Tenable completed its acquisition of industrial cybersecurity company Indegy on December 2, 2019, paying $78 million in cash, subject to customary purchase-price adjustments. Tenable’s stated goal was to extend its vulnerability-management business into operational technology (OT) and industrial control systems (ICS), helping customers assess risk across connected IT and industrial environments.
The deal at a glance
| Item | Details |
|---|---|
| Buyer | Tenable, Inc. |
| Acquired company | Indegy Ltd., an industrial cybersecurity company |
| Announcement and completion | December 2, 2019 |
| Purchase price | $78 million in cash, subject to customary purchase-price adjustments |
| Strategic focus | Combine Tenable’s IT vulnerability-management capabilities with Indegy’s OT and ICS expertise |
Tenable announced that the transaction had been completed on the same day. The company’s acquisition announcement describes the terms and the product plans stated at closing.
What Indegy brought to Tenable
Indegy focused on visibility and security for industrial networks and control systems. Unlike a conventional office IT environment, an OT network can include programmable logic controllers (PLCs), engineering workstations, and other equipment that directly monitors or controls physical processes. Security changes must account for operational continuity and safety as well as software vulnerabilities.
Industrial asset visibility and vulnerability assessment
Indegy’s publicly described capabilities included discovering and inventorying industrial assets, assessing vulnerabilities, and providing visibility into OT devices and networks. That information can help security teams identify equipment that may be poorly documented or difficult to evaluate using ordinary IT scanning approaches.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →#1 Best Overall
Configuration and controller-change monitoring
The platform also monitored configuration changes, including changes to controller firmware and logic. SecurityWeek reported that Indegy could identify changes to industrial controllers, which can matter when an unauthorized or unexpected change signals compromise, sabotage, misconfiguration, or operator error. A change alert is a signal to investigate, not proof of an attack.
Passive monitoring and active analysis
Indegy described a combination of passive monitoring and safe, non-intrusive active analysis. Passive collection observes network activity without initiating queries to devices. Active assessment can provide additional information, but any interaction with production equipment needs site-specific approval and validation: legacy devices and industrial protocols may react unpredictably, and plant operators may prohibit active queries.
Why Tenable wanted an OT security business
Tenable framed the acquisition around IT/OT convergence. As industrial environments become connected to enterprise networks and remote-access systems, security teams face risks that cross the traditional boundary between office IT and plant operations. Tenable argued that CISOs needed to manage industrial assets alongside IT vulnerabilities and to prioritize risk across both environments.
Rank #2
- Ideal for Gifting
- Ideal for a bookworm
- Compact for travelling
Indegy supplied OT-specific asset knowledge and monitoring capabilities that Tenable’s traditional vulnerability-management products did not provide on their own. The strategic point was broader than adding another vulnerability scanner: Tenable aimed to bring asset inventory, configuration monitoring, and threat detection for industrial environments into a shared risk-management approach.
- Shared risk context: A common view can help security and operations teams discuss IT and OT exposures using consistent reporting.
- Better industrial asset context: Device type, network position, and operational role can make a vulnerability finding more useful than a severity score alone.
- Operationally aware prioritization: Industrial systems may not be patchable on the same schedule as office software. Production constraints, safety, vendor support, and maintenance windows shape remediation decisions.
Tenable later described Indegy as part of its effort to extend security insight across IT and critical-infrastructure environments in a 2022 company blog. That supports continuity in the company’s stated strategy, not a claim that the acquisition itself improved customers’ security outcomes.
What Tenable said about integration in 2019
At closing, Tenable said integration of the Indegy Industrial Cybersecurity Suite with Tenable.sc was available immediately. It said integrations with Tenable.io and Tenable Lumin were planned for the first half of 2020. Those were roadmap statements made in 2019; the announcement alone does not verify whether or when each planned integration was delivered.
Rank #3
The financial impact Tenable forecast
In its announcement, Tenable said Indegy’s financial results were expected to have an immaterial effect on fourth-quarter 2019 revenue and calculated billings. The company forecast an approximately $2 million increase in fourth-quarter non-GAAP net loss, or about $0.02 per share, and deal-related costs of $15 million to $17 million. It also forecast a GAAP net-loss-per-share impact of approximately $0.15 to $0.17 for that quarter.
These figures were management estimates published at the time of the transaction, not audited post-close results. The $78 million was the corporate purchase price; it does not establish the price of any current Tenable product or subscription.
How Tenable presents OT security today
Tenable’s current product page presents its OT offering as Tenable One OT Exposure, rather than as a standalone Indegy-branded product. The page describes a platform intended for connected OT and IT environments, with capabilities that include:
Rank #4
- Discovering and inventorying OT, IoT, and IT assets, including PLCs and other industrial devices.
- Passive traffic monitoring and “Safe Active Query” for additional device details.
- Identifying vulnerabilities and exposures and prioritizing them.
- Detecting configuration changes and anomalies, and visualizing network communications and potential segmentation violations.
- Compliance reporting for frameworks including NERC CIP, NIST, ISO 27001, PCI DSS, and IEC 62443.
- Cloud, on-premises, hybrid, and air-gapped deployment support, as described by Tenable.
The available product material does not map each present-day feature to its origin, so it would be inaccurate to say that every capability in Tenable One OT Exposure came directly from Indegy. Nor does the original announcement establish whether Indegy continues as a legal subsidiary or operating brand.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What organizations should assess when evaluating OT exposure tools
The acquisition explains Tenable’s move into OT security, but it does not by itself establish that a platform is suitable for a particular plant. Buyers should evaluate product fit against operating conditions and the controls they already use.
Collection method and operational safety
Determine which assets can be discovered passively and what information requires active querying. Confirm permitted methods with plant operations, validate them in a representative environment, and document restrictions for sensitive or safety-related systems. Passive monitoring can reduce interaction with devices, but it does not necessarily provide complete asset or vulnerability coverage.
Best Value
- It can be a gift option
- Comes with secure packaging
- Helpful in various ways
Prioritization and remediation reality
Do not equate a high vulnerability score with the highest plant risk. Consider process criticality, safety function, exploitability, network position, compensating controls, vendor support, and the timing of maintenance windows. Finding an exposure is not the same as being able to patch it immediately.
Architecture and asset data
Check support for air-gapped or intermittently connected facilities, local versus cloud management, and integration with existing security operations. In multi-vendor plants, validate how the tool handles duplicate asset records, incomplete ownership data, and inconsistent device metadata; a consolidated dashboard is only as reliable as the underlying inventory.
Complementary controls
OT exposure management is not a replacement for network segmentation, secure remote access, backups, incident response, or safety-system engineering. A unified inventory and risk view can inform those measures, but cannot perform all of their functions.
Alternatives to compare
Tenable is one option among products with different emphases. These vendors are comparison candidates, not interchangeable equivalents. Compare them using the same criteria: asset discovery, industrial protocol coverage, passive versus active collection, vulnerability intelligence, threat detection, deployment and air-gap support, integrations, safety controls, services, and pricing.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →| Provider | Stated area to investigate | Official site |
|---|---|---|
| Dragos | OT/ICS threat detection, threat intelligence, and incident-response-oriented capabilities | dragos.com |
| Claroty | Cyber-physical-system visibility and risk management | claroty.com |
| Nozomi Networks | OT/IoT visibility, monitoring, and anomaly detection | nozominetworks.com |
| Microsoft Defender for IoT | Industrial security tooling to assess alongside an existing Microsoft security and cloud environment | Microsoft industrial-control-systems security |
For current Tenable packaging and commercial terms, consult the product page or request a quote from the vendor; the historical acquisition price is unrelated to licensing. The current product page presents a demo and quote path rather than a published numeric price.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




