Try our new research platform with insights from 80,000+ expert users

Pentera vs Rapid7 InsightVM comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
5.2
Pentera automates security tests, proving valuable for retests, but rising licensing costs pose ROI challenges for some users.
Sentiment score
6.0
Rapid7 InsightVM offers financial benefits, efficient vulnerability management, and supports risk control with its flexible subscription model.
Some customers consider the ROI favorable, but facing difficulties now due to changes in the licensing model, which has made it more expensive compared to last year.
Director at Infosonik Systems Ltd
 

Customer Service

Sentiment score
6.0
Pentera's support team is reliable and responsive, but documentation needs updating; users rate support highly despite some inconsistency.
Sentiment score
6.7
Rapid7 InsightVM's support is rated favorably for helpfulness, despite occasional delays due to regional issues and slow communication.
Support is not available promptly, especially when issues are escalated to another region.
Head of Cyber Security at Super Secure
Sometimes support requests coincide with holidays in their support region, causing slight delays.
Professional services team lead at a tech services company with 1,001-5,000 employees
I cannot comment specifically regarding the support part because I have never needed Rapid7 support for the InsightVM solution as it is very stable.
Senior Manager - Pre-Sales at Trillium Information Security Systems
 

Scalability Issues

Sentiment score
7.0
Pentera is highly scalable with adaptable equipment requirements, earning strong satisfaction ratings across various enterprise environments.
Sentiment score
7.5
Rapid7 InsightVM is highly scalable and adaptable, ideal for various environments, despite minor scan engine integration issues.
Scalability in the Rapid7 InsightVM solution is straightforward.
Senior Manager - Pre-Sales at Trillium Information Security Systems
Rapid7 InsightVM is recommended for large-scale companies with more than 30,000 users.
Enterprise Security Architect at a energy/utilities company with 10,001+ employees
Integration with other tools has been fine, with no major issues reported.
Head of Cyber Security at Super Secure
 

Stability Issues

Sentiment score
7.3
Pentera is praised for high stability, with most users rating it highly despite minor initial setup concerns.
Sentiment score
8.1
Rapid7 InsightVM is reliable and stable, praised for updates, with most issues stemming from user configuration, not the software.
We have not faced any issues with stability, and I would rate it a nine out of ten.
Professional services team lead at a tech services company with 1,001-5,000 employees
This is a very stable solution.
Senior Manager - Pre-Sales at Trillium Information Security Systems
There have been some challenges, especially with support response times, which affect stability.
Head of Cyber Security at Super Secure
 

Room For Improvement

Pentera struggles with cost, licensing flexibility and needs better virtualization, dashboards, hardware support, and detailed credential information.
Rapid7 InsightVM needs improvements in usability, integration, pricing, support, documentation, reporting, and lacks patch management functionality.
When the IP is imported into a system, we cannot withdraw or revoke the license.
Pre-sale manager at Nam Truong Son
It is best on the OS to identify and discover the OS-related vulnerabilities, more of open ports and the discovery of vulnerable ports or services.
Manager at a financial services firm with 5,001-10,000 employees
The major improvement needed is prompt support.
Head of Cyber Security at Super Secure
The current process requires manually telling IT teams to remediate vulnerabilities, and then they update the status of these vulnerabilities in the platform.
Senior Manager - Pre-Sales at Trillium Information Security Systems
 

Setup Cost

Pentera's pricing receives mixed reviews, though many appreciate its value in effectively assessing ransomware protection.
Rapid7 InsightVM's IP-based pricing is seen as costly, but offers flexibility and support; customer satisfaction is mixed.
Pricing is reasonable and competitive compared to other solutions in the market.
Head of Cyber Security at Super Secure
Rapid7 InsightVM is expensive, possibly one of the highest in pricing among similar products.
0 at a tech vendor with 5,001-10,000 employees
I would rate the pricing for Rapid7 InsightVM as eight out of ten.
Enterprise Security Architect at a energy/utilities company with 10,001+ employees
 

Valuable Features

Pentera offers automated vulnerability assessments with valued features like attack surface mapping, AI reporting, and quick, effective processes.
Rapid7 InsightVM provides robust vulnerability management with customizable dashboards, tool integrations, and flexible risk assessments for specific infrastructure needs.
We can automate the Pentera processes by automatically creating scenarios to validate the system.
Pre-sale manager at Nam Truong Son
The dashboard is excellent as it helps in visualizing our vulnerability management data.
Manager at a financial services firm with 5,001-10,000 employees
It's based on the CVSS risk scoring system, which is well-recognized and effective.
Professional services team lead at a tech services company with 1,001-5,000 employees
We have integrated our SIEM solutions and antivirus with each other through Rapid7.
0 at a tech vendor with 5,001-10,000 employees
 

Categories and Ranking

Pentera
Average Rating
8.0
Reviews Sentiment
6.7
Number of Reviews
9
Ranking in other categories
Penetration Testing Services (4th), Breach and Attack Simulation (BAS) (3rd), Continuous Threat Exposure Management (CTEM) (1st)
Rapid7 InsightVM
Average Rating
8.0
Reviews Sentiment
6.9
Number of Reviews
65
Ranking in other categories
Risk-Based Vulnerability Management (4th)
 

Mindshare comparison

While both are Security Software solutions, they serve different purposes. Pentera is designed for Breach and Attack Simulation (BAS) and holds a mindshare of 26.3%, down 30.3% compared to last year.
Rapid7 InsightVM, on the other hand, focuses on Risk-Based Vulnerability Management, holds 11.7% mindshare, down 13.3% since last year.
Breach and Attack Simulation (BAS) Market Share Distribution
ProductMarket Share (%)
Pentera26.3%
Cymulate18.3%
Picus Security16.8%
Other38.599999999999994%
Breach and Attack Simulation (BAS)
Risk-Based Vulnerability Management Market Share Distribution
ProductMarket Share (%)
Rapid7 InsightVM11.7%
Qualys VMDR13.7%
Tenable Security Center9.1%
Other65.5%
Risk-Based Vulnerability Management
 

Featured Reviews

Sabbir Ahmed - PeerSpot reviewer
Director at Infosonik Systems Ltd
Comprehensive attack surface coverage and real-world threat emulation strengthen security while licensing models need improvement
Comprehensive Attack Surface includes several features. Omni Attack Surface discovers, assesses, and exploits vulnerabilities across both internal networks and external assets, including cloud environments from a single platform. External Attack Surface Management (EASM) and Internal Network Validation test internal security controls and identify weaknesses within the internal network. Automated Penetration Testing features are provided through the Pentera Surface module. Surface provides automated validation and penetration testing features with a proactive, continuous, and highly realistic approach to cybersecurity validation, helping organizations understand and reduce their true cyber exposure. They have AI-based reporting that leverages AI to identify patterns of exploitability over time, aggregate results across sites, and highlight recurring weaknesses. They offer two types of reports: an elaborate technical report for CTOs and an Executive Summary for management. When customers see the reports after completing the POC, they are impressed by how detailed the technical report is, while management can understand what actions need to be taken to protect their network and infrastructure. Recent Gartner reports indicate that traditional VAPT companies perform vulnerability testing at specific times, which creates security gaps. Pentera provides continuous validation, running 24/7 in the infrastructure. This means when any vulnerability appears due to firmware upgrades, OS updates, or software changes, it can be automatically identified in real-time.
FL
Senior Manager - Pre-Sales at Trillium Information Security Systems
Offers robust compliance features but needs improved automation in remediation
The automation capability remediation needs improvement. The current process requires manually telling IT teams to remediate vulnerabilities, and then they update the status of these vulnerabilities in the platform. This basic feature that Rapid7 calls an automated remediation process is actually manual. We can update the status of vulnerabilities in the Rapid7 InsightVM platform and collectively see how many vulnerabilities we have identified and how many are remediated by our IT team. More automation in the remediation feature is a basic demand from many customers. The remediation part and vulnerability identification of network devices or rigid devices are not currently supported by Rapid7 InsightVM. More integration and automation are the two areas Rapid7 needs to improve in their product.
report
Use our free recommendation engine to learn which Breach and Attack Simulation (BAS) solutions are best for your needs.
879,310 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
13%
Computer Software Company
12%
Manufacturing Company
11%
Educational Organization
6%
Financial Services Firm
12%
Manufacturing Company
11%
Computer Software Company
10%
Government
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business5
Midsize Enterprise1
Large Enterprise4
By reviewers
Company SizeCount
Small Business29
Midsize Enterprise13
Large Enterprise24
 

Questions from the Community

What do you like most about Pentera?
What I like the most about Pentera is its solution-oriented approach.
What needs improvement with Pentera?
The licensing model has changed from earlier versions. Previously, there was a 500 IP cap, and customers needed to buy a minimum of 500 IP and consider 500 domains. In Bangladesh, many large organi...
What is your primary use case for Pentera?
Common use cases include several features. The POC is completed before any customer goes for procurement. Once the POC is done, customers appreciate features such as comprehensive attack surface co...
How would you choose between Rapid7 InsightVM and Tenable Nessus?
You have full visibility across cloud, network, virtual, and containerized infrastructures with Rapid7 Insight VM. You can easily prioritize vulnerabilities using attacker analytics. Overall, Rapid...
What do you like most about Rapid7 InsightVM?
The product's initial setup phase was very easy.
What is your experience regarding pricing and costs for Rapid7 InsightVM?
The customers are mostly SMBs, though some enterprise organizations have also deployed the solution. This is neither a cheap nor the most expensive solution. Qualys and some other vendors are more ...
 

Also Known As

No data available
InsightVM, NeXpose
 

Overview

 

Sample Customers

Blackstone Group Caterpillar Apria Healthcare Taylor Vinters Sandler Capital Management Drawbridge BNP Paribas British Red Cross
ACS, Acosta, AllianceData, amazon.com, biogen idec, CBRE, CATERPILLAR, Deloitte, COACH, GameStop, IBM
Find out what your peers are saying about Cymulate, Horizon3.ai, Pentera and others in Breach and Attack Simulation (BAS). Updated: November 2025.
879,310 professionals have used our research since 2012.