The SecureW2 Dynamic PKI engine queries Tenable exposure scores prior to certificate issuance and processes real-time webhooks post-enrollment. When a vulnerability metric changes, network authorization updates automatically.
Overview
Traditional RADIUS perimeters and legacy PKI setups require heavy manual maintenance and lack real-time device vulnerability context. SecureW2 replaces outdated infrastructure with a managed, cloud-native Dynamic PKI and a 99.999% uptime Cloud RADIUS service that automates enrollment, certificate validation, and device revocation based on live security telemetry. The integration runs automated identity and posture validation checks across the entire certificate lifecycle. During device enrollment, the certificate authority coordinates with the Tenable API using unique Asset UUID strings to confirm the active exposure score. Compliant hosts receive hardware-bound digital certificates, while at-risk assets face immediate denial. For active sessions, continuous webhook tracking triggers instant token revocation across the wireless infrastructure when a new vulnerability pushes a device out of compliance, reducing manual configuration windows to about 30 minutes.
How It Works
Before generating network credentials, SecureW2 Dynamic PKI queries Tenable with the device’s unique Asset UUID to extract its active exposure score. Endpoints carrying elevated risk markers face automatic block enforcement before certificate delivery can execute.
Following certificate deployment, Tenable continuous scanning tracking watches for configuration adjustments. If a threat metric crosses compliance guidelines post-enrollment, outbound webhooks update the policy engine to handle revocation routines instantly.
When Tenable sends a webhook with an updated exposure score, SecureW2’s policy engine evaluates it against three configurable thresholds that determine the certificate’s fate. IT administrators define score ranges for each outcome: retain (score within acceptable bounds, no action), suspend (temporary elevation, certificate paused and network access halted until remediation), or revoke (device out of policy, certificate permanently invalidated).
Suspension is useful for transient risk events, failed compliance checks, or temporary vulnerability spikes that can be remediated. If the score returns to acceptable range after suspension, SecureW2 automatically restores access without re-enrollment or IT helpdesk involvement. Revocation is reserved for confirmed compromise scenarios where a device should never regain access with its existing credential.
Threshold configuration lives in the Dynamic PKI policy engine and can be scoped per device population, certificate template, or network segment. Different thresholds apply to managed vs unmanaged devices, or to high-security segments where stricter score cutoffs are appropriate.
Cloud RADIUS assigns devices to VLANs based on their Tenable posture score at every 802.1X authentication. A healthy score connects to production, an elevated but not critical score to remediation with limited access, and a compromised device receives a RADIUS Reject. VLAN policy is evaluated live at each authentication using the device’s current certificate and synchronized posture state from Tenable, ensuring automatic updates when scores change due to patches or vulnerabilities. VLAN IDs and posture thresholds are configured in the Cloud RADIUS policy engine, allowing unique firewall rules, ACLs, and access permissions for tiered access control based on device security posture.
Frequently Asked Questions
This integration connects SecureW2’s Dynamic PKI and policy engine with Tenable's risk signals. It turns device risk assessments into automated certificate issuance, updates, or revocations—ensuring only compliant, trusted devices retain access to your network and applications.
This integration helps automate your security processes. Instead of relying on manual actions, it uses real-time data to automatically manage device access, which helps prevent breaches and simplifies your IT workload
SecureW2 uses the "Overall Assessment" value, which is considered the device's risk score. It can also use other attributes like the device's serial number, operating system, and a unique agent ID.
The integration uses webhooks to automatically update access policies. This means that if a device's risk score changes or a user's status is altered in Tenable, SecureW2 is notified instantly and can automatically apply the correct network policy, ensuring security is always up to date.
Yes, this integration can also support BYOD (Bring Your Own Device). It allows for a simplified and secure onboarding process for personal devices, ensuring they are automatically validated for compliance and risk before being granted network access, without requiring an agent.
Connect with our integration specialists to implement this solution in your environment and transform your security posture.