Try our new research platform with insights from 80,000+ expert users

NAVEX One vs Rapid7 InsightVM comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

NAVEX One
Average Rating
7.0
Reviews Sentiment
7.3
Number of Reviews
1
Ranking in other categories
GRC (23rd), IT Governance (7th), IT Vendor Risk Management (14th)
Rapid7 InsightVM
Average Rating
8.0
Reviews Sentiment
6.9
Number of Reviews
65
Ranking in other categories
Risk-Based Vulnerability Management (4th)
 

Mindshare comparison

While both are Security Software solutions, they serve different purposes. NAVEX One is designed for GRC and holds a mindshare of 1.4%, up 1.2% compared to last year.
Rapid7 InsightVM, on the other hand, focuses on Risk-Based Vulnerability Management, holds 11.0% mindshare, down 13.2% since last year.
GRC Market Share Distribution
ProductMarket Share (%)
NAVEX One1.4%
RSA Archer5.8%
AuditBoard3.8%
Other89.0%
GRC
Risk-Based Vulnerability Management Market Share Distribution
ProductMarket Share (%)
Rapid7 InsightVM11.0%
Qualys VMDR12.7%
Tenable Security Center9.0%
Other67.3%
Risk-Based Vulnerability Management
 

Featured Reviews

EV
Information Security Business Enablement Mgr. at a insurance company with 5,001-10,000 employees
Useful for risk assessment and has customization capability
The tool helps us with security incidents, policies, business continuity, disaster recovery, and internal audits. The feature I like the most is its customization capability. It acts like a blank canvas where you can construct forms and workflows according to your needs. You can configure and customize a lot yourself, whether starting from scratch or using some out-of-the-box options. The solution has impacted our operations by helping us manage and prioritize environmental risks. It also assists in establishing ownership of risks and enables us to mitigate or mediate existing risks. Additionally, it facilitates tracking risks throughout their entire lifecycle.
FL
Senior Manager - Pre-Sales at Trillium Information Security Systems
Offers robust compliance features but needs improved automation in remediation
The automation capability remediation needs improvement. The current process requires manually telling IT teams to remediate vulnerabilities, and then they update the status of these vulnerabilities in the platform. This basic feature that Rapid7 calls an automated remediation process is actually manual. We can update the status of vulnerabilities in the Rapid7 InsightVM platform and collectively see how many vulnerabilities we have identified and how many are remediated by our IT team. More automation in the remediation feature is a basic demand from many customers. The remediation part and vulnerability identification of network devices or rigid devices are not currently supported by Rapid7 InsightVM. More integration and automation are the two areas Rapid7 needs to improve in their product.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The tool helps us with security incidents, policies, business continuity, disaster recovery, and internal audits. The feature I like the most is its customization capability. It acts like a blank canvas where you can construct forms and workflows according to your needs. You can configure and customize a lot yourself, whether starting from scratch or using some out-of-the-box options."
"The feature that I have found most valuable is its dashboards."
"It's a relevant management tool."
"The cost is what is most valuable. Compared to the other products on the market, the cost is more palatable."
"The most valuable feature for us is the different types of reporting it provides."
"Rapid7 InsightVM has given us a practical view of the vulnerabilities present in our organization."
"You can bring in and get online to do reports fairly quickly,"
"The solution is automatically scheduled so it runs by itself."
"InsightVM has a very organized GUI with ease of use."
 

Cons

"We think there's room for improvement, especially with customizing NAVEX One. Their development on the roadmap can be slow."
"There should be containerization within the VM."
"They should integrate the solution with multiple products."
"There needs to be much clearer instructions surrounding scanning."
"The solution could improve by being more secure."
"There is a significant learning curve, that non-technical individuals, especially those not specialized in computer science or the information security industry, might face."
"There are end-user needs and expectations that are being overlooked in the development that could be addressed by appointing a customer advisory board."
"There are certain limitations because of the product being used on a hybrid model. Rapid7 InsightVM doesn't offer a solution purely in the cloud."
"The team needs to improve the speed and focus on the new bandwidth feed. Sometimes, it takes a while to scan, especially with new updates."
 

Pricing and Cost Advice

"NAVEX One's pricing comes in the middle range when compared to other products."
"In some cases, we procure the licenses. In some cases, the customers directly buy the license from Rapid7."
"The price of the solution is less than the competitors."
"It is pretty expensive. It depends on what you consider pricey, however, if you only look at vulnerability management solutions, such as within VM or VMDR, there are, I suppose the prices are almost the same. But I believe you will discover that for yourself."
"I do not have experience with the pricing of the solution."
"Comparing the price with the value that we receive, I am not happy with it."
"The solution is a bit more reasonably priced than other products."
"Pricing is reasonable because we pay according to asset usage. We can define our assets and sites according to our preference."
"The license is IP based. How many IPs you are using to scan is the amount of the license you have to buy. The number of users doesn't matter; many users can use it or only person. It depends on the culture of the organization."
report
Use our free recommendation engine to learn which GRC solutions are best for your needs.
879,371 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
18%
Retailer
11%
Energy/Utilities Company
8%
Legal Firm
7%
Financial Services Firm
12%
Manufacturing Company
11%
Computer Software Company
10%
Government
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
By reviewers
Company SizeCount
Small Business29
Midsize Enterprise13
Large Enterprise24
 

Questions from the Community

What is your experience regarding pricing and costs for NAVEX One?
NAVEX One's pricing comes in the middle range when compared to other products.
What needs improvement with NAVEX One?
We think there's room for improvement, especially with customizing NAVEX One. Their development on the roadmap can be slow.
What is your primary use case for NAVEX One?
We use the solution to conduct risk assessments on our environment.
How would you choose between Rapid7 InsightVM and Tenable Nessus?
You have full visibility across cloud, network, virtual, and containerized infrastructures with Rapid7 Insight VM. You can easily prioritize vulnerabilities using attacker analytics. Overall, Rapid...
What do you like most about Rapid7 InsightVM?
The product's initial setup phase was very easy.
What is your experience regarding pricing and costs for Rapid7 InsightVM?
The customers are mostly SMBs, though some enterprise organizations have also deployed the solution. This is neither a cheap nor the most expensive solution. Qualys and some other vendors are more ...
 

Also Known As

Lockpath Keylight
InsightVM, NeXpose
 

Overview

 

Sample Customers

Claims Recovery Financial Services (CRFS), Surescript, The University of Chicago
ACS, Acosta, AllianceData, amazon.com, biogen idec, CBRE, CATERPILLAR, Deloitte, COACH, GameStop, IBM
Find out what your peers are saying about RSA, OneTrust, Diligent and others in GRC. Updated: November 2025.
879,371 professionals have used our research since 2012.