Rapid7 InsightVM vs Tenable Nessus comparison

Cancel
You must select at least 2 products to compare!
Wiz Logo
Read 1 Wiz review
7,061 views|5,622 comparisons
Rapid7 Logo
15,852 views|11,473 comparisons
Tenable Network Security Logo
24,113 views|18,902 comparisons
Comparison Buyer's Guide
Executive Summary
Updated on Mar 16, 2022

We performed a comparison between Rapid7 InsightVM and Tenable Nessus based on our users’ reviews in four categories. After reading all of the collected data, you can find our conclusion below.

  • Ease of Deployment: Users said that both solutions were easy and straightforward to set up.

  • Features: Users of Rapid7 InsightVM noted that it was easy to use and rarely gave false positives. Reviewers of Rapid7 gave mixed reviews regarding its reporting and integrations. Some were pleased and others felt it was lacking in these areas. One reviewer noted that Rapid7 doesn’t do patching. Several Tenable Nessus users described it as the best vulnerability solution in the industry. They said it works well out of the box and does not need customization. Like Rapid7 InsightVM, Tenable Nessus is easy to use and received mixed reviews on its reporting.

  • Pricing: Most reviewers rated both solutions as on the expensive side, although one user of Tenable Nessus noted that the price doesn’t matter because if he ended up with a ransomware attack, he’d be out of business.

  • Service and Support: Most reviewers of Rapid7 InsightVM were pleased with the service. Reviewers of Tenable Nessus gave its service mixed reviews.

Comparison Results: Both solutions were considered by our users as easy to deploy but on the expensive side. Rapid7 users were happier with the service and support, but PeerSpot users ranked Tenable Nessus as number one overall at the time this comparison was written.

To learn more, read our detailed Rapid7 InsightVM vs. Tenable Nessus Report (Updated: November 2022).
657,397 professionals have used our research since 2012.
Featured Review
Quotes From Members
We asked business professionals to review the solutions they use.
Here are some excerpts of what they said:
Pros
"Out of all the features, the one item that has been most valuable is the fact that Wiz puts into context all the pieces that create an issue, and applies a particular risk evaluation that helps us prioritize when we need to address a misconfiguration, vulnerability, or any issue that would put our environment into risk."

More Wiz Pros →

"It's a relevant management tool.""The performance is good.""The most valuable feature is the vulnerability scan.""This solution's most useful feature is that it is entirely a single-page application.""The cost is what is most valuable. Compared to the other products on the market, the cost is more palatable.""One of the most valuable features is it's graphical dashboard feature. It is quite easy to manage the widgets, and we can customize those according to our queries.""The solution scales well.""The most valuable features of Rapid7 InsightVM are the accurate level of scanning and the workflows are good."

More Rapid7 InsightVM Pros →

"A valuable feature of the solution is that it is easy to understand.""The most valuable feature of Tenable Nessus is the dashboard. They are convenient to use.""Tenable integrates well with other solutions such as SIEM and batch management.""Tenable Nessus is one of the best vulnerability assessment tools, that I know.""The solution is easy to understand for users because instructions are included on the platform.""The results are not that bad, but the key selling point is that it is an affordable tool set.""The solution is the most dynamic one I have seen thus far.""I have experience with it on my attack stations, and it's pretty good to optimize. Personally, I think Nessus is quite a good product."

More Tenable Nessus Pros →

Cons
"We wish there were a way, beyond providing visibility and automated remediation, to wait on a given remediation, due to a critical aspect, such as the cost associated with a particular upgrade... We would like to see preventive controls that can be applied through Wiz to protect against vulnerabilities that we're not going to be able to remediate immediately."

More Wiz Cons →

"Rapid7 InsightVM could be easier to use for those who are using it for the first time.""It is still not a fully cloud-based solution. It will be helpful for customers if it is a complete cloud solution. It is a hybrid solution at the moment.""All products have room for increased security and Rapid7 InsightVM is no exception.""Rapid7 could be easier to manage.""The integration with other solutions like JIRA could be better. Perhaps there could be some additional updates in the next phase that could integrate with it, so then you can proceed with the VT much easier.""InsightVM is getting a little stale and is in danger of falling behind its competitors.""We are a registered reseller and a trusted partner. However, for us to get any support from them I can't log a call directly with Rapid7 InsightVM. I have to work with the distributor to log the call for me.""I would say that it improved our visibility, but it left things open."

More Rapid7 InsightVM Cons →

"The report for counters is too simple and would be improved by a dashboard.""The reports are okay, but the interface is a bit difficult to navigate in some cases.""Scans aren't done properly and some devices aren't pinged.""Multiple user access would be an area for improvement from a user-access perspective. A role-based access control feature would be great because at present, there is a limitation with only one account. If that account gets compromised or gets locked, then we will encounter problems.""The inventory management function in this solution needs improvement.""Tenable Nessus could improve the reporting.""They could make their reporting a little better.""The price could be reduced."

More Tenable Nessus Cons →

Pricing and Cost Advice
  • "The pricing seems pretty simple. We don't have to do a lot of calculations to figure out what the components are. They do it by enabling specific features, either basics or advanced, which makes it easy to select."
  • More Wiz Pricing and Cost Advice →

  • "Its price is too high. My only concern or issue with Rapid7 is its pricing."
  • "Comparing the price with the value that we receive, I am not happy with it."
  • "The license is annual and this is the optimal approach when it comes to most software."
  • "In some cases, we procure the licenses. In some cases, the customers directly buy the license from Rapid7."
  • "Licensing fees are paid on a yearly basis."
  • "We have an annual license to use Rapid7 InsightVM and if we want to extend it, we will possibly choose more than one year."
  • "Pricing is reasonable because we pay according to asset usage. We can define our assets and sites according to our preference."
  • "InsightVM is an expensive product, especially compared to its competitors, at around a million NOK per year."
  • More Rapid7 InsightVM Pricing and Cost Advice →

  • "Nowadays, your vulnerability applications are going to be kind of pricey because lots of them, including Rapid7, are based upon a base price, but then they add in the nodes. That's where they get you. If you're a big network, obviously, you need to scan everything. Therefore, it's going to be costly. The risk and insurance money associated with having ransomware on my networks is going to cost me more money, time, and marketing than the price of the tool. That's why I'm speaking only as an information security officer to security operations. This is the tool that is there in my toolbox to say whether we vulnerable or not. At this point, I don't care about how much it costs my company to have it because if I wasn't able to report it and we got ransomware, then who cares? I'm probably going to be out of business because it happened. That's why I don't care about the price. I have it, and I could use it effectively and do my report. At the end of the day, even if we get ransomware, as long as I reported it, followed my protocol, and put in the change, irrespective of whether it was ignored or denied, I did my job."
  • "We pay approximately $2,500 on a yearly basis."
  • "We have a subscription, the licensing fees are paid yearly, and I am using the latest version."
  • "We incurred a single cost for a perpetual license, although I cannot comment on the price as this is above my management level."
  • "The price is reasonable."
  • "In general, it is extremely expensive."
  • "The price of the solution is reasonable."
  • "One problem with Tenable is its pricing policy. Optimal results can be achieved with Greenbone Solutions which has much more friendly pricing policies."
  • More Tenable Nessus Pricing and Cost Advice →

    report
    Use our free recommendation engine to learn which Vulnerability Management solutions are best for your needs.
    657,397 professionals have used our research since 2012.
    Answers from the Community
    Netanya Carmi
    Max Iversen - PeerSpot reviewerMax Iversen
    User

    InsightVM - better functions on granting users different access to different asset groups. 


    It fits better for our company and is slightly cheaper.

    Questions from the Community
    Top Answer:Wiz and Lacework sucks... Buy Orca. 
    Top Answer:You have full visibility across cloud, network, virtual, and containerized infrastructures with Rapid7 Insight VM. You… more »
    Top Answer:The cost is what is most valuable. Compared to the other products on the market, the cost is more palatable.
    Top Answer:The main purpose for using Rapid7 InsightVM is vulnerability management and visibility.
    Top Answer: Tenable Nessus is a vulnerability assessment solution that is both easy to deploy and easy to manage. The design of the… more »
    Top Answer:Another department handles the licensing. I can't speak to the exact costs. I do know that we pay a yearly licensing… more »
    Comparisons
    Also Known As
    InsightVM, NeXpose
    Learn More
    Overview

    Wiz is reinventing cloud security from the inside out.

    We’re on a mission to help organizations effectively reduce risks in their Cloud and Kubernetes environments. Purpose-built for the unique complexities of multi-environment, multi-workload, and multi-project cloud estates, Wiz automatically correlates the critical risk factors to deliver actionable insights that don't waste time.

    Wiz connects in minutes using a 100% API-based approach that scans both platform configurations and inside every workload. Our full security stack context surfaces the toxic combinations that show the attackers’ view to a breach. Security and development teams use Wiz workflows to proactively remove risks and prevent them from becoming breaches.

    Get a demo | Wiz

    Rapid7 InsightVM is a comprehensive vulnerability management platform that protects your systems from attackers and is easy to scale. The solution provides easy access to vulnerability management, application security, detection and response, external threat intelligence, orchestration and automation, and more. Rapid7 InsightVM is ideal for security, IT, and DevOps teams, helping them reduce risk by enabling them to detect and respond to attacks quickly.

    Rapid7 InsightVM Features

    Rapid7 InsightVM has many valuable key features. Some of the most useful ones include:

    • Automated containment: With this feature, you can decrease exposure from vulnerabilities by automatically implementing temporary (or permanent) compensating controls via your network access control (NAC) systems, firewalls, and endpoint detection and response tools.
    • Policy assessment: Rapid7 InsightVM offers pre-built scan templates for common compliance requirements. The solution helps you take clear, actionable steps to compliance once you have assessed your risk posture. In addition, Rapid7 InsightVM’s Custom Policy Builder allows you to modify existing benchmarks or create new policies from scratch.
    • REST API: Rapid7 InsightVM REST API is easy to use and was built to easily automate virtually any aspect of vulnerability management, from data collection to risk analysis.
    • Live dashboards: Rapid7 InsightVM includes dashboards that are live and interactive by nature. The live dashboards enable you to create custom cards and full dashboards for anyone in your organization and allow you to track progress of your security program.
    • Automation-assisted patching: Rapid7 InsightVM’s automation-assisted patching gives you the autonomy to make key decisions in your patching process, such as your approval to apply certain patches to certain vulnerabilities.
    • Real risk prioritization: Rapid7 InsightVM makes it simple to know which vulnerabilities need to be prioritized and where your riskiest assets lie.
    • Goals and SLA’s: This feature enables you to make and track progress toward your goals and service level agreements (SLAs) at an appropriate pace.

    Rapid7 InsightVM Benefits

    There are many benefits to implementing Rapid7 InsightVM. Some of the biggest advantages the solution offers include:

    • Attack surface monitoring for maintained visibility: By leveraging attack surface monitoring with Project Sonar (a Rapid7 research project that regularly scans the internet to gain insights into global exposure to common vulnerabilities), you can gain more control of all of your external-facing assets, both known and unknown.
    • Container security: Rapid7 InsightVM integrates with your CI/CD tools, public container repositories, and private repositories to assess container images for vulnerabilities during the build process even before they are deployed.
    • Lightweight endpoint agent: Rapid7 InsightVM unifies data so you only need to install a single agent for continuous vulnerability assessment, incident detection, and log data collection.
    • Easily assign and track remediation duties: Using Rapid7 InsightVM, IT and security teams can assign as well as track remediation duties without having to deal with remediation reports, complex spreadsheets, or back-and-forth email tags.
    • Integration with cloud services and virtual infrastructure: Rapid7 InsightVM provides full visibility into risk across your physical, virtual, and cloud infrastructure.
    • Integrated threat feeds: Rapid7 InsightVM is designed with integrated threat feeds, giving you a dynamic view that shows you which threats are most relevant to your environment, enabling you to better protect against current, impending threats so you can react quickly to critical vulnerabilities.

    Reviews from Real Users

    Below are some reviews and helpful feedback written by PeerSpot users currently using the Rapid7 InsightVM solution.

    An owner at a tech services company says, "I liked the dashboard on it. I could customize my dashboard with different widgets and different heat maps."

    PeerSpot user Kimeang S., Technical Consultant at Yip Intsoi, mentions, "The most important aspect of the solution is that it rarely gives false positives, especially compared to other products. It provides very clear reports for our IT teams to look at."

    A Director of Information Technology at a government explains, "The main functionality of identifying item endpoints that weren't properly patched or had vulnerabilities is the solution's most valuable feature."

    Tenable Nessus is a vulnerability management solution that aims to empower organizations to be aware of threats that both they and their customers face. It is the most deployed scanner in the vulnerability management industry. Organizations that use this product have access to the largest continuously updated global library of vulnerability and configuration checks. They can stay ahead of threats that Tenable Nessus’s competitors may be unable to spot. Additionally, Tenable Nessus supports a greater number of technologies than its competitors.

    Tenable Nessus Benefits

    Some of the ways that organizations can benefit by deploying Tenable Nessus include:

    • Ease of use. Tenable Nessus is designed with security administrators in mind. It is built so that users can manipulate it intuitively without having to undergo special systems training. Users can create security policies with the greatest level of ease and can initiate scans of their entire networks with only a few clicks.
    • Support and resources. Tenable Nessus has both a support system of clarification resources and technical support for users to rely on. The solution has a resource center that contains guides and tips that can clarify things that confuse users and can aid them in gaining the maximum level of value. Additionally, users can reach out to Tenable Nessus’s technical support team, which is available around the clock and is reachable via a number of methods. This makes it simple for users to get help if they need it.
    • Reduction of threat vectors. Tenable Nessus provides users with the ability to reduce the number of potential threat vectors that a hacker can exploit. It enables users to find where the vulnerabilities in their networks are so their security won’t be compromised. They can then quickly address those weak points and head off issues before any have the chance to arise.

    Tenable Nessus Features

    • Report customization. Tenable Nessus enables users to customize the security reports that their system produces. They are able to set Tenable Nessus to generate reports that contain the information that is most relevant to their business objectives. Users can also utilize these report customization capabilities to customize the formats of their reports.
    • Vulnerability triage capability. Included in the Tenable Nessus security suite is a feature that enables users to conduct a triage of their vulnerabilities. The solution can apply one of five ratings to vulnerabilities that it detects. This makes it possible for organizations to work on addressing issues by order of severity.
    • Scaling. Tenable Nessus can scale to meet an organization’s needs by migrating the network that it is connected to, to other Tenable solutions. Users can scale up their systems as their security demands increase. It is capable of reaching hundreds of thousands of systems.

    Reviews from Real Users

    Tenable Nessus is a solution that stands out when compared to many of its competitors. Two major advantages it offers are its ease of use and its vulnerability scanning feature.

    Rallis F., the principal security architect at a technology vendor, writes, “The ease of use is the primary valuable feature. This specific version is very straightforward. I like the ability to modify it and configure it based on the different policies.”

    Sandip D., a cyber security expert at Birlasoft India Ltd, writes, “The vulnerability scanner is the most valuable feature. It's an important feature for us. We use the plugin output for that. It shows us the exact version of Nessus and what is needed for remediation. Based on that, we decide what should be remediated first to get the best result for security.”

    Offer
    Learn more about Wiz
    Learn more about Rapid7 InsightVM
    Learn more about Tenable Nessus
    Sample Customers
    Wiz is the fastest growing software company ever - $100M ARR in 18 months: Wiz becomes the fastest-growing software company ever | Wiz Blog  Discover why companies, including Salesforce, Morgan Stanley, Fox, and Bridgewater choose Wiz as their cloud security partner. Read their success stories here: Customers | Wiz
    ACS, Acosta, AllianceData, amazon.com, biogen idec, CBRE, CATERPILLAR, Deloitte, COACH, GameStop, IBM
    Bitbrains, Tesla, Just Eat, Crosskey Banking Solutions, Covenant Health, Youngstown State University
    Top Industries
    VISITORS READING REVIEWS
    Computer Software Company18%
    Financial Services Firm14%
    Manufacturing Company6%
    Healthcare Company5%
    REVIEWERS
    Financial Services Firm17%
    Comms Service Provider13%
    Computer Software Company13%
    Insurance Company9%
    VISITORS READING REVIEWS
    Computer Software Company18%
    Comms Service Provider10%
    Financial Services Firm8%
    Government8%
    REVIEWERS
    Computer Software Company16%
    Financial Services Firm13%
    Manufacturing Company11%
    Security Firm11%
    VISITORS READING REVIEWS
    Computer Software Company18%
    Government11%
    Comms Service Provider11%
    Financial Services Firm8%
    Company Size
    VISITORS READING REVIEWS
    Small Business21%
    Midsize Enterprise17%
    Large Enterprise63%
    REVIEWERS
    Small Business43%
    Midsize Enterprise19%
    Large Enterprise38%
    VISITORS READING REVIEWS
    Small Business22%
    Midsize Enterprise17%
    Large Enterprise61%
    REVIEWERS
    Small Business38%
    Midsize Enterprise25%
    Large Enterprise37%
    VISITORS READING REVIEWS
    Small Business21%
    Midsize Enterprise16%
    Large Enterprise64%
    Buyer's Guide
    Rapid7 InsightVM vs. Tenable Nessus
    November 2022
    Find out what your peers are saying about Rapid7 InsightVM vs. Tenable Nessus and other solutions. Updated: November 2022.
    657,397 professionals have used our research since 2012.

    Rapid7 InsightVM is ranked 6th in Vulnerability Management with 25 reviews while Tenable Nessus is ranked 1st in Vulnerability Management with 48 reviews. Rapid7 InsightVM is rated 7.6, while Tenable Nessus is rated 8.4. The top reviewer of Rapid7 InsightVM writes "Understands and defends your network from vulnerabilities". On the other hand, the top reviewer of Tenable Nessus writes "Easy to use, good support, and gives full reports of what's vulnerable per device". Rapid7 InsightVM is most compared with Qualys VM, Tenable.sc, Tenable.io Vulnerability Management, Microsoft Intune and Rapid7 InsightIDR, whereas Tenable Nessus is most compared with Qualys VM, Tenable.io Vulnerability Management, Tenable.sc, Rapid7 Metasploit and Microsoft Intune. See our Rapid7 InsightVM vs. Tenable Nessus report.

    See our list of best Vulnerability Management vendors.

    We monitor all Vulnerability Management reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.