Try our new research platform with insights from 80,000+ expert users

Rapid7 InsightIDR vs Sophos UTM comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Rapid7 InsightIDR
Average Rating
8.4
Reviews Sentiment
7.4
Number of Reviews
32
Ranking in other categories
Security Information and Event Management (SIEM) (13th), User Entity Behavior Analytics (UEBA) (3rd), Endpoint Detection and Response (EDR) (24th), Threat Deception Platforms (5th), Extended Detection and Response (XDR) (15th)
Sophos UTM
Average Rating
8.4
Reviews Sentiment
7.2
Number of Reviews
113
Ranking in other categories
Unified Threat Management (UTM) (4th)
 

Mindshare comparison

While both are Network Security Systems solutions, they serve different purposes. Rapid7 InsightIDR is designed for Security Information and Event Management (SIEM) and holds a mindshare of 2.5%, down 2.7% compared to last year.
Sophos UTM, on the other hand, focuses on Unified Threat Management (UTM), holds 14.5% mindshare, up 13.6% since last year.
Security Information and Event Management (SIEM)
Unified Threat Management (UTM)
 

Featured Reviews

Asim Naeem - PeerSpot reviewer
Providing comprehensive insight into alerts while working towards AI enhancement
I definitely recommend Rapid7 InsightIDR. It is becoming better, with improvements being continuously made to the product. Right now, I do not have any advice about Rapid7 for other users because every organization or user has different criteria or multiple use cases, so I refrain from commenting on that. I rate the overall solution seven out of ten.
Samaila Yusuf - PeerSpot reviewer
Network protection strengthens through effective threat management features and secure access control
The zero-day protection and firewall rules are some of the most effective features for threat management. I can set the rules and features, and also use IPsec to connect all my on-premises servers and link them to Sophos UTM so that they are protected even when in the cloud. Additionally, I use it to control access into the building through a captive portal integrated across all the PCs we have, ensuring secure access only for authenticated users.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The ability to ingest Office 365 log files, then process them into events and display them on a map."
"Great coverage of all systems within our network from endpoint to firewall."
"InsightIDR has allowed us to find potential security issues that we did not know existed, and get remediation quickly."
"Rapid7 InsightIDR integrates well with other solutions. It's also easy to configure because Rapid7 InsightIDR has a lot of instructions posted on their website that customers can follow if they need to get the source log."
"Intelligent alerting to avoid the common problem of alert fatigue associated with traditional SIEMs."
"I definitely recommend Rapid7 InsightIDR."
"The solution is very scalable in terms of the licensing model."
"The product works well. Stability-wise, I rate the solution a ten out of ten."
"It is a very good product. The threat monitoring process is the most valuable feature."
"We find all of the features valuable because together they fit the needs of our customers."
"Sophos UTM provides security for our network here and access through a VPN connection for our remote users. It also offers the flexibility to create different tools for accessibility."
"What I like about the solution is the ease of use."
"The most valuable feature of Sophos UTM is the endpoint protection feature."
"It improved bandwidth utilization and provided link load balancing features for internet and intranet lease lines."
"It meets our compliance needs in an elastic computer environment."
"It works well without any maintenance. So far, it has worked pretty well regardless of the traffic."
 

Cons

"I would like the ability to adjust the threshold of certain existing alerts. Currently the only option is to change the notifications or create my own alert."
"The APIs can be further improved in Rapid7."
"InsightIDR is only available in a cloud version. Some of our customers prefer an on-prem solution because they want to manage the security within their environment."
"The ability to tune the collector for custom logs would greatly help."
"It takes time for the product's support team to resolve issues, making it an area of concern where improvements are required."
"Tenable Nessus is easier to deal with. It's more efficient and accurate. InsightIDR is heavier than Tenable in terms of performance and scanning. Rapid7 would be much easier to use if it had a network connector like Tenable. Tenable's connector allows continuous monitoring over the B caps."
"Rapid7 InsightIDR is not intuitive to search for logs. It should be more user-friendly and improve the dashboards. We should be able to use ready-made templates instead of having to build one."
"Sometimes, it is hard to get the right queries to use. Currently, the tool lacks a pre-made set of queries."
"VPN needs IKEv2, but it’s in the roadmap. Also, all new, cool features will only come to the new Sophos XG Firewall."
"We need to speed up the support."
"There can be a delay when it comes to reaching out to technical support."
"The technical support only communicates via email. I would prefer to communicate directly with someone."
"With Sophos UTM, there is a general rule in the firewall when the country blocking can block some countries from accessing your data. In the current version, you still need to add it by putting in the IP range. This feature would be helpful for administrators and it gives them the advantage to block stuff in less time."
"The reporting system needs to allow for customizations because many reports do not include details that we expect."
"The five-factor authentication needs improvement."
"It is a pretty straightforward setup, but it should be some sort of documentation that takes you step-by-step to help set it up for your VPC."
 

Pricing and Cost Advice

"The pricing is good, and it is not very expensive."
"Rapid7 InsightIDR's pricing is reasonable but we have challenges with the Minimum Order Quantity. It is not reasonable for customers who have less than one hundred devices. If they can reduce Minimum Order Quantity, it is good. You have to pay around 5000-6000 dollars per year for the product. The pricing includes maintenance and support costs."
"It is a reasonably priced solution."
"It is more reasonably priced than other vendors."
"The pricing and licensing are competitive."
"The solution has a mid-range price point in the market"
"​I am sure that there are cheaper products out there, but none that meet so many of our needs whilst maintaining stability and usability.​"
"Rapid7 InsightIDR is priced very well and is cost-effective."
"This solution is less expensive than FortiGate."
"The price of the solution is high. The price from USD to my currency is expensive."
"Our licensing fees are paid on a monthly basis."
"Pricing for Sophos UTM is OK. Here in Egypt, many companies use the solution because of its price and features. My company pays the Sophos UTM license fee yearly."
"Sophos UTM has very reasonable pricing."
"The price is comparable to other products of this kind."
"Compared to the current market offerings, like FortiGate or SonicWall, Sophos offers its solution at a good price."
"Pricing for the upgrade was very competitive as Sophos wanted to retain existing customers."
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
850,760 professionals have used our research since 2012.
 

Comparison Review

it_user216600 - PeerSpot reviewer
Jan 3, 2016
Sophos UTM vs. Fortinet FortiGate
I have used both Sophos and Fortinet products in production and I have found the Sophos UTM appliances (hardware and virtual) to be a better fit most of the time -- with a few caveats which I will touch on below. In both instances, the transition from TMG will be mostly straightforward. The main…
 

Top Industries

By visitors reading reviews
Computer Software Company
16%
Financial Services Firm
9%
Manufacturing Company
7%
Government
7%
Computer Software Company
18%
Comms Service Provider
8%
Government
7%
Educational Organization
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What do you like most about Rapid7 InsightIDR?
During simulations or demonstrations, the tool generates alerts, providing details such as the specific application, its origin, and potential threats. For instance, it can identify if an applicati...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite good. The most valuable features for me are their web and email filtering. I wou...
What do you like most about Sophos UTM?
The most valuable feature of Sophos UTM is the endpoint protection feature.
What is your experience regarding pricing and costs for Sophos UTM?
The value between what I receive and what I pay is the best in the industry.
 

Also Known As

InsightIDR
Astaro
 

Overview

 

Sample Customers

Liberty Wines, Pioneer Telephone, Visier
One Housing Group
Find out what your peers are saying about Splunk, Wazuh, Microsoft and others in Security Information and Event Management (SIEM). Updated: May 2025.
850,760 professionals have used our research since 2012.