The primary use case of this solution is for critical business applications for the web. We have also implemented it to identify when we are changing and an older system like the application client-server, the server two, the network equipment like switch routers, and security solutions.
Information Security Senior Expert (Founding member, African Cybersecurity Center) at a financial services firm with 10,001+ employees
Stable and Scalable solution with good technical support and reporting capabilities
Pros and Cons
- "The most valuable feature for us is the different types of reporting it provides."
- "This solution integrates with another module in Metasploit, that doesn't exist in the other solutions. It is subscribed to on our roadmap, but we chose to implement both Nexppose and AppSpider."
What is our primary use case?
What is most valuable?
The most valuable feature for us is the different types of reporting it provides. For example, the compliance reporting, compliance with the international standard in which we are certified and compliant. This is important for us to escalate the dashboard to our top management.
What needs improvement?
We need to scan and identify the different RPGs, the critical ones and the major ones that can generate risk or a measure of risk. We generate the reporting from the system and relay the report to our internal developers. We have our internal developers in the bank.
This solution integrates with another module in Metasploit, that doesn't exist in the other solutions. It is subscribed to on our roadmap, but we chose to implement both Nexppose and AppSpider.
For how long have I used the solution?
I have been using this solution for six months.
Buyer's Guide
Rapid7 InsightVM
January 2025
Learn what your peers think about Rapid7 InsightVM. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,265 professionals have used our research since 2012.
What do I think about the stability of the solution?
This solution is stable. It's a good solution.
What do I think about the scalability of the solution?
This solution is scalable.
It takes two people to manage this solution and to be the backup for the succession plan. Our manager has access and performs audits.
How are customer service and support?
Technical support is good and responsive.
Which solution did I use previously and why did I switch?
In this current company, they were using Qualys and I convinced the management to change to Rapid 7.
After every event, we are required to automize with information control tools like Sandbox, IPS, and vulnerability management. All of those security tools need to be implemented and automized.
That is not the case with Rapid 7. It can be automized and we are dependant on ourselves. We can perform in having this solution customized with the confines of our text.
How was the initial setup?
The initial setup was not complex and it was easy to implement.
It took a week to prepare and install the virtual machine, and to implement the solution it took one month.
Our Regulatory requires that all banks must implement all security solutions on-premises, not on the cloud because they are worried that the data will be compromised and available on different data centers around the world.
What about the implementation team?
We had the help of an integrator to implement this solution. There were three engineers to help. One was for Nexpose and two for Appsider.
What's my experience with pricing, setup cost, and licensing?
This solution is expensive, but it's fine for us as we have an open budget for security solutions. Protection and having the system secured is more important.
What other advice do I have?
Rapid 7 is a leading solution that has been implemented in many companies.
In Nexpose you have the console and the app assistant for Rapid 7. The design can be implemented in all of the segments of the network to scan, perform the scale of the scan, perform the reporting, generate the reports, and send it to the central console.
I would suggest that customers acquire this solution.
In addition to management, we are subscribed to the security dispense team and the company emergency dispense team. We always receive the bulletins, so we are always aware of the vulnerabilities.
I appreciate this solution. All of the features that are included are enough for me.
This is an excellent solution and I would rate it a ten out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Cyber Security Engineer at Unemployed
A high-performing solution that collects real-time data, is capable of more detections, and allows you to use the Scheduled Forensics feature
Pros and Cons
- "most valuable features of Rapid7 InsightVM for me are creating dynamic asset tags, generating reports, and deploying the agent. The agent scans assets every four hours, providing real-time data on any devices. Although there weren't any significant new features compared to our previous tool, having both SIEM and vulnerability management handled by one tool made things easier. We could gather logs from different devices and cloud sources, and perform detailed investigations without switching tools. I haven't worked with the automation capabilities of InsightVM. For remediation prioritization, we check the vulnerability, search for solutions on open platforms, and work with different teams to apply patches after proper testing. Currently, we don’t have any AI or ASM projects assisted by InsightVM"
- "I’d like to see Rapid7 InsightVM improve by adding a knowledge base similar to what Qualys offers. This would help us easily check and search for vulnerabilities using Rapid7 IDs associated with CVs or CVSS. From a features perspective, everything was fine at the time, and the security features of Rapid7 InsightVM were effective."
What is our primary use case?
We mainly use it for vulnerability management, generating monthly reports to address and resolve vulnerabilities. The main use cases involve receiving alerts based on predefined settings by Rapid7, investigating these alerts to understand their causes, and performing fine-tuning activities.
What is most valuable?
The most valuable features of Rapid7 InsightVM for me are creating dynamic asset tags, generating reports, and deploying the agent. The agent scans assets every four hours, providing real-time data on any devices. Although there weren't any significant new features compared to our previous tool, having both SIEM and vulnerability management handled by one tool made things easier. We could gather logs from different devices and cloud sources, and perform detailed investigations without switching tools.
I haven't worked with the automation capabilities of InsightVM. For remediation prioritization, we check the vulnerability, search for solutions on open platforms, and work with different teams to apply patches after proper testing. Currently, we don’t have any AI or ASM projects assisted by InsightVM
What needs improvement?
I’d like to see Rapid7 InsightVM improve by adding a knowledge base similar to what Qualys offers. This would help us easily check and search for vulnerabilities using Rapid7 IDs associated with CVs or CVSS.
From a features perspective, everything was fine at the time, and the security features of Rapid7 InsightVM were effective.
For how long have I used the solution?
I've been working with Rapid7 InsightVM since December.
What other advice do I have?
Overall, I would recommend Rapid7 InsightVM to others. My advice would be to first understand your requirements and infrastructure before implementing the product. I would rate InsightVM as an eight.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Last updated: Sep 30, 2024
Flag as inappropriateBuyer's Guide
Rapid7 InsightVM
January 2025
Learn what your peers think about Rapid7 InsightVM. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,265 professionals have used our research since 2012.
Defense protection study manager at Ministère de la Défense
Simple to use and scalable while installing scan engines in various network zones
Pros and Cons
- "The solution works well."
- "They should integrate the solution with multiple products."
What is our primary use case?
We use the solution for vulnerability management. We perform scanning and security patching in selected network zones utilizing it.
What is most valuable?
The solution's most valuable features are the simplicity of use, identifying vulnerable assets, and the ability to create remediation projects.
What needs improvement?
They should integrate the solution with multiple products along with ServiceNow.
For how long have I used the solution?
We have been using the solution for two or three months.
What do I think about the stability of the solution?
I rate the solution's stability as an eight.
What do I think about the scalability of the solution?
We have a few tens of users of the solution. They include IT specialists, engineers, and administrators. We can easily install scan engines in different zones of our network. But, we face difficulties pairing the scan engines to the management console.
I rate the solution's scalability as an eight.
What about the implementation team?
The vendor team helps us install the solution.
What's my experience with pricing, setup cost, and licensing?
The solution's pricing depends on the number of users per month as per our contract. We have a limit of scanning around 4000 appliances. It covers a sufficient scope regarding our requirements.
What other advice do I have?
The solution works well. I recommend it to others and rate it as an eight.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Owner at a tech services company with 1-10 employees
Understands and defends your network from vulnerabilities
Pros and Cons
- "I liked the dashboard on it. I could customize my dashboard with different widgets and different heat maps."
- "I would say that it improved our visibility, but it left things open."
What is our primary use case?
We used InsightVM mainly for vulnerability management. I thought it was a pretty interesting application. I'm a fan of Rapid7's Metasploit, so when I saw InsightVM I was like, "Let's see what else they have." I liked it up until we experienced some issues relating to scans. If I wanted to do mitigation, I needed to wait until the next scan was available or ran so that I could get to see if any indentations were made.
While I was in there, if I was searching for a specific vulnerability, sometimes it was hard to find the specific ones. In the dashboard, it'll tell you the results from the scans, and it will also tell you the vulnerabilities and it will rank them for risk. I would have liked to have been able to click on the vulnerability and it would take me to another area that just has the vulnerability with all the hosts. It wouldn't let you do that. You had to come back out of that window and go into another window and search for it. Well, you wouldn't get the same results as the number of hosts. I had to work a little bit harder to find exactly what I needed.
Within our organization, there were two of us using it. Both of us were IT analysts. One was an IT analyst III (which was me), and the other one was the IT analyst manager.
How has it helped my organization?
I would say that it improved our visibility, but it left things open.
What is most valuable?
I liked the dashboard on it. I could customize my dashboard with different widgets and different heat maps. I liked that. That was a feature I liked. If your manager had a different dashboard that they liked, and you tried to go into a meeting and they say, "Well, I think your numbers are wrong because my dashboard says this" Well, you couldn't rapidly say, "Here's the default dashboard for this for risk." Whereas, with Tenable, you could go through a dashboard just for risks, and say, "Hey, let's switch to this dashboard so we're seeing the same numbers without customization."
What needs improvement?
They just need to fix it to make it more fluid. If it shows you vulnerabilities, I want to be able to click on the vulnerability and drill down into the vulnerability. If it's rating it as a 10 and it says it's got 30 hosts in it for this vulnerability, I want to click on that vulnerability and get a separate report that says, "Here's the vulnerability specific and here's the host involved." That way I could export it and say, "Hey, this vulnerability's out there, it matches a CVE number that is critical, that Microsoft, Cisco, whatever, has put a patch out there, and here guys, here's what it is and here's the proof. Here's your host that's vulnerable. Here's a change request, fix it, send me back the proof that you fixed it, then allow me to rerun a scan specific to that, on-demand, to say 'Yes, boss, we have mitigated it.'"
I want to be able to just drill down on the reports. If it showing me there's a vulnerability and there's a said number of nodes that's vulnerable to it, I want to be able to drill down and export that list without having to come back out of it, going into my assets, trying to find the name of the vulnerability, which doesn't match what the dashboard says. To me, that was backward.
For how long have I used the solution?
I have used this solution for one year.
What do I think about the stability of the solution?
It was pretty stable. We didn't have any real hiccups, but it was stable. We didn't have any real hiccups there.
What do I think about the scalability of the solution?
As far as I know, it says it's scalable. I'm not sure if that company I used to work for had to scale it up or down.
How are customer service and technical support?
The tech support was very helpful. Actually, I knew a couple of them so it was very helpful.
I would give their tech support a rating of 10 — I knew them from using Metasploit and some other products. It was more of a, "Hey, I got this issue, how can you help me with it?" They'd point me and say, "Hey, check this out."
How was the initial setup?
I wasn't involved in the initial setup, so I can't comment on that.
What other advice do I have?
Do your proof of concepts if you can. Make sure you develop your risk strategy. That's important, because it's going to give you a risk number, it's going to give you critical: highs, mediums, but you need to understand what is the risk methodology that you're going to follow. Just because it says it's critical because of how many vulnerabilities you have, doesn't mean that you need to work on it right away.
For example, there was a vulnerability that had 2,000 nodes affected. It put it as a high-risk, whereby there was another vulnerability where there were only about 10 hosts affected — it put it at medium-risk. However, the high-risk one, because it had more nodes affected, did not have a POC associated with it. A novice person looking at it would say, "I need to work on these 1,000 vulnerabilities because it's a high-risk, and ignore the medium." Well, the medium one had an active POC on it. If you didn't have a person who understood how to read the report and what it's actually telling you, then you would say, "Hey, you know what, I'm going to use these, I'm going to cut my risk down because I got 1,000 nodes with this vulnerability and I'm going to put this chain out real quick and I'm going to reduce my risk real quick because of the numbers." Well, in my opinion, you didn't reduce your risk because you have 10 nodes out there with a vulnerability that's rated medium and it has a POC on it.
Overall, on a scale from one to ten, I would give this solution a rating of eight. I'm going to say that is because shame on Rapid7 for having such great applications, but then that little piece there that they know about hasn't been fixed. If I remember, if I go probably log back into the community, it's probably been asked a couple of times.
Which deployment model are you using for this solution?
Private Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Head of Cyber Security at a tech services company with 51-200 employees
Easy deployment, but technical support could respond faster
Pros and Cons
- "The ease of deployment and configuration allows users to onboard quickly."
- "Technical support does not respond quickly."
What is our primary use case?
The core domain use of the solution is verification, scanning, and finding out the vulnerabilities in real time.
How has it helped my organization?
The ease of deployment and configuration allows users to onboard quickly, aligning smoothly with various functionalities.
What is most valuable?
The data sheet is good in pricing and promises. The customers are very price-conscious. You have to satisfy technical requirements. This combo makes the product valuable and usable.
What needs improvement?
Two things are consistent. The rest of the things run fine. The technical side does not respond quickly. They take a lot of time. The priority should be to respond to the customer to serve the customer.
For how long have I used the solution?
I have been using Rapid7 InsightVM for more than three years.
What do I think about the stability of the solution?
The solution’s stability is good. It keeps on running. There are no system complaints.
What do I think about the scalability of the solution?
The solution’s scalability is linked to the new scope and the cost.
Which solution did I use previously and why did I switch?
We are actively seeking alternatives. If you can offer a better solution, superior after-sales service, and overall better everything, we would like to explore what you have to offer.
How was the initial setup?
The initial setup is not so complex. It is quickly deployable configurable and integrated with your existing setup.
The common process for Rapid7 InsightVM involves comparing it against their standard procedures to ensure compliance with the required licenses and resources. Users download the necessary files and initiate/reactivate licenses. Certain configurations are also set up. This process typically takes two to three days for the department, but we usually allocate a week for completion.
Our team feels enabled enough after completing the training session on Rapid7 InsightVM. We conduct our tests independently, and whenever we need support, we seek assistance directly from Rapid7. This process isn't overly complex or time-consuming. We ensure thorough preparation by gathering all necessary information, addressing internet concerns, and informing the customer. Once fully prepared, we proceed forward.
What's my experience with pricing, setup cost, and licensing?
The solution’s pricing is good because the value proposition delivers a report box. It is not very costly.
What other advice do I have?
Since the product is cloud-based, there's no maintenance. Whatever the information or the customization of the customer needs to be confirmed. The hardware needs maintenance.
Overall, I rate the solution a six out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Cyber Security Architect at a healthcare company with 11-50 employees
Easily exposes misconfigurations, flaws, or security risks
Pros and Cons
- "The solution is automatically scheduled so it runs by itself."
- "The solution should include a tighter integration with third-party threat modeling and threat intelligence tools."
What is our primary use case?
Our company uses the solution to discover, identify, and patch vulnerabilities or disable certain services. The solution provides the patch recommendations that we implement via another tool.
Four team members manage the solution internally and for various clients who each have fifty users.
What is most valuable?
The solution helps to identify lots of misconfigurations, flaws, or security risks. Anything insecure is exposed easily.
The solution is automatically scheduled so it runs by itself.
What needs improvement?
The solution should include a tighter integration with third-party threat modeling and threat intelligence tools. Rapid7 is the solution's own threat intelligence platform but third-party platforms would be a great addition.
It would be nice to have patching capabilities built within the solution rather than using third-party products.
For how long have I used the solution?
I have been using the solution for three years.
What do I think about the stability of the solution?
The solution is extremely stable.
What do I think about the scalability of the solution?
The solution is easily scalable with the purchase of additional licenses.
How are customer service and support?
Technical support is extremely good and we get support quite fast. Technical support is rated a ten out of ten.
How would you rate customer service and support?
Positive
How was the initial setup?
The setup is very straightforward so I rate it a ten out of ten.
What about the implementation team?
We implement the solution for customers.
What's my experience with pricing, setup cost, and licensing?
The solution is a bit more reasonably priced than other products.
Which other solutions did I evaluate?
Most products in this category are similar with no real difference so it all comes down to price.
What other advice do I have?
It is important to have a strong patch management plan that prioritizes what and how you need to patch.
The solution does the vast majority of work but you need a proper system so you can take output to your operations team for patching. A good workflow between teams is important.
I rate the solution a ten out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Engineering Lead - DevOps at Persistent Systems
Can integrate with JIRA but needs to have custom image analysis for assessment
Pros and Cons
- "One of the most valuable features is it's graphical dashboard feature. It is quite easy to manage the widgets, and we can customize those according to our queries."
- "Within InsightVM, there is no feature to assign a ticket. If we can have more API calls, we can do that from InsightVM."
What is most valuable?
One of the most valuable features is it's graphical dashboard feature. It is quite easy to manage the widgets, and we can customize those according to our queries.
The other most valuable feature is that we can integrate Rapid7 InsightVM with JIRA. If a vulnerability in our services or server is found, it directly connects with JIRA and will assign a ticket. We can then share that with our development team or infrastructure team. Within a team, we can share it and assign the ticket, and we can smoothly do the mitigation process.
Also, InsightVM has an image container that can be utilized via a CI/CD pipeline. We can directly integrate with building tools, and we can have vulnerability assessment throughout the development life cycle.
Rapid7's initiative Project Sonar digs out the vulnerabilities arising all over the world and sends feedback to the systems. They then immediately update their databases and begin mitigation processes.
What needs improvement?
Within InsightVM, there is no feature to assign a ticket. If we can have more API calls, we can do that from InsightVM.
There is room for improvement when it comes to JIRA integration. If they can collaborate with the JIRA team, then it will be easier for people to use it.
If we can configure and define more features such as the critical elite level through InsightVM, it would be better.
I would prefer to have vulnerability assessment with more features, like code analysis, code coverage, etc.
I would also prefer to have a method of custom image analysis for assessment.
In the SDLC (software development lifecycle), if we could easily integrate with a particular lifecycle, then we could have more descriptive reports.
For how long have I used the solution?
I have worked with this solution for two years now.
What do I think about the stability of the solution?
It is definitely stable.
What do I think about the scalability of the solution?
The scalability is quite good. We can increase the number of assets by paying either onsite or online. Also, we have an onsite engine, and we can install it in our cloud or AWS cloud, for instance.
How are customer service and support?
The technical support team has answered our questions within a couple of hours. They have provided precise answers so far to all the questions we have asked them.
How was the initial setup?
The initial setup was an easy task because we have a Linux server installed.
InsightVM has a framework that's very interesting, and they have very detailed documentation. They have step-by-step directions for the installation process, and we can download them from their site. This means that anyone can easily install it and configure it.
The harder part is writing the queries. We need to have knowledge of InsightVM and how queries, assets, and conditional formats occur. Extensive knowledge can be valuable at this stage of the process.
What's my experience with pricing, setup cost, and licensing?
Pricing is reasonable because we pay according to asset usage. We can define our assets and sites according to our preference.
What other advice do I have?
I recommend doing a comparison of Qualys, Rapid7, and Nessus. Because the scope is different from company to company and cluster to cluster, it would be good to research each product and decide according to your needs.
If I were to rate Rapid7 InsightVM, I would rate it at seven on a scale from one to ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Network and Security engineer at a university with 1,001-5,000 employees
Gives reliable information, risk management, including prioritization
What is our primary use case?
We'll use Rapid7 InsightVM for on-premises scanning and the virtual machine option for cloud-based environments.
How has it helped my organization?
It is a good tool for comprehensive risk management, including prioritization and remediation.
What is most valuable?
It is a great endpoint agent. It gives you reliable information about that infrastructure and offers strong accuracy for risk management. However, unlike other management tools that have improved precision testing, InsightVM requires an additional purchase for full access to some of its advanced features.
What needs improvement?
Other solutions, like Cisco, have strengths, but Rapid7 InsightVM has some solid features, such as the RapidServer Active Response, the ability to create endpoint agents, and a live dashboard. However, the main concern is the system's reliability. For instance, during a scan on an Ubuntu machine, the system mistakenly identified the OS as Windows. This kind of inaccuracy is problematic.
For how long have I used the solution?
I have been using Rapid7 InsightVM for a year.
What do I think about the scalability of the solution?
How are customer service and support?
The response takes some time.
How would you rate customer service and support?
Neutral
What's my experience with pricing, setup cost, and licensing?
Rapid7 is a bit expensive.
Which other solutions did I evaluate?
Tenable has 20% lower pricing and includes built-in web application testing, which gives it an advantage over Rapid7 InsightVM.
What other advice do I have?
I recommend Tennable for small and Rapid for big enterprises.
Overall, I rate the solution an eight out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Last updated: Aug 15, 2024
Flag as inappropriateBuyer's Guide
Download our free Rapid7 InsightVM Report and get advice and tips from experienced pros
sharing their opinions.
Updated: January 2025
Product Categories
Risk-Based Vulnerability ManagementPopular Comparisons
Qualys VMDR
Tenable Security Center
Tenable Vulnerability Management
Microsoft Defender Vulnerability Management
Nucleus
Arctic Wolf Managed Risk
Cisco Vulnerability Management (formerly Kenna.VM)
SanerNow CyberHygiene Platform
Balbix BreachControl
SecureWorks Taegis VDR
Fortra's Vulnerability Management
Buyer's Guide
Download our free Rapid7 InsightVM Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions: