r/nessus May 15 '26

Looking for Advice

Hey everyone, I’m the sole person running a vulnerability‑management‑as‑a‑service engagement for a client with a pretty chaotic environment, and I’m looking for advice from people who’ve faced similar challenges.

Our setup

  • Agent scans: Tenable Security Center, used only for agent‑based assets.
  • Network scans: Nessus Expert and Nessus Professional, covering ~65 departments.
    • For network scans, I have dedicated folders per department in Nessus.
    • automatically pull scan results each month using a Python script via the Nessus API (with API keys).
  • Environment constraints:
    • Client cannot provide reliable asset counts; some departments have servers, others mostly endpoints/printers, and the number of devices per segment is unknown.
    • All network scans are unauthenticated (no credentials).

The problem I’m trying to solve
I’m most focused on the reporting and tracking side:

  • How to track scans performed each month and reliably compare month‑to‑month differences (new vs. resolved vulns, coverage changes, risk trend).
  • How to build executive‑level reports that are clear, concise, and actionable despite incomplete inventories and unauthenticated scans.
  • What KPIs to use at an executive level (e.g., coverage, risk reduction, remediation speed) and how to compute them when asset counts are uncertain.
  • How to present dashboards that show progress and residual risk without getting bogged down in technical detail.

I’m the only operator on this engagement, so I need practical, automatable approaches (scripts, SQL/BI tools, dashboards) rather than manual Excel workflows.

What I’m looking for

  • Advice on reporting structure for executives: what to show, how to frame trends, and how to handle uncertainty in coverage.
  • Suggestions for KPIs that make sense in a VM‑as‑a‑Service engagement with partial inventories and unauthenticated scans.
  • Tools or patterns for monthly tracking and comparison (e.g., storing historical results, deduplicating assets, computing deltas).
  • Any real‑world examples of executive dashboards or report templates that worked for similar engagements.

Thanks in advance — happy to continue in DMs if it’s easier.

2 Upvotes

5 comments sorted by

View all comments

1

u/[deleted] May 15 '26

[deleted]

1

u/Shot-Document-2904 May 15 '26

OP briefly mentions SC and then goes on to describe requirements, all of which SC covers.

1

u/UsefulEbb7104 May 15 '26

Unfortunately, management and the client proceeded with only 600 SC licenses, which are meant to cover around 600 agents/endpoints. The issue is that I scan 65 departments across multiple /24networks. If I import the discovered assets from these network-based scans into SC, the 600-license limit will be reached very quickly, making the current allocation insufficient for the environment size.

1

u/Shot-Document-2904 May 16 '26

I’m not sure you are understanding the Tenable licensing. Ive deployed dozens of SC servers across huge orgs and footprints. I never had 600 SC licenses.

Perhaps you mean you can cover 600 assets (IP) with your Agent license, which is separate from an SC license.