No more typing reviews! Try our Samantha, our new voice AI agent.

Rapid7 InsightIDR vs Sophos UTM comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Rapid7 InsightIDR
Average Rating
8.4
Reviews Sentiment
7.0
Number of Reviews
32
Ranking in other categories
Security Information and Event Management (SIEM) (21st), User Entity Behavior Analytics (UEBA) (10th), Endpoint Detection and Response (EDR) (34th), Threat Deception Platforms (8th), Extended Detection and Response (XDR) (20th)
Sophos UTM
Average Rating
8.6
Reviews Sentiment
6.7
Number of Reviews
119
Ranking in other categories
Unified Threat Management (UTM) (5th)
 

Mindshare comparison

While both are Network Security Systems solutions, they serve different purposes. Rapid7 InsightIDR is designed for Security Information and Event Management (SIEM) and holds a mindshare of 2.1%, down 2.6% compared to last year.
Sophos UTM, on the other hand, focuses on Unified Threat Management (UTM), holds 8.2% mindshare, up 6.6% since last year.
Security Information and Event Management (SIEM) Mindshare Distribution
ProductMindshare (%)
Rapid7 InsightIDR2.1%
Splunk Enterprise Security7.2%
Wazuh5.8%
Other84.9%
Security Information and Event Management (SIEM)
Unified Threat Management (UTM) Mindshare Distribution
ProductMindshare (%)
Sophos UTM8.2%
Fortinet FortiGate30.5%
WatchGuard Firebox9.2%
Other52.099999999999994%
Unified Threat Management (UTM)
 

Featured Reviews

SohailHyder - PeerSpot reviewer
Head Of Cyber Security at Super Secure
Has supported compliance needs for mid-sized organizations but lacks customization and advanced integration
If we pitch Rapid7 InsightIDR against solutions such as SIEMs from Splunk or LogRhythm, it is not as customizable as a SIEM solution is. This is where it can improve if we keep in front the feature sets of a complete SIEM solution. Most common in the market is QRadar, but it is depleting now. It has been taken over by some other products such as Splunk and LogRhythm. If we compare these things with Rapid7 InsightIDR, then there are definitely some gaps that need to be filled. Data retention is also one concern because Rapid7 InsightIDR is cloud-based and operates on a subscription model. Whatever data you want to retain, it has to be paid for separately or it has a cost. Other solutions that are on-premises can have their own infrastructure or they provide some data retention for a month or in some capacity-wise, they provide that solution to them which makes them more attractive.
Bashir Bashir - PeerSpot reviewer
IT Manager at Vegol
Firewall management has become simpler and now provides real-time visibility and bandwidth control
The features I have found most valuable in Sophos UTM are that it is much easier to configure, I appreciate the reporting side of it, and the rules are very straightforward to work with. Sophos UTM's real-time insights into network health help my organization because I get real-time reports on what is happening on my network, what is trying to access me, the destination, and all that. I can then be reactive or proactive, and for zero-day, I think it is beneficial because it can learn what my network does. If anything goes outside what it expects, it sends a report on Sophos Central, so I find zero-day makes my work a bit easier. The use of Sophos UTM's intuitive management console has impacted my security policy enforcement in that it is much easier to configure; I configure with information rather than with presumptions.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"I am able to run automated actions based on the output of reports, leaving me extra time to focus on more pressing matters."
"The web interface is great — very useful and user-friendly."
"The product works well. Stability-wise, I rate the solution a ten out of ten."
"The technical support is a solid 10 out of 10 as they take the time to answer any questions or problems which may arise in a reasonable time frame."
"Integration with threat modeling from the Metasploit and InsightIDR repositories."
"It improved my organization by building a security alerting program."
"InsightIDR helps us investigate an environment to discover information about incidents."
"The solution is easy to use, and the interface is intuitive."
"The most valuable features of Sophos UTM are the ease of use, it is very user-friendly."
"It is easy to manage."
"It has helped by identifying threats within the company. If there are computers or servers that are compromised, then we are able to identify them right away in the system."
"The solution's sandboxing, application center, and database engine are good."
"The intrusion prevention is great, and I like dual virus scanning on the network layer because we scan it through Avira and Sophos. Web filtering is also a fantastic option for clients who want to really lock down internet access."
"With over 150 firewalls in our portal, management and monitoring have never been easier."
"Other than that, Sophos offers a full replacement for TMG on UTM9."
"Brings greater visibility into the network traffic coming inside and passing away from the company."
 

Cons

"Cloud risk assessment is one area where I think they need a lot of improvement."
"Rapid7's customer support is awful. They didn't respond at all."
"Inability to get access to compliance reports within the solution."
"The reporting is the weakest aspect. There needs to be multi-level grouping for events (for example, group by user and destination)."
"The reporting is the weakest aspect. There needs to be multi-level grouping for events (for example, group by user and destination). Right now, we can do a group by user and a separate table or group by destination. But I'd be more interested in where a person was logging into instead of who was logging in or where he was logging in."
"The dashboard is an area that could be simplified."
"I would like to see more development in InsightIDR towards building their SIEM solution and converting it to XDR."
"The searching feature in Rapid7 InsightIDR needs to evolve"
"VPN needs IKEv2, but it’s in the roadmap. All other new, cool features will only come to the new Sophos XG Firewall."
"Anti-phishing functionality should be improved."
"Setup: Getting an exchange server to work behind Sophos is incredibly difficult with rules invoked that are simple numbers (e.g. 9054)."
"The product could be simplified and made more self-explanatory."
"They should have more powerful appliances."
"Enhancing the user interface to achieve the same level of flexibility as the older UTM interface could improve the product."
"They could definitely improve on the support, especially in other countries."
"Needs to improve the certificate management (ex. Let's Encrypt support)."
 

Pricing and Cost Advice

"​I am sure that there are cheaper products out there, but none that meet so many of our needs whilst maintaining stability and usability.​"
"Licensing is by endpoint and amount of retention time (at least ours is). Default retention was one year, but we are able to push the retention further if needed. There's also a provide-your-own-S3 option for longer retention if you don't want to pay for the additional retention years in your Rapid7 agreement."
"The pricing of the solution depends on the user. But there is a yearly licensing cost."
"The pricing is good, and it is not very expensive."
"Licensing is straightforward. If, for some reason, you don’t meet the minimum licensing requirements, there is a third-party managed service that can help."
"The pricing and licensing are competitive."
"It is a reasonably priced solution."
"It is more reasonably priced than other vendors."
"The pricing for Sophos UTM is quite acceptable compared to other UTM vendors."
"It is necessary to pay for a licence to use the solution, but it is not very expensive."
"We originally purchased the solution through the AWS Marketplace. I started my proof of concept doing pay-as-you-go, then moved to a VAR for a 'Bring Your Own Licence' (BYOL) licensing model. The BYOL license still requires you to accept the terms of the AWS Marketplace to deploy."
"Our licensing fees are paid on a monthly basis."
"Pricing for the upgrade was very competitive as Sophos wanted to retain existing customers."
"It will cost approximately $67 US per device. We have 300 devices in our organization."
"The solution's pricing is based on a licensing model and is competitive."
"There is a license for the device and for the software. We pay annually for the solution and the cost is competitive."
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
885,667 professionals have used our research since 2012.
 

Comparison Review

it_user216600 - PeerSpot reviewer
Senior Technical Consultant with 51-200 employees
Jan 3, 2016
Sophos UTM vs. Fortinet FortiGate
I have used both Sophos and Fortinet products in production and I have found the Sophos UTM appliances (hardware and virtual) to be a better fit most of the time -- with a few caveats which I will touch on below. In both instances, the transition from TMG will be mostly straightforward. The main…
 

Top Industries

By visitors reading reviews
Computer Software Company
10%
Financial Services Firm
9%
Manufacturing Company
8%
Government
6%
Comms Service Provider
11%
Construction Company
8%
Manufacturing Company
8%
Computer Software Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business20
Midsize Enterprise5
Large Enterprise6
By reviewers
Company SizeCount
Small Business75
Midsize Enterprise28
Large Enterprise27
 

Questions from the Community

What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What needs improvement with Rapid7 InsightIDR?
If we pitch Rapid7 InsightIDR against solutions such as SIEMs from Splunk or LogRhythm, it is not as customizable as a SIEM solution is. This is where it can improve if we keep in front the feature...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite good. The most valuable features for me are their web and email filtering. I wou...
What do you like most about Sophos UTM?
The most valuable feature of Sophos UTM is the endpoint protection feature.
What is your experience regarding pricing and costs for Sophos UTM?
I have no declaration regarding my experience with pricing, setup cost, and licensing for Sophos UTM.
 

Also Known As

InsightIDR
Astaro
 

Overview

 

Sample Customers

Liberty Wines, Pioneer Telephone, Visier
One Housing Group
Find out what your peers are saying about Splunk, Wazuh, IBM and others in Security Information and Event Management (SIEM). Updated: March 2026.
885,667 professionals have used our research since 2012.