Tenable Cloud Security
An agentless, graph-based cloud identity and posture platform, born as Israeli startup Ermetic, now folded into Tenable's exposure-management platform.
Visit Website ↗Overview
Tenable Cloud Security traces back to Ermetic, an Israeli CIEM startup that Tenable acquired in October 2023 for approximately $265 million. Combined with Tenable’s earlier Accurics (IaC security) and Eureka (DSPM) acquisitions, it now forms the cloud pillar of Tenable One, Tenable’s broader exposure-management platform.
The product is agentless, continuously mapping entitlements and effective permissions across AWS, Azure, and GCP, correlating that identity graph with vulnerability data, public exposure, and asset criticality to surface ‘toxic combinations.’ Tenable Cloud Security was named a Customers’ Choice in the 2025 Gartner Peer Insights Voice of the Customer report for CNAPP.
Innovation Matrix Assessment
Steady integration of Accurics, Ermetic, and Eureka acquisitions into a unified Tenable One cloud pillar shows consistent platform-building over the past three years.
Agentless deployment plus identity-graph correlation and 'toxic combination' prioritization directly targets alert fatigue, a top operational complaint about traditional CSPM tools.
Public parent and a named 2025 Gartner Peer Insights Customers' Choice distinction for CNAPP provide credible momentum signals.
Ermetic's original agentless, graph-based CIEM model was a genuine departure from siloed CSPM scanning, structurally different from single-purpose posture tools.
Gartner Peer Insights Customers' Choice is a credible aggregated customer-review signal, though not equivalent to a documented breach-prevention case study.
Identity-centric cloud risk is widely regarded as the dominant cloud breach vector, keeping this approach highly relevant.
Why CISOs Should Care
It collapses the usual gap between 'we have a CSPM alert' and 'is this actually exploitable' by correlating identity permissions, exposure, and vulnerability data into a short list of real attack paths.
What Makes It Different
Rather than scanning configurations in isolation, it builds a live entitlement graph across clouds and identity providers and reasons over combinations of weaknesses.
The Matrix Verdict
73/100 — MEANINGFUL INNOVATOR
A well-differentiated upper-middle-tier entry: genuinely disruptive underlying technology now benefiting from a large public parent's distribution.
Editorial Note: Claims vs. Verified Findings
Deal value and Gartner Peer Insights status were found directly on Wikipedia/Tenable's product page; broader customer-count or breach-specific efficacy claims could not be independently verified.
Sources
Alternatives to Tenable Cloud Security
Wiz
Agentless, graph-based cloud security platform that maps multi-cloud risk end-to-end, now owned by Google after a record $32B…
Chainguard
Provides hardened, minimal, continuously-rebuilt container images and software packages to eliminate vulnerabilities before they reach production.
Microsoft Defender for Cloud
Microsoft's built-in cloud-native application protection platform, unifying CSPM, workload protection, and DevOps security natively across Azure, AWS, and…
Sysdig
The company behind Falco, the CNCF's runtime security standard, offering an eBPF/kernel-level CNAPP built on live syscall-based threat…
Upwind Security
Fast-growing, venture-backed CNAPP startup combining agentless scanning with eBPF runtime sensors for real-time cloud and AI workload risk…
CrowdStrike Falcon Cloud Security
Hybrid agent/agentless cloud security module inside CrowdStrike's Falcon platform, pairing posture management with endpoint-grade runtime detection.