Kenna Security
Kenna Security provides a SaaS risk-based vulnerability management platform that uses data science and real-world threat intelligence to prioritize remediation. Its Kenna.VM product, now Cisco Vulnerability Management, serves enterprise security teams and was acquired by Cisco in 2021.
- Company typePrivate
- Founded2010
- HeadquartersSan Francisco, United States
- Headcount51–100
- GTM typeB2B
- OfferingSoftware
What Kenna Security does
Kenna Security is a SaaS risk and vulnerability intelligence platform founded in 2010 and headquartered in San Francisco. Its flagship product, Kenna.VM, applies data science to real-world threat intelligence to score vulnerabilities by actual exploitability and organizational risk rather than relying on generic CVSS severity. The platform is targeted at large enterprise security teams that need to triage overwhelming vulnerability backlogs and focus remediation on the threats most likely to materialize into business impact. The horizontal segmentation approach means Kenna sells across industries rather than specializing in a vertical use case.
The product architecture combines vulnerability data ingestion with external threat intelligence feeds, applying proprietary prioritization models to produce a ranked remediation backlog. Distribution was historically enterprise field sales, with quote-based subscription licensing typical of the B2B security category. Kenna was acquired by Cisco Systems on June 30, 2021, after raising roughly $98 million across six venture rounds from 2011 to 2019 with backing from Bessemer Venture Partners, U.S. Venture Partners, PeakSpan Capital, Citi Ventures, Sorenson Capital, and Costanoa Ventures. Following the acquisition, Kenna.VM was rebranded as Cisco Vulnerability Management and integrated into Cisco's SecureX security platform, gaining access to Cisco's global enterprise sales channel and broader security ecosystem. As a product line within Cisco, the standalone company no longer operates as an independent entity.
Kenna Security firmographics
Firmographics- Name
- Kenna Security
- Website
- https://kennasecurity.com
- Company type
- Private
- Founded year
- 2010
- Operating status
- Acquired
- Headcount range
- 51–100 employees
- Short description
- Kenna Security provides a SaaS risk-based vulnerability management platform that uses data science and real-world threat intelligence to prioritize remediation. Its Kenna.VM product, now Cisco Vulnerability Management, serves enterprise security teams and was acquired by Cisco in 2021.
- Ownership category
- akta.pro rank
Where Kenna Security is headquartered
LocationHeadquarters
- HQ city
- San Francisco
- HQ country
- United States
- HQ region
- North America
Markets served
Kenna Security business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Infrastructure, Operations
Revenue model
- Enterprise Security Software: Kenna Security generated revenue through enterprise software licensing for risk-based vulnerability management. Following its acquisition by Cisco, the product is now offered as Cisco Vulnerability Management as part of Cisco's broader security platform.
Go-to-market motion1 record
Distribution channels1 record
Marketing channels2 records
Kenna Security product offering
Product offeringCore offering
Kenna Security offered Kenna.VM, a SaaS risk-based vulnerability management platform that uses real-world threat intelligence and advanced data science to prioritize security vulnerabilities based on actual risk and exploitability rather than generic severity scores. The platform helps enterprise security teams focus remediation efforts on the most critical threats amid overwhelming vulnerability volumes. Following Cisco's June 2021 acquisition, the product was rebranded as Cisco Vulnerability Management and integrated with Cisco's SecureX platform.
Product overview
Kenna Security offered a single unified product called Kenna.VM (Kenna Vulnerability Management), a risk-based vulnerability management platform that prioritizes security vulnerabilities using real-world threat intelligence and advanced data science. Following Cisco's acquisition on June 30, 2021, Kenna.VM has been rebranded as Cisco Vulnerability Management, integrating with Cisco's SecureX platform to enhance the combined security offering.
Differentiator
Problem solved
Functional benefit
Products and services
- Kenna.VM Kenna's flagship risk-based vulnerability management SaaS platform that helps enterprise security teams identify, prioritize, and remediate security vulnerabilities based on real-world threat intelligence and data science, focusing remediation on the most critical risks rather than theoretical severity.
- Cisco Vulnerability Management The rebranded version of Kenna.VM offered as part of Cisco's security portfolio, combining Kenna's vulnerability prioritization technology with Cisco's SecureX platform for enhanced enterprise risk-based vulnerability management.
Companies that use Kenna Security
Customer profileSegments1 record
Ideal customer profiles1 record
Kenna Security technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
AI capability1 record
Feature1 record
Kenna Security partnerships and signals
Strategic signalScale indicators1 record
Recent moves6 records
Expansion highlights5 records
Kenna Security competitors and assessment
Company assessmentDirect peers
- Rapid7: Rapid7's InsightVM provides risk-based vulnerability prioritization across on-prem and cloud environments. Like Kenna, it leverages threat intelligence and analytics to focus remediation on real-world risk.
- Tenable: Tenable is the leader in enterprise vulnerability management with Nessus and Tenable One. It is the most direct competitor to Kenna's risk-based prioritization approach, operating at much larger scale.
- Qualys: Qualys delivers cloud-based VMDR (Vulnerability Management, Detection, and Response) as part of its TruRisk platform. It directly competes with Kenna.VM / Cisco Vulnerability Management in enterprise risk-based vulnerability management.
- Skybox Security: Skybox Security offers vulnerability management with a strong emphasis on network and security posture context — closely aligned with Kenna's risk-prioritization philosophy for large enterprise environments.
Broad incumbents
- Forescout: Forescout delivers continuous device discovery and vulnerability assessment for IT, IoT, and OT environments, overlapping with Kenna's risk-based asset and exposure management capabilities.
- Palo Alto Networks: Palo Alto Networks provides VM and exposure management through Cortex Xpanse and Prisma Cloud. It is a broad incumbent that competes in the same enterprise risk-prioritization conversation as Cisco Vulnerability Management.
- CrowdStrike: CrowdStrike Falcon Spotlight offers vulnerability management bundled within its endpoint and XDR platform. As a broad incumbent, it competes indirectly by embedding VM into a wider security suite.
Emerging players
- Armis: Armis provides asset intelligence and exposure management with a focus on unmanaged and connected devices — adjacent to Kenna's risk-prioritization thesis around attack surface visibility.
- Balbix: Balbix uses AI/ML to quantify cyber risk and prioritize vulnerabilities, closely mirroring Kenna's data-science-driven prioritization approach but as an independent emerging vendor.
- Wiz: Wiz is a cloud-native security platform that incorporates vulnerability and exposure findings into a unified CNAPP. It overlaps with Kenna's exposure-management ambitions, particularly for cloud-first customers.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat6 records
Key risks5 records
Key highlights5 records
Customer concentration
Kenna Security social profiles
Digital presenceKenna Security financial estimates
Financial estimateRevenue estimate
Valuation estimate
Kenna Security leadership team
Management profileNumber of profiles
Profiles7 records
Kenna Security funding detail
Funding detailFunding overview
Funding rounds6 records
Investors12 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Kenna Security M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Kenna Security
What does Kenna Security do?
Kenna Security offered Kenna.VM, a SaaS risk-based vulnerability management platform that uses real-world threat intelligence and advanced data science to prioritize security vulnerabilities based on actual risk and exploitability rather than generic severity scores. The platform helps enterprise security teams focus remediation efforts on the most critical threats amid overwhelming vulnerability volumes. Following Cisco's June 2021 acquisition, the product was rebranded as Cisco Vulnerability Management and integrated with Cisco's SecureX platform.
Is Kenna Security a public or private company?
Kenna Security is a private company. It is classified as corporate owned and is currently acquired.
When was Kenna Security founded?
Kenna Security was founded in 2010. It employs 51 to 100 people.
Where is Kenna Security based?
Kenna Security is headquartered in San Francisco, United States, in the North America region.
How does Kenna Security make money?
One revenue line is on record: enterprise Security Software.
Who are Kenna Security's main competitors?
Direct peers on record are Rapid7, Tenable, Qualys and Skybox Security. Broad incumbents are Forescout, Palo Alto Networks and CrowdStrike. Emerging players are Armis, Balbix and Wiz.
Does Kenna Security have an API?
No public API is recorded for Kenna Security.