Skip to content
KStart free
AI InfrastructureDefenseQuantumAll studies →

TENB US Equity

Tenable Holdings, Inc.Information Technology · Services-Prepackaged Software · CIK 1660280 · FY ends Dec 31
$34.38
+0.27 (+0.79%)
USD · as of 2026-08-21 · marketstack

TENB · 10-K · period ended 2021-12-31

← all TENB documents
filed 2022-02-25 · EDGAR original ↗

Our rendering of the filing — original pagination and typography are not reproduced, and tables are reduced to their short label cells (the figures live on FA). Nothing is summarized: every line below is the filing's own text.

blocks 1493 of 1,556332k characters rendered

tenb-20211231

UNITED STATES

SECURITIES AND EXCHANGE COMMISSION

Washington, D.C. 20549

______________________________________

FORM 10-K

______________________________________

For the fiscal year ended December 31, 2021

or

For the transition period from _____ to _____

Commission file number 001-38600

______________________________________

TENABLE HOLDINGS, INC.

(Exact name of registrant as specified in its charter)

______________________________________

6100 Merriweather Drive, Columbia, Maryland21044

(Address of principal executive offices, including zip code)

(410) 872-0555

(Registrant’s telephone number, including area code)

______________________________________

Securities registered pursuant to Section 12(b) of the Act:

Title of each class Trading symbol(s) Name of exchange on which registered

Common stock, par value $0.01 per share TENB Nasdaq Global Select Market

Securities registered pursuant to Section 12(g) of the Act: None

Indicate by check mark if the registrant is a well-known seasoned issuer, as defined in Rule 405 of the Securities Act. Yes☒ No ☐

Indicate by check mark if the registrant is not required to file reports pursuant to Section 13 or Section 15(d) of the Act. Yes ☐No☒

Indicate by check mark whether the Registrant (1) has filed all reports required to be filed by Section 13 or 15(d) of the Securities Exchange Act of 1934 during the preceding 12 months (or for such shorter period that the Registrant was required to file such reports), and (2) has been subject to such filing requirements for the past 90 days. Yes☒ No ☐

Indicate by check mark whether the registrant has submitted electronically every Interactive Data File required to be submitted pursuant to Rule 405 of Regulation S-T (§ 232.405 of this chapter) during the preceding 12 months (or for such shorter period that the registrant was required to submit such files). Yes☒ No ☐

Indicate by check mark whether the registrant is a large accelerated filer, an accelerated filer, a non-accelerated filer, a smaller reporting company or an emerging growth company. See the definitions of “large accelerated filer,” “accelerated filer,” “smaller reporting company” and "emerging growth company" in Rule 12b-2 of the Exchange Act.

Large accelerated filer ☒ Accelerated filer ☐

Non-accelerated filer ☐ Smaller reporting company ☐

Emerging growth company ☐

Indicate by check mark whether the registrant has filed a report on and attestation to its management's assessment of the effectiveness of its internal control over financial reporting under Section 404(b) of the Sarbanes-Oxley Act (15 U.S.C. 7262(b)) by the registered public accounting firm that prepared or issued its audit report. ☒

Indicate by check mark whether the registrant is a shell company (as defined in Rule 12b-2 of the Exchange Act). Yes ☐ No ☒

As of June 30, 2021, the aggregate market value of the common stock of the registrant held by non-affiliates was approximately $3.9 billion.

The number of shares of the Registrant's common stock outstanding as of February 22, 2022 was 109,780,284.

DOCUMENTS INCORPORATED BY REFERENCE

Portions of the registrant's definitive Proxy Statement relating to the 2022 Annual Meeting of Stockholders are incorporated herein by reference in Part III of this Annual Report on Form 10-K. The Proxy Statement will be filed with the Securities and Exchange Commission within 120 days after the year ended December 31, 2021.

Table of Contents

TENABLE HOLDINGS, INC.

TABLE OF CONTENTS

Page

PART I

Item 1. Business 4

Item 1A. Risk Factors 12

Item 1B. Unresolved Staff Comments 39

Item 2. Properties 39

Item 3. Legal Proceedings 40

Item 4. Mine Safety Disclosures 40

PART II

Item 6. Selected Financial Data 42

Item 7A. Quantitative and Qualitative Disclosures about Market Risk 65

Item 8. Financial Statements and Supplementary Data 67

Item 9A. Controls and Procedures 98

Item 9B. Other Information 99

Item 9C. Disclosure Regarding Foreign Jurisdictions that Prevent Inspections 99

PART III

Item 10. Directors, Executive Officers and Corporate Governance 100

Item 11. Executive Compensation 100

Item 14. Principal Accountant Fees and Services 100

PART IV

Item 15. Exhibits, Financial Statement Schedules 101

Signatures

2

Table of Contents

PART I

Forward-Looking Statements

This Annual Report on Form 10-K, including the sections entitled "Business," "Risk Factors," and "Management's Discussion and Analysis of Financial Condition and Results of Operations," contains forward-looking statements that involve known and unknown risks, uncertainties and other factors that may cause our actual results, levels of activity, performance or achievements to be materially different from the information expressed or implied by these forward-looking statements. Statements that are not purely historical are forward-looking statements within the meaning of Section 27A of the Securities Act of 1933, as amended, and Section 21E of the Securities Exchange Act of 1934, as amended. In some cases, you can identify forward-looking statements by the words “anticipate,” “believe,” “continue,” “could,” “estimate,” “expect,” “intend,” “may,” “might,” “objective,” “ongoing,” “plan,” “predict,” “project,” “potential,” “should,” “will,” or “would,” or the negative of these terms, or other comparable terminology intended to identify statements about the future. These forward-looking statements include, but are not limited to, statements concerning the following:

•the anticipated impact of the global economic uncertainty and financial market conditions caused by the COVID-19 pandemic on our business, results of operations and financial condition, including on our sales and our revenue growth rate;

•our market opportunity;

•the effects of increased competition as well as innovations by new and existing competitors in our market;

•our ability to adapt to technological change, release new products and product features and effectively enhance, innovate and scale our enterprise platform and solutions;

•our ability to effectively manage or sustain our growth and to achieve profitability;

•our ability to maintain and expand our customer base, including by attracting new customers;

•our relationships with third parties, including channel partners;

•completed and potential acquisitions and integration of complementary businesses and technologies;

•our ability to maintain, or strengthen awareness of, our brand;

•perceived or actual problems with the security, integrity, reliability, compatibility and quality of our platform and solutions;

•future revenue, hiring plans, expenses, capital expenditures, capital requirements and stock performance;

•our ability to attract and retain qualified employees and key personnel and further expand our overall headcount;

•our ability to stay abreast of new or modified laws and regulations that currently apply or become applicable to our business both in the United States and internationally;

•our ability to maintain, protect and enhance our intellectual property;

•costs associated with defending intellectual property infringement and other claims; and

•the future trading prices of our common stock and the impact of securities analysts’ reports on these prices.

These statements represent the beliefs and assumptions of our management based on information currently available to us. Such forward-looking statements are subject to risks, uncertainties and other important factors that could cause actual results and the timing of certain events to differ materially from future results expressed or implied by such forward-looking statements. Factors that could cause or contribute to such differences include, but are not limited to those discussed in the section titled “Risk Factors” included under Part I, Item 1A. Such risks and uncertainties may be amplified by the COVID-19 pandemic and its potential impact on our business and the global economy. You should not rely upon forward-looking statements as predictions of future events. Furthermore, such forward-looking statements speak only as of the date of this report. Except as required by law, we undertake no obligation to update any forward-looking statements to reflect events or circumstances that occur after the date of this report.

3

Table of Contents

Item 1. Business

Overview

We are a leading provider of Cyber Exposure solutions. Cyber Exposure is a discipline for managing, measuring and comparing cybersecurity risk in the digital era.

Digital transformation is driving radical change and is powering the economy and our social infrastructure. A digital-first economy is only sustainable if it is built with a solid cybersecurity foundation. As organizations modernize their IT infrastructures and adopt cloud or hybrid cloud architectures that are no longer housed in the confines of their traditional on-premise IT networks, they have less visibility and control over the security of these assets. Organizations are also increasingly implementing modern solutions, such as Cloud, DevOps, Infrastructure as Code, or IaC, Mobility, Internet of Things, or IoT, devices, digital identity, web applications and application containers, to enable the rapid development and deployment of new products, services and business models, as well as to drive operational efficiencies. Further, safety-critical Operational Technology, or OT, such as Industrial Control Systems, are now network-connected and must be secured from cybersecurity threats. As organizations implement these modern solutions, they significantly expand their cyber attack surface.

While other functions in an organization, such as finance and operations, have systems to help them manage and measure risk, cybersecurity risk has not historically been adequately measured or understood. We are building on our deep technology expertise as a pioneer in the vulnerability assessment and management market to provide broad visibility across the modern attack surface and deep insights to help security teams, executives and boards of directors prioritize and measure Cyber Exposure. We believe our Cyber Exposure solutions are transforming how cybersecurity risk is managed and measured and will help organizations more rapidly embrace digital transformation.

In 2021, 2020 and 2019 our total revenue was $541.1 million, $440.2 million and $354.6 million, respectively, representing year-over-year growth rates of 23% from 2020 to 2021 and 24% from 2019 to 2020. Our net loss was $46.7 million, $42.7 million and $99.0 million in 2021, 2020 and 2019, respectively. Our cash flows from operating activities were $96.8 million, $64.2 million and $(10.7) million in 2021, 2020 and 2019, respectively.

Our Enterprise Platform Offerings

Our enterprise platform enables organizations to answer foundational and strategic questions such as:

•Where are we exposed?

•Where should we prioritize remediation based on risk?

•Are we reducing our exposure over time?

•How do we compare to our peers?

We have continued to expand and diversify our platform offerings from traditional vulnerability management (VM) solutions, which include Tenable.sc and Nessus, to our cloud exposure solutions, which include Tenable.ep, Tenable.io, Tenable.cs, Tenable Web Scanning, or Tenable.io WAS, Tenable.ad and Tenable.ot. Our platform offerings provide broad visibility into security issues such as vulnerabilities, misconfigurations, internal and regulatory compliance violations and other indicators of the state of an organization’s security across IT infrastructure and applications, cloud environments, DevOps environments, Active Directory and Identity environments, and Industrial IoT and OT environments. We also provide deep analytics to help organizations score, trend and compare their cyber exposure over time, and communicate cyber risk in business terms to make better strategic decisions. Our platform offerings integrate and analyze data from our native collectors alongside IT asset, vulnerability and threat data from third-party systems and applications to prioritize security issues for remediation and focus an organization’s resources based on risk and business criticality.

Tenable.ep is our unified platform that helps organizations identify, assess and accurately prioritize cyber risks across the entire attack surface. In addition to streamlining risk-based vulnerability management, Tenable.ep delivers deep business insights that empower organizations to calculate, communicate and compare their cyber risk exposure over time with that of their industry peers. These advanced capabilities enable a better understanding of the overall effectiveness of

4

Table of Contents

security programs and provide a key guide for strategic decision-making. Tenable.ep includes Tenable.io, Tenable.cs, Tenable.io WAS, Tenable.ad, and Tenable Lumin risk analytics.

Tenable.io is our cloud-delivered software as a service, or SaaS, offering that provides organizations with a risk-based view of traditional and modern attack surfaces. Tenable.io is designed with views, workflows and dashboards to deliver a complete and continuous view of all assets, both known and previously unknown, and any associated vulnerabilities, internal and regulatory compliance violations, misconfigurations and other cybersecurity issues, prioritize these issues for remediation based on risk assessment and predictive analytics, and provide insightful remediation guidance. Tenable.io is available as a standalone solution or as part of Tenable.ep.

Tenable.cs is our cloud-native application platform that enables organizations to programmatically detect and fix cloud infrastructure misconfigurations in the design, build and runtime phases of the Software Development Lifecycle to prevent unresolved insecure configuration or exploitable vulnerabilities from reaching production. Tenable.cs secures IaC before deployment, maintains a secure posture in runtime, and controls policy deviations over time by synchronizing configuration between runtime and IaC. Tenable.cs also includes Frictionless or Nessus Assessment for cloud workloads as well as Container Security to assess cloud hosts and container images for vulnerabilities without the need to manage scan schedules, credentials or agents. Tenable.cs is available as a standalone solution, as part of Tenable.io or as part of Tenable.ep.

Tenable.io WAS provides easy-to-use, comprehensive and automated vulnerability scanning for modern web applications, and allows organizations to quickly configure and manage web app scans, enabling them to identify vulnerabilities and prioritize remediation. Tenable.io WAS is available as part of Tenable.io or Tenable.ep.

Tenable.ad is our solution to secure Active Directory environments by enabling users to find and fix existing weaknesses before they are exploited and detect and respond to ongoing attacks in real time without the need to deploy agents or use privileged accounts. Tenable.ad is sold as a stand-alone solution and integrates with Tenable.io and Tenable.sc.

Tenable.ot is our solution that provides threat detection, asset tracking, vulnerability management, and configuration control capabilities to protect OT environments, including industrial networks. Tenable.ot is sold as a stand-alone solution and integrates with Tenable.io and Tenable.sc.

Tenable.sc is our on-premise offering that provides a risk-based view of an organization’s IT, security and compliance posture so organizations can quickly identify, investigate and prioritize their assets and vulnerabilities based on risk assessment and predictive analytics, and provide insightful remediation guidance.

Our enterprise platform offerings deliver the following capabilities:

•Live asset discovery. We can automatically discover a broad range of traditional and modern IT assets, including on-premises infrastructure, web applications, cloud environments, mobile devices, containers, IoT devices and OT systems. We use a combination of active scanning, passive network monitoring and public cloud monitoring via our connectors to identify known and unknown assets on the network.

•Automated exposure assessment. With every change in a customer’s computing environment, we can automatically assess and identify where there are vulnerabilities, internal and regulatory compliance violations and misconfigurations across assets and cloud environments, such as missing software patches or outdated software versions. In addition, we can help optimize existing security technology investments to identify indicators of cyber exposure, such as improperly configured anti-virus software.

•Deep analytics to allow for prioritization. We combine our product, vulnerability data and threat intelligence with third-party data to provide business context and enable organizations to prioritize remediation efforts based on the business criticality of the asset and the likelihood of exploit. Predictive Prioritization enables organizations to reduce business risk by focusing on the vulnerabilities with the greatest likelihood of imminently being exploited. It combines Tenable vulnerability data with third-party threat and vulnerability data across more than 150 data sources using a proprietary machine learning algorithm developed by Tenable Research and data science teams to provide clear guidance on where to focus remediation efforts. Predictive Prioritization provides a threat-based view of vulnerabilities, which is a critical component of modern risk-based vulnerability management.

5

Table of Contents

•Open and extensible platform. Our enterprise platform integrates with industry-leading IT workflow, security information and event management, or SIEM, and systems management tools to accelerate remediation and provide common visibility across security and IT operations teams.

•Cyber exposure measurement. Tenable Lumin leverages our expansive knowledge base of assets and vulnerabilities coupled with data science insights to help our customers objectively score, trend and benchmark cyber exposure across their organizations, including by business unit or geography, for comparison and best practices. We believe this capability is critical to help security executives effectively translate technical information and communicate cybersecurity risk to a non-technical audience, including the C-suite and the board of directors, to make better strategic decisions on where to focus investment to maximize cybersecurity risk reduction. As we continue to expand our database with more vulnerability and asset intelligence as well as additional third-party data sources, we anticipate that we will be able to leverage these insights in Lumin to measure an organization’s cyber exposure beyond vulnerabilities to overall cybersecurity program effectiveness.

Nessus

Nessus is one of the most widely deployed vulnerability assessment solutions in the cybersecurity industry and underpins our enterprise platform. Since the introduction of Nessus in 1998, an extensive community of Nessus users has emerged. We continue to cultivate knowledge and affinity within this user base, which, when combined with our enterprise customers and our Tenable Research team of cybersecurity and data science experts, creates powerful network effects in the form of a continuous feedback loop of data and insights. We use these learnings to expand our assessment capabilities and coverage, continually optimize our solutions and inform our product strategy and innovation priorities. We believe these data and insights will also fuel and strengthen our benchmarking capabilities over time.

Nessus Professional is a vulnerability assessment solution for identifying security vulnerabilities, configuration issues and malware. Nessus Professional serves as both a stand-alone product designed for security consultants and practitioners performing one-time or ad-hoc assessment as well as an on-ramp product to our enterprise platform. With broad vulnerability coverage, accurate analysis and an easy-to-use interface, Nessus Professional offers a cost-effective and comprehensive solution for security consultants and users with ad-hoc assessment needs.

Nessus Essentialsis our free version of our Nessus product, which includes vulnerability assessment for a limited number of assets, but does not include access to support and certain features that Nessus Professional customers enjoy.

Technology Architecture

Our platform is built from the ground up to support the needs of modern IT assets and environments. Our platform’s scalability can meet the requirements of the largest global enterprise customers, which may require assessment for millions of assets.

Foundational elements of our technology architecture include:

•Public cloud infrastructure for agility. Our use of the public cloud delivers agility and market responsiveness without the capital investment or time delay involved with planning, purchasing and deploying hardware. It also provides a flexible cost profile in which capacity can be quickly adjusted up or down in response to new opportunities and market demand, with relatively modest fixed costs.

•Scalability. Our platform scales up and down to continuously meet customer demands, through the use of public cloud infrastructure around the world. This approach provides elastic resources for compute, data transfer and storage, and allows us to meet the needs of even the largest global enterprises and government agencies. Our platform manages and supports millions of assets for multiple enterprise customers across a variety of industries, with the ability to process millions of application programming interface, or API, calls daily. The platform can scale to support IoT deployments that are an order of magnitude larger than IT deployments.

•Availability. Our modern architecture, leveraging state-of-the-art public cloud services, offers high availability and high performance. It provides geographic redundancy, as well as automated backup, without the need for us to build redundant infrastructure. As a result, we offer a service level agreement for Tenable.io that promises 99.95% availability to help ensure the reliability of operation for our customers.

6

Table of Contents

•Extensibility and integration. Our open API and software development kit, or SDK, enables import of data from third-party sources and sensors, including competitor products, to augment our native discovery, assessment and analytics. This is essential to providing a unified view of assets, vulnerabilities and exposure across the enterprise. These capabilities also enable flexible export of our data to third party systems.

•Unified Platform. Our products are built on a unified platform with a unified data model that enables us to share data, assets and vulnerabilities across our applications so our customers can run workflows and have a consistent user experience across our products.

•Widely adopted industry standard file format. The “.Nessus” file format for vulnerability data used in all of our products is openly documented and supported by dozens of products and programming languages, which simplifies integration with our ecosystem partners’ technologies.

Our Technology Ecosystem

We have partnered and/or integrated with market leading technology companies to pioneer the industry’s first Cyber Exposure ecosystem to help organizations build resilient cybersecurity programs. Our ecosystem consists of a variety of third-party data import sources into our platform offerings, as well as export of our data out to third-party IT systems. Our technology ecosystem connects disparate solutions and data to automate processes and accelerate an organization’s ability to understand, manage and reduce its cyber exposure.

We integrate a variety of third-party data sources, including ticketing, configuration management databases, or CMDBs, and systems management, into our platform to augment our native data collection and help with analysis and remediation prioritization. Furthermore, our data is also exported out to enrich third-party IT management and security systems.

Our Growth Strategy

Our objectives are to maintain our market leadership in Cyber Exposure and to capture our large market opportunity. To accomplish these objectives, we intend to:

•Continue to Acquire New Enterprise Platform Customers. We believe there is a substantial opportunity to increase adoption of our enterprise platform offerings. We have experienced growth in new enterprise platform customers due to improved product capabilities and investments in sales and marketing. We intend to continue to aggressively pursue new domestic and international customers by adding sales capacity and leveraging our network of channel partnerships around the world.

•Expand Asset Coverage Within Our Customer Base. We believe we have a significant opportunity to expand our relationships with our existing customers by targeting additional teams, business units or geographies, pursuing broad enterprise deployments and generally expanding our coverage of their IT assets and cross-selling new applications and solutions.

•Invest in Our Technology Platform. We intend to continue to innovate, develop and broaden our exposure and traditional vulnerability management solutions, including expanding the coverage of emerging attack surfaces and asset types and the addition of analytical capabilities, to help our customers measure and manage their cyber exposure. As we collect more data and ingest more data from third-party sources, we believe our data set will become even more valuable over time, which will allow us to continue to develop new analytical products and capabilities to our existing product suite over time.

•Explore Acquisition Opportunities. We intend to acquire other businesses, technology and/or development personnel that will expand and enhance the functionality of our platform offerings.

◦In February 2022, we acquired Cymptom to expand our products' ability to identify, understand and disrupt attack paths in enterprise networks.

◦In October 2021, we acquired Accurics to expand our cloud strategy and ability to assess IaC.

◦In April 2021, we acquired Alsid to expand our product offerings to include active directory security.

7

Table of Contents

◦In 2019, we acquired Indegy Ltd., or Indegy, to expand our depth of OT expertise and intelligence and our breadth of OT-specific capabilities from vulnerability management to asset inventory, configuration management and threat detection.

Customers

We sell and market our enterprise platform offerings through our field sales force that works closely with our channel partners, which includes a network of distributors and resellers, in developing sales opportunities. We use a two-tiered channel model whereby we sell our enterprise platform offerings to our distributors, which in turn sell to our resellers, which then sell to end users, which we call customers.

Our customers are located in over 170 countries and include enterprises of all sizes and span a wide range of industries, including manufacturing, energy and industrials; technology, media and telecommunications; banking, insurance and finance; government, education and non-profit; healthcare; and retail and consumer.

As of December 31, 2021, we had approximately 40,000 customers. At December 31, 2021 our customers included approximately 60% of the Fortune 500 and approximately 40% of the Global 2000. In 2021, 2020 and 2019, no single customer represented more than 2% of our revenue.

Sales and Marketing

Our sales strategy employs both a direct-touch approach through our sales forces and a low-touch approach through sales closed by our channel partners and transacted on our e-commerce website. Both direct-touch and channel-originated sales are fulfilled through our channel partnerships. Our sales and customer success renewal teams collaborate closely with our channel partners to prospect, manage and support our customers, developing and maintaining close relationships with all of our enterprise platform customers.

We sell to organizations of all sizes across a broad range of industries, with a specific focus on enterprise accounts. Our sales team is divided by customer size and geography, including the Americas; Europe, the Middle East and Africa ("EMEA"); and Asia Pacific and Japan.

Our partner ecosystem provides us with a number of advantages, including increased in-bound registered sales leads, broader geographic reach and greater deal velocity. Our channel partners include distributors, value-added resellers, system integrators and managed security service providers.

Our marketing efforts focus on cultivating brand awareness and leveraging our brand strength with Nessus, building demand across all segments with a specific emphasis on our enterprise customers and delivering tailored marketing programs focused on security executives, functional managers and security practitioners and consultants with Nessus. We also provide educational programs to DevOps teams for our Container Security and Web Application Scanning products. We execute marketing programs targeted at new customer acquisition, customer retention and cross-selling and up-selling of products across our platform.

Research and Development

We continue to invest substantial resources in research and development to enhance our platform offerings by developing new features, functionality, and applications. Our engineering expertise combines extensive security product development experience with individuals who possess deep cloud and user interface design background.

Additionally, our Tenable Research team includes a team of cybersecurity and data science experts who deliver Cyber Exposure intelligence, data science insights, alerts and security advisories. Frequent updates from Tenable Research ensure the latest vulnerability checks, zero-day research, and configuration benchmarks are available within our Cyber Exposure solutions.

We believe ongoing and timely development of new products and features is imperative to maintaining our competitive position. We continue to invest in development of our solutions across our global research and development team.

8

Table of Contents

Our research and development expense was $116.4 million, $101.7 million and $87.1 million in 2021, 2020 and 2019, respectively.

Backlog

We define backlog as contractually committed orders to be invoiced under our existing agreements that are not included in the deferred revenue on our consolidated balance sheets. At December 31, 2021 and 2020, we had backlog of $27.7 million and $8.0 million, respectively. We expect substantially all of the backlog at December 31, 2021 to be invoiced within the following twelve months.

Competition

The market for cybersecurity solutions is fragmented, intensely competitive and constantly evolving. We compete with a range of established and emerging cybersecurity software and services vendors, as well as homegrown solutions. With the introduction of new technologies and market entrants, we expect the competitive environment to remain intense going forward. Our competitors include: vulnerability management and assessment vendors, including Qualys and Rapid7; diversified security software and services vendors; endpoint security vendors with nascent vulnerability assessment capabilities, including CrowdStrike; public cloud vendors and companies, such as Palo Alto Networks, that offer solutions for cloud security (private, public and hybrid cloud); and providers of point solutions that compete with some of the features present in our solutions. We also compete against internally-developed efforts that often use open source solutions.

We believe that the principal competitive factors affecting the market for cybersecurity solutions include product functionality, breadth and depth of offerings, flexibility of delivery models, ease of deployment and use, integration capabilities such as open APIs and scalability, uptime and performance. We believe that our suite of solutions generally competes favorably with respect to these factors and may serve as a complement to the solutions offered by our competitors in some cases. Some of our more established actual and potential competitors have greater name recognition, longer operating histories, more established customer relationships, larger marketing budgets and significantly greater resources than we do. In addition, as our market grows and rapidly changes, we expect it will continue to attract new competitors, including companies that are larger and more established than us and smaller emerging companies, which could introduce new products and services.

Intellectual Property

Our success depends in part upon our ability to protect our core technology and intellectual property. We rely on a combination of trade secrets, copyrights, patents and trademarks, as well as contractual protections, to establish and protect our intellectual property rights and protect our proprietary technology.

As of December 31, 2021, we had 23 issued patents and 15 patent applications pending in the United States. Our issued patents expire between 2027 and 2039 and cover our network scanning, monitoring and analysis technologies and additional features of our platform offerings. As of December 31, 2021, we had 15 registered trademarks and 13 trademark applications pending in the United States. We view our copyrights, trade secrets and know-how as a significant component of our intellectual property assets.

We also license certain software from third parties for integration into our solutions, including open source software and other software available on commercially reasonable terms. We cannot assure you that such third parties will maintain such software or continue to make it available.

We control access to and use of our proprietary software and other confidential information through the use of internal and external controls, including contractual protections with employees, contractors, customers and partners, and our software is protected by U.S. and international copyright and trade secret laws. Despite our efforts to protect our trade secrets and proprietary rights through intellectual property rights, licenses and confidentiality and invention assignment agreements, unauthorized parties may still attempt to copy, reverse engineer, misappropriate or otherwise obtain and use our software and technology. In addition, we intend to continue to expand our international operations, and effective patent, copyright, trademark and trade secret protection may not be available or may be limited in foreign countries.

9

Table of Contents

Government Regulation

Various federal, state and foreign legislative and regulatory bodies have legislation pending that could affect our business.

In the ordinary course of our business, we process personal information. Accordingly, we are, or may become, subject to numerous data privacy and security obligations, including federal, state, local, and foreign laws, regulations, guidance, and industry standards related to data privacy and security. Such obligations may include, without limitation, the Federal Trade Commission Act, the California Consumer Privacy Act of 2018, or the CCPA, the Colorado Privacy Act, Virginia’s Consumer Data Protection Act, the European Union’s General Data Protection Regulation 2016/679, or EU GDPR, the EU GDPR as it forms part of the United Kingdom law by virtue of section 3 of the European Union (Withdrawal) Act of 2018, or UK GDPR, and the ePrivacy Directive.

The CCPA and EU GDPR are examples of the increasingly stringent and evolving regulatory frameworks related to personal information. The EU GDPR applies to companies established in the European Economic Area, or EEA, and to companies established outside the EEA that process personal information in connection with the offering of goods or services to individuals in the EEA or the monitoring of the behavior of individuals in the EEA.The EU GDPR includes stringent and complex obligations on entities that receive or process personal information, along with significant penalties for non-compliance, more robust obligations on data processors and data controllers, greater rights for individuals, and heavier documentation requirements for data protection compliance programs. In addition, the EU GDPR increases the scrutiny of transfers of personal information from locations in the EEA to the United States and other jurisdictions that the European Commission does not recognize as having “adequate” data protection laws and imposes substantial fines for breaches and violations (up to the greater of €20 million or 4% of consolidated annual worldwide gross revenue). Similarly, the CCPA imposes many obligations on covered businesses, including to provide specific disclosures related to a business’s collecting, using, and disclosing personal information and to respond to certain requests from California residents related to their personal information (for example, requests to know of the business’s personal information processing activities, to delete the individual’s personal information, and to opt out of certain personal information disclosures).The CCPA provides for civil penalties (up to $7,500 per violation) and has a private cause of action for data breaches.

Like other U.S.-based IT security products, our products are subject to U.S. export control laws and regulations, specifically the Export Administration Regulations, or EAR, U.S. economic and trade sanctions regulations and applicable foreign government import, export and use requirements. Certain of our products are subject to encryption controls under the EAR due to the nature of the product and its use or incorporation of encryption functionality. Under the encryption controls in the EAR, applicable products may only be exported outside of the United States with required export authorizations, such as a license, a license exception or other appropriate government authorizations. In addition to the restrictions under the EAR, U.S. export control laws and economic sanctions prohibit the export of products and services to countries, governments, entities or persons subject to U.S. embargoes or trade sanctions.

Human Capital

As of December 31, 2021, we had 1,617 employees, including 635 employees located outside of the United States. None of our U.S. employees are represented by a labor union or covered by a collective bargaining agreement. Certain international employees are subject to collective bargaining agreements in connection with local labor laws. We have not experienced any work stoppages, and we consider our relations with our employees to be good.

We believe in upholding a core set of values for our entire global workforce:

•One Tenable: We are united as one Tenable team. We win together. We are one team internally, with our customers, with our partners and in the market.

•We Care: About our work, about our customers, about one another and about our communities. We speak straight and we do the right thing.

•Deliver Results: We set high goals, take bold risks, measure honestly and deliver results that exceed expectations.

•What We Do Matters: The work that we do makes a difference in the world.

10

Table of Contents

Our key human capital objectives are to attract, retain and develop our highly talented existing and future employees, while cultivating a diverse and inclusive workforce and environment to achieve exceptional business results. We strive to be a career destination where employees from all backgrounds are welcome and empowered, are treated with fairness and respect, can make a difference, and have the opportunity to grow.

Compensation, Benefits and Talent Development

We provide robust compensation and benefits packages to attract and retain our talent. We aim to incentivize our employees by aligning a portion of their compensation with the overall success of our business. In addition to base salary, our benefits packages include annual bonuses, equity awards, an employee stock purchase plan, retirement plans, along with health and wellness benefits. Equity awards of restricted stock units that vest over time are granted to new hires and to employees on an annual basis. Employees are eligible to participate in our Employee Stock Purchase Plan, in which employees may contribute a percentage of their compensation to purchase shares of our common stock at a discount. Our health and welfare benefits include health and life insurance, paid time off, family leave, and employee assistance programs. We are committed to a hybrid workplace strategy where employees have the flexibility to define the environment where they can do their best work.

We promote and support employee development and organizational effectiveness by providing high-quality learning and development programs as well as tuition assistance programs. These programs are designed to meet individual, team, and organizational needs and objectives. We strive to enhance learning and development programs to create a better workplace environment and to build a better Tenable.

Diversity and Inclusion

We seek to cultivate a diverse and inclusive workforce and environment to achieve exceptional business results. When we value and celebrate differences, we drive more innovation and grow closer to our customers, partners, and communities. We strive to be a career destination where employees from all backgrounds are welcome and empowered, treated with fairness and respect, presented with opportunities to make a difference, and provided opportunities to grow.

We undertake numerous efforts to increase diversity in our employee population and to foster a culture of fairness and belonging through a number of measures in our recruiting, engagement, retention, and outreach practices. Our dedicated Diversity and Inclusion Council and Employee Resource Groups – along with our committed leaders and managers – strive to attract and hire employees who bring broad diversity of background, thought, and style into the company and foster a sense of inclusion to make them want to stay. To support these initiatives, we build partnerships within our communities to support organizations and events that strive for greater representation of women and underrepresented minorities in cybersecurity, hold inclusion and bias mitigation training and offer targeted development opportunities to assist with career advancement. In addition to our global talent acquisition team receiving a diversity sourcing and recruiting certification, we have hired a team to help spearhead these initiatives.

Environmental Stewardship

Our Board and management team recognize that we have a role to play in environmental stewardship. We believe that environmentally responsible operating practices are important to generating value for our stockholders, being a good partner with our customers, and being a good employer to our employees.

Energy consumption and usage within data centers is an important component of our day-to-day operations of our business. We outsource our data center needs to Amazon Web Services (“AWS”). In 2014, AWS shared its long-term commitment to achieve 100 percent renewable energy usage for the global AWS infrastructure footprint. Additionally, our corporate headquarters is a LEED Certified Gold for Core Construction and we are pursuing an Energy Star rating.

Financial Information and Segments

Segment and geographic information required by Part I, Item 1 of Form 10-K can be found in Note 1 and Note 13 of the Notes to our Consolidated Financial Statements included in Part II, Item 8, Financial Statements, of this Form 10-K.

11

Table of Contents

Corporate Information

Tenable Network Security, Inc., our predecessor, was incorporated under the laws of the State of Delaware in 2002. Tenable Holdings, Inc. was incorporated in Delaware in October 2015, and in November 2015, Tenable Network Security, Inc. was merged into our wholly-owned indirect subsidiary and in 2017 was renamed as Tenable, Inc.

Our principal executive offices are located at 6100 Merriweather Drive, Columbia, Maryland 21044. Our telephone number is (410) 872-0555. Our website address is www.tenable.com. The information contained on, or that can be accessed through, our website is not incorporated by reference, and you should not consider any information contained on, or that can be accessed through, our website as part of this Annual Report on Form 10-K.

“Tenable,” “Nessus,” “Tenable.io," "Lumin" and the Tenable logo, and other trademarks or service marks of Tenable Holdings, Inc. appearing in this Annual Report on Form 10-K are the property of Tenable Holdings, Inc. This Annual Report on Form 10-K contains additional trade names, trademarks and service marks of others, which are the property of their respective owners. Solely for convenience, trademarks and trade names referred to in this Annual Report on Form 10-K may appear without the ® or TM symbols.

Available Information

Our Annual Report on Form 10-K, Quarterly Reports on Form 10-Q, Current Reports on Form 8-K, Proxy Statement, and amendments to reports filed pursuant to Sections 13(a) and 15(d) of the Exchange Act, are available for download free of charge from our investor relations website https://investors.tenable.com after we file them with the Securities and Exchange Commission, or the SEC. The SEC’s website https://www.sec.gov contains reports, proxy and information statements, and other information regarding issuers that file electronically with the SEC.

The contents of any website referred to in this Form 10-K are not intended to be incorporated into this Annual Report on Form 10-K or in any other report or document we file with the SEC.

Item 1A. Risk Factors

Our operations and financial results are subject to significant risks and uncertainties including those described below. You should carefully consider the risks and uncertainties described below, in addition to other information contained in this Annual Report on Form 10-K, including our consolidated financial statements and related notes. The risks and uncertainties described below are not the only ones we face. Additional risks and uncertainties that we are unaware of, or that we currently believe are not material, may also become important factors that adversely affect our business. If any of the following risks or others not specified below materialize, our business, financial condition and results of operations could be materially and adversely affected.

Selected Risks Affecting Our Business

Our business is subject to a number of risks of which you should be aware before making a decision to invest in our common stock. These risks are more fully described in this “Risk Factors” section, including the following:

•Our business, operations and financial performance may be negatively affected by adverse changes in the evolving COVID-19 pandemic.

•We have a history of losses and may not achieve or maintain profitability in the future.

•We face intense competition. If we do not continue to innovate and offer solutions that address the dynamic cybersecurity landscape, we may not remain competitive.

•We may not be able to sustain our revenue growth rate in the future.

•We may not be able to scale our business quickly enough to meet our customers’ growing needs.

•Our brand, reputation and ability to attract, retain and serve our customers are dependent in part upon the reliability and accuracy of our data, solutions, infrastructure and those of third parties upon which we rely. If our information technology systems or data, or those of third parties upon which we rely, are or were compromised, or

12

Table of Contents

if our solutions fail to detect vulnerabilities or incorrectly detect vulnerabilities, or if they contain undetected errors or defects, we could experience adverse consequences.

•Our future quarterly results of operations are likely to fluctuate significantly due to a wide range of factors, which makes our future results difficult to predict.

•Our business and results of operations depend substantially on our customers renewing their subscriptions with us and expanding the number of IT assets or IP addresses under their subscriptions. Any decline in our customer renewals, terminations or failure to convince our customers to expand their use of subscription offerings would harm our business, results of operations, and financial condition.

•We rely on third parties to maintain and operate certain elements of our network infrastructure.

•We are subject to stringent and changing obligations related to data privacy and security. Our failure or perceived failure to comply with such obligations could lead to regulatory investigations or actions; litigation; fines and penalties; disruptions of our business operations; reputational harm; loss of revenue or profits; loss of customers or sales; and other adverse business consequence.

•We rely on our third-party channel partner network of distributors and resellers to generate a substantial amount of our revenue.

•We rely on the performance of highly skilled personnel, including senior management and our engineering, professional services, sales and technology professionals, and our ability to increase our customer base will depend to a significant extent on our ability to expand our sales and marketing operations.

Risks Related to Our Business and Industry

Our business, operations and financial performance may be negatively affected by adverse changes in the evolving COVID-19 pandemic.

As of December 31, 2021, we have not seen a significant adverse impact to our financial position, results of operations, cash flows and liquidity as a result of the COVID-19 pandemic. However, the COVID-19 pandemic is continuing to evolve rapidly, and significant adverse changes in the spread or severity of COVID-19 infections and the resulting societal impact, and response thereto, could have material adverse impacts on our business, operations and financial performance. The COVID-19 pandemic resulted in travel and other restrictions, including state and local orders across the United States and in countries in which we operate that, among other things, directed individuals to follow social distancing guidelines and or to shelter at their places of residence, directed businesses and governmental agencies to cease non-essential operations at physical locations, prohibited certain non-essential gatherings and events and ordered cessation of non-essential travel. In response to public health directives and orders, we implemented work-from-home policies for our global workforce, including at our headquarters in Columbia, Maryland. As the COVID-19 pandemic has evolved and as these restrictions have eased or been reinstated in response to COVID-19 variants such as Delta and Omicron, we have continued to update our employee health and safety policies, including relating to business travel and in-person office work. As conditions permit, we will continue to allow some activities, including limited business travel and in-person work at the option of the employee at certain of our global office locations, including at our headquarters. In-person work at our offices or business travel could expose our employees to health risks, and us to associated liability, and could create additional risks and operational challenges that require us to make additional investments in the design, implementation and enforcement of new workplace and travel health and safety protocols. We expect to continue our hybrid work policies indefinitely and that many employees will choose to continue to work remotely or a hybrid of in-person and remote work, which presents risks, uncertainties and costs that could affect our performance, including operational and workplace culture challenges, uncertainty regarding office space needs and heightened vulnerability to cyberattacks. Further, we anticipate that our revenue growth could be adversely impacted by developments in the COVID-19 pandemic that negatively impact global economic conditions, including, for example, as a result of the tightening of health and safety restrictions in the United States or globally.

Adverse developments in the COVID-19 pandemic could also impact our partners, customers and service providers. Health concerns and political or governmental developments in response to COVID-19 has created or contributed to economic, social or labor instability or prolonged contractions in the industries in which our customers or partners operate. As a result, existing and potential customers have and may continue to choose to reduce or delay technology spending in response to the ongoing COVID-19 pandemic, or may attempt to renegotiate contracts and obtain concessions, which could materially and negatively impact our operating results, financial condition and prospects. Because our platform

13

Table of Contents

offerings are primarily sold on a subscription basis, any such adverse effects may not be fully reflected in our operating results until future periods, and such effects may be offset by temporary decreases in our expenses related to restrictions on the conduct of our business. We expect to incur additional costs as we resume business-related travel and return to the office, the timing and extent of which remains subject to ongoing developments in the COVID-19 pandemic.

The full extent to which changes in the COVID-19 pandemic impact our business and operations will depend on future developments that are highly uncertain and cannot be predicted with confidence at the time of this Form 10-K, such as the duration of the outbreak, the duration and effect of business disruptions, the ongoing effectiveness and widespread adoption of vaccines, both domestically and globally, the duration and ultimate effectiveness of the travel restrictions, quarantines, social distancing requirements and business closures in the United States and other countries to contain and treat the disease, and the impact of new variants or mutations of the coronavirus, such as the Delta or Omicron variants. An increase or extended period of global supply chain and economic disruption as a result of the COVID-19 pandemic could have a material negative impact on our business, results of operations, access to sources of liquidity and financial condition, though the full extent and duration of these impacts is uncertain. Accordingly, we do not yet know the full extent of potential impacts on our business and operations, or those of our partners and customers, or the global economy as a whole.

In addition, to the extent the ongoing COVID-19 pandemic adversely affects our business and results of operations, it may also have the effect of heightening many of the other risks and uncertainties described in this “Risk Factors” section.

We have a history of losses and may not achieve or maintain profitability in the future.

We have historically incurred net losses, including net losses of $46.7 million, $42.7 million and $99.0 million in 2021, 2020 and 2019, respectively. As of December 31, 2021, we had an accumulated deficit of $654.5 million. Because the market for our offerings is highly competitive and rapidly evolving and these solutions have not yet reached widespread adoption, it is difficult for us to predict our future results of operations. Further, although we have not seen a significant adverse impact to our financial position, results of operations, cash flows and liquidity as a result of the COVID-19 pandemic as of December 31, 2021, we do not yet know the full effects of the evolving pandemic, which increases the difficulty in predicting future results of operations.

While we have experienced significant revenue growth in recent periods, we are not certain whether or when we will obtain a high enough volume of sales of our offerings to sustain or increase our growth or achieve or maintain profitability in the future. We also expect our costs to increase in future periods, which could negatively affect our future operating results if our revenue does not increase at a greater rate. In particular, we expect to continue to expend substantial financial and other resources on:

•public cloud infrastructure and computing costs;

•research and development related to our offerings, including investments in our research and development team;

•sales and marketing, including a significant expansion of our sales organization, both domestically and internationally;

•continued international expansion of our business; and

•general and administrative expense, including legal and accounting expenses related to being a public company.

These investments may not result in increased revenue or growth in our business. If we are unable to increase our revenue at a rate sufficient to offset the expected increase in our costs, our business, financial position and results of operations will be harmed and we may not be able to achieve or maintain profitability over the long term. Additionally, we may encounter unforeseen operating expenses, difficulties, complications, delays and other unknown factors that may result in losses in future periods. If our revenue growth does not meet our expectations in future periods, our financial performance may be harmed, and we may not achieve or maintain profitability in the future.

We face intense competition. If we do not continue to innovate and offer solutions that address the dynamic cybersecurity landscape, we may not remain competitive.

The market for cybersecurity solutions is fragmented, intensely competitive and constantly evolving. We compete with a range of established and emerging cybersecurity software and services vendors, as well as homegrown solutions. With

14

Table of Contents

the introduction of new technologies and market entrants, we expect the competitive environment to remain intense going forward. Our competitors include: vulnerability management and assessment vendors, including Qualys and Rapid7; diversified security software and services vendors; endpoint security vendors with nascent vulnerability assessment capabilities, including CrowdStrike; public cloud vendors and companies, such as Palo Alto Networks, that offer solutions for cloud security (private, public and hybrid cloud); and providers of point solutions that compete with some of the features present in our solutions. We also compete against internally-developed efforts that often use open source solutions.

Some of our actual and potential competitors have significant advantages over us, such as longer operating histories, significantly greater financial, technical, marketing or other resources, stronger brand and business user recognition, larger intellectual property portfolios, government certifications and broader global distribution and presence. In addition, our industry is evolving rapidly and is becoming increasingly competitive. Companies that are larger and more established than us are focusing on cybersecurity and could directly compete with us. For example, in 2019 Microsoft introduced a vulnerability management offering as part of their existing endpoint security platform. Smaller companies could also launch new products and services that we do not offer and that could gain market acceptance quickly.

In addition, some of our larger competitors have substantially broader product offerings and can bundle competing products and services with other software offerings which customers may choose even if individual products have more limited functionality than our solutions. These competitors may also offer their products at a lower price, which could increase pricing pressure on our offerings and cause the average sales price for our offerings to decline. These larger competitors are also often better positioned to withstand any significant reduction in capital spending, and will therefore not be as susceptible to economic downturns. One component of our enterprise platform involves assessing Cyber Exposure in a public cloud environment. We are dependent upon the providers to allow our solutions to access their cloud offerings. If one or more cloud providers elected to offer exclusively their own cloud security product or otherwise eliminate the ability of our solutions to access their cloud on behalf of our customers, our business and financial results could be harmed.

Additionally, the cybersecurity market is characterized by very rapid technological advances, changes in customer requirements, frequent new product introductions and enhancements and evolving industry standards. Our success depends on continued innovation to provide features that make our solutions responsive to the cybersecurity landscape, including the shift to employees working from home or in hybrid environments and the increasing adoption by organizations of cloud or hybrid cloud architectures during the COVID-19 pandemic. Developing new solutions and product enhancements is uncertain, expensive and time-consuming, and there is no assurance that such activities will result in significant cost savings, revenue or other expected benefits. If we spend significant time and effort on research and development and are unable to generate an adequate return on our investment, our business and results of operations may be materially and adversely affected. Further, we may not be able to successfully anticipate or adapt to changing technology or customer requirements or the dynamic threat landscape on a timely basis, or at all, which would impair our ability to execute on our business strategy. Our competitors may be able to respond more quickly and effectively than we can to new or changing opportunities, technologies, standards or customer requirements or new or evolving attacks by, or indicators of compromise that identify, cyber bad actors.

Furthermore, our current and potential competitors may establish cooperative relationships among themselves or with third parties that may further enhance their resources and products and services offerings in the markets we address. In addition, current or potential competitors may be acquired by third parties with greater available resources, which may enable them to adapt more quickly to new technologies and customer needs, devote greater resources to the promotion or sale of their products and services, initiate or withstand substantial price competition, take advantage of other opportunities more readily or develop and expand their product and service offerings more quickly than we do. For all of these reasons, we may not be able to compete successfully against our current or future competitors.

We may not be able to sustain our revenue growth rate in the future.

From 2020 to 2021, our revenue grew from $440.2 million to $541.1 million, representing year-over-year growth of 23%. This growth was primarily from an increase in subscription revenue. Although we have experienced rapid growth historically and currently have high customer renewal rates, we may not continue to grow as rapidly in the future due to a

15

Table of Contents

decline in our renewal rates, failure to attract new customers or other factors. Any success that we may experience in the future will depend in large part on our ability to, among other things:

•maintain and expand our customer base;

•increase revenue from existing customers through increased or broader use of our offerings within their organizations;

•improve the performance and capabilities of our offerings through research and development;

•continue to develop and expand our enterprise platform;

•maintain the rate at which customers purchase and renew subscriptions to our enterprise platform offerings;

•continue to successfully expand our business domestically and internationally; and

•successfully compete with other companies.

If we are unable to maintain consistent revenue or revenue growth, including as a result of the ongoing COVID-19 pandemic or related macroeconomic conditions, our stock price could be volatile, and it may be difficult to achieve and maintain profitability. You should not rely on our revenue for any prior quarterly or annual periods as any indication of our future revenue or revenue growth.

We may be unable to rapidly and efficiently adjust our cost structure in response to significant revenue declines, which could adversely affect our operating results.

We recognize substantially all of our revenue ratably over the term of our subscriptions and, to a lesser extent, perpetual licenses ratably over an expected period of benefit and, as a result, downturns in sales may not be immediately reflected in our operating results.

We recognize substantially all of our revenue ratably over the terms of our subscriptions with customers, which generally occurs over a one-year period and, for our perpetual licenses, over a five-year expected period of benefit. As a result, a substantial portion of the revenue that we report in each period will be derived from the recognition of deferred revenue relating to agreements entered into during previous periods. Consequently, a decline in new sales or renewals in any one period, including as a result of the ongoing COVID-19 pandemic or related macroeconomic conditions, may not be immediately reflected in our revenue results for that period. This decline, however, would negatively affect our revenue in future periods. Accordingly, the effect of significant downturns in sales and market acceptance of our solutions and potential changes in our rate of renewals may not be fully reflected in our results of operations until future periods. This also makes it difficult for us to rapidly increase our revenue growth through additional sales in any period, as revenue from new customers generally will be recognized over the term of the applicable agreement.

We may not be able to scale our business quickly enough to meet our customers’ growing needs.

As usage of our enterprise platform grows, and as customers expand in size or expand the number of IT assets or IP addresses under their subscriptions, we may need to devote additional resources to improving our technology architecture, integrating with third-party systems and maintaining infrastructure performance. In addition, we will need to appropriately scale our sales and marketing headcount, as well as grow our third-party channel partner network, to serve our growing customer base. If we are unable to scale our business appropriately, it could reduce the attractiveness of our solutions to customers, resulting in decreased sales to new customers, lower renewal rates by existing customers or the issuance of service credits or requested refunds, each of which could hurt our revenue growth and our reputation. Even if we are able to upgrade our systems and expand our personnel, any such expansion will be expensive and complex, requiring management time and attention. We could also face inefficiencies or operational failures as a result of our efforts to scale our infrastructure. Moreover, there are inherent risks associated with upgrading, improving and expanding our information technology systems. We cannot be sure that the expansion and improvements to our infrastructure and systems will be fully or effectively implemented on a timely basis, if at all. These efforts may reduce revenue and our margins and adversely impact our financial results.

16

Table of Contents

If our enterprise platform offerings do not interoperate with our customers’ network and security infrastructure, including remote devices, or with third-party products, websites or services, our results of operations may be harmed.

Our enterprise platform offerings, Tenable.ep, Tenable.io, Tenable.cs, Tenable.ad, Tenable.ot, and Tenable.sc must interoperate with our customers’ existing network and security infrastructure, including remote devices. These complex systems are developed, delivered and maintained by the customer, their employees and a myriad of vendors and service providers. As a result, the components of our customers’ infrastructure, including remote devices, have different specifications, rapidly evolve, utilize multiple protocol standards, include multiple versions and generations of products and may be highly customized. We must be able to interoperate and provide our security offerings to customers with highly complex and customized networks, including remote devices, which requires careful planning and execution between our customers, our customer support teams and our channel partners. Further, when new or updated elements of our customers’ infrastructure, new usage trends, such as remote and hybrid work during the COVID-19 pandemic, or new industry standards or protocols are introduced, we may have to update or enhance our cloud platform and our other solutions to allow us to continue to provide service to customers. Our competitors or other vendors may refuse to work with us to allow their products to interoperate with our solutions, which could make it difficult for our cloud platform to function properly in customer networks that include these third-party products.

We may not deliver or maintain interoperability quickly or cost-effectively, or at all. These efforts require capital investment and engineering resources. If we fail to maintain compatibility of our cloud platform and our other solutions with our customers’ network and security infrastructures, including for remote devices, our customers may not be able to fully utilize our solutions, and we may, among other consequences, lose or fail to increase our market share and experience reduced demand for our services, which would materially harm our business, operating results and financial condition.

Our brand, reputation and ability to attract, retain and serve our customers are dependent in part upon the reliability and accuracy of our data, solutions, infrastructure and those of third parties upon which we rely. If our information technology systems or data, or those of third parties upon which we rely, are or were compromised, or if our solutions fail to detect vulnerabilities or incorrectly detect vulnerabilities, or if they contain undetected errors or defects, we could experience adverse consequences.

In the ordinary course of our business, we may collect, store, use, transmit, disclose or otherwise process proprietary, confidential, and sensitive information, including personal information, intellectual property, and trade secrets. We rely on third party service providers and technologies to operate critical business systems, including processing this confidential and sensitive information.

Threats to information systems and data come from a variety of sources. In addition to computer “hackers,” threat actors, personnel (such as through theft or misuse), sophisticated nation-states and nation-state-supported actors now engage in attacks. We and the third parties upon which we rely may be subject to a variety of evolving threats, including but not limited to: social-engineering attacks (including through phishing attacks); malicious code (such as viruses and worms); malware (including as a result of persistent threat intrusions); denial-of-service attacks (such as credential stuffing); personnel misconduct or error; ransomware attacks; supply-chain attacks; software bugs; server malfunctions; software or hardware failures; loss of data or other information technology assets; adware; telecommunications failures, and other similar threats. Ransomware attacks, including those from organized criminal threat actors, nation-states and nation-state supported actors, are becoming increasingly prevalent and severe and can lead to significant interruptions, delays, or outages in our operations, loss of data, loss of income, significant extra expenses to restore data or systems, reputational loss and the diversion of funds. To alleviate the financial, operational and reputational impact of a ransomware attack, it may be necessary to make extortion payments, but we may be unable to do so if applicable laws prohibit such payments.

Any of these or similar threats could cause a security incident or other interruption. These incidents and interruptions can include, but are not limited to, gaining unauthorized access to digital systems for purposes of misappropriating assets or sensitive information, corrupting data or causing operational disruption. Because the techniques used to obtain unauthorized access, insert malicious code or otherwise sabotage systems change frequently and may not immediately produce signs of intrusion, we may be unable to implement adequate preventative measures or timely discover these intrusions.

17

Table of Contents

If we, or a third party upon which we rely, experience a security incident or interruption, or are perceived to have experienced a security incident or interruption, we may experience adverse consequences. These consequences may include: government enforcement actions (for example, investigations, fines, penalties, audits, and inspections); additional reporting obligations and/or oversight; restrictions on processing information (including personal information); litigation (including class claims); indemnification obligations; negative publicity; reputational harm; monetary fund diversions; interruptions of our operations (including availability of data); financial loss; and other similar harm. We sell cybersecurity products and, as a result, may be at increased risk of being a target of cyberattacks designed to penetrate our platform or internal systems or to otherwise impede the performance of our products. We may be required to expend additional, significant resources, fundamentally change our business activities or practices, or modify our operations or information technology in an effort to protect against security incidents or other interruptions.

We have experienced, and may in the future experience, disruptions, outages and other performance problems due to a variety of factors, including infrastructure changes, deliberate or unintentional human or software errors, capacity constraints and fraud or cybersecurity attacks. Any disruptions or other performance problems with our solutions could harm our reputation and business and may damage our customers’ businesses, including by interrupting their networking traffic or operational technology environments. Interruptions in our service delivery might reduce our revenue, cause us to issue credits to customers, subject us to potential liability and cause customers to not renew their purchases of our solutions.

In addition, if our solutions fail to detect vulnerabilities in our customers’ cybersecurity infrastructure, including for remote devices, or if our solutions fail to identify new and increasingly complex methods of cyberattacks, our business and reputation may suffer. There is no guarantee that our solutions will detect all vulnerabilities, especially in light of the rapidly changing security landscape to which we must respond, including as a result of the increased remote work environment during the COVID-19 pandemic. Additionally, our solutions may falsely detect vulnerabilities or threats that do not actually exist. For example, our solutions rely on information provided by an active community of users who contribute new exploits, attacks and vulnerabilities. If the information from these third parties is inaccurate, the potential for false indications of security vulnerabilities increases. These false positives, while typical in the industry, may impair the perceived reliability of our offerings and adversely impact market acceptance of our products and could result in negative publicity, loss of customers and sales and increased costs to remedy any problem.

We have experienced errors or defects in the past in connection with the release of new solutions and product upgrades, and we expect that these errors or defects will be found from time to time in the future in new or enhanced solutions after commercial release. In addition, we use third parties to assist in the development of our products and these third parties could be a source of errors or defects. Defects may cause our solutions to be vulnerable to attacks, cause them to fail to detect vulnerabilities, or temporarily interrupt customers’ networking traffic or operational technology environments, any of which may damage our customers’ business and could hurt our reputation. If our solutions fail to detect vulnerabilities for any reason, we may incur significant costs, the attention of our key personnel could be diverted, our customers may delay or withhold payment to us or elect not to renew or other significant customer relations problems may arise. We may also be subject to liability claims for damages related to errors or defects in our solutions. A material liability claim or other occurrence that harms our reputation or decreases market acceptance of our solutions may harm our business and operating results.

Additionally, applicable data protection requirements may require us to implement specific security measures or use new or different industry-standard measures designed to protect against security incidents. Data protection requirements may also require us to notify relevant stakeholders of security incidents, including affected individuals, partners, collaborators, customers, regulators, law enforcement agencies and others. Such disclosures are costly, and the disclosures or failure to comply with such requirements could lead to adverse impacts, including reputational harm or fines and penalties. There can be no assurance that any limitations or exclusions of liabilities in our contracts would be enforceable or adequate or would otherwise protect us from liabilities or damages if we fail to comply with data protection requirements related to information security or security incidents. We cannot be sure that our insurance coverage, if any, will be adequate or otherwise protect us from or adequately mitigate liabilities or damages with respect to claims, costs, expenses, litigation, fines, penalties, business loss, data loss, regulatory actions or other impacts arising out of security incidents.

18

Table of Contents

Our future quarterly results of operations are likely to fluctuate significantly due to a wide range of factors, which makes our future results difficult to predict.

Our revenue and results of operations have historically varied from period to period, and we expect that they will continue to do so as a result of a number of factors, many of which are outside of our control, including:

•the potential impact of the evolving COVID-19 pandemic on our business and that of our partners and customers;

•the level of demand for our enterprise platform;

•the introduction of new products and product enhancements by existing competitors or new entrants into our market, and changes in pricing for solutions offered by us or our competitors;

•the rate of renewal of subscriptions, and extent of expansion of assets under such subscriptions, with existing customers;

•the mix of customers licensing our products on a subscription basis as compared to a perpetual license;

•large customers failing to renew their subscriptions;

•the size, timing and terms of our subscription agreements with new customers;

•our ability to interoperate our solutions with our customers’ network and security infrastructure, including remote devices;

•the timing and growth of our business, in particular through our hiring of new employees and international expansion;

•network outages, security breaches, technical difficulties or interruptions with our solutions (including security breaches by our service providers or vendors);

•changes in the growth rate of the markets in which we compete;

•the length of the license term, amount prepaid and other material terms of subscriptions to our solutions sold during a period;

•customers delaying purchasing decisions in anticipation of new developments or enhancements by us or our competitors or otherwise;

•changes in customers’ budgets;

•seasonal variations related to sales and marketing and other activities, such as expenses related to our customers;

•our ability to increase, retain and incentivize the channel partners that market and sell our solutions;

•our ability to integrate our solutions with our ecosystem partners’ technology;

•our ability to integrate any future acquisitions of businesses;

•our brand and reputation;

•the timing of our adoption of new or revised accounting pronouncements applicable to public companies and the impact on our results of operations;

•our ability to control costs, including our operating expenses, such as third-party cloud infrastructure costs and facilities costs;

•our ability to hire, train and maintain our direct sales force;

•unforeseen litigation and intellectual property infringement;

•fluctuations in our effective tax rate;

•general economic and political conditions, both domestically and internationally, as well as economic conditions specifically affecting industries in which our customers operate; and

•other events or factors, including those resulting from pandemics, war, incidents of terrorism or responses to these events.

Any one of these or other factors discussed elsewhere in this Annual Report on Form 10-K, or the cumulative effect of some of these factors, may result in fluctuations in our revenue and operating results, meaning that quarter-to-quarter comparisons of our revenue, results of operations and cash flows may not necessarily be indicative of our future performance and may cause us to miss our guidance and analyst expectations and may cause our stock price to decline.

19

Table of Contents

In addition, we have historically experienced seasonality in entering into agreements with customers. We typically enter into a significantly higher percentage of agreements with new customers, as well as renewal agreements with existing customers, in the third and fourth quarters. The increase in customer agreements in the third quarter is primarily attributable to U.S. government and related agencies, and the increase in the fourth quarter is primarily attributable to large enterprise account buying patterns typical in the software industry. We expect that seasonality will continue to affect our operating results in the future and may reduce our ability to predict cash flow and optimize the timing of our operating expenses.

Our business and results of operations depend substantially on our customers renewing their subscriptions with us and expanding the number of IT assets or IP addresses under their subscriptions. Any decline in our customer renewals, terminations or failure to convince our customers to expand their use of subscription offerings would harm our business, results of operations, and financial condition.

Our subscription offerings are term-based and a majority of our subscription contracts are for one year in duration. In order for us to maintain or improve our results of operations, it is important that a high percentage of our customers renew their subscriptions with us when the existing subscription term expires, and renew on the same or more favorable terms. Our customers have no obligation to renew their subscriptions, and we may not be able to accurately predict customer renewal rates. In addition, the growth of our business depends in part on our customers expanding their use of subscription offerings and related services. Historically, some of our customers have elected not to renew their subscriptions with us for a variety of reasons, including as a result of changes in their strategic IT priorities, budgets, costs and, in some instances, due to competing solutions. Our retention rate may also decline or fluctuate if our existing customers choose to reduce or delay technology spending in response to economic conditions resulting from the ongoing COVID-19 pandemic or other macroeconomic factors that could lead to decreased spending, as well as a result of a number of other factors, including our customers’ satisfaction or dissatisfaction with our software, the increase in the contract value of subscription and support contracts from new customers, the effectiveness of our customer support services, our pricing, the prices of competing products or services, mergers and acquisitions affecting our customer base, global economic conditions, and the other risk factors described in this Annual Report on Form 10-K. Additionally, many of our customers, including certain top customers, have the right to terminate their agreements with us for convenience and for other reasons. We cannot assure you that customers will maintain their agreements with us, renew subscriptions or increase their usage of our software. If our customers do not maintain or renew their subscriptions or renew on less favorable terms, or if we are unable to expand our customers’ use of our software, our business, results of operations, and financial condition may be harmed.

We must maintain and enhance our brand.

We believe that developing and maintaining widespread awareness of our brand in a cost-effective manner is critical to achieving widespread acceptance of our enterprise platform and attracting new customers. Brand promotion activities may not generate customer awareness or increase revenue and, even if they do, any increase in revenue may not offset the expenses we incur in building our brand. If we fail to successfully promote and maintain our brand, or incur substantial expenses, we may fail to attract or retain customers necessary to realize a sufficient return on our brand-building efforts, or to achieve the widespread brand awareness that is critical for broad customer adoption of our solutions.

We rely on third parties to maintain and operate certain elements of our network infrastructure.

We utilize data centers located in North America, Europe and Asia to operate and maintain certain elements of our own network infrastructure. Some elements of this complex system are operated by third parties that we do not control and that could require significant time to replace. We expect this dependence on third parties to continue. For example, Tenable.io is hosted on Amazon Web Services, or AWS, which provides us with computing and storage capacity. Interruptions in our systems or the third-party systems on which we rely, particularly AWS, whether due to system failures, computer viruses, physical or electronic break-ins or other factors, could affect the security or availability of our solutions, network infrastructure and website.

Our existing data center facilities and third-party hosting providers have no obligations to renew their agreements with us on commercially reasonable terms or at all, and certain of the agreements governing these relationships may be terminated by either party with notice or access to hosting services may be restricted by the provider at any time, with no

20

Table of Contents

or limited notice. For example, our agreement with AWS allows AWS to terminate the agreement with two years’ written notice and allows AWS, under certain circumstances, to temporarily restrict access to hosting services provided by AWS without prior notice. Although we expect that we could receive similar services from other third parties, if any of our arrangements with third parties, including AWS, are terminated, we could experience interruptions on our platform and in our ability to make our platform available to customers, as well as downtime, delays and additional expenses in arranging alternative cloud infrastructure services.

It is possible that our customers and potential customers would hold us accountable for any breach of security affecting third parties’ infrastructure. We may incur significant liability from those customers and from third parties with respect to any such breach. Because our agreement with AWS limits their liability for damages, we may not be able to recover a material portion of our liabilities to our customers and third parties from AWS in the event of any breach affecting AWS systems.

Organizations may be reluctant to purchase our enterprise platform offerings that are cloud-based due to the actual or perceived vulnerability of cloud solutions.

Some organizations, including those in the defense industry and highly regulated industries such as healthcare and financial services, have historically been reluctant to use cloud-based solutions for cybersecurity because they have concerns regarding the risks associated with the reliability or security of the technology delivery model associated with these solutions. If we or other software companies with cloud-based offerings experience security incidents, breaches of customer data, disruptions in service delivery or other problems, the market for cloud-based solutions as a whole may be negatively impacted, which in turn would negatively impact our revenue and our growth prospects.

Our sales cycle is long and unpredictable.

The timing of sales of our offerings is difficult to forecast because of the length and unpredictability of our sales cycle, particularly with large enterprises and with respect to certain of our solutions. We sell our solutions primarily to IT departments that are managing a growing set of user and compliance demands, which has increased the complexity of customer requirements to be met and confirmed during the sales cycle and prolonged our sales cycle. Our average sales cycle with an enterprise customer is approximately four months, and to the extent we continue to enter into larger deals, our average sales cycle is likely to increase. Further, the length of time that potential customers devote to their testing and evaluation, contract negotiation and budgeting processes varies significantly, depending on the size of the organization and nature of the product or service under consideration. The ongoing COVID-19 pandemic and related economic uncertainty have also continued to impact the budgets and purchasing decisions and processes of certain of our customers and prospective customers, some of whom have added additional controls on expenditures and require additional internal approvals of expenditures, even if relatively small in dollar amount, all of which could lengthen our sales cycle. In addition, we might devote substantial time and effort to a particular unsuccessful sales effort, and as a result, we could lose other sales opportunities or incur expenses that are not offset by an increase in revenue, which could harm our business.

We are subject to stringent and changing obligations related to data privacy and security. Our failure or perceived failure to comply with such obligations, could lead to regulatory investigations or actions; litigation; fines and penalties; disruptions of our business operations; reputational harm; loss of revenue or profits; loss of customers or sales; and other adverse business consequences.

In the ordinary course of our business, we process personal information and other sensitive information, including proprietary and confidential business information, trade secrets, intellectual property, and sensitive third-party information. Our data processing activities subject us, and third parties upon which we rely, to numerous data privacy and security obligations, such as various laws, rules, regulations, guidance, industry standards, external and internal privacy policies, contracts, and other obligations that govern the processing of personal information by us and on our behalf.

In the United States, federal, state, and local governments have enacted numerous data privacy security laws, including data breach notification laws, personal information privacy laws, and consumer protection laws. For example, the California Consumer Privacy Act, or the CCPA, imposes obligations on businesses to which it applies including, but not limited to, providing specific disclosures in privacy notices and affording California residents certain rights related to

21

Table of Contents

their personal information. The CCPA allows for statutory fines for noncompliance (up to $7,500 per violation). Further, the California Privacy Rights Act, or CPRA, effective on January 1, 2023, will expand the CCPA, including by expanding certain consumers’ rights. The CPRA also creates a new state agency that will be vested with authority to implement and enforce the CPRA, which could increase the risk of an enforcement action. Other states have enacted data privacy laws. For example, Virginia recently passed its Consumer Data Protection Act and Colorado recently passed the Colorado Privacy Act, both of which differ from the CPRA and go into effect on January 1, 2023 and July 1, 2023 respectively.

Outside the United States, an increasing number of laws, regulations, and industry standards apply to data privacy and security. For example, the European Union’s General Data Protection Regulation, or EU GDPR, and the United Kingdom’s GDPR, or UK GDPR, impose strict requirements for processing the personal information of individuals. Violations of these obligations carry significant potential consequences. For example, under the EU GDPR, government regulators may impose temporary or definitive bans on processing, as well as fines of up to €20 million or up to 4% of the annual global revenue, whichever is greater. We have an internal data privacy function that oversees and supervises our compliance with European and UK data protection regulations but, despite our efforts, we may fail, or be perceived to have failed, to comply.

Additionally, certain jurisdictions have enacted data localization laws and cross-border personal information transfer laws, which could make it more difficult to transfer personal information across jurisdictions (such as transferring or receiving personal information that originates in the EU or UK). Existing mechanisms that may facilitate cross-border personal information transfers may change or be invalidated. For example, absent appropriate safeguards or other circumstances, the EU GDPR generally restricts the transfer of personal information to countries outside of the European Economic Area, such as the United States, which the EU does not consider to provide an adequate level of data privacy and security, unless certain safeguards are in place. While we have taken steps to lawfully transfer personal information, the efficacy and longevity of these mechanisms remains uncertain.

Our obligations related to data privacy and security are quickly changing in an increasingly stringent fashion, creating some uncertainty as to the effective future legal framework. Additionally, these obligations may be subject to differing applications and interpretations, which may be inconsistent or in conflict among jurisdictions. Existing and proposed laws and regulations can be costly to comply with, can delay or impede the development or adoption of our products and services and require significant management time and attention. Although we endeavor to comply with all data privacy and security obligations, we may at times fail (or be perceived to have failed) to do so. Moreover, despite our efforts, our personnel or third parties upon which we rely may fail to comply with such obligations, which could negatively impact our business operations and compliance posture. If we fail, or are perceived to have failed, to address or comply with applicable data privacy and security obligations, we could face significant consequences. These consequences include, but are not limited to: government enforcement actions (such as investigations, fines, penalties, audits, inspections); litigation (including class-related claims); additional reporting requirements and/or oversight. Any of these events could have a material adverse effect on our reputation, business, or financial condition, including but not limited to: interruptions or stoppages in our business operations, inability to process personal information or operate in certain jurisdictions; limited ability to develop or commercialize our products; expenditure of time and resources to defend any claim or inquiry; reputational harm; loss of customers; reduction in the use of our products; or revision or restricting of our operations.

We rely on our third-party channel partner network of distributors and resellers to generate a substantial amount of our revenue.

Our success is dependent in part upon establishing and maintaining relationships with a variety of channel partners that we utilize to extend our geographic reach and market penetration. We use a two-tiered, indirect fulfillment model whereby we sell our products and services to our distributors, which in turn sell to our resellers, which then sell to our end users, which we call customers. We anticipate that we will continue to rely on this two-tiered sales model in order to help facilitate sales of our offerings as part of larger purchases in the United States and to grow our business internationally. In 2021, 2020 and 2019, we derived 92%, 91% and 90%, respectively, of our revenue from subscriptions and perpetual licenses sold through channel partners, and the percentage of revenue derived from channel partners may continue to increase in future periods. Ingram Micro, Inc., a distributor, accounted for 39%, 43% and 43% of our revenue in 2021, 2020 and 2019, respectively, and 32% of our accounts receivable as of December 31, 2021 and 41% as of December 31, 2020. Our agreements with our channel partners, including our agreement with Ingram Micro, are non-exclusive and do not prohibit them from working with our competitors or offering competing solutions, and some of our channel partners

22

Table of Contents

may have more established relationships with our competitors. Similarly, our channel partners have no obligations to renew their agreements with us on commercially reasonable terms or at all, and certain of the agreements governing these relationships may be terminated by either party at any time, with no or limited notice. For example, our agreement with Ingram Micro allows Ingram Micro to terminate the agreement in their discretion upon 30 days’ written notice to us. If our channel partners choose to place greater emphasis on products of their own or those offered by our competitors or a result of an acquisition, competitive factors or other reasons do not continue to market and sell our solutions in an effective manner or at all, our ability to grow our business and sell our solutions, particularly in key international markets, may be adversely affected. In addition, our failure to recruit additional channel partners, or any reduction or delay in their sales of our solutions and professional services, including as a result of the ongoing COVID-19 pandemic, or conflicts between channel sales and our direct sales and marketing activities may harm our results of operations. Finally, even if we are successful, our relationships with channel partners may not result in greater customer usage of our solutions and professional services or increased revenue.

A portion of our revenue is generated from subscriptions and perpetual licenses sold to domestic governmental entities, foreign governmental entities and other heavily regulated organizations, which are subject to a number of challenges and risks.

A portion of our revenue is generated from subscriptions and perpetual licenses sold to governmental entities in the United States. Additionally, many of our current and prospective customers, such as those in the financial services, energy, insurance and healthcare industries, are highly regulated and may be required to comply with more stringent regulations in connection with subscribing to and implementing our enterprise platform. Selling licenses to these entities can be highly competitive, expensive and time-consuming, often requiring significant upfront time and expense without any assurance that we will successfully complete a sale. Governmental demand and payment for our enterprise platform may also be impacted by public sector budgetary cycles and funding authorizations, with funding reductions or delays adversely affecting public sector demand for our enterprise platform. In addition, governmental entities have the authority to terminate contracts at any time for the convenience of the government, which creates risk regarding revenue anticipated under our existing government contracts.

Further, governmental and highly regulated entities often require contract terms that differ from our standard customer arrangements, including terms that can lead to those customers obtaining broader rights in our solutions than would be expected under a standard commercial contract and terms that can allow for early termination. The U.S. government will be able to terminate any of its contracts with us either for its convenience or if we default by failing to perform in accordance with the contract schedule and terms. Termination for convenience provisions would generally enable us to recover only our costs incurred or committed, settlement expenses, and profit on the work completed prior to termination. Termination for default provisions do not permit these recoveries and would make us liable for excess costs incurred by the U.S. government in procuring undelivered items from another source. Contracts with governmental and highly regulated entities may also include preferential pricing terms. In the United States, federal government agencies may promulgate regulations, and the President may issue executive orders, requiring federal contractors to adhere to different or additional requirements after a contract is signed. If we do not meet applicable requirements of law or contract, we could be subject to significant liability from our customers or regulators. Even if we do meet these requirements, the additional costs associated with providing our enterprise platform to government and highly regulated customers could harm our operating results. Moreover, changes in the underlying statutory and regulatory conditions that affect these types of customers could harm our ability to efficiently provide them access to our enterprise platform and to grow or maintain our customer base. In addition, engaging in sales activities to foreign governments introduces additional compliance risks, including risks specific to anti-bribery regulations, including the U.S. Foreign Corrupt Practices Act of 1977, as amended, or the FCPA, the U.K. Bribery Act 2010 and other similar statutory requirements prohibiting bribery and corruption in the jurisdictions in which we operate. Further, in some jurisdictions we may be required to obtain government certifications, which may be costly to maintain and, if we lost such certifications in the future or if such certification requirements changed, would restrict our ability to sell to government entities until we have attained such certifications.

Some of our revenue is derived from contracts with U.S. government entities, as well as subcontracts with higher-tier contractors. As a result, we are subject to federal contracting regulations, including the Federal Acquisition Regulation, or the FAR. Under the FAR, certain types of contracts require pricing that is based on estimated direct and indirect costs, which are subject to change.

23

Table of Contents

In connection with our U.S. government contracts, we may be subject to government audits and review of our policies, procedures, and internal controls for compliance with contract terms, procurement regulations, and applicable laws. In certain circumstances, if we do not comply with the terms of a contract or with regulations or statutes, we could be subject to contract termination or downward contract price adjustments or refund obligations, could be assessed civil or criminal penalties, or could be debarred or suspended from obtaining future government contracts for a specified period of time. Any such termination, adjustment, sanction, debarment or suspension could have an adverse effect on our business.

In the course of providing our solutions and professional services to governmental entities, our employees and those of our channel partners may be exposed to sensitive government information. Any failure by us or our channel partners to safeguard and maintain the confidentiality of such information could subject us to liability and reputational harm, which could materially and adversely affect our results of operations and financial performance.

Our pricing model subjects us to various challenges that could make it difficult for us to derive expected value from our customers and we may need to reduce our prices or change our pricing model to remain competitive.

Subscriptions and perpetual licenses to our enterprise platform are generally priced based on the number of IP addresses or total IT assets that can be monitored. We expect that we may need to change our pricing from time to time. As competitors introduce new products that compete with ours or reduce their prices, we may be unable to attract new customers or retain existing customers based on our historical pricing. We also must determine the appropriate price to enable us to compete effectively internationally. Moreover, mid- to large-size enterprises may demand substantial price discounts as part of the negotiation of sales contracts and, as the amount of IT assets or IP addresses within our customers' organization grows, we may face additional pressure from our customers regarding our pricing. As a result, we may be required or choose to reduce our prices or change our pricing model, which could adversely affect our business, revenue, operating margins and financial condition.

Further, our subscription agreements and perpetual licenses generally provide that we can audit our customers’ use of our offerings to ensure compliance with the terms of such agreement or license and monitor an increase in IT assets and IP addresses being monitored. However, a customer may resist or refuse to allow us to audit their usage, in which case we may have to pursue legal recourse to enforce our rights under the agreement or license, which would require us to spend money, distract management and potentially adversely affect our relationship with our customers and users.

If our enterprise platform offerings do not achieve sufficient market acceptance, our results of operations and competitive position will suffer.

We spend substantial amounts of time and money to research and develop and enhance our enterprise platform offerings to meet our customers’ rapidly evolving demands. In addition, we invest in efforts to continue to add capabilities to our existing products and enable the continued detection of new network vulnerabilities. We typically incur expenses and expend resources upfront to market, promote and sell our new and enhanced offerings. Therefore, when we develop and introduce new or enhanced offerings, they must achieve high levels of market acceptance in order to justify the amount of our investment in developing and bringing them to market. For example, if Tenable Lumin does not garner widespread market adoption and implementation, our operating results and competitive position could suffer.

Further, we may make enhancements to our offerings that our customers do not like, find useful or agree with. We may also discontinue certain features, begin to charge for certain features that are currently free or increase fees for any of our features or usage of our offerings.

Our new offerings or enhancements and changes to our existing offerings could fail to attain sufficient market acceptance for many reasons, including:

•failure to predict market demand accurately, including changes in demand as a result of the ongoing COVID-19 pandemic or related macroeconomic trends, in terms of functionality and to supply offerings that meets this demand in a timely fashion;

•defects, errors or failures;

•negative publicity about their performance or effectiveness;

24

Table of Contents

•delays in releasing our new offerings or enhancements to our existing offerings to the market;

•introduction or anticipated introduction of competing products by our competitors;

•poor business conditions for our customers, including as a result of the ongoing COVID-19 pandemic, causing them to delay or forgo IT purchases; and

•reluctance of customers to purchase cloud-based offerings.

If our new or enhanced offerings do not achieve adequate acceptance in the market, our competitive position will be impaired, and our revenue will be diminished. The adverse effect on our operating results may be particularly acute because of the significant research, development, marketing, sales and other expenses we will have incurred in connection with the new or enhanced offerings.

Our strategy of offering and deploying our solutions in the cloud, on-premises environments or using a hybrid approach causes us to incur increased expenses and may pose challenges to our business.

We offer and sell our enterprise platform for use in the cloud, on-premises environments or using a hybrid approach using the customer’s own infrastructure. Our cloud offering enables our customers to eliminate the burden of provisioning and maintaining infrastructure and to scale their usage of our solutions quickly, while our on-premises offering allows for the customer’s complete control over data security and software infrastructure. Historically, our solutions were developed in the context of the on-premises offering, and we have less operating experience offering and selling subscriptions to our solutions via our cloud offering. Although a substantial majority of our revenue has historically been generated from customers using our solutions on an on-premises basis, our customers are increasingly adopting our cloud offering. We expect that our customers will continue to move to our cloud offering and that it will become more central to our distribution model. We expect our gross profit to increase in absolute dollars and our gross margin to decrease to the extent that revenue from our cloud-based subscriptions increases as a percentage of revenue, although our gross margin could fluctuate from period to period. To support both on-premises environments and cloud instances of our product, our support team must be trained on and learn multiple environments in which our solution is deployed, which is more expensive than supporting only a cloud offering. Moreover, we must engineer our software for an on-premises environment, cloud offering and hybrid installation, which we expect will cause us additional research and development expense that may impact our operating results. As more of our customers transition to the cloud, we may be subject to additional competitive pressures, which may harm our business. We are directing a significant portion of our financial and operating resources to implement a robust and secure cloud offering for our customers, but even if we continue to make these investments, we may be unsuccessful in growing or implementing our cloud offering in a way that competes successfully against our current and future competitors and our business, results of operations and financial condition could be harmed.

Our customers’ increased usage of our cloud-based offerings requires us to continually improve our computer network and infrastructure to avoid service interruptions or slower system performance.

As usage of our cloud-based offerings grows and as customers use them for more complicated applications, increased assets and with increased data requirements, we will need to devote additional resources to improving our platform architecture and our infrastructure in order to maintain the performance of our cloud offering. Any failure or delays in our computer systems could cause service interruptions or slower system performance. If sustained or repeated, these performance issues could reduce the attractiveness of our enterprise platform to customers. These performance issues could result in lost customer opportunities and lower renewal rates, any of which could hurt our revenue growth, customer loyalty and reputation.

A component of our growth strategy is dependent on our continued international expansion, which adds complexity to our operations.

We market and sell our solutions and professional services throughout the world and have personnel in many parts of the world. International operations generated 42% and 39% of our revenue in 2021 and 2020, respectively. Our growth strategy is dependent, in part, on our continued international expansion. We expect to conduct a significant amount of our business with organizations that are located outside the United States, particularly in Europe and Asia. We cannot assure that our expansion efforts into international markets will be successful in creating further demand for our solutions and

25

Table of Contents

professional services outside of the United States or in effectively selling our solutions and professional services in the international markets that we enter. Our current international operations and future initiatives will involve a variety of risks, including:

•increased management, infrastructure and legal costs associated with having international operations;

•reliance on channel partners;

•trade and foreign exchange restrictions, including potential changes in trade relations arising from policy initiatives;

•economic or political instability in foreign markets, including instability related to the United Kingdom’s recent exit from the European Union and the corresponding impact on its ongoing legal, political, and economic relationship with the European Union and heightened levels of inflation;

•travel restrictions resulting from the COVID-19 pandemic, including restrictions on U.S. travelers entering some foreign countries;

•greater difficulty in enforcing contracts, accounts receivable collection and longer collection periods;

•changes in regulatory requirements, including, but not limited to data privacy, data protection and data security regulations;

•difficulties and costs of staffing, managing and potentially reorganizing foreign operations, including increased employee recruitment, training and retention costs related to global employment turnover trends and inflationary pressures in the labor market stemming from the COVID-19 pandemic;

•the uncertainty and limitation of protection for intellectual property rights in some countries;

•costs of compliance with foreign laws and regulations and the risks and costs of non-compliance with such laws and regulations;

•differing labor regulations in foreign jurisdictions where labor laws are generally more advantageous to employees, including deemed hourly wage and overtime regulations in these locations;

•costs of compliance with U.S. laws and regulations for foreign operations, including the FCPA, import and export control laws, tariffs, trade barriers, economic sanctions and other regulatory or contractual limitations on our ability to sell or provide our solutions in certain foreign markets, and the risks and costs of non-compliance;

•requirements to comply with foreign privacy, data protection and information security laws and regulations and the risks and costs of noncompliance;

•heightened risks of unfair or corrupt business practices in certain geographies and of improper or fraudulent sales arrangements that may impact financial results and result in restatements of, and irregularities in, financial statements;

•the potential for political unrest, pandemics, acts of terrorism, hostilities or war;

•management communication and integration problems resulting from cultural differences and geographic dispersion;

•costs associated with language localization of our solutions; and

•costs of compliance with multiple and possibly overlapping tax structures and regimes.

Our business, including the sales of our solutions and professional services by us and our channel partners, may be subject to foreign governmental regulations, which vary substantially from country to country and change from time to time. Our failure, or the failure by our channel partners, to comply with these regulations could adversely affect our business. Further, in many foreign countries it is common for others to engage in business practices that are prohibited by our internal policies and procedures or U.S. regulations applicable to us. Although we have implemented policies and procedures designed to comply with these laws and policies, there can be no assurance that our employees, contractors, channel partners and agents have complied, or will comply, with these laws and policies. Violations of laws or key control policies by our employees, contractors, channel partners or agents could result in delays in revenue recognition, financial reporting misstatements, fines, penalties or the prohibition of the importation or exportation of our solutions and could have a material adverse effect on our business and results of operations. If we are unable to successfully manage the challenges of international expansion and operations, our business and operating results could be adversely affected.

26

Table of Contents

We rely on the performance of highly skilled personnel, including senior management and our engineering, professional services, sales and technology professionals, and our ability to increase our customer base will depend to a significant extent on our ability to expand our sales and marketing operations.

We believe our success has depended, and continues to depend, on the efforts and talents of our senior management team and our highly skilled team members, including our sales personnel, professional services personnel and software engineers. We do not maintain key person insurance on any of our executive officers or key employees. Our senior management and key employees are employed on an at-will basis, which means that they could terminate their employment with us at any time. The loss of any of our senior management or key employees could adversely affect our ability to execute our business plan, and we may not be able to find adequate replacements. We cannot ensure that we will be able to retain the services of any members of our senior management or other key employees.

Our ability to successfully pursue our growth strategy also depends on our ability to attract, motivate and retain our personnel. Competition for well-qualified employees in all aspects of our business is intense. The recent move by companies to offer a remote or hybrid work environment may increase competition for such employees outside of our traditional office locations. In addition, employee turnover rates in the broader global economy and inflationary pressures in the labor market have increased during the ongoing COVID-19 pandemic and may continue to be elevated, which has led, and could continue to lead. to increased recruiting, training and retention costs. If we do not succeed in attracting well-qualified employees, retaining and motivating existing employees or maintaining our corporate culture in a hybrid or remote work environment, our business would be adversely affected.

In addition, our ability to increase our customer base and achieve broader market acceptance of our Cyber Exposure solutions will depend to a significant extent on our ability to expand our sales force and our third-party channel partner network of distributors and resellers, both domestically and internationally. We may not be successful in attracting and retaining talented sales personnel or strategic partners, and any new sales personnel or strategic partners may not be able to achieve productivity in a reasonable period of time or at all. We also plan to dedicate significant resources to sales and marketing programs, including through electronic marketing campaigns and, when deemed safe to do so, trade event sponsorship and participation. All of these efforts will require us to invest significant financial and other resources and our business will be harmed if our efforts do not generate a correspondingly significant increase in revenue.

We must offer high-quality support.

Our customers rely on our personnel for support of our enterprise platform. High-quality support is important for the renewal of our agreements with existing customers and to our existing customers expanding the number of IP addresses or IT assets under their subscriptions. The importance of high-quality support will increase as we expand our business and pursue new customers. If we do not help our customers quickly resolve issues and provide effective ongoing support, our ability to sell new software to existing and new customers would suffer and our reputation with existing or potential customers would be harmed.

Our growth depends in part on the success of our strategic relationships with third parties.

In order to grow our business, we anticipate that we will continue to depend on relationships with strategic partners to provide broader customer coverage and solution delivery capabilities. We depend on partnerships with market leading technology companies to maintain and expand our Cyber Exposure ecosystem by integrating third party data into our platform. Identifying partners, and negotiating and documenting relationships with them, requires significant time and resources. Our agreements with our strategic partners generally are non-exclusive and do not prohibit them from working with our competitors or offering competing solutions. Our competitors may be effective in providing incentives to third parties to favor their products or services or to prevent or reduce subscriptions to our services. If our partners choose to place greater emphasis on products of their own or those offered by our competitors or do not effectively market and sell our product, our ability to grow our business and sell software and professional services may be adversely affected. In addition, acquisitions of our partners by our competitors could result in a decrease in the number of our current and potential customers, as our partners may no longer facilitate the adoption of our solutions by potential customers. We also license third-party threat data that is used in our solutions in order to deliver our offerings. In the future, this data may not be available to us on commercially reasonable terms, or at all. Any loss of the right to use any of this data could result in

27

Table of Contents

delays in the provisioning of our offerings until equivalent data is either developed by us, or, if available, is identified, obtained and integrated, which could harm our business.

If we are unsuccessful in establishing or maintaining our relationships with third parties, our ability to compete in the marketplace or to grow our revenue could be impaired and our operating results may suffer. Even if we are successful, we cannot assure you that these relationships will result in increased customer usage of our solutions or increased revenue.

Catastrophic events may disrupt our business.

Our corporate headquarters are located in Columbia, Maryland. The area around Washington, D.C. could be subject to terrorist attacks. Additionally, we rely on our network and third-party infrastructure and enterprise applications, internal technology systems and our website for our development, marketing, operational support, hosted services and sales activities.

While we have begun to initiate hybrid remote and in-person work policies, substantially all of our employees have been working remotely due to the COVID-19 pandemic, which may pose additional security risks. Our business operations are subject to interruption by natural disasters, including those related to the long-term effects of climate change, and other catastrophic events such as fire, floods, power loss, telecommunications failure, cyberattack, war or terrorist attack, or epidemic or pandemic, such as the COVID-19 pandemic. To the extent such events impact our corporate headquarters, other facilities, or off-premises infrastructure, we may be unable to continue our operations and may endure system interruptions, reputational harm, delays in our software development, lengthy interruptions in our services, breaches of data security and loss of critical data, all of which could have an adverse effect on our future operating results.

Recent and future acquisitions could disrupt our business and adversely affect our business operations and financial results.

We have in the past acquired products, technologies and businesses from other parties, such as our 2021 acquisitions of Alsid and Accurics, and we expect to expand our current business by acquiring additional businesses or technologies in the future. Acquisitions involve many risks, including the following:

•an acquisition may negatively affect our financial results because it may require us to incur charges or assume substantial debt or other liabilities, may cause adverse tax consequences or unfavorable accounting treatment, may expose us to claims and disputes by third parties, including intellectual property claims and disputes, or may not generate sufficient financial return to offset additional costs and expenses related to the acquisition;

•we may encounter difficulties or unforeseen expenditures in integrating the business, technologies, products, personnel or operations of any company that we acquire, particularly if key personnel of the acquired company decide not to work for us;

•an acquisition may disrupt our ongoing business, divert resources, increase our expenses and distract our management;

•an acquisition may result in a delay or reduction of customer purchases for both us and the company acquired due to customer uncertainty about continuity and effectiveness of service from either company;

•we may encounter difficulties in, or may be unable to, successfully sell any acquired solutions;

•an acquisition may involve the entry into geographic or business markets in which we have little or no prior experience or where competitors have stronger market positions;

•our use of cash to pay for an acquisition would limit other potential uses for our cash; and

•if we incur debt to fund such acquisition, such debt may subject us to material restrictions on our ability to conduct our business as well as financial maintenance covenants.

The occurrence of any of these risks could have a material adverse effect on our business operations and financial results. In addition, we may only be able to conduct limited due diligence on an acquired company’s operations. Following an acquisition, we may be subject to unforeseen liabilities arising from an acquired company’s past or present operations and these liabilities may be greater than the warranty and indemnity limitations that we negotiate. Any unforeseen liability that is greater than these warranty and indemnity limitations could have a negative impact on our financial condition.

28

Table of Contents

We may require additional capital to support business growth, and this capital might not be available on acceptable terms, if at all.

We expect that our existing cash and cash equivalents will be sufficient to meet our anticipated cash needs for working capital and capital expenditures for at least the next 12 months. However, we intend to continue to make investments to support our business growth and may require additional funds to respond to business challenges, including the need to develop new features or enhance our product, improve our operating infrastructure or acquire complementary businesses and technologies. Accordingly, we may need to engage in equity or debt financings to secure additional funds. If we raise additional funds through future issuances of equity or convertible debt securities, our existing stockholders could suffer significant dilution, and any new equity securities we issue could have rights, preferences and privileges superior to those of holders of our common stock. Our current loan agreement includes, and we expect that any future agreements governing our indebtedness will include, restrictive covenants relating to our capital raising activities and other financial and operational matters, which may make it more difficult for us to obtain additional capital and to pursue business opportunities, including potential acquisitions. We may not be able to obtain additional financing on terms favorable to us, if at all. If we are unable to obtain adequate financing or financing on terms satisfactory to us when we require it, our ability to continue to support our business growth and to respond to business challenges could be significantly impaired, and our business may be adversely affected.

If we do not generate sufficient cash flows, we may be unable to service all of our indebtedness.

To service our indebtedness, we will require a significant amount of cash. Our ability to generate cash, make scheduled payments or to refinance our debt obligations depends on our successful financial and operating performance, which may be affected by a range of economic, competitive and business factors, many of which are outside of our control and some of which are described elsewhere in the “Risk Factors” section of this report.

If our cash flows and capital resources are insufficient to fund our debt service obligations, or to repay the term loan when it matures, we may have to undertake alternative financing plans, such as refinancing or restructuring our debt, selling assets or operations, reducing or delaying capital investments, or seeking to raise additional capital. We may not be able to refinance our debt, or any refinancing of our debt could be at higher interest rates and may require us to comply with more restrictive covenants that could further restrict our business operations. Our ability to implement successfully any such alternative financing plans will depend on a range of factors, including general economic conditions, the level of activity in capital markets generally, and the terms of our various debt instruments then in effect.

Covenants under our Credit Agreement may restrict our business and operations in many ways, and if we do not effectively manage our covenants, our financial conditions and results of operations could be adversely affected.

Our Credit Agreement imposes various covenants that limit our ability and/or our restricted subsidiaries’ ability to, among other things:

•pay dividends or distributions, repurchase equity, prepay, redeem or repurchase certain debt, and make certain investments;

•incur additional debt and issue certain preferred stock;

•provide guarantees in respect of obligations of other persons;

•incur liens on assets;

•engage in certain asset sales, including capital stock of our subsidiaries;

•merge, consolidate with, or sell all or substantially all our assets to another person;

•enter into transactions with affiliates;

•enter into agreements that restrict distributions from our subsidiaries;

•designate subsidiaries as unrestricted subsidiaries; and

•prohibit certain restrictions on the ability of restricted subsidiaries to pay dividends or make other payments to us.

29

Table of Contents

These covenants may:

•limit our ability to borrow additional funds for working capital, capital expenditures, acquisitions, or other general business purposes;

•limit our ability to use our cash flow or obtain additional financing for future working capital, capital expenditures, acquisitions, or other general business purposes;

•require us to use a substantial portion of our cash flow from operations to make debt service payments;

•limit our flexibility to plan for, or react to, changes in our business and industry;

•place us at a competitive disadvantage compared to less leveraged competitors; and

•increase our vulnerability to the impact of adverse economic and industry conditions.

If we are unable to successfully manage the limitations and decreased flexibility on our business due to our significant debt obligations, we may not be able to capitalize on strategic opportunities or grow our business to the extent we would be able to without these limitations.

Our failure to comply with any of the covenants could result in a default under the Credit Agreement, which could permit the administrative agent or the lenders to cause the administrative agent to declare all or part of any of our outstanding senior secured term loans or revolving loans to be immediately due and payable or to exercise any remedies provided to the administrative agent, including, proceeding against the collateral granted to secure our obligations under the Credit Agreement. An event of default under the Credit Agreement could also lead to an event of default under the terms of certain of our other agreements. Any such event of default or any exercise of rights and remedies by our creditors could seriously harm our business.

The LIBOR calculation method may change, and LIBOR is expected to be phased out after 2021.

Loans under the Credit Agreement bear interest at a rate based on the London Interbank Offered Rate, or LIBOR. On July 27, 2017, the U.K. Financial Conduct Authority, or the FCA, announced that it will no longer require banks to submit rates for the calculation of LIBOR after 2021. However, the cessation date has been deferred to June 30, 2023 for the most commonly used tenors in U.S. dollar LIBOR (i.e., overnight and one, three and six months). This extension to 2023 means that many legacy U.S. dollar LIBOR contracts would terminate before related LIBOR rates cease to be published. In the meantime, actions by the FCA, other regulators, or law enforcement agencies may result in changes to the method by which LIBOR is calculated. If changes to LIBOR result in an increase in rates, our interest expense under the Credit Agreement would increase. Further, if LIBOR is no longer available, our Credit Agreement provides a process to determine a substitute rate, and if such substitute rate is higher than LIBOR, our interest expense under the Credit Agreement would increase.

The nature of our business requires the application of complex accounting rules and regulations. If there are significant changes in current principles, financial reporting standards or interpretations, or if our estimates or judgments relating to our critical accounting policies prove to be incorrect, we may experience unexpected financial reporting fluctuations and our results of operations could be adversely affected.

The accounting rules and regulations that we must comply with are complex and subject to interpretation by the Financial Accounting Standards Board, the Securities and Exchange Commission, or SEC, and various bodies formed to promulgate and interpret appropriate accounting principles. In addition, many companies’ accounting disclosures are being subjected to heightened scrutiny by regulators and the public. Further, the accounting rules and regulations are continually changing in ways that could impact our financial statements.

The preparation of financial statements in conformity with generally accepted accounting principles in the United States, or U.S. GAAP, requires management to make estimates and assumptions that affect the amounts reported in the consolidated financial statements and accompanying notes. We base our estimates on historical experience and on various other assumptions that we believe to be reasonable under the circumstances, as provided in the section of this report titled “Management’s Discussion and Analysis of Financial Condition and Results of Operations.” Significant assumptions and estimates used in preparing our consolidated financial statements include the determination of the

30

Table of Contents

estimated economic life of perpetual licenses for revenue recognition, the estimated period of benefit for deferred commissions, useful lives of long-lived assets, the valuation of stock-based compensation, the incremental borrowing rate for operating leases, and the valuation of deferred tax assets. Our results of operations may be adversely affected if our assumptions change or if actual circumstances differ from those in our assumptions, which could cause our results of operations to fall below the expectations of securities analysts and investors, resulting in a decline in the trading price of our common stock.

Additionally, we regularly monitor our compliance with applicable financial reporting standards and review new pronouncements and drafts thereof that are relevant to us. We might be required to change our accounting policies, alter our operational policies and implement new or enhance existing systems, or we may be required to restate our published financial statements, as a result of new standards, changes to existing standards and changes in their interpretation. Such changes to existing standards or changes in their interpretation may have an adverse effect on our reputation, business, financial position and profit, or cause an adverse deviation from our revenue and operating profit target, which may negatively impact our financial results.

Risks Related to Government Regulation, Data Collection and Intellectual Property

Our business could be adversely affected if our employees cannot obtain and maintain required security clearances or we cannot establish and maintain a required facility security clearance.

Certain U.S. government contracts may require our employees to maintain various levels of security clearances, and may require us to maintain a facility security clearance, to comply with Department of Defense, or DoD, requirements. The DoD has strict security clearance requirements for personnel who perform work in support of classified programs. Obtaining and maintaining a facility clearance and security clearances for employees can be a difficult, sometimes lengthy process. If we do not have employees with the appropriate security clearances, then a customer requiring classified work could terminate an existing contract or decide not to renew the contract upon its expiration. To the extent we are not able to obtain or maintain a facility security clearance, we may not be able to bid on or win new classified contracts, and existing contracts requiring a facility security clearance could be terminated.

Any failure to protect our proprietary technology and intellectual property rights could substantially harm our business and operating results.

Our success and ability to compete depend in part on our ability to protect our proprietary technology and intellectual property. To safeguard these rights, we rely on a combination of patent, trademark, copyright and trade secret laws and contractual protections in the United States and other jurisdictions, all of which provide only limited protection and may not now or in the future provide us with a competitive advantage.

As of December 31, 2021, we had 23 issued patents and 15 patent applications pending in the United States relating to our technology. We cannot assure you that any patents will issue from any patent applications, that patents that issue from such applications will give us the protection that we seek or that any such patents will not be challenged, invalidated or circumvented. Any patents that may issue in the future from our pending or future patent applications may not provide sufficiently broad protection and may not be enforceable in actions against alleged infringers. Obtaining and enforcing software patents in the United States is becoming increasingly challenging. Any patents we have obtained or may obtain in the future may be found to be invalid or unenforceable in light of recent and future changes in the law. We have registered the “Tenable,” “Nessus,” “Tenable.io” and "Lumin" trademarks and our Tenable logo in the United States and certain other countries. We have registrations and/or pending applications for additional trademarks in the United States; however, we cannot assure you that any future trademark registrations will be issued for pending or future applications or that any registered trademarks will be enforceable or provide adequate protection of our proprietary rights. While we have copyrights in our software, we do not typically register such copyrights with the Copyright Office. This failure to register the copyrights in our software may preclude us from obtaining statutory damages for infringement under certain circumstances. We also license software from third parties for integration into our software, including open source software and other software available on commercially reasonable terms. We cannot assure you that such third parties will maintain such software or continue to make it available.

31

Table of Contents

In order to protect our unpatented proprietary technologies and processes, we rely on trade secret laws and confidentiality and invention assignment agreements with our employees, consultants, strategic partners, vendors and others. Despite our efforts to protect our proprietary technology and trade secrets, unauthorized parties may attempt to misappropriate, copy, reverse engineer or otherwise obtain and use them. In addition, others may independently discover our trade secrets, in which case we would not be able to assert trade secret rights, or develop similar technologies and processes. Further, several agreements may give customers limited rights to access portions of our proprietary source code, and the contractual provisions that we enter into may not prevent unauthorized use or disclosure of our proprietary technology or intellectual property and may not provide an adequate remedy in the event of unauthorized use or disclosure of our proprietary technology or intellectual property rights. Moreover, policing unauthorized use of our technologies, trade secrets and intellectual property is difficult, expensive and time-consuming, particularly in foreign countries where the laws may not be as protective of intellectual property rights as those in the United States and where mechanisms for enforcement of intellectual property rights may be weak. To the extent that we expand our activities outside of the United States, our exposure to unauthorized copying and use of our solutions and proprietary information may increase. We may be unable to determine the extent of any unauthorized use or infringement of our solutions, technologies or intellectual property rights.

There can be no assurance that the steps that we take will be adequate to protect our proprietary technology and intellectual property, that others will not develop or patent similar or superior technologies, solutions or services, or that our trademarks, patents, and other intellectual property will not be challenged, invalidated or circumvented by others. Furthermore, effective trademark, patent, copyright, and trade secret protection may not be available in every country in which our software is available or where we have employees or independent contractors. In addition, the legal standards relating to the validity, enforceability, and scope of protection of intellectual property rights in internet and software-related industries are uncertain and still evolving.

In order to protect our intellectual property rights, we may be required to spend significant resources to monitor and protect these rights. Litigation brought to protect and enforce our intellectual property rights could be costly, time-consuming and distracting to management and could result in the impairment or loss of portions of our intellectual property. Furthermore, our efforts to enforce our intellectual property rights may be met with defenses, counterclaims and countersuits attacking the validity and enforceability of our intellectual property rights. Our failure to secure, protect and enforce our intellectual property rights could seriously adversely affect our brand and adversely impact our business.

We may be subject to intellectual property rights claims by third parties, which are extremely costly to defend, could require us to pay significant damages and could limit our ability to use certain technologies.

Companies in the software and technology industries, including some of our current and potential competitors, own significant numbers of patents, copyrights, trademarks and trade secrets and frequently enter into litigation based on allegations of infringement or other violations of intellectual property rights. In addition, many of these companies have the capability to dedicate substantially greater resources to enforce their intellectual property rights and to defend claims that may be brought against them. The litigation may involve patent holding companies or other adverse patent owners that have no relevant product revenue and against which our patents may therefore provide little or no deterrence. In the past, we have been subject to allegations of patent infringement that were unsuccessful, and we expect in the future to be subject to claims that we have misappropriated, misused, or infringed other parties’ intellectual property rights, and, to the extent we gain greater market visibility or face increasing competition and as we acquire more companies, we face a higher risk of being the subject of intellectual property infringement claims, which is not uncommon with respect to enterprise software companies. We may in the future be subject to claims that employees or contractors, or we, have inadvertently or otherwise used or disclosed trade secrets or other proprietary information of our competitors or other parties. To the extent that intellectual property claims are made against our customers based on their usage of our technology, we have certain obligations to indemnify and defend such customers from those claims. The term of our contractual indemnity provisions often survives termination or expiration of the applicable agreement. Large indemnity payments, defense costs or damage claims from contractual breach could harm our business, results of operations and financial condition.

There may be third-party intellectual property rights, including issued or pending patents that cover significant aspects of our technologies or business methods, including those relating to companies we acquire. Any intellectual property claims, with or without merit, could be very time-consuming, could be expensive to settle or litigate, could divert our

32

Table of Contents

management’s attention and other resources and could result in adverse publicity. These claims could also subject us to making substantial payments for legal fees, settlement payments, and other costs or damages, potentially including treble damages if we are found to have willfully infringed patents or copyrights. These claims could also result in our having to stop making, selling, offering for sale, or using technology found to be in violation of a third party’s rights. We might be required to seek a license for the third-party intellectual property rights, which may not be available on reasonable terms or at all. Even if a license is available to us, we may be required to pay significant upfront fees, milestones or royalties, which would increase our operating expenses. Moreover, to the extent we only have a license to any intellectual property used in our solutions, there may be no guarantee of continued access to such intellectual property, including on reasonable terms. As a result, we may be required to develop alternative non-infringing technology, which could require significant effort and expense. If a third party is able to obtain an injunction preventing us from accessing such third-party intellectual property rights, or if we cannot license or develop technology for any infringing aspect of our business, we would be forced to limit or stop sales of our software or cease business activities covered by such intellectual property, and may be unable to compete effectively. Any of these results would adversely affect our business, results of operations, financial condition and cash flows.

Portions of our solutions utilize open source software, and any failure to comply with the terms of one or more of these open source licenses could negatively affect our business.

Our software contains software made available by third parties under so-called “open source” licenses. From time to time, there have been claims against companies that distribute or use open source software in their products and services, asserting that such open source software infringes the claimants’ intellectual property rights. We could be subject to suits by parties claiming that what we believe to be licensed open source software infringes their intellectual property rights. Use and distribution of open source software may entail greater risks than use of third-party commercial software, as open source licensors generally do not provide warranties or other contractual protections regarding infringement claims or the quality of the code. In addition, certain open source licenses require that source code for software programs that are subject to the license be made available to the public and that any modifications or derivative works to such open source software continue to be licensed under the same terms. Further, certain open source licenses also include a provision that if we enforce any patents against the software programs that are subject to the license, we would lose the license to such software. If we were to fail to comply with the terms of such open source software licenses, such failures could result in costly litigation, lead to negative public relations or require that we quickly find replacement software which may be difficult to accomplish in a timely manner.

Source: SEC EDGAR (public domain) · 10-K for the period ended 2021-12-31, filed 2022-02-25 · accession 0001660280-22-000035

Filing HTML rendered to line-structured narrative text by the shipped reducer (datafeeds.edgar_fulltext.visible_text, keep_table_headers=True): scripts and inline-XBRL headers are dropped, and table content is reduced to its short label cells — numeric table data is not rendered and is therefore not counted. The same rendering is used for every year, so a year-over-year comparison is like for like.

The text is our rendering of the filing, not a facsimile: original pagination, typography and tables are not reproduced, and the numbers live in the financial statements (FA).

The outline locates item HEADINGS in this document. Only Items 1A and 7 have certified boundaries elsewhere in the terminal (the redline and the narrative-overlap number); every span here runs from one heading found to the next heading found.

How the outline was chosen. It is the longest chain of item headings that runs forward through both the document and the standard item order: 22 headings are on that chain and 16 further heading-shaped lines are not — the table-of-contents echo of every item, cross-references and exhibit-list mentions. Each entry's length is measured from its heading to the next heading on the chain.