Try our new research platform with insights from 80,000+ expert users

Rapid7 InsightVM vs XM Cyber comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Rapid7 InsightVM
Average Rating
8.0
Number of Reviews
59
Ranking in other categories
Risk-Based Vulnerability Management (4th)
XM Cyber
Average Rating
8.0
Number of Reviews
2
Ranking in other categories
Vulnerability Management (29th), Breach and Attack Simulation (BAS) (5th), Cloud Security Posture Management (CSPM) (25th)
 

Mindshare comparison

While both are Security Software solutions, they serve different purposes. Rapid7 InsightVM is designed for Risk-Based Vulnerability Management and holds a mindshare of 18.8%, up 13.6% compared to last year.
XM Cyber, on the other hand, focuses on Cloud Security Posture Management (CSPM), holds 0.8% mindshare, up 0.7% since last year.
Risk-Based Vulnerability Management
Cloud Security Posture Management (CSPM)
 

Featured Reviews

Shakeel Ahmad - PeerSpot reviewer
Dec 8, 2022
Brilliant audit report and scorecard but scans often get blocked by firewalls
Our company uses the Nexpose automation tools for validity, deactivation, assessment, and penetration testing. We can easily see if something has been exposed and manually focus on or follow main vulnerabilities.  We have 28 users and a JV license key for using the solution in our offline systems…
Chee Young Tan - PeerSpot reviewer
Feb 9, 2024
Has a valuable feature for attack simulation; it highlights the vulnerability and offers recommendations for improvement
We use the product to identify the vulnerabilities in the network The platform's most valuable feature is attack simulation. It provides an efficient testing ground for security functionalities. XM Cyber could identify all areas of vulnerability. They could expand the identification span for…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The solution scales well."
"The cost is what is most valuable. Compared to the other products on the market, the cost is more palatable."
"The feature that I have found most valuable is its dashboards."
"The discovery and prioritization of vulnerabilities."
"InsightVM's most valuable feature is risk scoring, a formula based on different vectors like the ease of exploitation and the availability of the machine."
"NeXpose is a pretty good vulnerability scanner... There's a nice dashboard."
"When it comes to the process, installation is very easy and does not take long."
"The most valuable feature for us is the different types of reporting it provides."
"What I personally like very much, from my experience, is that it is very reliable."
"The platform's most valuable feature is attack simulation."
 

Cons

"It would be great to have a mobile application client. Currently, you have to use a mobile web browser on a device, but it is not similar to the desktop web browser in terms of user experience. It would be nice to have a mobile application to access the platform."
"The authentication scan is not working."
"The team needs to improve the speed and focus on the new bandwidth feed. Sometimes, it takes a while to scan, especially with new updates."
"The on-premise updates could improve from Rapid7 InsightVM."
"There was functionality present previously, however, currently, we can't integrate directly with Jira Service Desk - only the cloud version."
"The product does not have the capability to do dynamic scanning of non-web applications."
"It would be nice to have an additional feature that would provide reports on who has logged onto the console or who did what on the console."
"In terms of improvements, its price could be better. Our main issue with Rapid7 is that it is too expensive. You can only sell it to enterprise accounts. In terms of new features, Rapid7 came up with a product called InsightIDR a couple of years ago, which is a good SIEM solution. We expect that Rapid7 will work on some sort of integration between InsightVM and InsightIDR, where vulnerability or anomaly detected by InsightVM can be reported in InsightIDR in some sort of real-time. Rapid7 doesn't patch. For example, if you have a vulnerability, some products can scan and also do the patching, but Rapid7 does not do the patching. It would be nice if it can also patch."
"XM Cyber could identify all areas of vulnerability. They could expand the identification span for different areas."
"We'd like to see a cheaper price."
 

Pricing and Cost Advice

"The licensing is asset-based and very straightforward."
"Its pricing depends on the number of users per month."
"Pricing is reasonable because we pay according to asset usage. We can define our assets and sites according to our preference."
"InsightVM is an expensive product, especially compared to its competitors, at around a million NOK per year."
"The solution's pricing is better than Nexus which charges a high amount for very little use."
"We have an annual license to use Rapid7 InsightVM and if we want to extend it, we will possibly choose more than one year."
"This solution is expensive, but it's fine for us as we have an open budget for security solutions. Protection and having the system secured is more important."
"In some cases, we procure the licenses. In some cases, the customers directly buy the license from Rapid7."
"We have to pay standard licensing fees."
report
Use our free recommendation engine to learn which Risk-Based Vulnerability Management solutions are best for your needs.
815,854 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
40%
Computer Software Company
10%
Financial Services Firm
7%
Manufacturing Company
6%
Computer Software Company
15%
Financial Services Firm
14%
Manufacturing Company
9%
Government
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

How would you choose between Rapid7 InsightVM and Tenable Nessus?
You have full visibility across cloud, network, virtual, and containerized infrastructures with Rapid7 Insight VM. You can easily prioritize vulnerabilities using attacker analytics. Overall, Rapid...
What do you like most about Rapid7 InsightVM?
The product's initial setup phase was very easy.
What do you like most about XM Cyber?
The platform's most valuable feature is attack simulation.
What is your experience regarding pricing and costs for XM Cyber?
We have to pay standard licensing fees. There are no additional costs. It is an expensive product. I rate the pricing a seven out of ten.
What needs improvement with XM Cyber?
XM Cyber could identify all areas of vulnerability. They could expand the identification span for different areas.
 

Comparisons

 

Also Known As

InsightVM, NeXpose
No data available
 

Learn More

 

Overview

 

Sample Customers

ACS, Acosta, AllianceData, amazon.com, biogen idec, CBRE, CATERPILLAR, Deloitte, COACH, GameStop, IBM
Hamburg Port Authority, Plymouth Rock Corporation
Find out what your peers are saying about Tenable, Qualys, Rapid7 and others in Risk-Based Vulnerability Management. Updated: November 2024.
815,854 professionals have used our research since 2012.