The SecureW2 Dynamic PKI engine queries Tenable exposure scores prior to certificate issuance and processes real-time webhooks post-enrollment. When a vulnerability metric changes, network authorization updates automatically.
Overview
Traditional RADIUS perimeters and legacy PKI systems demand extensive manual upkeep and don’t offer real-time device vulnerability insights. SecureW2 modernizes this setup with a managed, cloud-based Dynamic PKI and a Cloud RADIUS service boasting 99.999% uptime, which automates processes like enrollment, certificate validation, and device revocation, all driven by live security telemetry. The system performs automated identity and posture assessments throughout the certificate lifecycle. During device enrollment, the certificate authority interacts with the Tenable API using unique Asset UUIDs to verify the current exposure score. Compliant devices receive hardware-bound digital certificates, whereas at-risk devices are immediately denied access. For ongoing sessions, continuous webhook monitoring facilitates instant token revocation across the wireless network if a new vulnerability causes a device to go out of compliance, minimizing manual adjustments to around 30 minutes.
How It Works
Before generating network credentials, SecureW2 Dynamic PKI queries Tenable with the device’s unique Asset UUID to extract its active exposure score. Endpoints carrying elevated risk markers face automatic block enforcement before certificate delivery can execute.
Enable automated network access control and segmentation for devices based on real-time threat intelligence from Tenable. When Tenable detects a risk event, SecureW2 enforces the appropriate access policy at the next authentication attempt, suspending access, placing the device in a quarantine VLAN, or removing it from network access, based on administrative decisions.
When Tenable sends a webhook with an updated exposure score, SecureW2’s policy engine evaluates it against three configurable thresholds that determine the certificate’s fate. IT administrators define score ranges for each outcome: retain (score within acceptable bounds, no action), suspend (temporary elevation, certificate paused and network access halted until remediation), or revoke (device out of policy, certificate permanently invalidated).
Suspension is useful for transient risk events, failed compliance checks, or temporary vulnerability spikes that can be remediated. If the score returns to acceptable range after suspension, SecureW2 automatically restores access without re-enrollment or IT helpdesk involvement. Revocation is reserved for confirmed compromise scenarios where a device should never regain access with its existing credential.
Threshold configuration lives in the Dynamic PKI policy engine and can be scoped per device population, certificate template, or network segment. Different thresholds apply to managed vs unmanaged devices, or to high-security segments where stricter score cutoffs are appropriate.
Cloud RADIUS assigns devices to VLANs based on their Tenable posture score at every 802.1X authentication. A healthy score connects to production, an elevated but not critical score to remediation with limited access, and a compromised device receives a RADIUS Reject. VLAN policy is evaluated live at each authentication using the device’s current certificate and synchronized posture state from Tenable, ensuring automatic updates when scores change due to patches or vulnerabilities. VLAN IDs and posture thresholds are configured in the Cloud RADIUS policy engine, allowing unique firewall rules, ACLs, and access permissions for tiered access control based on device security posture.
Frequently Asked Questions
This integration connects SecureW2’s Dynamic PKI and policy engine with Tenable's risk signals. It turns device risk assessments into automated certificate issuance, updates, or revocations—ensuring only compliant, trusted devices retain access to your network and applications.
This integration helps automate your security processes. Instead of relying on manual actions, it uses real-time data to automatically manage device access, which helps prevent breaches and simplifies your IT workload
SecureW2 uses the "Overall Assessment" value, which is considered the device's risk score. It can also use other attributes like the device's serial number, operating system, and a unique agent ID.
The integration uses webhooks to automatically update access policies. This means that if a device's risk score changes or a user's status is altered in Tenable, SecureW2 is notified instantly and can automatically apply the correct network policy, ensuring security is always up to date.
Yes, this integration can also support BYOD (Bring Your Own Device). It allows for a simplified and secure onboarding process for personal devices, ensuring they are automatically validated for compliance and risk before being granted network access, without requiring an agent.
Connect with our integration specialists to implement this solution in your environment and transform your security posture.