With InsightVM, I continuously monitor my network by setting up regular scans to identify vulnerabilities in real-time. It IS particularly useful for focusing on customer-facing systems at our perimeter, helping me prioritize and quickly address any security risks.
Executive Manager at B2B-Solutions LLC
Particularly useful for focusing on customer-facing systems and offers excellent scalability
Pros and Cons
- "InsightVM offers a robust platform for identifying, prioritizing, and addressing vulnerabilities across an organization's IT infrastructure."
- "One area I would like to improve in InsightVM is its integration with other solutions."
What is our primary use case?
What is most valuable?
InsightVM offers a robust platform for identifying, prioritizing, and addressing vulnerabilities across an organization's IT infrastructure.
What needs improvement?
One area I would like to improve in InsightVM is its integration with other solutions, particularly for better compatibility with upcoming tools we plan to adopt. Enhanced functionality for budget management or change management databases could also be beneficial.
For how long have I used the solution?
I have been working with InsightVM for over two years.
Buyer's Guide
Rapid7 InsightVM
October 2025

Learn what your peers think about Rapid7 InsightVM. Get advice and tips from experienced pros sharing their opinions. Updated: October 2025.
871,829 professionals have used our research since 2012.
What do I think about the stability of the solution?
I would rate the stability of the solution as a nine out of ten.
What do I think about the scalability of the solution?
InsightVM's scalability is top-notch and I would rate it a solid nine out of ten. Being a cloud-based solution, it effortlessly adjusts to accommodate varying needs and can easily scale from small to large environments.
How are customer service and support?
Rapid7's technical support is highly responsive and helpful. I would rate them as a nine out of ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I chose Rapid7 over Tenable Nessus because of its better performance, comprehensive functionality, and stronger support for operating systems and services. While Tenable Nessus may be cheaper, it lacks integration with other features and is more suited for SMBs rather than enterprises.
How was the initial setup?
Implementing InsightVM was straightforward. Setting it up to scan external networks at the perimeter was effortless; I just needed to create a cloud account and start using the solution. For internal network scanning, I installed the software on my notebook, which took about five to ten minutes for a single version setup, but it is important to note that it doesn't support Windows platforms.
What's my experience with pricing, setup cost, and licensing?
InsightVM's pricing can vary depending on the coverage needed. While it may not be the cheapest option, purchasing an unlimited license could be cost-effective for larger environments. For smaller needs, it might be more expensive compared to competitors. I would rate the affordability of the product at a four out of ten.
What other advice do I have?
I prioritize vulnerabilities in InsightVM by first focusing on customer-facing systems at our perimeter, which helps me quickly identify and address any security risks. Then, I utilize the cloud-based engine to scan internal networks and ensure comprehensive coverage without the need for complex on-premise solutions, making it easy to manage from my notebook connected to the internet.
Additionally, in InsightVM, we prioritize vulnerabilities by utilizing comprehensive data sources like the NVD and Rapid7's specialized risk calculation methods. The solution provides detailed information, including exploitability and impact, and evaluates whether vulnerabilities could be exploited in specific environments like NetApp.
I would recommend InsightVM to others. Overall, I would rate the product as an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer.

Sr Cyber Security Consultant at Google
Brilliant audit report and scorecard but scans often get blocked by firewalls
Pros and Cons
- "The solution is very user friendly and easy to manage."
- "The solution needs to improve its vulnerability design to include CVC results."
What is our primary use case?
Our company uses the Nexpose automation tools for validity, deactivation, assessment, and penetration testing. We can easily see if something has been exposed and manually focus on or follow main vulnerabilities.
We have 28 users and a JV license key for using the solution in our offline systems on a trial basis.
What is most valuable?
The audit report and scorecard are brilliant.
The solution is very user friendly and easy to manage. Users who have a year of experience with this type of tool will have no issues.
What needs improvement?
The solution cannot scan third-party tools that have firewalls within them. The firewalls detect and block the solution. Conversely, Nexus is able to bypass firewalls because it has low detectability. We use Nexus when the solution cannot bypass a firewall. The solution can scan 60% of the time but Nexus can scan 90% of the time.
The solution needs to improve its vulnerability design to include CVC results. Nexus has a good, long range and a good database for finding CVC numbers. We need this level of security detail but the solution does not seem to provide it.
For how long have I used the solution?
I have been using the solution for five years.
What do I think about the stability of the solution?
The solution updates without interruption and has no database issues.
Nexus sometimes has issues with plugging time where all the paper is gone so we need to run the tool again.
What do I think about the scalability of the solution?
The solution is very scalable.
How are customer service and support?
The articles and videos provide the information we need so we do not use technical support.
How was the initial setup?
The setup is straightforward and user friendly.
New users can rely on the videos or articles to learn about setup. The solution and other tools might be a little bit tricky to setup. If you follow the article's commands, setup is easy.
What about the implementation team?
We implemented the solution in-house and it took about 25 minutes.
What's my experience with pricing, setup cost, and licensing?
The solution's pricing is better than Nexus which charges a high amount for very little use.
Which other solutions did I evaluate?
We also use Nexus which is a mature tool and gives pretty good results. It offers the best scanning and good reporting files.
The solution's audit report and scorecard provide better details than Nexus.
From the feature side, right now we choose Nexus because it can bypass firewalls. From the price side, we choose the solution.
What other advice do I have?
I recommend the solution from the reporting side but am not sure I recommend it from the scanning side. The issue with firewalls needs to be fixed and then I will definitely recommend the solution.
I rate the solution a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Rapid7 InsightVM
October 2025

Learn what your peers think about Rapid7 InsightVM. Get advice and tips from experienced pros sharing their opinions. Updated: October 2025.
871,829 professionals have used our research since 2012.
You can scan a network, and receive recommendations to address vulnerabilities with the click of a button
Pros and Cons
- "The most valuable feature is the vulnerability scan."
- "In order to be able to properly test the solution and make a decision, I would like to receive the test license code instantly and eliminate the wait time."
What is our primary use case?
The primary use case of the solution is for network monitoring.
What is most valuable?
The most valuable feature is the vulnerability scan. All you need to do is enter the IP address and the solution provides details about the machines, provides the vulnerabilities, and gives recommendations to address those vulnerabilities.
What needs improvement?
In order to be able to properly test the solution and make a decision, I would like to receive the test license code instantly and eliminate the wait time. If I have to wait a week to test the solution it may force me to move on to another solution.
For how long have I used the solution?
I have used the solution for three weeks.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
The free trial was able to monitor over 500 machines on the network. I believe the solution is scalable.
How was the initial setup?
The initial setup is straightforward. All you need to do is install the solution on your device and connect to the cloud service.
What about the implementation team?
The implementation was done in-house.
What's my experience with pricing, setup cost, and licensing?
A full license for the solution is expensive because it is at the organizational level and not by individual users. I used a free trial licensing by providing my email. For the free trial, you require a new license code each time and if you don't use a new email address it can take over a week to receive that code.
What other advice do I have?
I give the solution eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Information Security, Cyber Operations Analyst at a consultancy with 5,001-10,000 employees
Has a good user interface, but its threat intelligence could be improved
Pros and Cons
- "The solution's user interface is good and has some vulnerability prioritization."
- "Rapid7 InsightVM should improve its threat intelligence."
What is our primary use case?
We use the solution mainly for servers and vulnerability management.
What is most valuable?
The solution's user interface is good and has some vulnerability prioritization. Rapid7 InsightVM has good integrations with ServiceNow and its own remediation project creation options.
What needs improvement?
Rapid7 InsightVM is not PCI certified, which didn't help us in the London office because of the Cyber Essentials Plus certification, which is mandatory there. We had to outsource the vulnerability management for the London office.
One of the most important things for a vulnerability management tool is the identification of vulnerabilities. When it comes to Rapid7 InsightVM, the vulnerabilities are not updated within its database. This is one of the major things that should be changed in Rapid7 when it comes to customer reliability. If the database is not updated, it could jeopardize the customer's servers and data.
The solution's support staff does not reply on time, which should be improved. Rapid7 InsightVM should improve its threat intelligence.
For how long have I used the solution?
I have been using Rapid7 InsightVM for the last few years.
How was the initial setup?
The solution's initial setup is good.
What other advice do I have?
Overall, I rate the solution a six out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Head of Cyber Security at Super Secure
Easy deployment, but technical support could respond faster
Pros and Cons
- "The ease of deployment and configuration allows users to onboard quickly."
- "Technical support does not respond quickly."
What is our primary use case?
The core domain use of the solution is verification, scanning, and finding out the vulnerabilities in real time.
How has it helped my organization?
The ease of deployment and configuration allows users to onboard quickly, aligning smoothly with various functionalities.
What is most valuable?
The data sheet is good in pricing and promises. The customers are very price-conscious. You have to satisfy technical requirements. This combo makes the product valuable and usable.
What needs improvement?
Two things are consistent. The rest of the things run fine. The technical side does not respond quickly. They take a lot of time. The priority should be to respond to the customer to serve the customer.
For how long have I used the solution?
I have been using Rapid7 InsightVM for more than three years.
What do I think about the stability of the solution?
The solution’s stability is good. It keeps on running. There are no system complaints.
What do I think about the scalability of the solution?
The solution’s scalability is linked to the new scope and the cost.
Which solution did I use previously and why did I switch?
We are actively seeking alternatives. If you can offer a better solution, superior after-sales service, and overall better everything, we would like to explore what you have to offer.
How was the initial setup?
The initial setup is not so complex. It is quickly deployable configurable and integrated with your existing setup.
The common process for Rapid7 InsightVM involves comparing it against their standard procedures to ensure compliance with the required licenses and resources. Users download the necessary files and initiate/reactivate licenses. Certain configurations are also set up. This process typically takes two to three days for the department, but we usually allocate a week for completion.
Our team feels enabled enough after completing the training session on Rapid7 InsightVM. We conduct our tests independently, and whenever we need support, we seek assistance directly from Rapid7. This process isn't overly complex or time-consuming. We ensure thorough preparation by gathering all necessary information, addressing internet concerns, and informing the customer. Once fully prepared, we proceed forward.
What's my experience with pricing, setup cost, and licensing?
The solution’s pricing is good because the value proposition delivers a report box. It is not very costly.
What other advice do I have?
Since the product is cloud-based, there's no maintenance. Whatever the information or the customization of the customer needs to be confirmed. The hardware needs maintenance.
Overall, I rate the solution a six out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Technical Manager at a computer software company with 11-50 employees
Good for inventory and vulnerability management
Pros and Cons
- "The most valuable feature for me is the risk calculation based on monthly effects."
- "The team needs to improve the speed and focus on the new bandwidth feed. Sometimes, it takes a while to scan, especially with new updates."
What is our primary use case?
We primarily use it for inventory and vulnerability management in our environment. We also use it to identify real risks and focus on container email scanning.
What is most valuable?
The most valuable feature for me is the risk calculation based on monthly effects. It's interactive, and the risk calculation depends on various factors such as quantity, hardware, and package used.
What needs improvement?
The team needs to improve the speed and focus on the new bandwidth feed. Sometimes, it takes a while to scan, especially with new updates. So, they should update the database quickly for the scanning to work more efficiently. Additionally, they should add pack management solutions for better integration with products like Microsoft FC and IBM Bigfoot.
They need to add more features or focus on work screening, and adding pack management solutions would be great. Moreover, there is room for improvement in technical support.
For how long have I used the solution?
I've been using it for about three years now.
What do I think about the stability of the solution?
It is a stable product, and I would give it a seven.
What do I think about the scalability of the solution?
It is a scalable product. Currently, there are around 1,000 users in my company using Rapid7 InsightVM.
How are customer service and support?
Customer service and support are usually responsive, but there is room for improvement in their response time. The quality of support is good.
How was the initial setup?
The initial setup is simple.
Which other solutions did I evaluate?
Along with Rapid7 InsightVM, we use Metasploit for already scanning. We also use it for website vulnerability scanning. For vulnerability scanning, we also use solutions from Tenable Network Security. Tenable is better because of its more frequent updates. However, it may depend on the industry and the use case. For now, Nessus is better for vulnerability scanning because of its ability to quickly and accurately detect vulnerabilities. However, Rapid7's team should work on improving the capacity of InsightVM to do the same.
What other advice do I have?
Overall, I would rate the solution an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Chief Executive Officer at a outsourcing company with 11-50 employees
A single pane of glass with good functionality, and is easy to manage
Pros and Cons
- "The cost is what is most valuable. Compared to the other products on the market, the cost is more palatable."
- "We are a registered reseller and a trusted partner. However, for us to get any support from them I can't log a call directly with Rapid7 InsightVM. I have to work with the distributor to log the call for me."
What is our primary use case?
The main purpose for using Rapid7 InsightVM is vulnerability management and visibility.
What is most valuable?
The cost is what is most valuable. Compared to the other products on the market, the cost is more palatable. Also the functionality.
It is a single pane of glass that I can do most things.
What needs improvement?
I see ongoing progress constantly. There isn't much opportunity to make recommendations for improvement from our end. Technology does what we want it to do.
The only issue I have with their business plan is how they interact with South African enterprises.
They have one singular distributor that I must work with, and that is where my two points go.
I can't interact with Rapid7 directly. I must work via the local incumbent, the distributor. And working with this third party can be tiresome at times.
Rapid7 InsightVM doesn't work with us directly. I have to work with a distributor. If I need quotes or technical support, for example, I have to work with the distributor rather than Rapid7 InsightVM directly.
We are a registered reseller and a trusted partner. However, for us to get any support from them I can't log a call directly with Rapid7 InsightVM. I have to work with the distributor to log the call for me.
For how long have I used the solution?
I have been working with Rapid7 InsightVM for two to three years.
We are using the latest version.
What do I think about the stability of the solution?
Rapid7 InsightVM is very stable. I would rate the stability a five out of five.
What do I think about the scalability of the solution?
Rapid7 InsightVM is a scalable product. I would rate the scalability a five out of five.
We have approximately 1, 500 endpoints in our company.
It's not users, but endpoints, because the model is built around the endpoints you want to monitor. We run on around 1,500 endpoints. It is not user-specific.
One person can easily manage this solution, but we have a team of four engineers to manage our environment.
How are customer service and support?
I have not contacted technical support directly.
Which solution did I use previously and why did I switch?
We also use Tenable Nessus.
How was the initial setup?
I am not involved with the initial setup. I have a support team that is managing that.
We deploy it depending on our client's requirements. We use it as well as our clients.
What about the implementation team?
The deployment was done in-house. We do it ourselves.
We had four, and all four worked on the project. This is not to say that there is just one primary job or four main jobs. Our engineers all work as a team.
What was our ROI?
I can definitely see a return on investment.
It's good. We get the value from the product.
What's my experience with pricing, setup cost, and licensing?
We purchase annual licenses.
We provide our own support. We have resources that have been certified to work on the product. It is purely the license fee.
In terms of affordability, I would rate it a three out of five.
What other advice do I have?
I believe they see us as resellers because we resell it, but when we use it for professional services, they regard us as partners. They use both terms in the same sentence.
We support it.
I strongly recommend it. It's a good product.
It's only the backend support that needs to be improved. However, there isn't very much that has room for improvement in the product right now.
They are not flawless. We have had problems here and there, but overall, I would rate Rapid7 InsightVM an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Cyber Security Engineer at Unemployed
A high-performing solution that collects real-time data, is capable of more detections, and allows you to use the Scheduled Forensics feature
Pros and Cons
- "most valuable features of Rapid7 InsightVM for me are creating dynamic asset tags, generating reports, and deploying the agent. The agent scans assets every four hours, providing real-time data on any devices. Although there weren't any significant new features compared to our previous tool, having both SIEM and vulnerability management handled by one tool made things easier. We could gather logs from different devices and cloud sources, and perform detailed investigations without switching tools. I haven't worked with the automation capabilities of InsightVM. For remediation prioritization, we check the vulnerability, search for solutions on open platforms, and work with different teams to apply patches after proper testing. Currently, we don’t have any AI or ASM projects assisted by InsightVM"
- "I’d like to see Rapid7 InsightVM improve by adding a knowledge base similar to what Qualys offers. This would help us easily check and search for vulnerabilities using Rapid7 IDs associated with CVs or CVSS. From a features perspective, everything was fine at the time, and the security features of Rapid7 InsightVM were effective."
What is our primary use case?
We mainly use it for vulnerability management, generating monthly reports to address and resolve vulnerabilities. The main use cases involve receiving alerts based on predefined settings by Rapid7, investigating these alerts to understand their causes, and performing fine-tuning activities.
What is most valuable?
The most valuable features of Rapid7 InsightVM for me are creating dynamic asset tags, generating reports, and deploying the agent. The agent scans assets every four hours, providing real-time data on any devices. Although there weren't any significant new features compared to our previous tool, having both SIEM and vulnerability management handled by one tool made things easier. We could gather logs from different devices and cloud sources, and perform detailed investigations without switching tools.
I haven't worked with the automation capabilities of InsightVM. For remediation prioritization, we check the vulnerability, search for solutions on open platforms, and work with different teams to apply patches after proper testing. Currently, we don’t have any AI or ASM projects assisted by InsightVM
What needs improvement?
I’d like to see Rapid7 InsightVM improve by adding a knowledge base similar to what Qualys offers. This would help us easily check and search for vulnerabilities using Rapid7 IDs associated with CVs or CVSS.
From a features perspective, everything was fine at the time, and the security features of Rapid7 InsightVM were effective.
For how long have I used the solution?
I've been working with Rapid7 InsightVM since December.
What other advice do I have?
Overall, I would recommend Rapid7 InsightVM to others. My advice would be to first understand your requirements and infrastructure before implementing the product. I would rate InsightVM as an eight.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Buyer's Guide
Download our free Rapid7 InsightVM Report and get advice and tips from experienced pros
sharing their opinions.
Updated: October 2025
Product Categories
Risk-Based Vulnerability ManagementPopular Comparisons
Qualys VMDR
Tenable Security Center
Tenable Vulnerability Management
Microsoft Defender Vulnerability Management
Red Canary
Nucleus
Arctic Wolf Managed Risk
Cisco Vulnerability Management (formerly Kenna.VM)
SanerNow CyberHygiene Platform
Balbix BreachControl
SecureWorks Taegis VDR
Fortra's Vulnerability Management
Buyer's Guide
Download our free Rapid7 InsightVM Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions: