allowing easy control, monitoring, and reporting of system configurations.
  • Users value the elimination of tedious compliance tasks that Senteon offers, enhancing system security and management efficiency.
  • Users appreciate the granular control and visibility Senteon offers, streamlining configuration management and enhancing system security.
  • Users appreciate the smooth integration capabilities of Senteon, enhancing automation and control for varied client needs.
  • Users value the deep policy-level visibility and granular control in Senteon, enhancing configuration management effortlessly.
Cons
  • Users note that the API's read-only limitations restrict automation capabilities, though improvements are anticipated soon.
  • Users note the lack of automation due to the API being read-only, limiting some desired implementations.
  • Users note the read-only API limitation, hindering desired automation despite strong documentation and potential improvements.
  • Users note the limited automation due to read-only API, but appreciate the ongoing improvements from the Senteon team.

What Are Recent G2 Reviews of Senteon System Hardening?

Threadfix

ThreadFix 3.0 provides a comprehensive view of your risk from applications and their supporting infrastructure. Skip the spreadsheets and PDFs forever.

Average Rating: 3.7/5.0

Total Reviews: 3

How Do G2 Users Rate Threadfix?

  • Reporting: 8.3/10 (Category avg: 8.8/10)
  • Vulnerability Intelligence: 8.3/10 (Category avg: 8.7/10)
  • Risk-Prioritization: 8.3/10 (Category avg: 8.8/10)

Who Is the Company Behind Threadfix?

  • Seller: Denim Group
  • HQ Location: N/A
  • Twitter: @denimgroup
    1,371 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    1 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 33% Small, 33% Large

What Are Recent G2 Reviews of Threadfix?

What Are G2 Users Discussing About Threadfix?

Tromzo

Tromzo accelerates risk remediation from code to cloud. As modern development teams are deploying code and infrastructure rapidly across many pipelines, security teams are facing significant gaps in visibility of who is deploying what artifacts and where. To keep up with this, most security teams have deployed a myriad of security scanning tools that report issues at each layer of the stack. While these security tools generate an overwhelming volume of issues, they also lack context and live in separate data silos making them unactionable. This leads to slowing remediation and growing risk. Tromzo solves this challenge by accelerating the remediation of risks at every layer from code to cloud. We do this by building a prioritized risk view of the entire software supply chain with context from code to cloud. This context helps our users understand which few assets are critical to the business, prevent risks from being introduced to those critical assets and automate the remediation lifecycle of the few issues that truly matter.

Average Rating: 3.3/5.0

Total Reviews: 3

How Do G2 Users Rate Tromzo?

  • Has the product been a good partner in doing business?: 8.9/10 (Category avg: 9.2/10)
  • Reporting: 6.7/10 (Category avg: 8.8/10)
  • Vulnerability Intelligence: 5.8/10 (Category avg: 8.7/10)
  • Risk-Prioritization: 4.2/10 (Category avg: 8.8/10)

Who Is the Company Behind Tromzo?

  • Seller: Tromzo
  • Year Founded: 2021
  • HQ Location: Mountain View, US
  • Twitter: @TromzoSecurity
    127 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    16 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 100% Medium

What Are Recent G2 Reviews of Tromzo?

Upwind

Upwind is the runtime-first cloud security platform that secures your deployments, configurations, and applications by providing real-time visibility from the inside out. We’ve built a unified fabric that maps your environment as it runs - revealing what’s truly at risk, what’s actively happening, and how to respond quickly and effectively. With Upwind, security, dev, and ops teams move faster, stay focused, and fix risks that matter most.

Average Rating: 4.9/5.0

Total Reviews: 8

How Do G2 Users Rate Upwind?

  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 9.2/10)
  • Reporting: 10.0/10 (Category avg: 8.8/10)
  • Vulnerability Intelligence: 10.0/10 (Category avg: 8.7/10)
  • Risk-Prioritization: 10.0/10 (Category avg: 8.8/10)

Who Is the Company Behind Upwind?

  • Seller: Upwind
  • Company Website:
  • Year Founded: 2022
  • HQ Location: San Francisco, California, United States
  • LinkedIn® Page: www.linkedin.com
    217 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 75% Medium, 25% Large

What Do G2 Reviewers Say About Upwind?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the ease of use of Upwind, praising its intuitive design and quick integration capabilities.
  • Users value the excellent visibility provided by Upwind, enhancing risk management and issue tracing effectively.
  • Users commend the exceptional customer support of Upwind, highlighting responsiveness and dedication to resolving issues.
  • Users appreciate the fast real-time detection efficiency of Upwind, effortlessly identifying and resolving threats.
  • Users find Upwind's implementation ease exceptional, making deployment in AWS a seamless experience.
Cons
  • Users often feel overwhelmed by the large number of vulnerability findings due to high visibility levels in Upwind.
  • Users note the need for improvement in compliance issues, particularly regarding NIST and GDPR reporting features.
  • Users struggle with the inability to bulk resolve or suppress alerts, which hampers effective data management.
  • Users find the data overload from numerous vulnerability findings to be overwhelming and hard to manage.
  • Users experience false positives in alerts, finding it difficult to bulk resolve or suppress them effectively.

What Are Recent G2 Reviews of Upwind?

Autobahn Security

Autobahn Security is a cyber security platform that supports your company’s vulnerability management initiatives by consolidating, prioritizing, and remediating issues efficiently and transparently. We provide Cyber Fitness Workouts – actionable remediation guides that will help your IT team optimize your IT-System against hackers, easily and quickly, even without security expertise.

Average Rating: 5.0/5.0

Total Reviews: 2

How Do G2 Users Rate Autobahn Security?

  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 9.2/10)
  • Reporting: 9.2/10 (Category avg: 8.8/10)
  • Vulnerability Intelligence: 6.7/10 (Category avg: 8.7/10)
  • Risk-Prioritization: 8.3/10 (Category avg: 8.8/10)

Who Is the Company Behind Autobahn Security?

Who Uses This Product?

  • Company Size: 100% Small

What Are Recent G2 Reviews of Autobahn Security?

Balbix

The Balbix Security Cloud uses AI and automation to reinvent how the world’s leading organizations reduce breach risk. With Balbix, security teams can now accurately inventory their cloud and on-premise assets, conduct risk-based vulnerability management, and quantify their cyber risk in monetary terms. Security leaders can measure and improve SLA compliance and other metrics in real time, show ROI for their cybersecurity program, and confidently report on their security posture to the board of directors and other stakeholders.

Average Rating: 4.8/5.0

Total Reviews: 2

How Do G2 Users Rate Balbix?

  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 9.2/10)
  • Reporting: 10.0/10 (Category avg: 8.8/10)
  • Vulnerability Intelligence: 10.0/10 (Category avg: 8.7/10)
  • Risk-Prioritization: 10.0/10 (Category avg: 8.8/10)

Who Is the Company Behind Balbix?

  • Seller: Balbix
  • Year Founded: 2015
  • HQ Location: San Jose California ,United States
  • LinkedIn® Page: www.linkedin.com
    124 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 50% Medium, 50% Large

What Do G2 Reviewers Say About Balbix?

AI-generated summary from verified user reviews

Pros
  • Users value the customizable and relevant dashboards of Balbix, enhancing their ability to access tailored data insights.
  • Users value the customizable and relevant dashboards that fit their specific needs and provide valuable insights.
Cons
  • Users find that Balbix lacks industry-tier separation, making risk management less tailored to specific needs.

What Are Recent G2 Reviews of Balbix?

BMC Helix Remediate

BMC Helix Remediate uses advanced analytics and automation to rapidly remediate security vulnerabilities for both on-premises and cloud-based infrastructure.

Average Rating: 3.3/5.0

Total Reviews: 2

How Do G2 Users Rate BMC Helix Remediate?

  • Risk-Prioritization: 6.7/10 (Category avg: 8.8/10)

Who Is the Company Behind BMC Helix Remediate?

Who Uses This Product?

  • Company Size: 50% Large, 50% Medium

What Are Recent G2 Reviews of BMC Helix Remediate?

What Are G2 Users Discussing About BMC Helix Remediate?

CyCognito

CyCognito is a cybersecurity solution designed to help organizations discover, test, and prioritize security issues across their digital landscape. By leveraging advanced artificial intelligence, CyCognito scans billions of websites, cloud applications, and APIs to identify potential vulnerabilities and critical risks. This proactive approach enables organizations to address security concerns before they can be exploited by malicious actors, thereby enhancing their overall security posture. The target audience for CyCognito includes emerging companies, government agencies, and Fortune 500 organizations, all of which face increasing threats in today's digital environment. These entities require robust security measures to protect sensitive data and maintain compliance with various regulations. CyCognito serves as an essential tool for security teams, providing them with the insights needed to understand their risk exposure and prioritize remediation efforts effectively. One of the key features of the CyCognito platform is its comprehensive scanning capability, which covers a vast range of digital assets. This extensive reach ensures that organizations can identify vulnerabilities across all their online presence, including third-party services and shadow IT. The platform's AI-driven analysis further enhances its effectiveness by automatically assessing the severity of identified risks, allowing security teams to focus on the most critical issues that could lead to significant breaches. In addition to risk discovery, CyCognito offers actionable guidance for remediation, helping organizations to implement effective security measures. The platform provides detailed insights into the nature of the vulnerabilities and suggests specific steps to mitigate them. This feature not only streamlines the remediation process but also empowers organizations to build a more resilient security framework over time. By integrating CyCognito into their cybersecurity strategy, organizations can significantly reduce their risk exposure and enhance their ability to respond to emerging threats. The platform's unique combination of extensive scanning, AI-driven risk assessment, and actionable remediation guidance positions it as a valuable asset for any organization looking to strengthen its security posture in an increasingly complex threat landscape.

Average Rating: 4.3/5.0

Total Reviews: 5

How Do G2 Users Rate CyCognito?

  • Has the product been a good partner in doing business?: 8.3/10 (Category avg: 9.2/10)
  • Reporting: 7.5/10 (Category avg: 8.8/10)
  • Vulnerability Intelligence: 8.3/10 (Category avg: 8.7/10)
  • Risk-Prioritization: 8.3/10 (Category avg: 8.8/10)

Who Is the Company Behind CyCognito?

  • Seller: CyCognito
  • Year Founded: 2017
  • HQ Location: Palo Alto, California, United States
  • Twitter: @CyCognito
    10,296 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    137 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 80% Small, 20% Large

What Do G2 Reviewers Say About CyCognito?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the fast and effective customer support of CyCognito, enhancing their overall experience with the product.
  • Users value CyCognito for its ability to identify hidden assets and prioritize risks, enhancing security effortlessly.
  • Users value the continuous monitoring of CyCognito, effectively detecting threats to external assets.
Cons
  • Users express frustration with authentication issues, as false positives lead to unresponsive support and delays in resolution.
  • Users indicate that the pricing of CyCognito is expensive and would prefer a reduction for better value.
  • Users experience a significant number of false positives, leading to frustration and lack of timely support responses.
  • Users find the inadequate remediation steps lacking detail, necessitating manual handling of issues and vulnerabilities.
  • Users find the lack of detailed remediation steps in CyCognito frustrating, requiring manual intervention for issues.

What Are Recent G2 Reviews of CyCognito?

H2Cyber

At H2Cyber our product is designed for small businesses. We are teaching you the basic arithmetic of cybersecurity via our prioritized approach. This will allow your business to grow over time and move to a more robust cybersecurity framework if needed as all our controls are aligned to the five basic functions of the NIST Cybersecurity Framework (Identify, Protect, Detect, Respond, and Recovery). Our prioritized approach takes the guessing out of where to start. We have identified 77 controls and spread them out over 7 phases to help you easily manage your Cybersecurity program. Implementation times generally take between 17 and 35 weeks if you are starting from scratch.

Average Rating: 5.0/5.0

Total Reviews: 2

Who Is the Company Behind H2Cyber?

  • Seller: H2Cyber
  • Year Founded: 2009
  • HQ Location: Prosper, US
  • LinkedIn® Page: www.linkedin.com
    2 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 100% Small

What Are Recent G2 Reviews of H2Cyber?

Hacknoid

CONTINUOUS VULNERABILITY DETECTION, ANALYSIS AND MANAGEMENT PLATFORM Your entire attack surface, automatically, continuously monitored with a unified view. Hacknoid automates vulnerability detection across all your network’s systems and devices, providing visibility and prioritizing alerts to help you optimize remediation efforts. We keep your asset inventory up to date and perform 24/7 automatic and intelligent analysis across your entire tech environment, enabling you to manage risks practically, simply, and proactively.

Average Rating: 4.6/5.0

Total Reviews: 4

How Do G2 Users Rate Hacknoid?

  • Has the product been a good partner in doing business?: 9.4/10 (Category avg: 9.2/10)
  • Reporting: 10.0/10 (Category avg: 8.8/10)
  • Vulnerability Intelligence: 10.0/10 (Category avg: 8.7/10)
  • Risk-Prioritization: 10.0/10 (Category avg: 8.8/10)

Who Is the Company Behind Hacknoid?

  • Seller: Hacknoid
  • Year Founded: 2013
  • HQ Location: Montevideo, UY
  • LinkedIn® Page: www.linkedin.com
    14 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 50% Medium, 25% Small

What Do G2 Reviewers Say About Hacknoid?

AI-generated summary from verified user reviews

Pros
  • Users love the continuous scanning feature, providing automatic background protection and effective risk management.
  • Users value the customization control of Hacknoid, allowing effective prioritization of real vulnerabilities effortlessly.
  • Users value the continuous scanning feature, as it effectively identifies and prioritizes real risks effortlessly.
  • Users value the continuous scanning efficiency of Hacknoid, as it autonomously identifies and prioritizes real risks.
  • Users value the continuous scanning feature of Hacknoid, allowing them to focus on real risks effortlessly.

What Are Recent G2 Reviews of Hacknoid?

Holm Security VMP

Holm Security’s unified platform delivers continuous, automated visibility and protection across millions of critical assets through a single unified platform - with one workflow and risk model. Our all-in-one platform provides a market-leading combination of Attack Surface Management (ASM) and vulnerability & exposure management, creating an efficient, proactive cyber defense. Use this platform to automatically identify new assets, monitor asset changes, eliminate blind spots, detect shadow IT, and find vulnerabilities. Holm Security’s platform is developed in Europe and delivered from European data centers, ensuring that sensitive data remains within the EU. Our European foundation reflects a strong commitment to data sovereignty, compliance, and secure development practices, providing organizations with a trusted and reliable framework for protecting critical assets.

Average Rating: 2.5/5.0

Total Reviews: 2

How Do G2 Users Rate Holm Security VMP?

  • Has the product been a good partner in doing business?: 5.0/10 (Category avg: 9.2/10)
  • Reporting: 8.3/10 (Category avg: 8.8/10)
  • Vulnerability Intelligence: 8.3/10 (Category avg: 8.7/10)
  • Risk-Prioritization: 5.0/10 (Category avg: 8.8/10)

Who Is the Company Behind Holm Security VMP?

Who Uses This Product?

  • Company Size: 50% Medium, 50% Small

What Do G2 Reviewers Say About Holm Security VMP?

AI-generated summary from verified user reviews

Pros
  • Users value the auth scanning and phishing simulation capabilities of Holm VMP, benefiting from various templates.
  • Users benefit from the increased awareness through comprehensive phishing simulations and various templates offered by Holm Security VMP.
  • Users value the innovation in phishing simulations offered by Holm Security VMP, enhancing security awareness effectively.
  • Users value the scanning efficiency of Holm Security VMP, benefiting from its robust authentication and phishing simulations.
Cons
  • Users experience frequent false positives with Holm Security VMP, leading to unreliable vulnerability assessments.
  • Users face frequent scanning issues with Holm Security VMP, including numerous false positives and failed scans.
  • Users report technical issues with Holm VMP, including frequent false positives and multiple scanning failures.

RiskRecon

Gain objective insight into your third-party security performance and IT landscape

Average Rating: 4.5/5.0

Total Reviews: 2

How Do G2 Users Rate RiskRecon?

  • Reporting: 8.3/10 (Category avg: 8.8/10)
  • Vulnerability Intelligence: 8.3/10 (Category avg: 8.7/10)
  • Risk-Prioritization: 8.3/10 (Category avg: 8.8/10)

Who Is the Company Behind RiskRecon?

  • Seller: RiskRecon
  • Year Founded: 2013
  • HQ Location: Salt Lake City, US
  • Twitter: @riskrecon
    651 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    98 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 50% Large, 50% Small

What Are Recent G2 Reviews of RiskRecon?

What Are G2 Users Discussing About RiskRecon?

Sonatype Lifecycle

Continuously secure your software supply chain with Sonatype Nexus Lifecycle, a software composition analysis (SCA) solution. Nexus Lifecycle helps development, security, and compliance teams reduce open source risk without slowing delivery. It detects vulnerable or non-compliant components early, provides clear remediation guidance, and enforces the same policies from development through CI/CD and release - powered by Sonatype Nexus Intelligence. Choose safer components up front: A Chrome extension and IDE integrations surface vulnerability, license, and quality insights as developers browse public repositories or add dependencies. Fix issues fast where work happens: In Eclipse, IntelliJ, and Visual Studio, developers can see exactly what's wrong and upgrade to an approved version with a click - no guesswork. Automate remediation in source control: Integrations with GitHub, GitLab, and Atlassian Bitbucket can comment on pull/merge requests and identify the specific dependency change that introduces risk, along with recommended versions to resolve it. You can also generate automated pull requests to update components that violate policy. Enforce open source policies across the SDLC: Create security, license, and architectural policies tailored by application type, team, or organization, then apply them consistently in developer tools, CI/CD, and repositories to prevent risky components from reaching production. Generate SBOMs in minutes: Produce accurate Software Bills of Materials (SBOMs) per application to understand what components and transitive dependencies are in use and verify compliance. Prove progress with reporting: Track trends like Mean Time to Resolution (MTTR) and violation reduction over time to demonstrate measurable risk reduction to stakeholders. Nexus Lifecycle integrates with common developer, CI/CD, and repository tools including Nexus Repository, Artifactory, Jira, Jenkins, Azure DevOps, and more.

Average Rating: 4.2/5.0

Total Reviews: 3

How Do G2 Users Rate Sonatype Lifecycle?

  • Has the product been a good partner in doing business?: 6.7/10 (Category avg: 9.2/10)

Who Is the Company Behind Sonatype Lifecycle?

  • Seller: Sonatype
  • Year Founded: 2008
  • HQ Location: Fulton, US
  • Twitter: @sonatype
    10,589 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    553 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 75% Large, 25% Medium

What Are Recent G2 Reviews of Sonatype Lifecycle?

Tenable Identity Exposure

Get real-time, unified visibility into Active Directory and Entra ID identities to help organizations proactively reduce identity-based cyber risks. By mapping pre-configured Indicators of Exposure to identities, it highlights the severity of associated risks, including misconfigurations, privilege escalation risks and structural security gaps. It continuously monitors identity attack paths and presents vulnerabilities through graphical views. Misconfigurations, exposures, and attack paths are identified and remediated in real time to reduce the AD and Entra ID attack surface. With risk-based prioritization and guided remediation, security teams can strengthen identity posture and prevent breaches without requiring agents or elevated privileges. As part of Tenable’s AI-powered exposure management platform, it brings identity context to your broader risk picture—delivering the visibility and control needed to reduce organizational risk.

Average Rating: 4.4/5.0

Total Reviews: 5

How Do G2 Users Rate Tenable Identity Exposure?

  • Has the product been a good partner in doing business?: 9.4/10 (Category avg: 9.2/10)
  • Reporting: 9.2/10 (Category avg: 8.8/10)
  • Vulnerability Intelligence: 9.2/10 (Category avg: 8.7/10)
  • Risk-Prioritization: 10.0/10 (Category avg: 8.8/10)

Who Is the Company Behind Tenable Identity Exposure?

  • Seller: Tenable
  • Company Website:
  • HQ Location: Columbia, MD
  • Twitter: @TenableSecurity
    87,752 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    2,350 employees on LinkedIn®
  • Ownership: NASDAQ: TENB

Who Uses This Product?

  • Company Size: 40% Large, 40% Medium

What Do G2 Reviewers Say About Tenable Identity Exposure?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the real-time monitoring of Tenable Identity Exposure, enhancing visibility and reducing breach detection time significantly.
  • Users appreciate the clear and actionable visibility Tenable Identity Exposure offers, enhancing proactive identity risk management.
  • Users value the clear and actionable visibility of Tenable Identity Exposure, enhancing identity risk management and security posture.
  • Users value the clear visibility into identity risks provided by Tenable Identity Exposure, enhancing proactive security management.
  • Users value the detection efficiency of Tenable Identity Exposure, appreciating immediate alerts for unauthorized modifications in Active Directory.
Cons
  • Users find the difficult learning curve for Tenable Identity Exposure to be a significant barrier for new users.
  • Users find the excessive notifications from Tenable Identity Exposure can overwhelm teams without proper adjustment.
  • Users often face false positives from Tenable Identity Exposure, leading to overwhelmed teams due to numerous low-priority findings.
  • Users report experiencing information overload due to excessive findings, impacting team efficiency and focus.
  • Users find the learning curve steep for Tenable Identity Exposure, requiring significant technical knowledge for effective use.

What Are Recent G2 Reviews of Tenable Identity Exposure?

What Are G2 Users Discussing About Tenable Identity Exposure?

Tenable OT Security

Tenable OT Security disrupts attack paths and protects industrial and critical infrastructure from cyber threats. From inventory management and asset tracking to threat detection at the device and network level, vulnerability management and configuration control, Tenable’s OT security capabilities provide maximum visibility, security, and control across your entire operations.

Average Rating: 4.8/5.0

Total Reviews: 4

How Do G2 Users Rate Tenable OT Security?

  • Has the product been a good partner in doing business?: 8.3/10 (Category avg: 9.2/10)
  • Reporting: 10.0/10 (Category avg: 8.8/10)
  • Vulnerability Intelligence: 10.0/10 (Category avg: 8.7/10)
  • Risk-Prioritization: 10.0/10 (Category avg: 8.8/10)

Who Is the Company Behind Tenable OT Security?

  • Seller: Tenable
  • Company Website:
  • HQ Location: Columbia, MD
  • Twitter: @TenableSecurity
    87,752 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    2,350 employees on LinkedIn®
  • Ownership: NASDAQ: TENB

Who Uses This Product?

  • Company Size: 75% Large, 25% Small

What Do G2 Reviewers Say About Tenable OT Security?

AI-generated summary from verified user reviews

Pros
  • Users value the comprehensive visibility provided by Tenable OT Security, enhancing understanding of complex OT environments.
  • Users value the enhanced OT awareness and visibility of Tenable OT Security, effectively supporting security teams without disrupting operations.
  • Users value the full visibility into OT assets provided by Tenable OT Security, enhancing security awareness without disrupting operations.
  • Users value the full visibility into OT assets provided by Tenable OT Security, enabling quick risk remediation without production impact.
  • Users value the detection efficiency of Tenable OT Security, enabling quick risk remediation without disrupting operations.
Cons
  • Users find the limited features of Tenable OT Security restricts customization and complicates asset management tasks.
  • Users find the complexity of advanced reporting and asset management to be a tedious aspect of Tenable OT Security.
  • Users find the pricing high for smaller plants, complicating budget considerations and creating concerns over value.
  • Users find the asset management process complicated and the discovery of OT assets tedious and challenging.
  • Users find the inadequate reporting and complex pricing of Tenable OT Security frustrating and limiting for their needs.

What Are Recent G2 Reviews of Tenable OT Security?

Brandon Summers-Miller
BS
Researched and written by Brandon Summers-Miller
Updated October 3, 2024