Try our new research platform with insights from 80,000+ expert users

Rapid7 InsightVM vs Varonis Platform comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Rapid7 InsightVM
Average Rating
8.0
Number of Reviews
59
Ranking in other categories
Risk-Based Vulnerability Management (4th)
Varonis Platform
Average Rating
8.2
Number of Reviews
13
Ranking in other categories
Data Loss Prevention (DLP) (13th), Data Governance (8th), SaaS Security Posture Management (SSPM) (4th), Data Security Posture Management (DSPM) (8th), Compliance Management (8th), Ransomware Protection (9th), Identity Threat Detection and Response (ITDR) (7th)
 

Mindshare comparison

While both are Security Software solutions, they serve different purposes. Rapid7 InsightVM is designed for Risk-Based Vulnerability Management and holds a mindshare of 17.7%, up 12.7% compared to last year.
Varonis Platform, on the other hand, focuses on Data Loss Prevention (DLP), holds 2.8% mindshare, up 0.6% since last year.
Risk-Based Vulnerability Management
Data Loss Prevention (DLP)
 

Featured Reviews

Shakeel Ahmad - PeerSpot reviewer
Dec 8, 2022
Brilliant audit report and scorecard but scans often get blocked by firewalls
Our company uses the Nexpose automation tools for validity, deactivation, assessment, and penetration testing. We can easily see if something has been exposed and manually focus on or follow main vulnerabilities.  We have 28 users and a JV license key for using the solution in our offline systems…
Frederic  Delos - PeerSpot reviewer
Mar 5, 2024
Offers the ability to identify sensitive areas, allowing you to drill down into the sensitive data
The most effective feature for me is its ability to identify sensitive areas, allowing you to drill down into the sensitive data, provided you have access, to determine whether it's a false positive or a true positive. That's the best thing for me, out of all of it. It's got everything, like other ones, but I like to be able to look at something if I'm doing forensics on the alert and say, "Okay, do I really need to do something with this?" For example, we don't want sensitive data in our OneDrive. So it identifies the sensitive data that's possibly in the OneDrive. And what I can do is look at it and identify whether it's actually sensitive data in Datalert or whether it looks like sensitive data, but I know it's a false positive. If it is a false positive, I can basically say ignore this pattern based on X, Y, and Z, you know, whether it's Redjax or keyword proximity. So I like that. With other tools, I gotta go through a whole process because it's a little bit more complex. Here, I can tag it and bag it in one shot. And the next good time I scan, it slips over it. So it helps in that.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable features are its reporting capabilities and the host discovery functionality."
"The solution is very user friendly and easy to manage."
"The product's initial setup phase was very easy."
"The most valuable features of Rapid7 InsightVM are the accurate level of scanning and the workflows are good."
"We can create our own templates."
"The risk score that they provide makes it easier to find out the biggest risks. It helped the security officers to understand where the biggest risks are so that they can act on them. They can instruct their IT teams to give them a higher priority and mitigate them."
"The pricing is reasonable."
"The discovery and prioritization of vulnerabilities."
"The solution ensures that users have not accidentally shared sensitive information with the wrong people or too many people."
"The telemetry to capture everything and the reports are very easy to configure without having a developer degree."
"The 24/7 support is the most valuable feature. They have been able to answer support questions pretty quickly."
"I also appreciate the reporting feature, which allows for the extraction of various reports based on specific needs. These reports can be used for audit purposes, such as tracking changes in file locations or deletions."
"The solution has significantly improved data security and compliance posture by allowing us to track and monitor activities. We can see who accesses data and when files are created and understand what's happening in our environment."
"That alerting and reporting service is great."
"On the Varonis side, technical support is phenomenal. Their ability to explain is very good, and they seem to be very knowledgeable. When I get an alert that doesn't quite make sense, they dive in there and kind of take me through it. That's very useful and very good. There are some false alerts, but it is better to have a false alert than no alert at all."
"It can easily identify unusual behavior or access patterns that may pose a potential threat, while operating as a unified reporting system."
 

Cons

"There are end-user needs and expectations that are being overlooked in the development that could be addressed by appointing a customer advisory board."
"I’d like to see Rapid7 InsightVM improve by adding a knowledge base similar to what Qualys offers. This would help us easily check and search for vulnerabilities using Rapid7 IDs associated with CVs or CVSS. From a features perspective, everything was fine at the time, and the security features of Rapid7 InsightVM were effective."
"InsightVM could be improved by providing passive scanning as an option."
"It is still not a fully cloud-based solution. It will be helpful for customers if it is a complete cloud solution. It is a hybrid solution at the moment."
"I think the improvement in the tool should be to provide a better update to users because sometimes the information within the cloud and the scanner are not synchronized very fast."
"Reporting could be expanded."
"The reporting is very bad when you compare it with other vulnerability assessment tools."
"This solution creates false-positives which can cause issues with reporting."
"We have Microsoft Office 365. I just saw an article today which says that they're actually getting integrated with Microsoft Office 365, which would be a useful feature. For user-based reports, log on activity, and stuff like that, it doesn't seem to really be present like Log360. That could just be my inexperience with it. I've been dealing with it for only about two and a half months."
"There is one thing that if I add something manually, I get so many alerts. That's the biggest bad thing."
"The remediation process can be improved. There will be no existing permission group for the McAfee channel domains. We can create a new permissions group for the required folder."
"I would like it to have cloud integration."
"For unstructured data monitoring, it's one of the top ones, if not the top one, due to its usability."
"It is significantly complex."
"The solution's areas of improvement are the interface and the dependency on on-premises deployment for some components."
"One area for improvement is the calculation engine. When applying rules in Varonis, especially for large datasets (terabytes of data), the calculations can be slow and require time to process. Speeding up this process would be beneficial."
 

Pricing and Cost Advice

"The license is annual and this is the optimal approach when it comes to most software."
"In some cases, we procure the licenses. In some cases, the customers directly buy the license from Rapid7."
"A full license for the solution is expensive because it is at the organizational level and not by individual users."
"It is less expensive compared to other competitors."
"Its licensing is yearly. Everything is included in the price for one year."
"Its pricing depends on the number of users per month."
"It is pretty expensive. It depends on what you consider pricey, however, if you only look at vulnerability management solutions, such as within VM or VMDR, there are, I suppose the prices are almost the same. But I believe you will discover that for yourself."
"The licensing is asset-based and very straightforward."
"The pricing is good. It neither expensive nor cheap. It is average."
"The platform is expensive. I rate the pricing a nine out of ten."
"Licensing is on an annual basis. Maintenance and renewal fees are separate. Varonis Datalert is quite expensive."
"Varonis Platform wasn't certainly the cheapest solution."
"It's expensive, kind of, really expensive."
"I would rate the pricing an eight out of ten, with ten being the most expensive."
"You could do a subscription, where you pay yearly, or you could purchase it outright. The licensing cost is based on the number of users on the system that you are monitoring."
report
Use our free recommendation engine to learn which Risk-Based Vulnerability Management solutions are best for your needs.
813,418 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
39%
Computer Software Company
10%
Financial Services Firm
7%
Manufacturing Company
6%
Financial Services Firm
15%
Computer Software Company
12%
Manufacturing Company
10%
Insurance Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

How would you choose between Rapid7 InsightVM and Tenable Nessus?
You have full visibility across cloud, network, virtual, and containerized infrastructures with Rapid7 Insight VM. You can easily prioritize vulnerabilities using attacker analytics. Overall, Rapid...
What do you like most about Rapid7 InsightVM?
The product's initial setup phase was very easy.
What do you like most about Varonis Platform?
The solution has significantly improved data security and compliance posture by allowing us to track and monitor activities. We can see who accesses data and when files are created and understand w...
What needs improvement with Varonis Platform?
The solution's areas of improvement are the interface and the dependency on on-premises deployment for some components. The interface has improved with the move to a SaaS model, but aspects could s...
What is your primary use case for Varonis Platform?
Customers use the product to identify sensitive information, correlate it with access permissions, and utilize its automation engine for remediation. It includes fixing broken permissions and manag...
 

Also Known As

InsightVM, NeXpose
No data available
 

Learn More

 

Overview

 

Sample Customers

ACS, Acosta, AllianceData, amazon.com, biogen idec, CBRE, CATERPILLAR, Deloitte, COACH, GameStop, IBM
Nottingham Building Society
Find out what your peers are saying about Tenable, Qualys, Rapid7 and others in Risk-Based Vulnerability Management. Updated: October 2024.
813,418 professionals have used our research since 2012.