← Deep Dives / July 31, 2026

$TENB: The Quiet Giant Waking Up to OT Security

Sector Research: Defending machines, not laptops →

The median time between a vulnerability being disclosed and a working exploit appearing in the wild was 771 days in 2021. By early 2026 it had collapsed to under two days. That is not a marginal improvement for attackers. That is a category change, and it is being driven by AI models that can analyze code, identify weaknesses, and generate working exploits faster than any human security team can patch.

Most investors looked at that number and bought CrowdStrike or Palo Alto. Fair enough. But there is a second order problem sitting underneath it, one that is larger and far less priced in. The factory floor, the water treatment plant, the hospital MRI machine, the building management system in every office tower: none of these were ever designed to be connected to the internet, none of them run conventional security agents, and most CISOs had no idea how many of them existed on their networks until somebody looked. More than half of CISOs are now responsible for OT security, which has remained a dangerous blind spot where IT networks meet cyber physical systems, and fears of operational disruptions have hindered cybersecurity progress.

The company that has spent 24 years building the most comprehensive map of enterprise vulnerabilities just launched a way to bring all of those invisible assets into that map without deploying new hardware, new agents, or specialized staff. That company is $TENB. The thesis is straightforward: OT security is entering its binding constraint moment, Tenable owns the scanning data layer that everything else depends on, and the stock has spent two years in the penalty box for reasons that are slowly reversing.

The curve

OT security sits in early deployment. The technology works. The regulatory pressure is real and accelerating. The customer awareness is finally there. What has been missing is the on ramp, the moment when a CISO at a food manufacturer or a regional utility can protect operational technology without hiring a six person specialist team or buying a dedicated sensor network that takes 18 months to deploy. That friction is the binding constraint, and it is starting to crack.

The OT security market grew from roughly $22 billion in 2025 to nearly $25 billion in 2026, expanding at a 12% compound annual growth rate. That sounds orderly. What it does not capture is the regulatory shock that arrived in the spring of 2026. For federal civilian agencies, OMB M-26-14, the new logging mandate, and CISA BOD 26-04, a binding directive requiring risk based vulnerability management, put OT and IoT firmly in scope for cybersecurity programs. Federal agencies now have hard deadlines. Private critical infrastructure operators are watching and moving one step behind.

CISA updated its advisory on Iranian affiliated APT actors exploiting internet connected OT devices as recently as July 22, 2026, adding new guidance on detecting malicious changes in Rockwell Automation PLC programs. That is a live, active threat, not a theoretical one. CISA’s April 2026 ICS advisories covering Honeywell, Mitsubishi Electric, Delta Electronics, and rail signaling systems urged critical infrastructure operators to apply mitigations immediately.

The thing that decides when this sector inflects is not awareness. Awareness is everywhere. It is ease of adoption. Unlike IT environments, OT networks present a unique challenge for defenders. Hardware lifecycles span 15 to 30 years. Industrial protocols like Modbus, DNP3, and PROFINET were designed for reliability, not security. Any solution that requires ripping out those systems or dropping passive sensors across a plant floor faces a decade long sales cycle. The inflection comes when you can achieve 80% of the visibility with a software update on infrastructure that already exists.

That is exactly what Tenable shipped in April 2026. Tenable announced a new OT asset discovery engine that enables security teams to quickly bring risks associated with cyber physical systems into a unified view of cyber exposure, with instant deployment and no additional IT overhead required. Early access customers across hospitality, financial services, education, food and beverage, and government uncovered a large number of unknown OT and IoT assets upon initial deployments, with most customers discovering between 100 and 1000 or more unique assets, including some with critical vulnerabilities. Those numbers matter. They prove the problem is real and that the friction is solvable.

The broader sector is also being reshaped by consolidation. In June 2026, Accenture agreed to acquire a majority stake in Dragos at a $3.25 billion valuation. Nozomi Networks was acquired by Mitsubishi Electric in January 2026. The two largest pure play OT security vendors just went private or were absorbed into industrial conglomerates. That leaves a vacuum for a publicly accessible, platform level OT security offering, and Tenable is the only name large enough and public enough to fill it.

The inflection point is the regulatory deadline stack. OMB M-26-14 and CISA BOD 26-04 are already in force. The NIS2 Directive is driving parallel spending across Europe. Both mandates explicitly call out AI accelerated attacks as the driver: adversaries are using automation to compress the window between vulnerability disclosure and weaponization to mere hours. Every new CISA advisory tightens the compliance clock. The constraint is not awareness. It is procurement friction. Tenable just removed it.

The company

Tenable was founded in 2002 and built its first reputation around Nessus, the vulnerability scanner that became the de facto standard for security teams trying to understand what was running on their networks. Today that heritage is both the asset and the misunderstanding that keeps the stock underpriced. Most analysts cover Tenable as a vulnerability management company facing competition from larger platforms. That framing is wrong, or at least incomplete.

The better frame is that Tenable sits on the largest proprietary asset and exposure data set in the industry, built from 24 years of scanning across millions of enterprise environments. According to Gartner, “Tenable’s long standing dominance in vulnerability assessment, its strong asset and attack surface discovery capabilities, and its ability to execute on its AI strategy make it the front runner in AI powered exposure assessment.” That data advantage is not something a competitor can buy or replicate quickly. It is a function of installed base and time.

The platform is called Tenable One. Gartner notes that “Tenable’s broad attack surface coverage sets it apart from competitors. Tenable One is a well integrated platform that spans traditional IT, identity, cloud, CPS, and container environments,” with visibility extending to emerging attack surfaces such as AI. The OT Security module, sitting inside that same platform, now benefits from the Instant OT Discovery engine launched in April. Tenable integrated OT discovery directly into its core solutions for risk based vulnerability management within the Tenable One Exposure Management Platform, requiring no specialized hardware, additional agents, or add ons.

The AI layer on top is called Hexa AI. Tenable Hexa AI is the agentic engine of the Tenable One Exposure Management Platform, built to turn exposure intelligence into coordinated action at machine speed. Powered by the Tenable Exposure Data Fabric, which combines native telemetry, third party data, and insights from Tenable Research, Hexa AI helps organizations prioritize and remediate cyber risk. The initiatives include new Claude powered workflows. That is not a marketing slide. Tenable joined both Anthropic’s Project Glasswing initiative and OpenAI’s Daybreak Cyber Partner Program. Both partnerships give Tenable access to non public model research and co development resources.

On the federal side, Tenable One Cloud Exposure achieved FedRAMP High and Impact Level 5 authorization in June 2026, reinforcing its position as a trusted exposure management platform for federal agencies. In July 2026, Tenable joined Cisco’s SolutionsPlus program, enabling Cisco customers to seamlessly transition from vulnerability management to exposure management with Tenable One. That Cisco distribution deal is the kind of thing that quietly adds pipeline without showing up in headline revenue for two or three quarters.

The co CEO structure, with Steve Vintz and Mark Thurmond sharing the role since the death of founder Amit Yoran in early 2024, was a source of uncertainty. That uncertainty has faded. The strategy is consistent, the execution has been clean, and the AI roadmap is credible. What changed my view on this company is not the OT product alone. It is the convergence of that product launch with the regulatory moment and the competitive vacuum left by the Dragos and Nozomi acquisitions happening simultaneously.

The numbers

Tenable reported Q1 2026 revenue of $262.1 million, a year over year growth rate of 9.6%, with a GAAP operating margin of 3.3% and a non GAAP operating margin of 23.6%, a year over year increase of 320 basis points. Net cash provided by operating activities was $88.0 million and unlevered free cash flow was $88.6 million. The cash flow number is the one that matters most for a recurring software business. Generating nearly a third of quarterly revenue in free cash flow is a sign of a business that no longer needs to prove itself operationally.

The company cited more than $1 billion of last twelve month revenue, $232 million of last twelve month operating income, and approximately 95% recurring revenue. Non GAAP operating margin is guided to rise from 9.4% in 2021 to 24.0% in 2026, while unlevered free cash flow margin improved from 17.6% to a guided 27.0%. Mid term non GAAP targets for 2029 include total revenue growth in the high single digit to low double digit range, gross margin of about 81.5 to 82.5%, and unlevered free cash flow margin of around 31%. These are not hockey stick projections. They are a straight line continuation of a margin expansion that has already been happening for five consecutive years.

Tenable raised earnings guidance for the year ending December 31, 2026, with the company expecting revenue in the range of $1.068 billion to $1.078 billion. Full year 2026 non GAAP earnings per share guidance is $1.90 to $1.98, a 22% year over year increase at the midpoint. As of a recent trading day, shares opened at $34.09 with a market cap of $3.76 billion, a debt to equity ratio of 1.42, and current and quick ratios of 0.85. The debt load is worth watching but is manageable given the free cash flow profile.

In Q4 2025, Tenable added 502 new enterprise platform customers and announced a $150 million expansion of its share repurchase program. In Q1 2026, the Tenable One platform accounted for 41% of new business, an 8-point increase from the previous year. That platform mix shift is the most important metric in the model. Every customer that moves from standalone Nessus to Tenable One becomes an upsell candidate for OT Security, cloud security, identity exposure, and eventually Hexa AI. The unit economics improve with each expansion.

Analysts expect Tenable to announce Q2 2026 earnings of $0.47 per share and revenue of $264.8 million for the quarter ending June 30, 2026, with results due after the market close on July 29. That is a two day window from today. One note of honest uncertainty: management’s guidance for the second half of 2026 suggests a slowdown in revenue growth compared to Q1. If that guidance proves conservative, the stock re rates. If the deceleration materializes, the near term narrative stalls. I watch Q2 guidance for H2 closely.

Why it wins

The actual moat is the Nessus data flywheel. Tenable’s scanner has been running inside enterprise environments for over two decades, accumulating a proprietary understanding of how assets behave, how vulnerabilities present, and how networks are actually structured versus how they appear on paper. Gartner noted that Tenable achieved its front runner status by combining its long standing dominance in vulnerability assessment with strong asset and attack surface discovery capabilities, support for third party telemetry ingestion, and AI. Tenable ingests asset and exposure data across the attack surface for cross domain context and applies AI to enhance prioritization, analyze attack paths, and enable greater automation. That is not a feature that a new entrant can replicate with a larger sales team.

The OT positioning specifically wins because Tenable is not asking industrial operators to replace their control systems or install passive sensors. The VM Native OT Discovery capability provides a fast, low friction entry point for organizations to gain comprehensive IT and OT visibility and accelerate AI driven exposure management, with instant deployment and no additional IT overhead required. This matters enormously in OT environments where a firmware update on a PLC requires a maintenance window, an engineer on site, and a change control board approval. The no new hardware approach removes most of the procurement friction that has kept OT security penetration low.

The competitive vacuum created by the Dragos and Nozomi acquisitions in 2026 is a legitimate structural tailwind. Both of those companies are now embedded inside Accenture and Mitsubishi respectively. Neither will be running aggressive enterprise software sales motions against Tenable’s installed base. That leaves $TENB as the most accessible pure play OT and exposure management option available to public market investors, with a platform and data asset that took 24 years to build.

The Hexa AI and Cisco partnerships are the upside optionality that the market has not fully priced. Tenable integrated Claude powered workflows into Hexa AI and joined OpenAI’s relevant programs. Tenable also introduced Flex pricing in Q1 2026, keeping pricing per asset but applying consistent pricing across asset types, which management said can reduce procurement friction as customers expand across the attack surface. Flex pricing is the kind of structural change that accelerates upsell velocity without requiring a new product. Combined with the Cisco distribution channel, the pipeline math improves materially in H2 2026 and into 2027.

What could go wrong

The clearest risk is platform consolidation by the large players. Palo Alto, CrowdStrike, and Microsoft are all building broader security platforms and all have OT security ambitions. Palo Alto’s acquisition strategy in particular has been aggressive. If one of those players buys a significant OT sensor network or acquires a Claroty like asset at scale, Tenable’s no new hardware advantage could be neutralized by a competitor that owns the hardware layer and gives away the software. I would want to see Tenable’s OT win rates in competitive deals before feeling fully comfortable here.

The H2 2026 guidance deceleration that management flagged is the near term financial risk. The company faces challenges in educating customers about the new AI driven threat landscape, which may prolong sales cycles. Tenable is also experiencing fluctuations in contract duration and billing metrics, which could impact financial predictability. If Flex pricing introduces any near term revenue recognition lumpiness, the street will punish the stock before understanding the underlying dynamics.

Tenable carries a debt to equity ratio of 1.42, which is not alarming but is worth monitoring in a higher for longer rate environment. The $150 million buyback announced in Q4 2025 competes with debt reduction for capital allocation attention. If free cash flow disappoints even slightly, the market will question whether the buyback was the right call. I would reverse my view on the capital allocation discipline if FCF margin contracts meaningfully from the guided 27% level.

There is also the AI existential question that the market has been pricing in fitfully. AI disruption fears weigh on valuation, yet management views AI as a collaborative force, not a replacement, and is integrating AI into its platform. The argument that AI models will discover vulnerabilities faster than Tenable can scan for them is real but cuts both ways. It also means organizations are more exposed than ever and need Tenable’s prioritization layer more than ever. The risk I am watching is whether a frontier model provider enters exposure management directly, bypassing the middleware layer that Tenable occupies. That would be a different and more serious threat than what we see today.

What I am watching

Tenable will release Q2 2026 financial results for the quarter ended June 30, 2026, after the U.S. market close on Wednesday, July 29. That is the single most important near term event. I am focused on three numbers: Q2 revenue versus the $264.8 million consensus, the H2 guidance revision relative to the existing full year $1.068 to $1.078 billion range, and the Tenable One platform mix as a percentage of new business. Any improvement above the 41% Q1 figure signals that the platform upsell motion is working. Any meaningful H2 guidance raise signals that OT and Hexa AI are pulling deal sizes up.

Tenable has scheduled Hexa AI general availability for September 1, 2026. That date is a catalyst regardless of the Q2 print. Hexa AI is the agentic layer that turns the Tenable One data advantage into automated remediation workflows. If the September launch lands with meaningful enterprise case studies attached, it changes the narrative from vulnerability scanner to autonomous security operations platform. The pricing structure for Hexa AI has not been fully disclosed publicly, which means the Q3 earnings call will be the first time investors hear management speak to attach rates.

I am also watching the Cisco SolutionsPlus partnership signed in July 2026 for any pipeline commentary on the Q2 call. Cisco has one of the largest installed bases of enterprise networking equipment globally. Cisco customers can now seamlessly transition from vulnerability management to exposure management with Tenable One. Distribution partnerships like this tend to look slow for two quarters and then accelerate. If Cisco sales reps are actively co selling Tenable One into their renewal cycles, the Q4 2026 pipeline should be measurably larger than Q4 2025.

On the regulatory side, I am tracking the compliance deadlines attached to CISA BOD 26-04 and OMB M-26-14. OMB issued M-26-14 on May 22, 2026, reframing logging around continuous event monitoring and real time visibility requirements. Federal agencies have hard deadlines tied to this memo. When those deadlines approach, procurement cycles compress and vendor selection speeds up. Any federal agency win announcement in Q3 or Q4 that explicitly references OT or ICS compliance is a signal that the regulatory tailwind is converting to revenue.

The bottom line

OT security is in early deployment. The sector’s binding constraint has been friction: the cost and complexity of getting visibility into industrial systems that were never designed to be monitored. Tenable just removed that friction with a software only OT discovery engine that deploys in hours instead of months. At the same moment, the two largest pure play OT security vendors vanished from the public market into private hands. The regulatory clock is running. The AI driven vulnerability velocity is accelerating. And Tenable is sitting on 24 years of scanning data that no competitor can replicate.

The stock is not obviously cheap at $3.76 billion with revenue growing in the high single digits. But 95% recurring revenue, a 27% free cash flow margin, a Gartner number one designation published in June 2026, a Q2 earnings print in two days, and a September general availability for Hexa AI create a sequence of catalysts that the market has not fully processed. The thing that would change my view: a large platform player announcing a no hardware OT discovery product with comparable scan depth, or Tenable’s H2 guidance missing below current consensus. Neither has happened yet.

Not financial advice.

Positions and business relationships. Assume that Dr. Paul Christianson and/or Disruptor Investing, LLC may hold a long or short position in any security mentioned above, whether or not a position is stated, and may buy or sell at any time without notice. Assume also that a company mentioned above may be a current or former paid client of Disruptor Investing's CEO interview program, or may otherwise have a business relationship with Disruptor Investing. This research is reviewed before publication but is not a substitute for your own diligence. Verify every figure against the company's SEC filings before relying on it. Nothing here is investment, legal, tax, or financial advice. Dr. Christianson is not a registered financial advisor, investment adviser, or broker-dealer. Educational content only. Full disclosures and compensation terms.