Developer docs
API playgroundTry for free, no card

Search company profiles

Kenna Security

Full company profile

uuid0000m9v

Namestring
Kenna Security
Company typeenum
Private
Founded yearint
2010
Descriptiontext

Kenna Security is a SaaS risk and vulnerability intelligence platform founded in 2010 and headquartered in San Francisco. Its flagship product, Kenna.VM, applies data science to real-world threat intelligence to score vulnerabilities by actual exploitability and organizational risk rather than relying on generic CVSS severity. The platform is targeted at large enterprise security teams that need to triage overwhelming vulnerability backlogs and focus remediation on the threats most likely to materialize into business impact. The horizontal segmentation approach means Kenna sells across industries rather than specializing in a vertical use case.

The product architecture combines vulnerability data ingestion with external threat intelligence feeds, applying proprietary prioritization models to produce a ranked remediation backlog. Distribution was historically enterprise field sales, with quote-based subscription licensing typical of the B2B security category. Kenna was acquired by Cisco Systems on June 30, 2021, after raising roughly $98 million across six venture rounds from 2011 to 2019 with backing from Bessemer Venture Partners, U.S. Venture Partners, PeakSpan Capital, Citi Ventures, Sorenson Capital, and Costanoa Ventures. Following the acquisition, Kenna.VM was rebranded as Cisco Vulnerability Management and integrated into Cisco's SecureX security platform, gaining access to Cisco's global enterprise sales channel and broader security ecosystem. As a product line within Cisco, the standalone company no longer operates as an independent entity.

Short descriptiontext

Kenna Security provides a SaaS risk-based vulnerability management platform that uses data science and real-world threat intelligence to prioritize remediation. Its Kenna.VM product, now Cisco Vulnerability Management, serves enterprise security teams and was acquired by Cisco in 2021.

Operating statusenum
Acquired
Ownership categoryenum
Headcount rangeband
51–100
akta.pro rankint
HeadquartersSan Francisco, United States
HQ citystring
San Francisco
HQ countrystring
United States
HQ regionstring
North America
Markets served

Serves global market

Keyword5 values
vulnerability management, risk-based prioritization, threat intelligence, cybersecurity platform, security risk analytics
Industry1 code
1HDADAHAI
CodeHDADAHAIPrimaryYes
NAICS code2 codes
  • 541519
  • 54151
SIC code1 code
  • 7373
Product category
Vulnerability Management Software
Social media profiles1 record
GTM motion1 record

Each record includes

Type, Description, Source

Revenue model1 record
1Enterprise Security Software
TypeSubscription Recurring
Description

Kenna Security generated revenue through enterprise software licensing for risk-based vulnerability management. Following its acquisition by Cisco, the product is now offered as Cisco Vulnerability Management as part of Cisco's broader security platform.

cisco.com
Marketing channels2 records

Each record includes

Title, Type, Stage, Description, Source

Distribution channels1 record

Each record includes

Title, Type, Scope, Target buyer, Description, Source

Cost components5 values
Personnel, Technology or R&D, Marketing or Sales, Infrastructure, Operations
GTM typeB2B
B2B
Offering typeSoftware
Software
Core offering1 text field

Kenna Security offered Kenna.VM, a SaaS risk-based vulnerability management platform that uses real-world threat intelligence and advanced data science to prioritize security vulnerabilities based on actual risk and exploitability rather than generic severity scores. The platform helps enterprise security teams focus remediation efforts on the most critical threats amid overwhelming vulnerability volumes. Following Cisco's June 2021 acquisition, the product was rebranded as Cisco Vulnerability Management and integrated with Cisco's SecureX platform.

Differentiator
Functional benefit
Problem solved
Product overview1 text field

Kenna Security offered a single unified product called Kenna.VM (Kenna Vulnerability Management), a risk-based vulnerability management platform that prioritizes security vulnerabilities using real-world threat intelligence and advanced data science. Following Cisco's acquisition on June 30, 2021, Kenna.VM has been rebranded as Cisco Vulnerability Management, integrating with Cisco's SecureX platform to enhance the combined security offering.

Product and service2 records
1Kenna.VM
CategoryVulnerability Management Software
Description

Kenna's flagship risk-based vulnerability management SaaS platform that helps enterprise security teams identify, prioritize, and remediate security vulnerabilities based on real-world threat intelligence and data science, focusing remediation on the most critical risks rather than theoretical severity.

2Cisco Vulnerability Management
CategoryVulnerability Management Software
Description

The rebranded version of Kenna.VM offered as part of Cisco's security portfolio, combining Kenna's vulnerability prioritization technology with Cisco's SecureX platform for enhanced enterprise risk-based vulnerability management.

Scale indicator1 record

Each record includes

Type, Value, Description, Source

Recent move6 records

Each record includes

Date, Type, Title, Description, Source

Expansion highlight5 records

Each record includes

Type, Description

Peers10 records
TypeDirect peer
Description

Rapid7's InsightVM provides risk-based vulnerability prioritization across on-prem and cloud environments. Like Kenna, it leverages threat intelligence and analytics to focus remediation on real-world risk.

TypeBroad incumbent
Description

Forescout delivers continuous device discovery and vulnerability assessment for IT, IoT, and OT environments, overlapping with Kenna's risk-based asset and exposure management capabilities.

TypeDirect peer
Description

Tenable is the leader in enterprise vulnerability management with Nessus and Tenable One. It is the most direct competitor to Kenna's risk-based prioritization approach, operating at much larger scale.

TypeBroad incumbent
Description

Palo Alto Networks provides VM and exposure management through Cortex Xpanse and Prisma Cloud. It is a broad incumbent that competes in the same enterprise risk-prioritization conversation as Cisco Vulnerability Management.

TypeDirect peer
Description

Qualys delivers cloud-based VMDR (Vulnerability Management, Detection, and Response) as part of its TruRisk platform. It directly competes with Kenna.VM / Cisco Vulnerability Management in enterprise risk-based vulnerability management.

TypeDirect peer
Description

Skybox Security offers vulnerability management with a strong emphasis on network and security posture context — closely aligned with Kenna's risk-prioritization philosophy for large enterprise environments.

TypeEmerging player
Description

Armis provides asset intelligence and exposure management with a focus on unmanaged and connected devices — adjacent to Kenna's risk-prioritization thesis around attack surface visibility.

TypeEmerging player
Description

Balbix uses AI/ML to quantify cyber risk and prioritize vulnerabilities, closely mirroring Kenna's data-science-driven prioritization approach but as an independent emerging vendor.

TypeBroad incumbent
Description

CrowdStrike Falcon Spotlight offers vulnerability management bundled within its endpoint and XDR platform. As a broad incumbent, it competes indirectly by embedding VM into a wider security suite.

10Wiz
TypeEmerging player
Description

Wiz is a cloud-native security platform that incorporates vulnerability and exposure findings into a unified CNAPP. It overlaps with Kenna's exposure-management ambitions, particularly for cloud-first customers.

Market position
Strengths4 records

Each record includes

Headline, Details, Source

Weaknesses4 records

Each record includes

Headline, Details, Source

Competitive moat6 records

Each record includes

Type, Details

Key risks5 records

Each record includes

Headline, Details, Source

Key highlights5 records

Each record includes

Headline, Details, Source

Customer concentration

Classification, Details

Segment1 record

Each record includes

Title, Type, Primary, Description, Pain point addressed, Use case, Source

Ideal customer profile1 record

Each record includes

Profile, Firmographic size, Sales motion, Sales cycle length, Buying structure, Purchase trigger, Buyer persona, Geography, Industry vertical, Primary use case, Description, Pain points, Evidence proof points, Target buyer

Technology focused
Yes
API detail
Has APIbool
No

Docs URL, Description

AI capability1 record

Each record includes

Type, Description, Source

AI maturity
App detail

Has app

Feature1 record

Each record includes

Title, Differentiator, Description, Source

Core technology
Revenue estimate
Valuation estimate
Number of profiles
Profiles7 records

Each record includes

Name, Designation, Designation category, Overview, Profile commentary, Source

No data
No data
Funding overview

Funding stage, Last funding date, Total funding USD

Funding rounds6 records

Each record includes

Round, Amount USD, Date, Pre money valuation, Total investors, Investors, News

Investors12 records

Each record includes

Name, Type, Date of entry, Rounds participated, Website

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

M&A

Each record includes

Name, Acquisition type, Announced date, Completed date, Status, Website, News

Investment

Each record includes

Name, Round, Announced date, Lead investor, Website, News

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Kenna Security

Vulnerability Management Softwarekennasecurity.com

Kenna Security provides a SaaS risk-based vulnerability management platform that uses data science and real-world threat intelligence to prioritize remediation. Its Kenna.VM product, now Cisco Vulnerability Management, serves enterprise security teams and was acquired by Cisco in 2021.

What Kenna Security does

Kenna Security is a SaaS risk and vulnerability intelligence platform founded in 2010 and headquartered in San Francisco. Its flagship product, Kenna.VM, applies data science to real-world threat intelligence to score vulnerabilities by actual exploitability and organizational risk rather than relying on generic CVSS severity. The platform is targeted at large enterprise security teams that need to triage overwhelming vulnerability backlogs and focus remediation on the threats most likely to materialize into business impact. The horizontal segmentation approach means Kenna sells across industries rather than specializing in a vertical use case.

The product architecture combines vulnerability data ingestion with external threat intelligence feeds, applying proprietary prioritization models to produce a ranked remediation backlog. Distribution was historically enterprise field sales, with quote-based subscription licensing typical of the B2B security category. Kenna was acquired by Cisco Systems on June 30, 2021, after raising roughly $98 million across six venture rounds from 2011 to 2019 with backing from Bessemer Venture Partners, U.S. Venture Partners, PeakSpan Capital, Citi Ventures, Sorenson Capital, and Costanoa Ventures. Following the acquisition, Kenna.VM was rebranded as Cisco Vulnerability Management and integrated into Cisco's SecureX security platform, gaining access to Cisco's global enterprise sales channel and broader security ecosystem. As a product line within Cisco, the standalone company no longer operates as an independent entity.

Kenna Security firmographics

Firmographics
Name
Kenna Security
Website
https://kennasecurity.com
Company type
Private
Founded year
2010
Operating status
Acquired
Headcount range
51–100 employees
Short description
Kenna Security provides a SaaS risk-based vulnerability management platform that uses data science and real-world threat intelligence to prioritize remediation. Its Kenna.VM product, now Cisco Vulnerability Management, serves enterprise security teams and was acquired by Cisco in 2021.
Ownership category
akta.pro rank

Where Kenna Security is headquartered

Location

Headquarters

HQ city
San Francisco
HQ country
United States
HQ region
North America

Markets served

Kenna Security business model

Business model
GTM type
B2B
Offering type
Software
Cost components
Personnel, Technology or R&D, Marketing or Sales, Infrastructure, Operations

Revenue model

  1. Enterprise Security Software: Kenna Security generated revenue through enterprise software licensing for risk-based vulnerability management. Following its acquisition by Cisco, the product is now offered as Cisco Vulnerability Management as part of Cisco's broader security platform.

Go-to-market motion1 record

Distribution channels1 record

Marketing channels2 records

Kenna Security product offering

Product offering

Core offering

Kenna Security offered Kenna.VM, a SaaS risk-based vulnerability management platform that uses real-world threat intelligence and advanced data science to prioritize security vulnerabilities based on actual risk and exploitability rather than generic severity scores. The platform helps enterprise security teams focus remediation efforts on the most critical threats amid overwhelming vulnerability volumes. Following Cisco's June 2021 acquisition, the product was rebranded as Cisco Vulnerability Management and integrated with Cisco's SecureX platform.

Product overview

Kenna Security offered a single unified product called Kenna.VM (Kenna Vulnerability Management), a risk-based vulnerability management platform that prioritizes security vulnerabilities using real-world threat intelligence and advanced data science. Following Cisco's acquisition on June 30, 2021, Kenna.VM has been rebranded as Cisco Vulnerability Management, integrating with Cisco's SecureX platform to enhance the combined security offering.

Differentiator

Problem solved

Functional benefit

Products and services

  • Kenna.VM Kenna's flagship risk-based vulnerability management SaaS platform that helps enterprise security teams identify, prioritize, and remediate security vulnerabilities based on real-world threat intelligence and data science, focusing remediation on the most critical risks rather than theoretical severity.
  • Cisco Vulnerability Management The rebranded version of Kenna.VM offered as part of Cisco's security portfolio, combining Kenna's vulnerability prioritization technology with Cisco's SecureX platform for enhanced enterprise risk-based vulnerability management.

Companies that use Kenna Security

Customer profile

Segments1 record

Ideal customer profiles1 record

Kenna Security technology and API

Technology

Technology focussed Yes

API detail

Has API
No
API docs
API detail

Core technology

AI maturity

App detail

AI capability1 record

Feature1 record

Kenna Security partnerships and signals

Strategic signal

Scale indicators1 record

Recent moves6 records

Expansion highlights5 records

Kenna Security competitors and assessment

Company assessment

Direct peers

  • Rapid7: Rapid7's InsightVM provides risk-based vulnerability prioritization across on-prem and cloud environments. Like Kenna, it leverages threat intelligence and analytics to focus remediation on real-world risk.
  • Tenable: Tenable is the leader in enterprise vulnerability management with Nessus and Tenable One. It is the most direct competitor to Kenna's risk-based prioritization approach, operating at much larger scale.
  • Qualys: Qualys delivers cloud-based VMDR (Vulnerability Management, Detection, and Response) as part of its TruRisk platform. It directly competes with Kenna.VM / Cisco Vulnerability Management in enterprise risk-based vulnerability management.
  • Skybox Security: Skybox Security offers vulnerability management with a strong emphasis on network and security posture context — closely aligned with Kenna's risk-prioritization philosophy for large enterprise environments.

Broad incumbents

  • Forescout: Forescout delivers continuous device discovery and vulnerability assessment for IT, IoT, and OT environments, overlapping with Kenna's risk-based asset and exposure management capabilities.
  • Palo Alto Networks: Palo Alto Networks provides VM and exposure management through Cortex Xpanse and Prisma Cloud. It is a broad incumbent that competes in the same enterprise risk-prioritization conversation as Cisco Vulnerability Management.
  • CrowdStrike: CrowdStrike Falcon Spotlight offers vulnerability management bundled within its endpoint and XDR platform. As a broad incumbent, it competes indirectly by embedding VM into a wider security suite.

Emerging players

  • Armis: Armis provides asset intelligence and exposure management with a focus on unmanaged and connected devices — adjacent to Kenna's risk-prioritization thesis around attack surface visibility.
  • Balbix: Balbix uses AI/ML to quantify cyber risk and prioritize vulnerabilities, closely mirroring Kenna's data-science-driven prioritization approach but as an independent emerging vendor.
  • Wiz: Wiz is a cloud-native security platform that incorporates vulnerability and exposure findings into a unified CNAPP. It overlaps with Kenna's exposure-management ambitions, particularly for cloud-first customers.

Market position

Strengths4 records

Weaknesses4 records

Competitive moat6 records

Key risks5 records

Key highlights5 records

Customer concentration

Kenna Security social profiles

Digital presence

Kenna Security financial estimates

Financial estimate

Revenue estimate

Valuation estimate

Kenna Security leadership team

Management profile

Number of profiles

Profiles7 records

Kenna Security funding detail

Funding detail

Funding overview

Funding rounds6 records

Investors12 records

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

Kenna Security M&A and investment

M&A and investment

M&A

Investments

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Frequently asked questions about Kenna Security

What does Kenna Security do?

Kenna Security offered Kenna.VM, a SaaS risk-based vulnerability management platform that uses real-world threat intelligence and advanced data science to prioritize security vulnerabilities based on actual risk and exploitability rather than generic severity scores. The platform helps enterprise security teams focus remediation efforts on the most critical threats amid overwhelming vulnerability volumes. Following Cisco's June 2021 acquisition, the product was rebranded as Cisco Vulnerability Management and integrated with Cisco's SecureX platform.

Is Kenna Security a public or private company?

Kenna Security is a private company. It is classified as corporate owned and is currently acquired.

When was Kenna Security founded?

Kenna Security was founded in 2010. It employs 51 to 100 people.

Where is Kenna Security based?

Kenna Security is headquartered in San Francisco, United States, in the North America region.

How does Kenna Security make money?

One revenue line is on record: enterprise Security Software.

Who are Kenna Security's main competitors?

Direct peers on record are Rapid7, Tenable, Qualys and Skybox Security. Broad incumbents are Forescout, Palo Alto Networks and CrowdStrike. Emerging players are Armis, Balbix and Wiz.

Does Kenna Security have an API?

No public API is recorded for Kenna Security.

Unlock the full company data

50 free credits on sign-up, no credit card required.

Contact sales
Live signals
SecurityWeekEmpirical Security Raises $25 Million in Series A FundingCybersecurity startup Empirical has secured $25 million in a Series A funding round led by Brightmind Partners, bringing its total capitalization to $37 million. The company intends to utilize these funds to accelerate the development of its predictive security products, Foundation and Radiant, designed to identify threats in the agentic AI era. Founded in 2024 by former Kenna Security executives, Empirical aims to provide data-driven insights for risk management in technology, healthcare, and financial services sectors.wiz.ioKenna EOL and the Shift to Exposure ManagementCisco announced the end-of-sale and end-of-life for Cisco Vulnerability Management (formerly Kenna Security), with support ending in June 2028. The transition highlights a shift from traditional risk-based vulnerability management (RBVM) to a holistic exposure management approach, exemplified by companies like Western Union adopting new strategies.NewsroomCisco completes the acquisition of Kenna SecurityCisco has completed its acquisition of Kenna Security, a cybersecurity firm specializing in risk-based vulnerability management, to enhance its security platform. This integration aims to improve threat detection, vulnerability prioritization, and response times by leveraging Kenna's machine learning technology within Cisco's broader security infrastructure.Persistence Market ResearchManaged Security Services Market Size & Trends Report, 2033The global Managed Security Services market was valued at US$ 25,400.3 million in 2022 and is projected to reach US$ 83,977.7 million by 2033, growing at a compound annual growth rate (CAGR) of 11.6%. Key transactions include Accenture's acquisition of Symantec Cyber Security Services from Broadcom in January 2020 and Cisco's announced acquisition of Kenna Security in March 2023, while IBM announced a multi-million dollar investment in human capital for the Asia Pacific region in February 2022. The BFSI sector held the largest market share at 36.3% in 2022, with cloud-based deployment emerging as the fastest-growing segment at a 13.6% CAGR.PR NewswireCisco Completes Acquisition of Kenna SecurityCisco has completed the acquisition of Kenna Security, Inc., which is known for its risk-based vulnerability management platform. This acquisition aims to enhance Cisco's capabilities in simplifying security measures and improving customer security postures. The integration of Kenna's technology with Cisco's SecureX platform is expected to enable more effective threat detection and response.FinSMEsCisco To Acquire Kenna SecurityCisco has completed the acquisition of Kenna Security, a cybersecurity provider based in Santa Clara, CA, on June 30, 2021. This acquisition is aimed at enhancing collaboration between security and IT teams to better detect and respond to threats, leveraging Kenna Security's capabilities alongside Cisco's SecureX platform. The deal's financial details were not disclosed.GlobeNewswireKenna Security Honored With 5-Star Rating in the 2021 CRN® Partner Program GuideKenna Security earned a 5-Star rating in CRN's 2021 Partner Program Guide, recognizing its partner program for excellence. The company's Kinetic program supports over 40 partners with tools for marketing, support, and technology. The guide is featured in the April 2021 issue of CRN.GlobeNewswireKenna Security expands in Canada, driven by triple-digit growthKenna Security is investing in new infrastructure to support operations in Canada, where revenue has grown triple-digit over four years. The company launched a Canada-native instance of its vulnerability management platform to meet data residency requirements. The platform uses threat intelligence to prioritize mitigation strategies.GlobeNewswireKenna Security Named CISO Choice Award Winner for Vulnerability ManagementKenna Security won the CISO Choice Award for Vulnerability Management from Security Current. The award recognizes its risk-based vulnerability management solution, Kenna.VM, which helps prioritize and patch dangerous security gaps. The company serves customers including CVS, KPMG, and Fortune 100 firms.