• 跳转至主导航
  • 跳转至主要内容
  • 跳转至页脚
Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070
Tenable
平台
解决方案
为何选择 Tenable
资源
公司
定价方式
contact_icon
English Deutsch Français (France) Español (América Latina) Português (Brasil) Italiano
简体中文 繁體中文 日本語 한국어 العربية
Tenable 产品登录
社区和支持
购买 试用

暴露风险管理

通过一个平台管理网络安全风险,发现、优先级分析并消除整个攻击面的暴露风险。
深入了解
AI 安全
云安全
OT 安全
漏洞管理
Hexa AI
身份安全
补丁管理
攻击面管理
Web 应用程序扫描
安全工具连接器

查看所有产品

按使用案例探索

安全 AI
安全的 OT/IoT
暴露风险管理
云安全
合规性
漏洞管理
资产清单
高度安全的环境
安全的数据中心
零信任

按行业探索

金融服务
能源
医疗保健
技术
教育
政府防务
零售
为何选择 Tenable
业界认可
客户案例
Tenable 与竞争对手的比较
报告
Tenable 是暴露风险管理领域毋庸置疑的领导者
了解原因
资源库
暴露风险管理资源
博客
研究中心
培训和认证
网络安全指南
客户案例
寻找合作伙伴
资源

暴露风险管理
资源中心

使用实用资源和工具加快实施您的暴露风险管理策略。
探索
关于 Tenable
领导层
投资者关系
Tenable Ventures
奖项和表彰
媒体中心
人才招聘
参与和包容
暴露风险管理领导委员会
平台
解决方案
为何选择 Tenable
资源
公司
定价方式
contact_icon
English Deutsch Français (France) Español (América Latina) Português (Brasil) Italiano
简体中文 繁體中文 日本語 한국어 العربية
Tenable 产品登录
社区和支持
购买 试用
暴露风险管理
AI 安全
云安全
OT 安全
漏洞管理
Hexa AI
身份安全
补丁管理
攻击面管理
Web 应用程序扫描
安全工具连接器

查看所有产品

按使用案例探索

安全的 AI
安全的 OT/IoT
暴露风险管理
云安全
合规性
漏洞管理
资产清单
高度安全的环境
安全数据中心
零信任

按行业探索

金融服务
能源
医疗保健
技术
教育
政府防务
零售
为何选择 Tenable
业界认可
客户案例
Tenable 与竞争对手的比较
报告
Tenable 是暴露风险管理领域毋庸置疑的领导者
了解原因
资源库
暴露风险管理资源
博客
研究中心
培训和认证
网络安全指南
客户案例
寻找合作伙伴
资源

暴露风险管理
资源中心

使用实用资源和工具加快实施您的暴露风险管理策略。
探索
关于 Tenable
领导层
投资者关系
Tenable Ventures
奖项和表彰
媒体中心
人才招聘
参与和包容
暴露风险管理领导委员会
  • 客户
  • Continental AG
案例研究

Continental AG Continental AG logo


TISAX 现今是业界最重要的认可标志。如果没有 Tenable One 暴露风险安全管理平台提供的强大、基于风险的漏洞管理和攻击面的统一视图,我们几乎无法满足 ENX 的要求,也会丧失许多商机。

Martin Sturm, Continental

下载案例研究
使用的主要产品

Tenable One


全球领先的由 AI 驱动的暴露风险安全管理平台

Tenable One 能全面整合跨 IT 基础架构、云端环境、关键基础设施等所有攻击破绽的安全态势、洞察信息及提供相关行动方案,协助现代企业有效隔离和消除来自四面八方的威胁。

Explore this product Request a demo
行业: Automotive Supply
Location: Germany

Continental AG achieves TISAX compliance readiness with Tenable One

As an automotive supplier, Continental AG operates in a strictly regulated market. In addition to NIS-2, KRITIS and GDPR, the TISAX industry standard maintained by the ENX Association is of central importance. More and more OEMs (Original Equipment Manufacturers) are making TISAX certification a prerequisite for participating in attractive tenders, and suppliers only receive the coveted seal if they can prove that they minimized their cyber risks with appropriate technical and organizational measures.

关键业务去求

  • Meet regulatory and compliance requirements (TISAX, NIS-2, GDPR) to stay eligible for OEM contracts
  • Prevent future cyberattacks after a major incident exposed vulnerabilities
  • Gain unified visibility across IT, OT, cloud, and web apps in a global environment
  • Enable risk-based decisions with prioritized insights, automation, and clear reporting

"TISAX is the most important seal of approval for our industry today. Without the robust, risk-based vulnerability management and unified view of our attack surface via the Tenable One Exposure Management Platform, we would hardly be able to meet the ENX requirements and many doors would remain closed to us," says Martin Sturm, CISSP and IT Security Manager.

Strengthening its position as a reliable supply chain partner

Sturm joined Continental in 2023, after the company experienced a serious cyber incident, to coordinate the introduction of company-wide vulnerability management for IT, OT and cloud. "But TISAX is a relatively recent development," he notes. "When we originally made the decision to invest in vulnerability management, the issues of governance and compliance played a relatively subordinate role. The overriding task at the time was to reliably prevent an attack like the one in 2022 from happening again."

The search for a suitable solution started with a comprehensive market analysis. As a first step, the newly formed vulnerability management team at Continental developed a detailed catalog of requirements and compared this with the portfolios of all established VM vendors. The four most promising candidates were then tested in a comprehensive proof of concept. "We set up a demo environment that was closely aligned with our actual IT and app landscape and hid dozens of vulnerabilities in there – from incorrectly configured Kubernetes clusters to unpatched OT systems and service accounts with unnecessarily broad authorizations. We then scanned this environment with each of the four VM solutions to see which performed best," says Sturm.

The rules were as simple as they were objective—the solution that found the most vulnerabilities was to be awarded the contract. Tenable One identified approximately 25 percent more vulnerabilities than the competition, including several critical use cases.

Tenable delivers strategic advantage

After a six-month test phase, Tenable outperformed nearly all competitors in a strong field. Its key advantage was the holistic approach enabled by its unified exposure management platform, Tenable One. The platform consolidated the broad feature set Continental required—spanning vulnerability and attack surface management, cloud and web application security, and OT security—into a consistent, all-in-one solution. The integrated view made it easy to correlate vulnerabilities, eliminate data silos, and reduce risk.

Outstanding detection rate in cloud and OT

Tenable One scored particularly well in the areas of cloud security and OT. The platform scored bonus points in several critical use cases – for example, in detecting misconfigurations in cloud environments, such as Azure PIM and Amazon S3 buckets.

Comprehensive platform provides holistic insights

In spring 2024, the project team set about transferring the Tenable One proof of concept (PoC) installation into live operation. In view of the high level of integration, the platform's wide range of functions and the complexity of the environment, the team opted for a multi-stage approach:

  • In Phase 1, a company-wide vulnerability management with Tenable Nessus scanners and company-wide attack surface management were rolled out in Continental's IT environment
  • Phase 2 focused on the parallel introduction of Tenable Web App Scanning and Tenable Cloud Security
  • Phase 3 saw the rollout of the OT security solution

Phase 1: Vulnerability and attack surface management with Tenable Nessus

As a multinational company that is active in 56 countries and employs 200,000 people, Continental operates over 500,000 dedicated IT systems worldwide. In order to reliably capture and scan these assets, more than 200,000 Tenable Nessus scanners were required – but despite this enormous volume, the rollout went quite smoothly.

"We set up a relatively simple metric. Locations with fewer than 1,000 IT systems are scanned centrally by us," recalls Sturm. "In all larger locations, we set up dedicated scanners because there were usually enough reserves there to manage the scans on-site. In this way, we were able to parallelize many tasks – and covered over 80 percent of the IT systems within a very short time."

10 percent more web assets than suspected

To identify potentially compromised and unknown web assets, the team accompanied the Nessus scans with Tenable Attack Surface Management. The solution analyzed the DNS entries, IP addresses and ASNs in the Continental network to locate all web-facing systems and found ten percent more assets than originally suspected. The identified systems were then inventoried using a wide range of metadata in order to obtain an optimal overview of the IT landscape.

Phase 2: Tenable Cloud Security and Tenable Web App Scanning

The cloud is omnipresent at Continental today especially in its more innovative units, where in-house application development plays a key role. At Continental, as in nearly every software company today, development takes place primarily in the cloud. To ensure the security of data and access in the cloud, the project team integrated Tenable Cloud Security, a comprehensive Cloud-Native Application Protection Platform (CNAPP). The solution connects to all major public cloud providers via open APIs, and continuously identifies – and provides actionable guidance for remediating – risks in hybrid and multi-cloud environments. This allows the team to secure cloud configurations, workloads and identities, while ensuring that development, Infrastructure as Code (IaC) and Kubernetes environments are secure and compliant at all times.

"Tenable Cloud Security helps us cut cloud risks faster and easier—no experts needed. It reveals toxic access, flags anomalies, and gets us closer to least privilege," notes Sturm.

At the same time, Continental integrated Tenable Web App Scanning – a powerful scanner that dynamically scans approximately 2,500 internal and external web applications and APIs in the corporation for potential vulnerabilities, thus paving the way for timely remediation without disruption.

Phase 3: Protecting the OT environment

After completing the first two phases, the team proceeded to the final phase of the project—the rollout of Tenable OT Security—a groundbreaking step in more than one respect. A few selected OT locations had already been integrated during the PoC, and the Tenable Professional Services team provided expert guidance and resources to streamline deployment in Continental’s complex environment.

The actual fleet was much more heterogeneous than the showcase selection. In addition, due to the high prevalence of on-prem systems, only a few tasks could be solved remotely and many steps had to be readjusted on-site where the wide range of operating systems, software versions, protocols and interfaces that characterize industrial environments today proved to be a real challenge.

"We were well aware of the difficulties that awaited us," confirms Sturm. "And most of these hurdles have materialized in one form or another. Nevertheless, the rollout of Tenable OT Security will not only improve our security standing, but also achieve very relevant savings by bringing our entire exposure management program into a modern and consolidated platform."

ISMS based on ISO 27001 sets the stage for NIS-2 and TISAX

When assessing and prioritizing the identified IT, cloud and OT vulnerabilities, Continental adopted a consistently risk-based approach from day one, which is closely aligned with the requirements of ISO 27001. Instead of simply tagging vulnerabilities according to their CVSS rating, the team uses the much more meaningful Vulnerability Priority Ratings (VPR) provided by Tenable, which takes into account the probability of an exploit as well as the severity of the vulnerabilities. The VPR ratings are then validated again with regard to their risk potential, explains Sturm. "If you have the same vulnerability on two notebooks, but one belongs to the CEO and the other to an intern, the criticality is of course much higher in the first case. Although this individual readjustment requires some effort, it enables us to take the business impact of the vulnerabilities into account and to always focus our energy on the most dangerous hotspots."

Executive liability is no longer an issue

This risk-based approach not only contributes to the efficiency of processes and the protection of critical systems, but is also crucial in terms of compliance. Both the TISAX standard mentioned at the beginning and the NIS-2 Directive require those responsible at companies to systematically manage risk and even enforce the personal liability of management in the event of breaches. "There can be no compromises when it comes to complying with legal requirements and relevant industry standards. Compliance is therefore a key issue for us, and Tenable One helps us to meet complex regulations and standards. By implementing this holistic, risk-based platform, we have set the course for seamless monitoring, implementation, and documentation of all relevant requirements", Sturm emphasizes.

Spillover effects on the company's patch culture

To make the most of Tenable’s exposure management platform potential, Sturm's team automatically forwards the vulnerability data, including for cloud vulnerabilities along with actionable recommendations, to the company's asset and patch managers. They then decide for themselves how to deal with the respective risks - in other words, whether to close the vulnerabilities or to accept the risks. Sturm sees the close exchange between the teams as a big plus. "The clear communication of vulnerabilities and business impacts has definitely led to a completely new, much more sensitive patch culture. If the responsible colleagues can see at a glance what danger a vulnerability poses and even receive concrete guidance on how to fix it, it is usually closed promptly."

Robust database for well-founded decisions

In addition, the raw data from Tenable One is also automatically transferred via API to Continental's reporting team, which then distributes the huge volume to decentralized databases and prepares it for the executives. In this way, stakeholders and decision-makers in the company are always kept up to date on the status quo and the successes in vulnerability management – and can make better decisions based on hard facts. "The extensive automation of processes is another major benefit for the team, and frees up the employees to focus on the jobs they were originally hired for – even if we are far from unlocking the full potential," says Sturm.

In December 2024, Continental's Executive Board announced that the Automotive division will be transformed into a dedicated organization by September 2025. This restructuring – which also includes the separation of the shared IT infrastructure of the Automotive, Tires, ContiTech and Vibration Control units into four dedicated environments – brings exciting opportunities to expand the successful implementation of the Tenable One platform.

返回顶部

  • Tenable One

相关客户案例研究

TechMatrix


阅读案例研究

美国主要电信公司


阅读案例研究

SRF Limited


阅读案例研究

探索所有案例研究 ›

风险暴露,止步于此。

合作伙伴

  • 成为合作伙伴
  • 寻找合作伙伴
  • 合作伙伴门户
  • 合作伙伴计划

资源

  • 服务
  • 技术支持
  • 培训和认证
  • 产品文档
  • 客户社区
  • Tenable 信任

公司

  • 关于我们
  • 高管团队
  • 新闻中心
  • 投资者关系

连接

  • 联系我们
  • 试用我们的产品
  • 与销售人员交流
  • 在活动中结识
  • 加入我们
  • 隐私政策
  • 不得出售/分享我的个人信息
  • 法律声明
  • 508 合规沪ICP备2023029599号

© 2026 Tenable®, Inc. 保留所有权利

Tenable One

申请演示

全球领先的由 AI 驱动的暴露风险安全管理平台。

谢谢

感谢关注 Tenable One。
我们的代表会尽快与您联系。

Debug:
Form ID: 7469
Form Name: one-eval
Form Class: c-form form-panel__global-form c-form--mkto js-mkto-no-css js-form-hanging-label c-form--hide-comments
Form Wrapper ID: one-eval-form-wrapper
Confirmation Class: one-eval-confirmform-modal
Simulate Success

Tenable One Cloud Exposure

申请演示

使用可操作的安全平台化解云风险暴露问题。

谢谢

感谢您关注 Tenable One Cloud Exposure。
我们的代表会尽快与您联系。

Debug:
Form ID: 10155
Form Name: tenable-cs
Form Class: c-form form-panel__global-form c-form--mkto js-mkto-no-css js-form-hanging-label c-form--hide-comments
Form Wrapper ID: tenable-cs-form-wrapper
Confirmation Class: tenable-cs-confirmform-modal
Simulate Success

Tenable Security Center

申请演示

根据对企业的风险识别漏洞并进行优先级分析。本地管理。

谢谢

感謝您對 Tenable Security Center 有興趣。
我们的代表会尽快与您联系。

Debug:
Form ID: 3504
Form Name: tenable-sc-eval
Form Class: c-form form-panel__global-form c-form--mkto js-mkto-no-css js-form-hanging-label c-form--hide-comments
Form Wrapper ID: tenable-sc-eval-form-wrapper
Confirmation Class: tenable-sc-eval-confirmform-modal
Simulate Success

Tenable Patch Management

申请演示

采用自动化流程,简化安全团队和 IT 团队之间的协作,从而缩短平均修复时间。

谢谢

感謝您對 Tenable Patch Management 有興趣。
我们的代表会尽快与您联系。

Debug:
Form ID: 13149
Form Name: patch-mgmt
Form Class: c-form form-panel__global-form c-form--mkto js-mkto-no-css js-form-hanging-label c-form--hide-comments
Form Wrapper ID: patch-mgmt-form-wrapper
Confirmation Class: patch-mgmt-confirmform-modal
Simulate Success

Tenable Enclave Security

申请演示

洞察、揭示和化解 IT 和容器功能。

谢谢

感谢您关注 Tenable Enclave Security。
我们的代表会尽快与您联系。

Debug:
Form ID: 12543
Form Name: enclave
Form Class: c-form form-panel__global-form c-form--mkto js-mkto-no-css js-form-hanging-label c-form--hide-comments
Form Wrapper ID: enclave-form-wrapper
Confirmation Class: enclave-confirmform-modal
Simulate Success

Tenable One 攻击面管理

申请演示

获得对连接互联网资产的可见性,消除盲点和未知风险来源。

谢谢

感谢您对 Tenable One 攻击面管理平台的关注。
我们的代表会尽快与您联系。

Debug:
Form ID: 6937
Form Name: asm-eval
Form Class: c-form form-panel__global-form c-form--mkto js-mkto-no-css js-form-hanging-label c-form--hide-comments
Form Wrapper ID: asm-eval-form-wrapper
Confirmation Class: asm-eval-confirmform-modal
Simulate Success

Tenable One AI Exposure

申请演示

查看、保护和管理您的团队使用 AI 平台的方式。

谢谢

感谢您关注 Tenable One AI Exposure。
我们的代表会尽快与您联系。

Debug:
Form ID: 14854
Form Name: ai-exposure
Form Class: c-form form-panel__global-form c-form--mkto js-mkto-no-css js-form-hanging-label c-form--hide-comments
Form Wrapper ID: ai-exposure-form-wrapper
Confirmation Class: ai-exposure-confirmform-modal
Simulate Success

Tenable One OT Exposure

申请演示

针对融合式 OT/IT 环境使用统一的安全解决方案,化解 OT 风险暴露问题

谢谢

感谢您关注 Tenable One OT Exposure。
我们的代表会尽快与您联系。

Debug:
Form ID: 3879
Form Name: ot-eval
Form Class: c-form form-panel__global-form c-form--mkto js-mkto-no-css js-form-hanging-label c-form--hide-comments
Form Wrapper ID: ot-eval-form-wrapper
Confirmation Class: ot-eval-confirmform-modal
Simulate Success

Tenable One Identity Exposure

申请演示

使用针对身份智能型企业的基本解决方案,化解身份风险暴露问题。

谢谢

感谢您关注 Tenable One Identity Exposure.
我们的代表会尽快与您联系。

Debug:
Form ID: 4178
Form Name: ad-eval
Form Class: c-form form-panel__global-form c-form--mkto js-mkto-no-css js-form-hanging-label c-form--hide-comments
Form Wrapper ID: ad-eval-form-wrapper
Confirmation Class: ad-eval-confirmform-modal
Simulate Success

为何选择 Tenable

请参阅 Tenable 实际应用案例

想了解 Tenable 如何帮助您的团队发现并修复危及贵企业的关键网络安全漏洞吗?填写此表格,获取定制报价或演示。

感谢您的订阅!

Debug:
Form ID: 13427
Form Name: why-compare-form
Form Class: c-form form-panel__global-form c-form--mkto js-mkto-no-css js-form-hanging-label c-form--hide-comments
Form Wrapper ID: why-compare-form-form-wrapper
Confirmation Class: why-compare-form-confirmform-modal
Simulate Success

SLCGP

了解 Tenable 如何帮助实现 SLCGP 网络安全计划要求

Tenable 解决方案可满足所有 SLCGP 要求。请联系 Tenable 代表深入了解情况。

谢谢

您很快会收到一封确认电子邮件,我们的销售开发代表将会与您联系。将任何问题发送到 [email protected]。

Debug:
Form ID: 10616
Form Name: slcgp
Form Class: c-form form-panel__global-form c-form--mkto js-mkto-no-css js-form-hanging-label c-form--hide-comments
Form Wrapper ID: slcgp-form-wrapper
Confirmation Class: slcgp-confirmform-modal
Simulate Success

订阅

您可加以利用的网络安全新闻

输入您的电子邮件,绝不要错过 Tenable 专家的及时提醒和安全指导。

感谢您的订阅!

Debug:
Form ID: 3971
Form Name: blog-subscribe
Form Class: c-form form-panel__global-form c-form--mkto js-mkto-no-css js-form-hanging-label c-form--hide-comments
Form Wrapper ID: blog-subscribe-form-wrapper
Confirmation Class: blog-subscribe-confirmform-modal
Simulate Success

免费试用

Tenable Vulnerability Management

可全面访问基于云的现代化漏洞管理平台,从而以无可比拟的精确度发现并追踪所有资产。

Tenable Vulnerability Management 试用版还包含 Tenable Web App Scanning。


立即购买

Tenable Vulnerability Management

可全面访问基于云的现代化漏洞管理平台,从而以无可比拟的精确度发现并追踪所有资产。 立即购买年度订阅。


资产数量

100

选择您的订阅

立即购买

请联系我们或 Tenable 合作伙伴。

谢谢

感谢关注 Tenable Vulnerability Management。
我们的代表会尽快与您联系。

Debug:
Form ID: 3174
Form Name: vm
Form Class: c-form c-form--mkto js-mkto-no-css js-form-hanging-label
Form Wrapper ID: vm-form-wrapper
Confirmation Class: vm-confirmform-modal
Simulate Success

免费试用

试用 Tenable Web App Scanning

您可以通过 Tenable One 暴露风险安全管理平台完全访问我们专为现代应用程序量身打造的最新 Web 应用程序扫描产品。可安全扫描全部在线资产组合的漏洞,具有高度准确性,而且无需繁重的手动操作或中断关键的 Web 应用程序。立即注册。

Tenable Web App Scanning 试用版还包含 Tenable Vulnerability Management。

立即购买

购买 Tenable Web App Scanning

可全面访问基于云的现代化漏洞管理平台,从而以无可比拟的精确度发现并追踪所有资产。 立即购买年度订阅。

FQDN

5
$3,578
立即购买

请联系我们或 Tenable 合作伙伴。

谢谢

感谢您关注 Tenable Web App Scanning。
我们的代表会尽快与您联系。

Debug:
Form ID: 3258
Form Name: was
Form Class: c-form c-form--mkto js-mkto-no-css js-form-hanging-label
Form Wrapper ID: was-form-wrapper
Confirmation Class: was-confirmform-modal
Simulate Success

免费试用

免费试用 Tenable Nessus Professional

Tenable Nessus 是当今市场上功能最全面的漏洞扫描器。填写下面的表格可继续试用 Nessus Pro。

立即购买

购买 Tenable Nessus Professional

购买多年期许可,即享优惠价格添加高级支持功能,获取一年 365 天、一天 24 小时的电话、社区和聊天支持。


选择您的许可证

购买多年许可证,节省幅度更大。

添加支持和培训

立即购买
续订现有的许可证
寻找经销商

*含增值税

免费试用

免费试用 Tenable Nessus Expert

Nessus Expert 针对现代攻击面而量身打造,可以查看更多信息,保护企业免遭从 IT 到云中漏洞的攻击。

已经有 Tenable Nessus Professional? 升级到 Nessus Expert,免费试用 7 天。

立即购买

购买 Nessus Expert


选择您的许可证

购买多年许可证,节省幅度更大。

添加支持和培训

立即购买
续订现有的许可证
寻找经销商

有了 Nessus Pro 高级支持,您的团队将获取一年 365 天、一天 24 小时的电话、社区和聊天支持。这一高级级别的技术支持有助于确保响应时间更短,解决问题的速度更快。

高级支持计划功能

电话支持

电话支持一天 24 小时、一年 365 天,最多可用于十 (10) 个具名支持联系人。

聊天支持

通过 Tenable Community 联系指定支持联系人全天候提供聊天支持

Tenable Community 支持门户

所有具名支持联系人可以打开 Tenable Community 中的支持案例。用户还可以访问知识库、文档、许可证信息、技术支持编号等;利用实时聊天,向 Community 提问,并从其他 Community 成员那里了解提示和技巧。

初始响应时间

P1-严重:< 2 小时
P2-高:< 4 小时
P3-中等:< 12 小时
P4-信息性: < 24 小时

支持联系人

支持联系人必须非常熟练地使用信息技术和他们从 Tenable 购买的软件,并了解通过软件手段监控的客户资源。支持联系人必须会讲英语,并且在申请支持时使用英语。支持联系人必须提供由 Tenable 合理申请的信息,以复制任何错误或以其他方式解决支持申请。