No more typing reviews! Try our Samantha, our new voice AI agent.

Cisco Vulnerability Management (formerly Kenna.VM) vs Rapid7 InsightVM vs Tenable Vulnerability Management comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Mindshare comparison

As of June 2026, in the Risk-Based Vulnerability Management category, the mindshare of Cisco Vulnerability Management (formerly Kenna.VM) is 2.3%, down from 2.4% compared to the previous year. The mindshare of Rapid7 InsightVM is 8.1%, down from 14.1% compared to the previous year. The mindshare of Tenable Vulnerability Management is 7.1%, down from 10.6% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Risk-Based Vulnerability Management Mindshare Distribution
ProductMindshare (%)
Rapid7 InsightVM8.1%
Tenable Vulnerability Management7.1%
Cisco Vulnerability Management (formerly Kenna.VM)2.3%
Other82.5%
Risk-Based Vulnerability Management
 

Featured Reviews

AshishPaliwal - PeerSpot reviewer
Self-employed at Self-employed
Offers contextual prioritization and risk-based remediation of vulnerability
An improvement would be some sort of an integration with any GRC suite. There are a lot of GRC suites available, like Archer, MetricStream, Rsam, Protiviti, for example. So how would a solution like this work if my company has already invested thousands or maybe millions in a GRC solution? Do I still need it and how does it fit into an existing SAP environment? There could be interoperability, having more data sources, integrating Splunk, Qualys, FireEye, Rapid7, Carbon Black. I'm sure all that can be done to an extent, with a little more insight and a little more accuracy on the industry numbers and trends. I'd like the solution to offer any sort of assistance in any way with the remediation part, not just identification of vulnerability risk, and that is second.
reviewer2775840 - PeerSpot reviewer
Manager at a financial services firm with 5,001-10,000 employees
Manages vulnerabilities effectively over time but needs improvement in web coverage and dashboard flexibility
Most of the dynamic asset tagging we use is manual, not dynamic. To manage the assets, we employed the manual approach because we have a limitation regarding the license, so we don't use the dynamic approach much. I don't know how the configuration assessment has assisted with meeting compliance standards. The product that we use is the on-premise solution where we configure assets and dynamically scan them. However, we use the default policies more, the template, so Rapid7 InsightVM on-premise version is not that effective in the web-related systems. However, it is best on the OS to identify and discover the OS-related vulnerabilities, more of open ports and the discovery of vulnerable ports or services. It would be better to improve Rapid7 InsightVM by including or working better to add web-related templates because it's not that effective in regard to web. I don't know if they may have a separate product regarding the web, but for the on-premise type, they are not strong in this area. I would prefer to see web-related templates in addition to improving the dashboard-related things because the dashboard has been constant for a very long time. It would be better to see various kinds of, perhaps a flexible type of dashboard. If it's not customizable at all, I would want to see the risk and asset over time with more flexibility. The current dashboard is not flexible in this regard; I have to dig down every day, so they should work on this as well, in addition to the web.
Chethan Gowda - PeerSpot reviewer
Windows Security Patching Operation III (Cyber Operations) at CBTS
Have maintained accurate vulnerability scans and gained actionable remediation insights across thousands of servers
Tenable Vulnerability Management agents are very lightweight, and the results we get are very accurate. The solutions they provide to us, assuming if one vulnerability exists, there will be a solution. The resolution they give us in wording will be the best solution. The exploit rates and the reports we get provide a lot of information, making it very easy for us to verify.The main benefit of integration with Tenable Vulnerability Management is that there will be no lack of missing vulnerabilities when it comes to the patching environment. That is one of the key aspects of why we have integrated Tenable to our patching tools. It has a vast capacity of pushing the data to our tools due to its capability and compatibility. That is also one of the reasons why we are using Tenable Vulnerability Management.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The risk context of any vulnerability is a valuable feature."
"The risk context of any vulnerability is a valuable feature; that is what it is used for and then data from different sources can be fed into it, and they have good dashboards, risk meters, and virtualization."
"When you connect any new device to the network, Rapid7 has the ability to detect the new device immediately. It can scan that device to detect if it has any vulnerability. It tells you what is vulnerable and what has been misconfigured. It also tells you what is the risk of that misconfiguration or lack of patches and how to resolve the problem."
"The risk score that they provide makes it easier to find out the biggest risks. It helped the security officers to understand where the biggest risks are so that they can act on them. They can instruct their IT teams to give them a higher priority and mitigate them."
"The product's initial setup phase was very easy."
"This solution is much more user-friendly than past solutions I have used."
"Overall, this is a product that I am very satisfied with."
"The assessment is most valuable."
"Insight VM vs Tenable Nessus is a more user-friendly product."
"The most valuable feature is the site scanning, where we can provide a complete subnet and what it is we need to scan on those devices."
"Overall, I am quite happy with Tenable.io."
"There is no burden of updating or upgrading this solution."
"The product offers good performance, with no bugs or glitches, and it doesn't crash or freeze."
"It has greatly impacted us by providing asset visibility."
"It is very stable, and it is updated periodically by adding new vulnerabilities."
"Tenable.io Vulnerability Management is an easy-to-use product. I"
"It's a great product, and it brings more value with every improvement in the quarter."
"The solution is easy to use and configuration is smooth with no complexities."
 

Cons

"An improvement would be some sort of an integration with any GRC suite."
"In order to be able to properly test the solution and make a decision, I would like to receive the test license code instantly and eliminate the wait time."
"InsightVM could be improved by providing passive scanning as an option."
"I would like to see more integration."
"The integration with other solutions like JIRA could be better."
"There should be containerization within the VM."
"I would say that it improved our visibility, but it left things open."
"For the community edition one of the big issues is with the registration. Rapid 7 only supports paid domains for registration, so no .gmail.com, .yahoo.com domains."
"I’d like to see Rapid7 InsightVM improve by adding a knowledge base similar to what Qualys offers. This would help us easily check and search for vulnerabilities using Rapid7 IDs associated with CVs or CVSS. From a features perspective, everything was fine at the time, and the security features of Rapid7 InsightVM were effective."
"I would evaluate Tenable Vulnerability Management's customer service and technical support as average."
"The price could be lower."
"More flexibility is required compared to other solutions."
"t needs additional reporting and intelligence features, as well as enhancements in AI-driven detection, which is still in its early stages."
"It can have more integration."
"They need to have more dependable and faster support."
"I would rate it four out of ten. For startups, freelancers, or companies between startup and midsize, Tenable is recommended. However, for midsize or enterprise-level companies, I would not prefer it."
"The solution seems to focus too much on enterprises, and they really need a product that works for SMBs."
 

Pricing and Cost Advice

"I think the pricing is based on the number of endpoints, so it's more subscription-based."
"The licensing is asset-based and very straightforward."
"Our licensing costs are somewhere around $40,000 annually. There are no additional fees."
"The price of the solution is less than the competitors."
"Its licensing is yearly. Everything is included in the price for one year."
"The license is IP based. How many IPs you are using to scan is the amount of the license you have to buy. The number of users doesn't matter; many users can use it or only person. It depends on the culture of the organization."
"The solution's pricing is better than Nexus which charges a high amount for very little use."
"The product is cheaper than the other similar tools available in the market."
"InsightVM is an expensive product, especially compared to its competitors, at around a million NOK per year."
"I would rate the pricing a five out of ten. It is in the middle."
"Tenable.io Vulnerability Management's pricing solution model isn't great."
"The total cost we pay for this solution is over 45K. This is for a large education organization."
"Yearly payments are to be made toward the licensing cost of the product. It is neither a cheap nor an expensive product."
"There are additional features that can be licensed for an additional cost."
"A yearly payment has to be made toward the solution's licensing costs."
"The product costs us around $137,000 annually for 4000 to 5000 assets."
"The solution is not too expensive."
report
Use our free recommendation engine to learn which Risk-Based Vulnerability Management solutions are best for your needs.
899,917 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Retailer
15%
Computer Software Company
14%
Financial Services Firm
10%
Construction Company
9%
Financial Services Firm
12%
Manufacturing Company
9%
Computer Software Company
7%
Comms Service Provider
6%
Financial Services Firm
14%
Manufacturing Company
10%
Computer Software Company
8%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
By reviewers
Company SizeCount
Small Business29
Midsize Enterprise14
Large Enterprise25
By reviewers
Company SizeCount
Small Business20
Midsize Enterprise3
Large Enterprise22
 

Questions from the Community

Ask a question
Earn 20 points
How would you choose between Rapid7 InsightVM and Tenable Nessus?
You have full visibility across cloud, network, virtual, and containerized infrastructures with Rapid7 Insight VM. Yo...
What is your experience regarding pricing and costs for Rapid7 InsightVM?
My experience with the pricing, setup cost, and licensing is that both the setup cost and licensing are great.
What needs improvement with Rapid7 InsightVM?
To improve Rapid7 InsightVM, I wish to have integration with patching systems, which would be useful to us. The usabi...
What's the difference between Tenable Nessus and Tenable.io Vulnerability Management?
Tenable Nessus is a vulnerability assessment solution that is both easy to deploy and easy to manage. The design of ...
What needs improvement with Tenable.io Vulnerability Management?
I don't think that there is any very specific area where enhancements need to happen in Tenable Vulnerability Managem...
What advice do you have for others considering Tenable.io Vulnerability Management?
I use Tenable Vulnerability Management, and that is the tool that I have primary experience with. Apart from zero-day...
 

Also Known As

Kenna.VM, Kenna Security, Kenna, Kenna Security Platform
InsightVM, NeXpose
Tenable.io
 

Overview

 

Sample Customers

TransUnion
ACS, Acosta, AllianceData, amazon.com, biogen idec, CBRE, CATERPILLAR, Deloitte, COACH, GameStop, IBM
Global Payments AU/NZ
Find out what your peers are saying about Qualys, Horizon3.ai, Tenable and others in Risk-Based Vulnerability Management. Updated: May 2026.
899,917 professionals have used our research since 2012.