No more typing reviews! Try our Samantha, our new voice AI agent.

Pentera vs Rapid7 InsightVM comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
4.8
Pentera enhances security and reduces testing time, but licensing costs pose challenges despite potential greater benefits in larger setups.
Sentiment score
6.5
Rapid7 InsightVM reduces cyber risks and incidents, enhancing security and cost-efficiency, with positive financial and risk reduction outcomes.
Pentera has significantly affected our organization by dropping our mean time to remediate critical vulnerabilities because the remediation team can clearly evidence the exploit instead of debating CVSS scores, and our security posture has improved.
Ai Expert at a educational organization with 1,001-5,000 employees
Some customers consider the ROI favorable, but facing difficulties now due to changes in the licensing model, which has made it more expensive compared to last year.
Director at Infosonik Systems Ltd
 

Customer Service

Sentiment score
4.2
Pentera's technical support is praised for efficiency and value, despite occasional slow updates, with high customer satisfaction ratings.
Sentiment score
6.9
Rapid7 InsightVM's customer service is praised for professionalism, though some experience delays; dedicated managers are preferred by some.
Support is not available promptly, especially when issues are escalated to another region.
Head Of Cyber Security at Super Secure
Sometimes support requests coincide with holidays in their support region, causing slight delays.
Professional services team lead at a tech services company with 1,001-5,000 employees
I cannot comment specifically regarding the support part because I have never needed Rapid7 support for the InsightVM solution as it is very stable.
Senior Manager - Pre-Sales at Trillium Information Security Systems
 

Scalability Issues

Sentiment score
4.8
Pentera is highly rated for scalability, efficiently supporting enterprise clients with minimal staff despite some password assessment challenges.
Sentiment score
7.5
Rapid7 InsightVM is highly scalable, flexible, and well-suited for varied environments, accommodating growth without performance issues.
Scalability in the Rapid7 InsightVM solution is straightforward.
Senior Manager - Pre-Sales at Trillium Information Security Systems
Rapid7 InsightVM is recommended for large-scale companies with more than 30,000 users.
Enterprise Security Architect at a energy/utilities company with 10,001+ employees
According to the environment requirements, we can scale the solution as needed.
Professional services team lead at a tech services company with 1,001-5,000 employees
 

Stability Issues

Sentiment score
7.2
Pentera is generally rated high for stability, functions seamlessly in networks, though some users note occasional issues.
Sentiment score
8.1
Rapid7 InsightVM is reliable and stable, despite occasional communication issues, scoring highly in user satisfaction ratings.
We have not faced any issues with stability, and I would rate it a nine out of ten.
Professional services team lead at a tech services company with 1,001-5,000 employees
The stability of Rapid7 InsightVM is excellent.
0 at a tech vendor with 5,001-10,000 employees
There have been some challenges, especially with support response times, which affect stability.
Head Of Cyber Security at Super Secure
 

Room For Improvement

Pentera requires UI enhancements, better cloud and virtualization capabilities, licensing flexibility, and affordability to attract more non-specialist users.
Rapid7 InsightVM users seek improved integration, reporting, and usability with better support, automation, cloud features, and secure ticketing.
When the IP is imported into a system, we cannot withdraw or revoke the license.
Pre-sale manager at Nam Truong Son
While Pentera excels in on-premises and hybrid setups, its AWS and Azure attack path simulation is not as deep compared to others.
Ai Expert at a educational organization with 1,001-5,000 employees
If I could change one thing about Pentera, I would definitely want faster navigation, which would improve my workflow.
Trainee Network Engineer at a tech services company with 11-50 employees
Having the ability to build our own audit file, similar to a feature in Tenable, would be beneficial.
Professional services team lead at a tech services company with 1,001-5,000 employees
The major improvement needed is prompt support.
Head Of Cyber Security at Super Secure
The current process requires manually telling IT teams to remediate vulnerabilities, and then they update the status of these vulnerabilities in the platform.
Senior Manager - Pre-Sales at Trillium Information Security Systems
 

Setup Cost

Pentera's pricing divides users; some see it as valuable, others find the $120,000 fee substantial yet noteworthy.
Rapid7 InsightVM's pricing is asset-based and flexible, with costs often high but valued for simplicity and included support.
The enterprise pricing is a big investment.
Works at a comms service provider with 1-10 employees
Rapid7 InsightVM is expensive, possibly one of the highest in pricing among similar products.
0 at a tech vendor with 5,001-10,000 employees
Pricing is reasonable and competitive compared to other solutions in the market.
Head Of Cyber Security at Super Secure
I would rate the pricing for Rapid7 InsightVM as eight out of ten.
Enterprise Security Architect at a energy/utilities company with 10,001+ employees
 

Valuable Features

Pentera enhances cybersecurity through automated vulnerability scanning, remediation, and AI-based reporting, improving efficiency and security posture.
Rapid7 InsightVM offers versatile modes, seamless integrations, user-friendly interface, effective scanning, and customizable dashboards for efficient vulnerability management.
I can show them a complete kill chain and how an attacker gets from the initial foothold to domain admin in our environment, step by step, with evidence.
Works at a comms service provider with 1-10 employees
Pentera has significantly affected our organization by dropping our mean time to remediate critical vulnerabilities because the remediation team can clearly evidence the exploit instead of debating CVSS scores, and our security posture has improved.
Ai Expert at a educational organization with 1,001-5,000 employees
The best features of Pentera for me are the dashboard. The dashboard is excellent. I can see everything at a glance.
Trainee Network Engineer at a tech services company with 11-50 employees
It's based on the CVSS risk scoring system, which is well-recognized and effective.
Professional services team lead at a tech services company with 1,001-5,000 employees
The dashboard is excellent as it helps in visualizing our vulnerability management data.
Manager at a financial services firm with 5,001-10,000 employees
We have integrated our SIEM solutions and antivirus with each other through Rapid7.
0 at a tech vendor with 5,001-10,000 employees
 

Categories and Ranking

Pentera
Average Rating
8.0
Reviews Sentiment
6.1
Number of Reviews
13
Ranking in other categories
Penetration Testing Services (4th), Breach and Attack Simulation (BAS) (3rd), Continuous Threat Exposure Management (CTEM) (2nd)
Rapid7 InsightVM
Average Rating
8.0
Reviews Sentiment
6.9
Number of Reviews
66
Ranking in other categories
Vulnerability Management (12th), Risk-Based Vulnerability Management (4th)
 

Mindshare comparison

While both are Security Software solutions, they serve different purposes. Pentera is designed for Breach and Attack Simulation (BAS) and holds a mindshare of 20.0%, down 29.7% compared to last year.
Rapid7 InsightVM, on the other hand, focuses on Risk-Based Vulnerability Management, holds 8.1% mindshare, down 14.1% since last year.
Breach and Attack Simulation (BAS) Mindshare Distribution
ProductMindshare (%)
Pentera20.0%
Cymulate14.9%
The NodeZero Platform by Horizon3.ai14.2%
Other50.900000000000006%
Breach and Attack Simulation (BAS)
Risk-Based Vulnerability Management Mindshare Distribution
ProductMindshare (%)
Rapid7 InsightVM8.1%
Qualys VMDR9.8%
Tenable Security Center7.6%
Other74.5%
Risk-Based Vulnerability Management
 

Featured Reviews

Sabbir Ahmed - PeerSpot reviewer
Director at Infosonik Systems Ltd
Comprehensive attack surface coverage and real-world threat emulation strengthen security while licensing models need improvement
Comprehensive Attack Surface includes several features. Omni Attack Surface discovers, assesses, and exploits vulnerabilities across both internal networks and external assets, including cloud environments from a single platform. External Attack Surface Management (EASM) and Internal Network Validation test internal security controls and identify weaknesses within the internal network. Automated Penetration Testing features are provided through the Pentera Surface module. Surface provides automated validation and penetration testing features with a proactive, continuous, and highly realistic approach to cybersecurity validation, helping organizations understand and reduce their true cyber exposure. They have AI-based reporting that leverages AI to identify patterns of exploitability over time, aggregate results across sites, and highlight recurring weaknesses. They offer two types of reports: an elaborate technical report for CTOs and an Executive Summary for management. When customers see the reports after completing the POC, they are impressed by how detailed the technical report is, while management can understand what actions need to be taken to protect their network and infrastructure. Recent Gartner reports indicate that traditional VAPT companies perform vulnerability testing at specific times, which creates security gaps. Pentera provides continuous validation, running 24/7 in the infrastructure. This means when any vulnerability appears due to firmware upgrades, OS updates, or software changes, it can be automatically identified in real-time.
reviewer2775840 - PeerSpot reviewer
Manager at a financial services firm with 5,001-10,000 employees
Manages vulnerabilities effectively over time but needs improvement in web coverage and dashboard flexibility
Most of the dynamic asset tagging we use is manual, not dynamic. To manage the assets, we employed the manual approach because we have a limitation regarding the license, so we don't use the dynamic approach much. I don't know how the configuration assessment has assisted with meeting compliance standards. The product that we use is the on-premise solution where we configure assets and dynamically scan them. However, we use the default policies more, the template, so Rapid7 InsightVM on-premise version is not that effective in the web-related systems. However, it is best on the OS to identify and discover the OS-related vulnerabilities, more of open ports and the discovery of vulnerable ports or services. It would be better to improve Rapid7 InsightVM by including or working better to add web-related templates because it's not that effective in regard to web. I don't know if they may have a separate product regarding the web, but for the on-premise type, they are not strong in this area. I would prefer to see web-related templates in addition to improving the dashboard-related things because the dashboard has been constant for a very long time. It would be better to see various kinds of, perhaps a flexible type of dashboard. If it's not customizable at all, I would want to see the risk and asset over time with more flexibility. The current dashboard is not flexible in this regard; I have to dig down every day, so they should work on this as well, in addition to the web.
report
Use our free recommendation engine to learn which Breach and Attack Simulation (BAS) solutions are best for your needs.
902,456 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Manufacturing Company
13%
Financial Services Firm
12%
Computer Software Company
8%
Government
6%
Financial Services Firm
12%
Manufacturing Company
9%
Computer Software Company
7%
Comms Service Provider
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business8
Midsize Enterprise1
Large Enterprise5
By reviewers
Company SizeCount
Small Business29
Midsize Enterprise14
Large Enterprise25
 

Questions from the Community

What needs improvement with Pentera?
Cloud testing capabilities need enhancement. The core product was built for on-premises internal network validation.
What is your primary use case for Pentera?
Continuous automated security validation across our internal network and external attack surface was necessary. The problem we were solving was that our manual penetration testing program, as good ...
How would you choose between Rapid7 InsightVM and Tenable Nessus?
You have full visibility across cloud, network, virtual, and containerized infrastructures with Rapid7 Insight VM. You can easily prioritize vulnerabilities using attacker analytics. Overall, Rapid...
What is your experience regarding pricing and costs for Rapid7 InsightVM?
My experience with the pricing, setup cost, and licensing is that both the setup cost and licensing are great.
What needs improvement with Rapid7 InsightVM?
To improve Rapid7 InsightVM, I wish to have integration with patching systems, which would be useful to us. The usability of Rapid7 InsightVM is excellent, and the reporting module is one of the mo...
 

Also Known As

No data available
InsightVM, NeXpose
 

Overview

 

Sample Customers

Blackstone Group Caterpillar Apria Healthcare Taylor Vinters Sandler Capital Management Drawbridge BNP Paribas British Red Cross
ACS, Acosta, AllianceData, amazon.com, biogen idec, CBRE, CATERPILLAR, Deloitte, COACH, GameStop, IBM
Find out what your peers are saying about Horizon3.ai, Cymulate, Pentera and others in Breach and Attack Simulation (BAS). Updated: June 2026.
902,456 professionals have used our research since 2012.