The solution is primarily used for vulnerability management, specifically vulnerability scanning of the endpoint devices.
Director of Information Technology at a government with 201-500 employees
Good at identifying vulnerabilities but had issues with scans and endpoint accuracy
Pros and Cons
- "The main functionality of identifying item endpoints that weren't properly patched or had vulnerabilities is the solution's most valuable feature."
- "We found that after you passed an endpoint, it didn't always reflect it in the next scan. I'm not sure if it was a glitch or some issue with the product's software. That was never clear. That was always an issue and something that definitely needed improvement."
What is our primary use case?
What is most valuable?
The main functionality of identifying item endpoints that weren't properly patched or had vulnerabilities is the solution's most valuable feature.
What needs improvement?
We found that after you passed an endpoint, it didn't always reflect it in the next scan. I'm not sure if it was a glitch or some issue with the product's software. That was never clear. That was always an issue and something that definitely needed improvement.
For how long have I used the solution?
We've used the solution for four years.
Buyer's Guide
Rapid7 InsightVM
July 2026
Learn what your peers think about Rapid7 InsightVM. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
908,800 professionals have used our research since 2012.
What do I think about the stability of the solution?
I didn't notice anything in terms of stability issues. There was always data in it, so I didn't, face any problems. We just had an issue once where we would scan and then we would patch and occasionally it wasn't reflected on the next scan that that patch was there. That was the biggest issue we faced. Other than that, it was reliable. We didn't really have glitchiness or bugs. It wasn't crashing or freezing on us.
What do I think about the scalability of the solution?
I probably don't have an opinion on the scalability. It seemed to function, however, beyond that I'm not sure. As an end-user, I just would log in and run reports. I wasn't in charge of expanding the solution. I used it in a pretty non-technical way.
There were only ever about 10 to 15 users on the solution at any given time.
How are customer service and support?
I never actually got in touch with technical support. I wouldn't be able to speak t their level of service.
Which solution did I use previously and why did I switch?
The company did not use a different solution before using this product.
How was the initial setup?
I never set up the software myself. I was always just an end-user. I can't speak to if the solution was straightforward or complex.
I have not idea how long deployment took. I'm not sure if it was a long process or not.
Maintenance was handled by our security division. I don't know if there was one person or there were multiple admins that handled that aspect of the solution.
What about the implementation team?
It's my understanding that the solution was set up in-house and an integrator or reseller was not used.
What's my experience with pricing, setup cost, and licensing?
I'm not sure what the solution would cost on a monthly or yearly basis.
Which other solutions did I evaluate?
I'm not sure if the company evaluated other options or not. I wasn't part of that process.
The company I'm working with now is looking at evaluating Tenable.io.
What other advice do I have?
The company I worked for was just a customer and I was just an end-user. There was no business relationship between the two companies that I was aware of.
The company is considering moving from on-premises to the cloud.
I am unsure of which version of the solution is being used currently. I'm no longer at the company where I used the product.
While the solution worked well, I have never compared other solutions, so I don't know if it's best in class or not.
I'd rate the solution six out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Speed and quality of vulnerability scanning translates to reliable and timely results
Pros and Cons
- "There are many integrations with things like the VMware NSX that are great, the reporting is really solid."
- "One of the big lessons we were able to get value from immediately was really just having good visibility of what's in our environment."
- "There are some difficulties with the online reporting and lack of integrations, the information that you can get from the APIs in the software is not the best."
What is our primary use case?
We have a few primary use cases. The main one is looking at the visibility of devices that are on our network to keep track of things as they come and go, we're looking for known vulnerabilities whether it's the operating system, network devices, mobile devices, and the like. When we find the vulnerabilities we remediate them, so it's also our job to verify that remediations have been successful. In addition, we are now beginning to get involved in setting security baselines and configuring baselines and using InsightVM to audit those configurations.
We're scanning about 6,000 devices. There are about 4,000 users in our environment, they are all IT staff. We also have technical leads from our user services, which is our workstation support, mobile devices, laptops, etc. We've got our infrastructure office which is servers and cloud administration, the IT security group, which is myself, and then our network support team and network administrators as well. It means our IT leadership gets some definite value from the reporting there. The CTO, his assistant, and all the IT managers receive their information from there as well. We have one person working in maintenance, and that's not a full-time position.
What is most valuable?
For us there are many integrations with things like the VMware NSX that are great, the reporting is really solid. I like the ability to set goals and SLAs for remediation. When a new vulnerability is found we can have an SLA associated with it automatically based on severity and some of those things. I like the integration with Cisco ISE for identity and doing automated containments and the like. But the biggest thing for me is the quality of the vulnerability scanning itself. The quality of the results and the timeliness, the speed with which they update with new checks for new vulnerabilities. That is the big thing for us.
What needs improvement?
There are some difficulties with the online reporting and lack of integrations, the information that you can get from the APIs in the software is not the best. There's still some fleshing out of their API that I think could benefit them as well.
I'd like to see more integrations with ticketing systems. Right now, JIRA and ServiceNow are the only ticketing systems that have integration with Rapid7. Extending that would be big. Some additional integrations with some patch management solutions would be good too. IBM BigFix and SCCM. Microsoft has integrations there. In our situation, we're not using either of those and that feature doesn't really give us a whole lot. If there were to be new integrations added on, both on the patch management and the ITMS side, that would be a big improvement.
Additional features would be the additional integrations for ticketing systems that I mentioned. There are always updates rolling out for new scans and things.
For how long have I used the solution?
We've been using the solution for quite a few years.
What do I think about the stability of the solution?
I've been impressed with the stability. The only issues that have really come up have been on the cloud reporting aspect. We've had a couple of issues here or there, but their support people were able to get us fixed up in a couple of hours. As far as the on-premises stuff, the only issues we've honestly had with it were problems of our own making. We didn't keep an eye on storage and it filled up but that was a lack of monitoring on our side. Since then it's been rock solid.
What do I think about the scalability of the solution?
I haven't thrown anything at it that it can't handle. The report generation slows down the larger your environment gets, and the greater the number of scans you're trying to integrate into a single report. Even with the increased resources that we gave the server when we did a rebuild hasn't caused any problems. I would anticipate that if you're getting up into the tens of thousands of devices and trying to report across all of those, I could see that grinding to a halt a little bit.
Otherwise, scalability is great. We have more than doubled the number of devices that we're scaling since we did the initial install. We're up to somewhere around 6,000 now and it's chugging right along.
How are customer service and technical support?
The technical support have been a pleasure to work with.
How was the initial setup?
The initial setup was pretty straightforward. There were a couple of things with integrating and some areas where it gets a bit more complex, but for the most part, it was very straightforward, especially for how powerful a solution it is. We're running a fairly advanced setup here with multiple scanning engines, scanning pools, and integrations into other systems in our environment and all of that. Defining all of the sites and asset grouping and all of those sorts of things, took some additional time after that. You'd have to do that no matter what.
What about the implementation team?
We used professional services from Rapid7 to assist with the initial deployment and set up was completed in less than two days. They were great. They took their time and didn't just do the setup, they also included user education and they have continued to reach out since then and make sure we're getting value from the product.
What's my experience with pricing, setup cost, and licensing?
Our licensing costs are somewhere around $40,000 annually. There are no additional fees. We will probably increase our license count annually as our environment kind of naturally grows. We started out with probably about a third of the network covered and we are up to probably 75, 80% now. We'll get that up to over 99%, I'm sure.
Which other solutions did I evaluate?
We looked at a few other options: Acunetix was on the list and we looked at Manage Engine, Nessus, Rubric, Alien Vault, Microfocus, ArcSight, FireMon and RedSeal. On the vulnerability management side, we were very, very impressed with Rapid7 and the Insight VMware product. We looked more in-depth at a few of the others but VMware Insight stood out. The ease of use on VMware Insight coming from an organization that doesn't have a large dedicated security team, and being able to split out some of those responsibilities amongst people who may have a strong IT background, but may not have an IT security background really helped us out. It became a no-brainer at that point.
What other advice do I have?
It's important to take the time to have a full understanding of how schemes are scheduled, how sites and asset groups are set up and make sure it's done upfront. It's a big help. If you remove an old site and recreate it with small differences you lose some of the data associated with the old site. Getting the organization sorted from the beginning would be the biggest piece of advice.
It's very important to know what your environment is made up of. People often leave companies without documenting things and there's a lot that not everybody knows about because it was in the back of someone's mind. We now have a great repository of information on what's active on our network, what's installed on it, how all of those systems are interacting, and really having that visibility is great. One of the big lessons we were able to get value from immediately was really just having good visibility of what's in our environment.
It's a very solid product, reporting is great, it's reliable. We have a lot of faith in the results it gives us. At least once a week, I get a notification with some great new features that they've added that I didn't really even know I wanted, but now I have it and can't imagine life without it.
The product is cloud-based, but with an on-prem portion, but it all auto-updates. The actual scanning engine and all of that is on-prem for us. It's a SaaS solution, it's not one where we are running our own servers. It's provided as a service for us on the cloud. The on-premises stuff that we're running is just virtual machines on our VMware environment.
I would rate this product an eight out of 10.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Rapid7 InsightVM
July 2026
Learn what your peers think about Rapid7 InsightVM. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
908,800 professionals have used our research since 2012.
Senior manager at Software Productivity Group
Affordable solution with an easy initial setup process
Pros and Cons
- "It is a stable solution."
- "They should improve the cybersecurity feature of the solution."
What is our primary use case?
We use the solution for vulnerability management of our on-cloud environments.
What is most valuable?
The solution provides all the required features for vulnerability management.
What needs improvement?
They should improve the cybersecurity feature of the solution.
For how long have I used the solution?
We have been using the solution for a month.
What do I think about the stability of the solution?
It is a stable solution. We can connect it with other platforms easily.
What do I think about the scalability of the solution?
We have four to five solution users in our organization.
How was the initial setup?
The solution's initial setup process is easy.
What's my experience with pricing, setup cost, and licensing?
The solution's license costs around $30 per month. It is less expensive compared to other competitors.
What other advice do I have?
I advise others to consider the number of IP addresses required to be scanned for their network while opting for Rapid7. I rate the solution as a nine.
Disclosure: My company has a business relationship with this vendor other than being a customer.
System Engineer at a tech services company with 201-500 employees
It's a good solution for capacity forecasting
Pros and Cons
- "I rate InsightVM eight out of 10 for ease of setup. It takes two or three engineers to deploy. The solution requires some maintenance. It's mainly cleaning up data."
What is our primary use case?
We use InsightVM for capacity forecasting.
For how long have I used the solution?
I've been working around, I don't know, it's about three years.
What do I think about the stability of the solution?
I rate Rapid7 nine out of 10 for stability.
What do I think about the scalability of the solution?
I rate Rapid7 nine out of 10 for scalability.
How are customer service and support?
I rate Rapid7 support nine out of 10.
How would you rate customer service and support?
Positive
How was the initial setup?
I rate InsightVM eight out of 10 for ease of setup. It takes two or three engineers to deploy. The solution requires some maintenance. It's mainly cleaning up data.
What other advice do I have?
I rate Rapid7 InsightVM 10 out of 10.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Cloud and Cyber-Security Technician at Software Productivity Group
It lets you scan your entire network for vulnerabilities, but it lacks patch management
Pros and Cons
- "I like Rapid7's scan optimization options."
- "Patch management is the only missing feature I can think of. Rapid7 detects vulnerabilities, but it should also help you manage patches."
What is our primary use case?
Rapid7 allows you to scan the entire network to discover information about devices, such as the type of operating system.
What is most valuable?
I like Rapid7's scan optimization options.
What needs improvement?
Patch management is the only missing feature I can think of. Rapid7 detects vulnerabilities, but it should also help you manage patches.
For how long have I used the solution?
I have used Rapid7 for about five months.
What do I think about the stability of the solution?
The product isn't stable. Sometimes I attempt to log in using the correct password, but I can't access the server. It tells me that the password is wrong, so I have to reboot the server to access it.
What's my experience with pricing, setup cost, and licensing?
We pay a monthly license.
What other advice do I have?
I rate Rapid7 InsightVM seven out of 10.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Security Solution Engineer II at a security firm with 501-1,000 employees
Easy to deploy, scalable, and helps in prioritizing the risks with risk scoring
Pros and Cons
- "The risk score that they provide makes it easier to find out the biggest risks. It helped the security officers to understand where the biggest risks are so that they can act on them. They can instruct their IT teams to give them a higher priority and mitigate them."
- "It is still not a fully cloud-based solution. It will be helpful for customers if it is a complete cloud solution. It is a hybrid solution at the moment."
How has it helped my organization?
A big vulnerability was discovered last year for jshell. We got a lot of questions from our customers about which services are vulnerable. We could give an answer in just a few minutes to the customers and also warn them.
What is most valuable?
The risk score that they provide makes it easier to find out the biggest risks. It helped the security officers to understand where the biggest risks are so that they can act on them. They can instruct their IT teams to give them a higher priority and mitigate them.
What needs improvement?
It is still not a fully cloud-based solution. It will be helpful for customers if it is a complete cloud solution. It is a hybrid solution at the moment.
For how long have I used the solution?
I have been working with this solution for two years. It is a cloud solution, and I have been using its latest version.
What do I think about the stability of the solution?
It is definitely stable.
What do I think about the scalability of the solution?
It is made for scalability. We use it to monitor our own company with 250 users. Day-to-day, three people are monitoring the environment.
How are customer service and support?
It is perfect. I would rate them a nine out of ten.
How would you rate customer service and support?
Positive
How was the initial setup?
It was straightforward. It took a couple of hours. I would rate it a nine out of ten in terms of ease of setup.
In terms of maintenance, it is all self-updating.
What was our ROI?
It is difficult to estimate the ROI. For our management, it is a really important tool. It helps us to understand if something is not going perfectly.
What's my experience with pricing, setup cost, and licensing?
Its licensing is yearly. Everything is included in the price for one year.
Which other solutions did I evaluate?
We checked other solutions. We went for it because it has a cloud platform inside, which integrates with our SIEM solution, and it has many more capabilities than other products.
What other advice do I have?
I would advise others to make sure that every asset in the environment is monitored by the tool. I see many customers who think they have full coverage of all assets, but they are missing a part of the network. In such a case, they will get an incorrect understanding of their security.
I would rate this solution a nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Manager Cyber Security Services & Solutions at Trillium
User-friendly and customizable with great risk scoring feature
Pros and Cons
- "InsightVM's most valuable feature is risk scoring, a formula based on different vectors like the ease of exploitation and the availability of the machine."
- "InsightVM is easy to use, has a well-defined dashboard, and can be customized according to your needs."
- "InsightVM could be improved by providing passive scanning as an option."
What is our primary use case?
InsightVM is mainly used for vulnerability management.
What is most valuable?
InsightVM's most valuable feature is risk scoring, a formula based on different vectors like the ease of exploitation and the availability of the machine. It can be customized according to the customer's needs - for example, if they have an asset that is more vulnerable, they can adjust the risk score according to their infrastructure. It also has a very robust dashboard system and good integration.
What needs improvement?
InsightVM could be improved by providing passive scanning as an option. They could also introduce license packages for fewer than 128 users for smaller organizations.
For how long have I used the solution?
I've been using InsightVM for almost five years.
What do I think about the stability of the solution?
InsightVM is stable.
What do I think about the scalability of the solution?
InsightVM has the option of implementing the scan engine separately, which helps with scalability.
How are customer service and support?
InsightVM's technical support is very good.
How would you rate customer service and support?
Positive
How was the initial setup?
InsightVM is easy to implement and deploy, even for small and medium businesses.
What's my experience with pricing, setup cost, and licensing?
InsightVM's licensing starts at a minimum of 128 IPs and can scale up to over 1,000.
What other advice do I have?
InsightVM is easy to use, has a well-defined dashboard, and can be customized according to your needs. You can also segregate your assets and define IP ranges. I would give InsightVM a rating of nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Integrator
Country Sales Lead at securic systems
Vulnerability management solution that has a good distribution network and support in Pakistan
Pros and Cons
- "Rapid7 have a good distribution network with good support and market presence."
- "Some of our customers want to be completely cloud based, and Rapid7 doesn't offer this as an option."
What needs improvement?
Their channel program and the process of their deal registration could be improved.
Some of our customers want to be completely cloud based, and Rapid7 doesn't offer this as an option.
For how long have I used the solution?
I have used this solution for one year.
What do I think about the stability of the solution?
This solution is fairly stable.
What do I think about the scalability of the solution?
This is a scalable solution suitable for large environments.
Which solution did I use previously and why did I switch?
We initially worked with Qualys and found that Qualys has a better reputation but it is expensive. Companies with bigger budgets and who would like a cloud solution, usually prefer Qualys. This is also because of the product maturity and the research they provide.
The challenge with Qualys is that they do not have any distributors in Pakistan. They do not have an on-premises product, which caters more towards the enterprise accounts in Pakistan. I prefer going with Rapid7 for this reason. Rapid7 have a good distribution network with good support and market presence.
What other advice do I have?
My advice is to explore many options and look at the integrations available. My personal experience is that only implementing vulnerability management doesn't solve all of the problems. We also needed evaluator integrations that provide preventative measures.
I would rate this solution an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer.
Security Consultant at a tech vendor with 11-50 employees
Highly flexible, beneficial workflows, and accurate scanning
Pros and Cons
- "The most valuable features of Rapid7 InsightVM are the accurate level of scanning and the workflows are good."
- "The on-premise updates could improve from Rapid7 InsightVM."
- "The technical support is good in their knowledge, but they are a little slow."
What is our primary use case?
The main use cases of Rapid7 InsightVM are finding configuration vulnerability checks and patching recommendations. These two are the main use cases that everybody's looking for.
What is most valuable?
The most valuable features of Rapid7 InsightVM are the accurate level of scanning and the workflows are good.
What needs improvement?
The on-premise updates could improve from Rapid7 InsightVM.
For how long have I used the solution?
I have been using Rapid7 InsightVM for approximately three years.
What do I think about the scalability of the solution?
Rapid7 InsightVM is scalable. You could use it for as many assets as you like. It is very scalable and flexible.
How are customer service and support?
The technical support is good in their knowledge, but they are a little slow.
How was the initial setup?
The initial setup of Rapid7 InsightVM was straightforward.
I would rate the ease of setup of Rapid7 InsightVM a three out of five.
What other advice do I have?
I rate Rapid7 InsightVM an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Assistant Engineer at Harel Mallac Technologies Ltd
Plenty of options, reliable, and simple installation
Pros and Cons
- "The solution is good because it has a lot of options."
- "The solution could improve by being more secure."
What is our primary use case?
We use Rapid7 InsightVM mostly for VM management.
What is most valuable?
The solution is good because it has a lot of options.
What needs improvement?
The solution could improve by being more secure.
For how long have I used the solution?
I have been using Rapid7 InsightVM for approximately one month.
What do I think about the stability of the solution?
The solution has been stable.
What do I think about the scalability of the solution?
Rapid7 InsightVM is scalable.
How are customer service and support?
I have not needed to contact the support at this time.
How was the initial setup?
The installation is simple, it took us approximately six hours.
What about the implementation team?
I did the implementation myself.
What other advice do I have?
I would recommend this solution to others.
I rate Rapid7 InsightVM a nine out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Buyer's Guide
Download our free Rapid7 InsightVM Report and get advice and tips from experienced pros
sharing their opinions.
Updated: July 2026
Popular Comparisons
Microsoft Defender for Cloud
Checkmarx One
Qualys VMDR
Orca Security
Tenable Nessus
FortiCNAPP
Acunetix
Tenable Security Center
Tenable Vulnerability Management
The NodeZero Platform by Horizon3.ai
Rapid7 Metasploit
Ivanti Autonomous Endpoint Management
Buyer's Guide
Download our free Rapid7 InsightVM Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:


















