Introduction
Tenable’s roots trace back to 1998, when a 17-year-old Renaud Deraison created Nessus, an open-source vulnerability scanner that became one of the most widely deployed security tools of its era. Deraison later joined forces with Ron Gula, a former National Security Agency researcher, and Jack Huffard to found Tenable Network Security in Columbia, Maryland, in September 2002, folding Nessus into the new company as its founding technology.
Tenable has since grown from a single scanning tool into a broader exposure-management platform used by a large share of the Fortune 500. For readers of Brel’s AI in cybersecurity coverage, Tenable’s 2026 partnership with Anthropic is a notable example of a frontier AI lab working directly with a specialized security vendor to power a named product, rather than the vendor simply integrating a general-purpose model API.
What the company does
Tenable’s core platform, Tenable One, unifies exposure data across vulnerability management, cloud security, identity, and operational technology and IoT environments into a single view, intended to help security teams prioritize which of the tens of thousands of vulnerabilities they face pose the most immediate, exploitable business risk rather than treating every finding as equally urgent. Nessus remains a widely used scanning engine underlying much of that data collection.
Who it serves
Tenable reports reducing business risk for more than 40,000 customers globally, according to its own public materials, spanning enterprises and government organizations that need to manage exposure across large, heterogeneous IT, cloud, and operational-technology environments. Business-history sources tracking the company’s customer base put roughly 65% of the Fortune 500 among its customers.
Company background
Tenable Network Security, Inc. was incorporated on September 16, 2002, in Columbia, Maryland, by Renaud Deraison, the creator of the Nessus scanner; Ron Gula, a former National Security Agency penetration researcher who had previously founded and sold a company to Enterasys Networks; and Jack Huffard, who brought business and commercial experience to the founding team. Nessus, originally released as open-source software in 1998, became proprietary in October 2005, prompting a fork of the codebase into the open-source OpenVAS project. The company rebranded to Tenable, Inc. in 2017 under then-CEO Amit Yoran and completed its initial public offering on Nasdaq under ticker TENB in 2018, raising $250 million. Tenable is headquartered in Columbia, Maryland, and is currently led by co-chief executives Steve Vintz and Mark Thurmond, with Art Coviello serving as chairman.
Product and AI capabilities
Tenable has layered AI into its exposure-management platform in stages. It introduced Predictive Prioritization, an AI-driven system that sifts through more than 200,000 known vulnerabilities to surface the roughly 3% posing genuine, immediate business risk, addressing what the industry calls vulnerability fatigue. In 2025, Tenable integrated ExposureAI generative-AI capabilities across the platform to help automate remediation guidance, and its acquisition of Apex Security that year led to the August 2025 launch of Tenable AI Exposure, extending exposure management specifically to an organization’s own AI systems and attack surfaces. Most recently, at its EXPOSURE 2026 conference in Boston, Tenable announced Tenable Hexa AI, an agentic engine for automating security orchestration, alongside a new partnership with Anthropic to power Claude-based workflows inside Hexa AI — a collaboration co-CEO Mark Thurmond described as accelerating Tenable’s research and development roadmap as the volume of exposures grows and the time between vulnerability discovery and exploitation continues to shrink.
Key developments
Tenable built its early business on commercializing the Nessus scanner before expanding into a broader vulnerability-management category, then rebranding around “exposure management” following the October 2022 launch of Tenable One. The company has pursued a steady acquisition strategy to broaden that platform’s coverage: Indegy in 2019 for operational-technology security, Alsid in 2021 for Active Directory security, Ermetic in 2023 for cloud and identity security, and Vulcan Cyber and Apex Security in 2025 for remediation orchestration and AI attack-surface protection, respectively. Its May 2026 partnership with Anthropic extends that acquisition-driven AI strategy through a direct model-provider relationship rather than another acquisition.
Why it matters
Tenable is a useful example of how a company built on a single, widely trusted scanning tool can evolve into a broader exposure-management platform without abandoning that original technical core. Its direct partnership with a frontier AI lab to co-develop agentic remediation workflows, rather than simply consuming a general-purpose API, is also a data point worth watching as more specialized security vendors seek closer, named collaborations with AI labs to differentiate their AI features from competitors building on the same underlying models.
Sector context
Within Brel’s AI in cybersecurity coverage, Tenable competes most directly with Rapid7 and Qualys in vulnerability and exposure management, and its cloud security capabilities, added via the Ermetic acquisition, place it in adjacent competition with agentless CNAPP vendors such as Wiz. Its Anthropic partnership also invites comparison with other AI-lab-and-security-vendor collaborations emerging across the sector as agentic remediation becomes a more common feature request from customers.
Sources and references
This profile draws on Tenable’s official press releases and independent reference sources on the company’s history and acquisitions.
- Tenable Press Release — “Tenable Partners with Anthropic for AI-Driven Exposure Management” (2026)
- Wikipedia — “Tenable, Inc.”
- businessmodelcanvastemplate.com — company history
- dcf-model.com — company history and ownership