Try our new research platform with insights from 80,000+ expert users
Khizar Butt - PeerSpot reviewer
Country Sales Lead at securic systems
Reseller
Top 5Leaderboard
Vulnerability management solution that has a good distribution network and support in Pakistan
Pros and Cons
  • "Rapid7 have a good distribution network with good support and market presence."
  • "Some of our customers want to be completely cloud based, and Rapid7 doesn't offer this as an option."

What needs improvement?

Their channel program and the process of their deal registration could be improved.

Some of our customers want to be completely cloud based, and Rapid7 doesn't offer this as an option. 

For how long have I used the solution?

I have used this solution for one year. 

What do I think about the stability of the solution?

This solution is fairly stable.

What do I think about the scalability of the solution?

This is a scalable solution suitable for large environments. 

Buyer's Guide
Rapid7 InsightVM
January 2025
Learn what your peers think about Rapid7 InsightVM. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,265 professionals have used our research since 2012.

Which solution did I use previously and why did I switch?

We initially worked with Qualys and found that Qualys has a better reputation but it is expensive. Companies with bigger budgets and who would like a cloud solution, usually prefer Qualys. This is also because of the product maturity and the research they provide.

The challenge with Qualys is that they do not have any distributors in Pakistan. They do not have an on-premises product, which caters more towards the enterprise accounts in Pakistan. I prefer going with Rapid7 for this reason. Rapid7 have a good distribution network with good support and market presence. 

What other advice do I have?

My advice is to explore many options and look at the integrations available. My personal experience is that only implementing vulnerability management doesn't solve all of the problems. We also needed evaluator integrations that provide preventative measures.

I would rate this solution an eight out of ten. 

Disclosure: My company has a business relationship with this vendor other than being a customer:
PeerSpot user
PeerSpot user
Security Analyst at Zavarovalnica Triglav dd
Real User
Vulnerability management that is easy to use and install, with good technical support
Pros and Cons
  • "This solution is very easy to use and easy to install."
  • "It would be nice to have an additional feature that would provide reports on who has logged onto the console or who did what on the console."

What is our primary use case?

The primary use case of this solution is for vulnerability management.

We have monthly scans and reporting. The results are in QRadar, which is our SIEM.

What is most valuable?

This solution is very easy to use and easy to install.

It has nice features.

What needs improvement?

It would be nice to have an additional feature that would provide reports on who has logged onto the console or who did what on the console. I don't have the time to log onto the console and use SSH to go through the logs. 

We have some users with certain privileges, and sometimes they do things that I don't like.  This is why it would be nice to have an easy way to report what is in the logs.

In the next release, I would like to see reporting added to the console. It would be helpful to have reports to tell you who did what, who created reports, who created groups or who created tags.

For how long have I used the solution?

I have been working with this solution for five years.

What do I think about the stability of the solution?

The stability is good. I am running it on Linux and from that point of view, Linux is stable.

We are using this solution daily. 

What do I think about the scalability of the solution?

This solution is easy to scale. 

I am working at Triglav Group which is the leading insurance-financial group in Slovenia and
in the Adria region and one of the leading groups in South-East Europe

Triglav Group operates together with its subsidiaries and associated companies on seven markets and in six countries.

We use with two consoles, one is international for subdiraies and other is for the Slovenia all thogether we have 15 scan engines on locations.

How are customer service and technical support?

Approximately a year ago, we had an issue with the dashboard. We contacted technical support to ask a question. Unfortunately, we were not able to resolve the issue that we were having. It could have been something in our network, but we don't know. It was not a big issue.

The technical support is good, they do give you answers and they are pretty quick.

How was the initial setup?

The initial setup was easy and straightforward.

I deployed this solution. It took a couple of days with ten engines.

What about the implementation team?

We did not use a vendor or integrator to implement this solution. We have five thousand people in this firm and I am the only one in technical team. 

What other advice do I have?

My advice would be to just use it. 


As a whole, it's a pretty good product. I don't have any problem with it.

If they had the audit reporting then I would rate it a ten out of ten, but as it is now, I would rate this solution a nine out of then.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Rapid7 InsightVM
January 2025
Learn what your peers think about Rapid7 InsightVM. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,265 professionals have used our research since 2012.
Smriti Rani - PeerSpot reviewer
System Engineer at a tech services company with 201-500 employees
MSP
It's a good solution for capacity forecasting
Pros and Cons
  • "I rate InsightVM eight out of 10 for ease of setup. It takes two or three engineers to deploy. The solution requires some maintenance. It's mainly cleaning up data."

    What is our primary use case?

    We use InsightVM for capacity forecasting.

    For how long have I used the solution?

    I've been working around, I don't know, it's about three years.

    What do I think about the stability of the solution?

    I rate Rapid7 nine out of 10 for stability.

    What do I think about the scalability of the solution?

    I rate Rapid7 nine out of 10 for scalability.

    How are customer service and support?

    I rate Rapid7 support nine out of 10.

    How would you rate customer service and support?

    Positive

    How was the initial setup?

    I rate InsightVM eight out of 10 for ease of setup. It takes two or three engineers to deploy. The solution requires some maintenance. It's mainly cleaning up data. 

    What other advice do I have?

    I rate Rapid7 InsightVM 10 out of 10.

    Which deployment model are you using for this solution?

    Public Cloud
    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    Information Security Officer at Umniah
    Real User
    It's smarter and more accurate from an application perspective
    Pros and Cons
    • "Using Rapid7, we can install a scan engine, we can do our VPN connections, and we can conduct internal scans of remote sites. We prefer the web application. It's smarter and more accurate from an application perspective."
    • "The integration with other solutions like JIRA could be better. Perhaps there could be some additional updates in the next phase that could integrate with it, so then you can proceed with the VT much easier."

    What is our primary use case?

    We use a hybrid setup. Some dashboards and configurations are uploaded to the Cloud, and some of them are on-premises. The main engine is on-premises. We have about 12 customers and some of them are big companies. 

    What is most valuable?

    There are a few main features that we are very happy with. Using Rapid7, we can install a scan engine, we can do our VPN connections, and we can conduct internal scans of remote sites. We prefer the web application. It's smarter and more accurate from an application perspective.

    What needs improvement?

    The integration with other solutions like JIRA could be better. Perhaps there could be some additional updates in the next phase that could integrate with it, so then you can proceed with the VT much easier.

    For how long have I used the solution?

    I've been using Rapid7 for about two years.

    What do I think about the scalability of the solution?

    From a scalability standpoint, it's good because they give you around 100%. If you want to increase your asset counts, for example, they give you permission for 100% above the limit that you pay for.

    How are customer service and technical support?

    Their support is very good. Technical support varies from person to person. Some cases have taken some time, but once it was escalated, everything was done well and the problem was solved. We've had some cases involving integration, remote sites, and some special configurations. They provided us with some support on all that.  

    How was the initial setup?

    It's straightforward. Everything is like setting up Lego cubes. It doesn't take much time to deploy. The first deployment may take around an hour or two.

    What's my experience with pricing, setup cost, and licensing?

    The license could be a little bit cheaper. For all these features, you would expect to pay a little bit lower but around the same general price. Licenses are paid yearly. For some customers, we pay two years at a time, but mostly it's yearly.

    What other advice do I have?

    I would rate it nine out of 10.

    Which deployment model are you using for this solution?

    Hybrid Cloud
    Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
    PeerSpot user
    reviewer1541043 - PeerSpot reviewer
    Head of Cybersecurity Assurance & Controls Director at a tech services company with 1,001-5,000 employees
    Real User
    Poor reporting, lacking in features, but the technical support is not bad
    Pros and Cons
    • "I have been in contact with technical support and they are not bad."
    • "The reporting is very bad when you compare it with other vulnerability assessment tools."

    What is our primary use case?

    I primarily using Rapid7 for vulnerability assessment and reporting.

    How has it helped my organization?

    At this point, we are not happy with Rapid7.

    What needs improvement?

    The reporting is very bad when you compare it with other vulnerability assessment tools.

    This product is for basic vulnerability assessments, only, and is lacking in features such as compliance, assessment, assets, inventory, and batch management.

    For how long have I used the solution?

    I have been using Rapid7 InsightVM for five years.

    What do I think about the scalability of the solution?

    I would say that the scalability is 50-50. It does not offer much in terms of being able to scale. We have approximately 3,000 users.

    How are customer service and technical support?

    I have been in contact with technical support and they are not bad.

    What's my experience with pricing, setup cost, and licensing?

    Comparing the price with the value that we receive, I am not happy with it.

    Which other solutions did I evaluate?

    We are currently looking to replace Rapid7 with another product.

    Currently, we are working with Tenable Nessus and Qualys.

    What other advice do I have?

    I would rate this solution a five out of ten.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    reviewer613356 - PeerSpot reviewer
    Information Security Manager at a educational organization with 5,001-10,000 employees
    Real User
    With an effective dashboard, it gives us visibility into people using VPNs
    Pros and Cons
    • "NeXpose is a pretty good vulnerability scanner... There's a nice dashboard."

      What is our primary use case?

      Our primary use case is looking for people who are using Tor, or VPNs generally, and the only way we can see that is if they log in and then they log in in a foreign country right away, which means they're jumping on to the "escalator".

      How has it helped my organization?

      We really didn't have any visibility at all and now we do. It's like night and day.

      What is most valuable?

      NeXpose is a pretty good vulnerability scanner, good enough. There's a nice dashboard and it's a pretty cool SIEM.

      What needs improvement?

      We could always have a cheaper price, but other than that it's pretty good stuff.

      Also, if they’d expand their product line, that would be good, and they are doing so, but they're not done yet.

      What do I think about the stability of the solution?

      Stability is rock solid.

      What do I think about the scalability of the solution?

      We're at a pretty big scale already. I don't expect us to get any bigger and it's handling our scale now. If anything, we’ll probably shrink.

      We're a school district and, in this area, there are three big districts, and they have open enrollment. We're not on the marketing end of our school district. If the marketing doesn't do well, we’ll shrink.

      How are customer service and technical support?

      Tech support is satisfactory.

      Which solution did I use previously and why did I switch?

      Last year got a new person in the position of information security officer, and he brought the news with him.

      We went with NeXpose because we wanted to get as many products as we could from the same vendor. A full suite would have been fantastic, but that doesn't exist yet. Rapid7 had the vulnerability scanner, the penetration testing, and the SIEM, and the web app evaluator. They're adding other things. They acquired another company recently that will benefit us if we get that product. It's the all-in-one works we like.

      My most important criterion when selecting a vendor is that they have to have a purchasing vehicle that is approved for school districts. It's harder than it sounds. We can't just say, "We want that, send us a bill."

      How was the initial setup?

      It's easy to install.

      Which other solutions did I evaluate?

      We started with SentinelOne, we looked at CrowdStrike, we looked at Red Canary. The funny thing was, Red Canary was just remarketing CrowdStrike, or something like that. It got to a point where I realized these weren’t additional vendors. They were just additional packagers of the same solution.

      What other advice do I have?

      Take a test drive. If you don't test drive it, how do you know you're going to like it or if it even works. Would you buy a car without test driving it? Absolutely not. In this case, it’s a sales contract. It's a service for one to three years. Backing out of it is pretty much impossible.

      I rate it at eight out of 10. It just works. We haven't had any trouble with it. We've had good support. What's not to like? But it's an eight because the software that can be purchased is not the ultimate software. It's hard to give anybody a 10.

      Disclosure: I am a real user, and this review is based on my own experience and opinions.
      PeerSpot user
      IT Security Engineer
      Real User
      Reliable, easy to set up, and has a good remediation feature
      Pros and Cons
      • "The solution scales well."
      • "There was functionality present previously, however, currently, we can't integrate directly with Jira Service Desk - only the cloud version."

      What is our primary use case?

      We primarily use the solution for vulnerability management and monitoring the progress of the remediation process.

      What is most valuable?

      The remediation feature has been quite useful. 

      It's easy to set up the solution. 

      It's stable.

      The solution scales well.

      What needs improvement?

      The solution isn't missing any features, and I haven't noticed any shortcomings. 

      There was functionality present previously, however, currently, we can't integrate directly with Jira Service Desk - only the cloud version. That, or we must share to the internet on-prem Jira Service Desk. It's not easy for us since we use only the on-prem Service Desk service, and we don't straight to the internet for our service.

      InsightVM can only directly connect to the internet. So, we can't use this integration and send tasks to our technical team from InsightVM. We, therefore, need better integration with Jira Service Desk. 

      What do I think about the stability of the solution?

      The stability has been good overall. I would rate it five out of five in terms of reliability. The performance is good. There are no bugs or glitches, and it doesn't crash or freeze. 

      What do I think about the scalability of the solution?

      The solution is suitable for big or small organizations. We have clients of different sizes using the product. 

      It's used at the engineering level, with security and administrators using it regularly.

      I'd rate it five out of five in terms of the ease of scaling. 

      How was the initial setup?

      The solution is straightforward to set up. I'd rate it four out of five in terms of ease of implementation. 

      We have one or two team members that can set up the solution. 

      How long it takes to deploy depends on the customer. For a small customer, it's less than one month or sometimes two weeks. For a big customer with many assets and services, it takes two or three months to deploy.

      We only need to have one or two people on hand to handle maintenance tasks. 

      What's my experience with pricing, setup cost, and licensing?

      The solution is not overly expensive.

      What other advice do I have?

      We use this solution for our clients.

      We're dealing with the latest version of the product.

      InsightVM is a solution based on on-prem infrastructure connected to the cloud service, so it's a hybrid solution.

      Overall, it's a nice tool. 

      I'd rate the solution nine out of ten. 

      Which deployment model are you using for this solution?

      Hybrid Cloud
      Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
      PeerSpot user
      reviewer1525941 - PeerSpot reviewer
      Service Delivery Manager at a security firm with 11-50 employees
      Real User
      Easy to deploy and flexible licensing but the reporting could be better
      Pros and Cons
      • "The product is scalable."
      • "The reporting could be better."

      What is our primary use case?

      We primarily use the solution for vulnerability management.

      What is most valuable?

      From a scanning perspective, it’s great. The customization associated with each and every scan is very good. It actually provides functionality from a CIS control perspective as well.

      It is easy to deploy.

      The product is scalable.

      The solution is very stable.

      What needs improvement?

      The reporting could be better.

      We do not need any additional features.

      For how long have I used the solution?

      I’ve been using the solution for two years.

      What do I think about the stability of the solution?

      The solution is very stable. The reliability is good. There are no bugs or glitches. It doesn’t crash or freeze.

      What do I think about the scalability of the solution?

      The solution is absolutely scalable.

      From a footprint perspective, there are about 780 servers. In totality, there's a license entitlement for about 1000 clients.

      How are customer service and support?

      Technical support has been accurate.

      How would you rate customer service and support?

      Neutral

      How was the initial setup?

      The solution is straightforward to set up and simple to deploy. It’s not overly complex. We only need one technical person to handle the setup process.

      How long it takes to deploy depends on multiple instances whereby multiple factors, depending on client, on-prem, et cetera. Your average deployment time would be anything from three to five days.

      What about the implementation team?

      As partners, we can handle the implementation.

      What was our ROI?

      The ROI is fair to mild.

      What's my experience with pricing, setup cost, and licensing?

      The licensing is market-related.

      The cost depends on the number of assets per annum.

      It is very flexible. What's nice about it is, from a client's perspective, the environment can either grow and you can chew up, or it can shrink, and it meets whatever needs you have.

      The licensing includes technical support.

      What other advice do I have?

      We’re partners.

      We’re always using the latest version of the solution.

      There's a mix of deployments. There's an on-prem deployment in certain customer areas. However, there's also a cloud deployment from the MSSV point of view as well.

      The scanner is always on-prem. The majority of the scanners that we've deployed are on-prem. Although some of the consoles are selling cloud-deployed, other consoles would be on-prem.

      I’d rate the solution seven out of ten.

      Which deployment model are you using for this solution?

      Public Cloud

      If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

      Amazon Web Services (AWS)
      Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
      PeerSpot user
      Buyer's Guide
      Download our free Rapid7 InsightVM Report and get advice and tips from experienced pros sharing their opinions.
      Updated: January 2025
      Buyer's Guide
      Download our free Rapid7 InsightVM Report and get advice and tips from experienced pros sharing their opinions.