Bernalillo county
Tenable One
The world’s leading AI-powered exposure management platform
Tenable One radically unifies security visibility, insight and action across the attack surface, equipping modern organizations to isolate and eradicate priority cyber exposures from IT infrastructure to cloud environments to critical infrastructure and everywhere in between.
How Bernalillo County freed 75% of its cybersecurity team from patching — A Public Sector blueprint for exposure management with Tenable One
Bernalillo County (BernCo), one of the geographically largest counties in the United States, supports a broad ecosystem of public services and mission-critical operations. Cybersecurity Engineer Julian Sanchez is responsible for defending an extensive and diverse attack surface, managing and monitoring up to 30,000 endpoints and infrastructure assets. His role includes safeguarding highly sensitive datasets spanning PII, PHI, HIPAA-regulated information, law enforcement systems such as CJIS, NCIC, and critical infrastructure intelligence, requiring rigorous security controls, continuous monitoring, and resilient incident-response capabilities.
BernCo’s transition from a fragmented vulnerability management (VM) model to a fully integrated exposure management (EM) program with Tenable One began as an accelerated, single-administrator initiative focused on stabilizing and modernizing core security operations. The effort targeted long-standing public-sector constraints, such as legacy infrastructure and gaps in institutional knowledge, while building a scalable foundation for continuous risk visibility and sustained EM maturity.This shift consolidated visibility from dozens of security consoles into a single source of truth, enabling BernCo to eliminate costly third-party scanning services and dramatically improving staff efficiency, freeing more than 75% of the dozen people dedicated to patching 200 critical servers to focus on other business supporting objectives.
This rapid deployment positions BernCo as a proactive leader in public sector cyber defense. "Tenable One gives us a unified, comprehensive view of our entire attack surface, spanning on-premise, cloud, OT, and IoT. Implemented successfully in less than four months, it has shifted us from a reactive to a proactive state, meaning we are no longer stopping various teams to address constant problems during day-to-day work," says Sanchez.
The massive scope and unique Public Sector challenges
BernCo’s attack surface spans over 300 square miles, requiring the cybersecurity team to account for virtually any network-connected device within the jurisdiction. The team is responsible for securing multiple mission-critical agencies and public services, including general elections, Treasurer, Assessor operations, and Clerk services.
Public safety remains a top priority, with the team supporting first responders—police, fire, and ambulance—who rely on secured CAD 911 emergency response systems and mobile data terminals. This includes maintaining Geographic Information Systems (GIS) for navigation and search-and-rescue operations. The scope extends to protecting essential community infrastructure and services, including Public Works, Planning and Development, Parks & Rec, Behavioral Health, and Animal Services.
Beyond traditional IT assets, the team is responsible for securing systems and operational technology across more than 200 physical properties and more than 120 buildings, including critical infrastructure such as power, water, and transportation systems.
The team also navigated challenges common to the public sector:
- Aging Legacy Infrastructure: Some network appliances date back to the mid 2000’s, posing constant compliance challenges.
- Resource Constraints: The county faces a severe lack of budget and manpower to protect a vast amount of citizen data.
- Shadow IT/Maverick Spending: Departments often skirt procurement processes to buy unauthorized hardware or software, creating severe budget and security risks.
- AI Sprawl/Governance Issues: Uncontrolled AI implementation by various departments and vendors, coupled with a lack of proper policies, presents a significant challenge to safeguarding the county's 30,000 assets, particularly those containing highly sensitive regulatory, law enforcement, and critical infrastructure data.
Why Tenable One: From reactive VM to proactive EM
BernCo selected Tenable One to move beyond siloed vulnerability workflows and establish a unified, end-to-end exposure management strategy. The transition was accelerated by a critical operational issue in which staff retirement and the loss of institutional knowledge resulted in misconfigured scanning processes, which also led to huge license overage. Tenable responded with an emergency engagement, providing expert guidance, targeted training, and technical resources that enabled Sanchez to fully rebuild and rearchitect the platform.
This rapid, four-month deployment delivered unified visibility across on-premise IT, cloud, OT, IoT, and BernCo’s remotely connected workforce, shifting the county from a reactive state of stopping teams during day-to-day work to address constant problems, to a proactive threat mitigation posture.
As it relates to standing up their exposure management program, Sanchez says, "We're not just telling you what we like to do; we're actually implementing and getting it done. Based on Tenable’s own standards, our deployment is one of the most sophisticated, advanced, and quick deployments you’ve seen across the nation in the last five years."
By consolidating security operations into a single source of truth, the implementation eliminated the need to log into dozens of disparate tools and enabled top-down management of more than 19,000 assets. This consolidation also introduced proactive OT/IoT discovery scans, positioning the county to meet emerging audit requirements for non-traditional infrastructure, such as HVAC, water, camera systems and physical control systems, well ahead of regulatory mandates. In addition, the adoption of Vulnerability Priority Ratings (VPR) has transformed risk triage, allowing a lean team to focus on high-impact exposures rather than every alert, significantly reducing noise and ensuring that mission-critical services remain protected.
“The absolute professionalism shown by Tenable, by providing specialist training and reallocating licenses, allowed us to rebuild our entire platform and immediately hit the ground running,” says Sanchez. “It eliminated the need to log into multiple consoles a day; it’s a single source of truth.”
Operational and strategic impact
Tenable’s platform significantly enhanced visibility and compliance across regulatory benchmarks by expanding BernCo’s asset inventory from an estimated 1,000 devices to tens of thousands across the Wide Area Network (WAN). This immediate visibility proved critical when external scans identified shadow IT, specifically, improperly placed internet-facing servers in the General Elections building during election operations, which Sanchez was able to remediate quickly. In addition, Tenable One Cloud Exposure delivers automated, continuous audits of BernCo’s Azure environment against CIS, NIST, and HIPAA benchmarks, helping eliminate over-privileged roles and reduce the blast radius through targeted, risk-based remediation.
Tenable One’s exposure management scoring (VPR, ACR, and Cyber Exposure Score) translates complex technical data into easy-to-read metrics, which has transformed risk communication for county leaders and secured management buy-in to enforce mandatory monthly departmental security meetings. These strategic and operational improvements help BernCo:
- Drive Modernization: Justified critical hardware upgrades and proved the need to accelerate hardware replacement cycles (e.g., from five years to three) to keep pace with modernization and new challenges like AI sprawl.
- Save Costs: Eliminated the cost of expensive third-party scanning and penetration testing services, saving taxpayer money and gaining real-time data.
- Improve Operational Efficiency: Redirected more than 75% of the team previously focused on patching 200 critical servers toward higher-value strategic initiatives.
- Accelerate Federal Grant Acquisition: Provided the necessary justification materials to secure state and federal grants for funding replacement appliances, software, and cybersecurity training at a quicker, better pace than in years past.
"As a result of our advanced exposure management program, neighboring counties and local governments now seek our guidance,” says Sanchez. “The City of Albuquerque, for instance, has collaborated on our calls and is leveraging the framework of our work, which we are actively supporting to foster their growth."
Next steps on BernCo’s exposure management journey
Looking ahead, BernCo plans to further expand its exposure management program to cover additional areas of the attack surface. The immediate priority is completing the labeling and tagging of remaining OT assets. While Tenable One provides baseline discovery and inventory capabilities for identifying AI-related applications and systems, the team is also evaluating Tenable One AI Exposure to gain deeper visibility and control over new AI tools being requested and deployed across the county. In parallel, BernCo intends to assess Tenable One Identity Exposure as part of a planned multi-year modernization of the county’s Active Directory environment.
“The success of our rapid deployment and program expansion to Exposure Management wasn't just about technology; it was fundamentally built on the excellent support and trusted relationship we established with Tenable,’ says Sanchez. “Their partnership allowed us to swiftly rebuild our platform and immediately hit the ground running, transforming our security posture.”
For organizations looking to implement an exposure management program, particularly those of similar size facing siloed tools, limited resources, and a highly distributed attack surface, Sanchez offers this guidance: “Tenable is not a one-size-fits-all solution. Instead, it provides a broad ecosystem of components that can be tailored to fit the needs of any environment, including scanners, connectors, agents, agentless options, and both virtual and physical appliances. This flexibility allows teams to build an exposure management architecture that aligns with their operational realities and constraints.”
- Tenable One
Tenable One
Request a demo
The world’s leading AI-powered exposure management platform.
Thank You
Thank you for your interest in Tenable One.
A representative will be in touch soon.
Form ID: 7469
Form Name: one-eval
Form Class: c-form form-panel__global-form c-form--mkto js-mkto-no-css js-form-hanging-label c-form--hide-comments
Form Wrapper ID: one-eval-form-wrapper
Confirmation Class: one-eval-confirmform-modal
Simulate Success