No more typing reviews! Try our Samantha, our new voice AI agent.

Brinqa vs Rapid7 InsightVM comparison

Why PeerSpot?
Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Qualys TotalCloud
Sponsored
Ranking in Vulnerability Management
11th
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
44
Ranking in other categories
Container Security (11th), Cloud Workload Protection Platforms (CWPP) (8th), Cloud Security Posture Management (CSPM) (8th), SaaS Security Posture Management (SSPM) (2nd), Cloud-Native Application Protection Platforms (CNAPP) (7th)
Brinqa
Ranking in Vulnerability Management
61st
Average Rating
7.0
Reviews Sentiment
6.8
Number of Reviews
1
Ranking in other categories
Cloud Security Posture Management (CSPM) (52nd), Attack Surface Management (ASM) (52nd), Risk-Based Vulnerability Management (19th)
Rapid7 InsightVM
Ranking in Vulnerability Management
13th
Average Rating
8.0
Reviews Sentiment
6.9
Number of Reviews
66
Ranking in other categories
Risk-Based Vulnerability Management (4th)
 

Featured Reviews

RO
IT Security Expert at Alior Bank S.A.
Unified risk scoring has improved our cloud visibility and simplifies remediation priorities
Qualys TotalCloud provides unified vulnerability and threat assessment across both IAS and SaaS. This solution provides a single prioritized view of risk, which helps reduce the work I would have to do. We are no longer based on CVSS; we are based on Qualys risk scoring, which is based on CVSS plus internal findings made by Qualys, and then assigns its own score. The TruRisk insight feature has found a small number of assets with high vulnerability scores, though I am cautious since some information is classified. Qualys TotalCloud has positively impacted our bank's performance, and we have definitely seen benefits after implementing this solution.
RB
Cybersecurity Director at RB Consultancy
Allows us to configure the risk algorithm to suit our specific needs
I would give the easiness of the initial setup a seven out of ten. It can be a bit complex. Some connections are straightforward, but some take a long time. Deploying Brinqa took time, as it was done in phases. Initially, it took about six months before we started getting valuable data from it. Then, it expanded from there. The deployment began with a product demo and contract negotiation. We connected some data sources to Brinqa's cloud service, which was straightforward. We used the default risk ranking algorithm but faced issues with the dashboards, so we customized them to fit our organization's needs over a few years. We depended a lot on Brinqa for the deployment. We had some internal resources, but they lacked the needed skills, so it took time to train our two-man team. Initially, it required one person for maintenance, and they spent most of their time on it.
reviewer2775840 - PeerSpot reviewer
Manager at a financial services firm with 5,001-10,000 employees
Manages vulnerabilities effectively over time but needs improvement in web coverage and dashboard flexibility
Most of the dynamic asset tagging we use is manual, not dynamic. To manage the assets, we employed the manual approach because we have a limitation regarding the license, so we don't use the dynamic approach much. I don't know how the configuration assessment has assisted with meeting compliance standards. The product that we use is the on-premise solution where we configure assets and dynamically scan them. However, we use the default policies more, the template, so Rapid7 InsightVM on-premise version is not that effective in the web-related systems. However, it is best on the OS to identify and discover the OS-related vulnerabilities, more of open ports and the discovery of vulnerable ports or services. It would be better to improve Rapid7 InsightVM by including or working better to add web-related templates because it's not that effective in regard to web. I don't know if they may have a separate product regarding the web, but for the on-premise type, they are not strong in this area. I would prefer to see web-related templates in addition to improving the dashboard-related things because the dashboard has been constant for a very long time. It would be better to see various kinds of, perhaps a flexible type of dashboard. If it's not customizable at all, I would want to see the risk and asset over time with more flexibility. The current dashboard is not flexible in this regard; I have to dig down every day, so they should work on this as well, in addition to the web.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Qualys TotalCloud's most valuable features are its security capabilities that help identify and mitigate risk factors."
"I like the web API security and IoT scanning features the most. The user-friendly design of TotalCloud's interface enables customers to navigate it and use its full potential easily"
"Qualys TotalCloud has positively impacted our organization by helping us save time and manage all assets and remediation, allowing us to achieve quarterly and half-yearly goals."
"I highly recommend Qualys TotalCloud to other users."
"Qualys TotalCloud has positively impacted our bank's performance, and we have definitely seen benefits after implementing this solution."
"TotalCloud's best feature is the integration of cloud accounts. It helps with the risk and security posture management of our cloud infrastructure."
"If I had to say something positive about the product that brings me the biggest benefit, I would say it has accurate reports, gets new update CVEs, zero-day attack detection, and is easy to manage with its GUI."
"The best part I like is the on-demand scans."
"The most valuable features of Brinqa are its data integration capabilities."
"One of the big lessons we were able to get value from immediately was really just having good visibility of what's in our environment."
"It is a stable solution."
"Nexpose is one of the best solution on the market with very good development."
"The performance is good."
"InsightVM provides a reliable and efficient solution with a very organized GUI, excellent ease of use, and reliable vulnerability scanning."
"This solution's most useful feature is that it is entirely a single-page application."
"Rapid7 gave us the ability to do a lot of that, and it was not a cumbersome tool to implement."
"The most valuable feature of the Rapid7 InsightVM solution is the Live Risk Score."
 

Cons

"From a downside perspective, the UI is not user-friendly and feels dated compared to other tools like Prisma Cloud."
"To be honest, I would move out from this tool because it does not give a full view of vulnerability."
"It has been working very well, but it would be helpful if the dashboard could generate reports tailored to specific compliance needs. For example, in India, we have to comply with RBI and SEBI guidelines. It w"
"A feature improvement could be the inclusion of Windows OS support for container security, as it is currently only supported for Linux."
"The vulnerability part is good, but the policy compliance module needs improvement because it involves a lot of manual work. Specifically, the remediation part of the controls requires enhancements."
"The areas in the solution that have room for improvement include the UI/UX design, which should be improved, and they should integrate more artificial intelligence into the product."
"With the growing integration of AI, I would like Qualys to enhance its service offerings to better accommodate AI-related risks."
"Their customer support needs improvement."
"Brinqa could improve in terms of the speed of their service and resource provision."
"Rapid7 InsightVM could be easier to use for those who are using it for the first time."
"This solution is expensive, but it's fine for us as we have an open budget for security solutions."
"The solution could improve by being more secure."
"The product does not have the capability to do dynamic scanning of non-web applications."
"They should integrate the solution with multiple products."
"The integration with other solutions like JIRA could be better."
"Rapid7 could be easier to manage. When you compare it to other similar solutions, it is a bit difficult to manage."
"Rapid7 InsightVM, has impressive capabilities, especially when it comes to managing video equipment. However, we've noticed that Rapid7 also offers a cloud solution called CloudSec, and we don't have that. We think it would be better if InsightVM had all the features for both on-premise and cloud management."
 

Pricing and Cost Advice

"The pricing is comparable. It is built into our other product, so I cannot piecemeal it. It is a part of our subscription."
"It isn't cheap, but it's reasonable. It helps us to manage things with very few resources."
"The pricing for TotalCloud is attractive and competitive in the market. Given the features, especially the dashboard, I have no concerns regarding pricing."
"Qualys TotalCloud is cost-efficient and was selected for its value compared to other products."
"I am not sure about the pricing. From what I understand, it is a bit on the higher side, but I do not have the exact numbers."
"The cost is high, but it meets our organizational needs."
"Its price seems higher compared to other tools, but it is worth it. If they could adjust the pricing and make it comparable with other tools, that would be great."
"Qualys TotalCloud offers competitive pricing given its comprehensive suite of features, including integration, assessment, remediation, and detection capabilities, all within a single platform."
Information not available
"A full license for the solution is expensive because it is at the organizational level and not by individual users."
"The license is annual and this is the optimal approach when it comes to most software."
"Its price is too high. My only concern or issue with Rapid7 is its pricing."
"It is less expensive compared to other competitors."
"Its pricing depends on the number of users per month."
"The license is IP based. How many IPs you are using to scan is the amount of the license you have to buy. The number of users doesn't matter; many users can use it or only person. It depends on the culture of the organization."
"The licensing is asset-based and very straightforward."
"Our licensing costs are somewhere around $40,000 annually. There are no additional fees."
report
Use our free recommendation engine to learn which Risk-Based Vulnerability Management solutions are best for your needs.
912,753 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Comms Service Provider
16%
Outsourcing Company
12%
Manufacturing Company
12%
Financial Services Firm
10%
Financial Services Firm
14%
Retailer
12%
Construction Company
9%
Comms Service Provider
7%
Financial Services Firm
11%
Manufacturing Company
8%
Comms Service Provider
7%
Computer Software Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business12
Midsize Enterprise5
Large Enterprise32
No data available
By reviewers
Company SizeCount
Small Business29
Midsize Enterprise14
Large Enterprise25
 

Questions from the Community

What needs improvement with Qualys TotalCloud?
In terms of improvement, remediation still belongs to the cloud team, which is one of the issues we faced with Qualys...
What is your primary use case for Qualys TotalCloud?
My main use case for Qualys TotalCloud is regarding the cloud visibility that we were not having previously. Previous...
Ask a question
Earn 20 points
How would you choose between Rapid7 InsightVM and Tenable Nessus?
You have full visibility across cloud, network, virtual, and containerized infrastructures with Rapid7 Insight VM. Yo...
What is your experience regarding pricing and costs for Rapid7 InsightVM?
My experience with the pricing, setup cost, and licensing is that both the setup cost and licensing are great.
What needs improvement with Rapid7 InsightVM?
To improve Rapid7 InsightVM, I wish to have integration with patching systems, which would be useful to us. The usabi...
 

Also Known As

Qualys TotalCloud with FlexScan
No data available
InsightVM, NeXpose
 

Overview

 

Sample Customers

Information Not Available
Depository Trust and Clearing Corporation
ACS, Acosta, AllianceData, amazon.com, biogen idec, CBRE, CATERPILLAR, Deloitte, COACH, GameStop, IBM
Find out what your peers are saying about Qualys, Horizon3.ai, Tenable and others in Risk-Based Vulnerability Management. Updated: September 2026.
912,753 professionals have used our research since 2012.