No more typing reviews! Try our Samantha, our new voice AI agent.

Firefly vs Rapid7 InsightCloudSec comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Firefly
Ranking in Cloud Management
34th
Average Rating
9.4
Reviews Sentiment
5.1
Number of Reviews
3
Ranking in other categories
No ranking in other categories
Rapid7 InsightCloudSec
Ranking in Cloud Management
18th
Average Rating
7.8
Reviews Sentiment
6.3
Number of Reviews
13
Ranking in other categories
Cloud Security Posture Management (CSPM) (19th), Cloud-Native Application Protection Platforms (CNAPP) (16th), AI Observability (13th)
 

Mindshare comparison

As of August 2026, in the Cloud Management category, the mindshare of Firefly is 0.5%, up from 0.2% compared to the previous year. The mindshare of Rapid7 InsightCloudSec is 1.0%, up from 0.5% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Cloud Management Mindshare Distribution
ProductMindshare (%)
Rapid7 InsightCloudSec1.0%
Firefly0.5%
Other98.5%
Cloud Management
 

Featured Reviews

MR
Senior Software Consultant at a hospitality company with 10,001+ employees
Design workflows have been transformed and now enable rapid ad visuals and campaign launches
Firefly offers several best features in my opinion. We have the TTS feature and TTV feature. Additionally, suppose I have a single image from the creative designer and I want to generate different variations or different sizes of that image that will get adapted mostly on Google Ads. For example, I want to generate different renditions of that same image in different resolutions. I can quickly go to Firefly and from a single image generate different multiple images in different renditions. Firefly also helps us expand images. For example, I have a small image that is a portrait and I want to convert that as a full image or a hero image, which fits on a wide screen. Firefly helps us generate the images. It will not be stretching or squeezing your image. Instead, Firefly takes the context from your image and generates the next object which could appear. For example, if I am standing on a beach, it will generate the beach. It will generate a few people, it will generate some pictures of the sea, maybe some coconut trees. Firefly has positively impacted my organization a lot. I can say it is helping us reduce the effort and cost, saving the cost. For example, I have to create one image for our social media post. For that, we have to request our creative team, and then a creative designer will work on that idea and take one day or two days to get the design complete. After that, it comes to the review. With the help of Firefly, we can quickly generate the images and get them reviewed. Our go-to-market becomes easy. Within two hours or three hours, we can complete this whole process: generation, review, and all, and go to the market instantly. Additionally, if we have one image available and I want to quickly launch a Google Ad campaign that requires different renditions of the image, I can quickly use Firefly and generate different renditions of the image using the single image. So, it also reduces the dependency which we had earlier with the creative designers and the creative team.
Arun Babu - PeerSpot reviewer
SOC analyst at a media company with 1,001-5,000 employees
Daily endpoint monitoring has improved investigations and saved time but detection rules still need tuning
It is important to note that Rapid7 InsightCloudSec's features are not 100% precise, but I find about 70% of the time it is satisfactory. I would like to suggest that you improve it to be more precise, ideally making it 100% if possible. Some cases in Rapid7 InsightCloudSec indicate that the log is not enough, as they mostly just generate alerts, and the synchronization between data connectors is often problematic, particularly in terms of not being in sync always, especially between the AD and Rapid7 alerts, which generates numerous false positives. Additionally, the traditional rules should be updated, as this is a main point worth mentioning since we spend a lot of time fine-tuning these traditional rules. I suggest improving the legacy detection rules. If there are any authentication cases, such as impossible travel activity where a user has their SharePoint hosted in a different location, Rapid7 can often trigger alerts, creating confusion as we cannot fine-tune it properly. Another issue is with honeypot access. We sometimes lack necessary logs because Defender's advanced threat protection scanning gets detected as honeypot activity by Rapid7, leading to annoying and noisy alerts that we need to constantly close. If you can improve the traditional detection rules to reflect current detection rules, it would make it significantly easier for us to manage, as we constantly need to check legacy rules to update or possibly turn them off. Updating the legacy rules should be a priority.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Firefly has a positive impact on my organization by improving cloud governance, infrastructure consistency, and engineering productivity."
"Firefly saves one employee, it saves 5 million annually, and we are currently improving 40% of our go-to-market time while reducing cost by 30% and increasing revenue by approximately 20%."
"Firefly has a positive impact on my organization by improving cloud governance, infrastructure consistency, and engineering productivity."
"Firefly has impacted my work positively by making it more creative and productive."
"ICSE is cheaper compared to other tools and has a pleasant user experience with good support."
"The tool provides centralized visibility through dashboards and alerts, allowing customers to receive reports on cloud vulnerabilities and security posture. Rapid7 InsightCloudSec provides customers with a robust understanding of cloud security."
"I can confirm money and time savings with Rapid7 InsightCloudSec, as we can scan the entire IP range simultaneously instead of manually checking each asset for vulnerabilities, reducing the need for technicians to move around the organization and thus saving significant time."
"Rapid7 InsightCloudSec has helped us save thirty percent time in our log retrievals, and it completely changed log searching, making it really fast when we search for logs, with no prior knowledge required."
"After implementing Rapid7 InsightCloudSec, we increased our CIS benchmark score from 48 to around 88 after addressing missing patches on some VM instances, indicating a significant positive impact."
"I find the security frameworks and security tools valuable. I think they're good in the infrastructure of the code security. They are also good at threat protection."
"Agentless scanning is a possible use with Rapid7 InsightCloudSec."
"The tool's most valuable feature is workload protection for Kubernetes and container security. It has agents that identify bugs or lack of security on runtime containers."
 

Cons

"If I talk about the cost, the cost is a little high."
"Some of the areas Firefly can improve are a simpler onboarding process for organizations with large and multi-cloud environments, more customization for generated Terraform code to better match existing coding standards and module structures, and more native integrations with DevOps and ITSM tools."
"Some of the areas Firefly can improve are a simpler onboarding process for organizations with large and multi-cloud environments, more customization for generated Terraform code to better match existing coding standards and module structures, and more native integrations with DevOps and ITSM tools."
"I feel that Firefly can be improved by getting more models to generate high-end videos."
"There are a lot of other solutions in the market, not only providing the features of a CSPM, but also CNAPP."
"The login piece needs improvement."
"The platform could be improved with more customizable dashboards and reporting."
"Technical support could be better. It could also be easier, more user-friendly, and intuitive. The API keys aren't easy to understand, and the cloud layouts aren't intuitive and user-friendly. We should be able to integrate IM governance and APIs into non-compliant workloads like legacy solutions."
"Some cases in Rapid7 InsightCloudSec indicate that the log is not enough, as they mostly just generate alerts, and the synchronization between data connectors is often problematic, particularly in terms of not being in sync always, especially between the AD and Rapid7 alerts, which generates numerous false positives."
"For a first-time user who starts using Rapid7 InsightCloudSec, it is somewhat complicated to navigate through the UI and search for logs or vulnerabilities, so this is one aspect that could be improved."
"I would say that because Rapid7 InsightCloudSec does not have automatic patching capabilities, it provides recommendations, but it does not execute anything from within Rapid7 InsightCloudSec."
"A couple of modules are missing when compared to other providers, specifically related to some IAM, and the login piece needs improvement."
 

Pricing and Cost Advice

Information not available
"Companies generally buy this tool because the pricing is not that high."
"We're doing an annual subscription. There are additional expenses, but not within the confines of this platform."
report
Use our free recommendation engine to learn which Cloud Management solutions are best for your needs.
909,725 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
No data available
Financial Services Firm
9%
Comms Service Provider
9%
Manufacturing Company
9%
Outsourcing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business3
Midsize Enterprise1
Large Enterprise4
By reviewers
Company SizeCount
Small Business7
Midsize Enterprise4
Large Enterprise8
 

Questions from the Community

What needs improvement with Firefly?
Some of the areas Firefly can improve are a simpler onboarding process for organizations with large and multi-cloud environments, more customization for generated Terraform code to better match exi...
What is your primary use case for Firefly?
My main use case for Firefly is cloud infrastructure management and Infrastructure as a Code governance. Specifically, I use it to discover and inventory cloud resources, detect configuration drift...
What advice do you have for others considering Firefly?
My advice for others looking into using Firefly would be to start with a well-organized Infrastructure as a Code strategy. Firefly delivers the most value when Terraform or another IaC tool is alre...
What is your experience regarding pricing and costs for Rapid7 InsightCloudSec?
The pricing, setup cost, and licensing for Rapid7 InsightCloudSec are reasonable, and since our organization is growing, I have observed that the more numbers you have, the less costly the product ...
What needs improvement with Rapid7 InsightCloudSec?
I would say that because Rapid7 InsightCloudSec does not have automatic patching capabilities, it provides recommendations, but it does not execute anything from within Rapid7 InsightCloudSec. It h...
What is your primary use case for Rapid7 InsightCloudSec?
In my role, my main use case for Rapid7 InsightCloudSec is for vulnerability management, where I scan my machines to see zero-day vulnerabilities and receive remediation tactics recommended by Rapi...
 

Also Known As

No data available
DivvyCloud
 

Overview

 

Sample Customers

Information Not Available
Fannie Mae, 3M, PizzaHut, Spotify, Autodesk, Discovery
Find out what your peers are saying about Firefly vs. Rapid7 InsightCloudSec and other solutions. Updated: August 2026.
909,725 professionals have used our research since 2012.