Skip to content

Tenable Cloud Security

An agentless, graph-based cloud identity and posture platform, born as Israeli startup Ermetic, now folded into Tenable's exposure-management platform.

Visit Website ↗
73/100Meaningful Innovator

Overview

Tenable Cloud Security traces back to Ermetic, an Israeli CIEM startup that Tenable acquired in October 2023 for approximately $265 million. Combined with Tenable’s earlier Accurics (IaC security) and Eureka (DSPM) acquisitions, it now forms the cloud pillar of Tenable One, Tenable’s broader exposure-management platform.

The product is agentless, continuously mapping entitlements and effective permissions across AWS, Azure, and GCP, correlating that identity graph with vulnerability data, public exposure, and asset criticality to surface ‘toxic combinations.’ Tenable Cloud Security was named a Customers’ Choice in the 2025 Gartner Peer Insights Voice of the Customer report for CNAPP.

Innovation Matrix Assessment

Innovation Velocity 7/10

Steady integration of Accurics, Ermetic, and Eureka acquisitions into a unified Tenable One cloud pillar shows consistent platform-building over the past three years.

Operational Value 8/10

Agentless deployment plus identity-graph correlation and 'toxic combination' prioritization directly targets alert fatigue, a top operational complaint about traditional CSPM tools.

Market Momentum 7/10

Public parent and a named 2025 Gartner Peer Insights Customers' Choice distinction for CNAPP provide credible momentum signals.

Category Disruption 8/10

Ermetic's original agentless, graph-based CIEM model was a genuine departure from siloed CSPM scanning, structurally different from single-purpose posture tools.

Real-World Efficacy 6/10

Gartner Peer Insights Customers' Choice is a credible aggregated customer-review signal, though not equivalent to a documented breach-prevention case study.

Enduring Relevance 8/10

Identity-centric cloud risk is widely regarded as the dominant cloud breach vector, keeping this approach highly relevant.

Why CISOs Should Care

It collapses the usual gap between 'we have a CSPM alert' and 'is this actually exploitable' by correlating identity permissions, exposure, and vulnerability data into a short list of real attack paths.

What Makes It Different

Rather than scanning configurations in isolation, it builds a live entitlement graph across clouds and identity providers and reasons over combinations of weaknesses.

The Matrix Verdict

73/100 — MEANINGFUL INNOVATOR

A well-differentiated upper-middle-tier entry: genuinely disruptive underlying technology now benefiting from a large public parent's distribution.

Editorial Note: Claims vs. Verified Findings

Deal value and Gartner Peer Insights status were found directly on Wikipedia/Tenable's product page; broader customer-count or breach-specific efficacy claims could not be independently verified.

Sources