InsightVM is mainly used for vulnerability management.
Senior Manager Cyber Security Services & Solutions at Trillium
User-friendly and customizable with great risk scoring feature
Pros and Cons
- "InsightVM's most valuable feature is risk scoring, a formula based on different vectors like the ease of exploitation and the availability of the machine."
- "InsightVM could be improved by providing passive scanning as an option."
What is our primary use case?
What is most valuable?
InsightVM's most valuable feature is risk scoring, a formula based on different vectors like the ease of exploitation and the availability of the machine. It can be customized according to the customer's needs - for example, if they have an asset that is more vulnerable, they can adjust the risk score according to their infrastructure. It also has a very robust dashboard system and good integration.
What needs improvement?
InsightVM could be improved by providing passive scanning as an option. They could also introduce license packages for fewer than 128 users for smaller organizations.
For how long have I used the solution?
I've been using InsightVM for almost five years.
Buyer's Guide
Rapid7 InsightVM
May 2025

Learn what your peers think about Rapid7 InsightVM. Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
856,873 professionals have used our research since 2012.
What do I think about the stability of the solution?
InsightVM is stable.
What do I think about the scalability of the solution?
InsightVM has the option of implementing the scan engine separately, which helps with scalability.
How are customer service and support?
InsightVM's technical support is very good.
How would you rate customer service and support?
Positive
How was the initial setup?
InsightVM is easy to implement and deploy, even for small and medium businesses.
What's my experience with pricing, setup cost, and licensing?
InsightVM's licensing starts at a minimum of 128 IPs and can scale up to over 1,000.
What other advice do I have?
InsightVM is easy to use, has a well-defined dashboard, and can be customized according to your needs. You can also segregate your assets and define IP ranges. I would give InsightVM a rating of nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Integrator

Country Sales Lead at securic systems
Vulnerability management solution that has a good distribution network and support in Pakistan
Pros and Cons
- "Rapid7 have a good distribution network with good support and market presence."
- "Some of our customers want to be completely cloud based, and Rapid7 doesn't offer this as an option."
What needs improvement?
Their channel program and the process of their deal registration could be improved.
Some of our customers want to be completely cloud based, and Rapid7 doesn't offer this as an option.
For how long have I used the solution?
I have used this solution for one year.
What do I think about the stability of the solution?
This solution is fairly stable.
What do I think about the scalability of the solution?
This is a scalable solution suitable for large environments.
Which solution did I use previously and why did I switch?
We initially worked with Qualys and found that Qualys has a better reputation but it is expensive. Companies with bigger budgets and who would like a cloud solution, usually prefer Qualys. This is also because of the product maturity and the research they provide.
The challenge with Qualys is that they do not have any distributors in Pakistan. They do not have an on-premises product, which caters more towards the enterprise accounts in Pakistan. I prefer going with Rapid7 for this reason. Rapid7 have a good distribution network with good support and market presence.
What other advice do I have?
My advice is to explore many options and look at the integrations available. My personal experience is that only implementing vulnerability management doesn't solve all of the problems. We also needed evaluator integrations that provide preventative measures.
I would rate this solution an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer:
Buyer's Guide
Rapid7 InsightVM
May 2025

Learn what your peers think about Rapid7 InsightVM. Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
856,873 professionals have used our research since 2012.
IT Security Analyst at a financial services firm with 1,001-5,000 employees
Could be better on the cloud side and offer more reporting, overall - recommended to check other options
Pros and Cons
- "The feature that I have found most valuable is its dashboards."
- "There is room for improvement on its cloud side. In the next release I would like to see better reporting."
What is our primary use case?
We use it for vulnerability scanning.
What is most valuable?
The feature that I have found most valuable is its dashboards.
What needs improvement?
There is room for improvement on its cloud side.
In the next release I would like to see better reporting.
For how long have I used the solution?
I have been using Rapid7 InsightVM for seven years.
What do I think about the stability of the solution?
It is stable.
What do I think about the scalability of the solution?
Rapid7 InsightVM is scalable.
In my company, it is just my team of less than five people using it.
It requires one engineer for deployment and maintenance of the solution.
We do not have plans to increase the usage of the solution in the future.
How are customer service and support?
Their customer support is really bad. On a scale of 1 to 10 I would probably give it a 1.
How was the initial setup?
The initial cloud setup was difficult. It took months even though we worked with their professional services.
What about the implementation team?
We used a consultant to implement.
What was our ROI?
We had a good return, but it could be better.
What's my experience with pricing, setup cost, and licensing?
We pay 100,000 yearly.
What other advice do I have?
We are thinking about changing right now. We have always used Rapid7, but we are thinking about changing now.
My advice to anyone considering Rapid7 InsightVM is to look at the other vendors first.
On a scale of one to ten, I would give Rapid7 InsightVM a 3.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Information Security Officer at Umniah
It's smarter and more accurate from an application perspective
Pros and Cons
- "Using Rapid7, we can install a scan engine, we can do our VPN connections, and we can conduct internal scans of remote sites. We prefer the web application. It's smarter and more accurate from an application perspective."
- "The integration with other solutions like JIRA could be better. Perhaps there could be some additional updates in the next phase that could integrate with it, so then you can proceed with the VT much easier."
What is our primary use case?
We use a hybrid setup. Some dashboards and configurations are uploaded to the Cloud, and some of them are on-premises. The main engine is on-premises. We have about 12 customers and some of them are big companies.
What is most valuable?
There are a few main features that we are very happy with. Using Rapid7, we can install a scan engine, we can do our VPN connections, and we can conduct internal scans of remote sites. We prefer the web application. It's smarter and more accurate from an application perspective.
What needs improvement?
The integration with other solutions like JIRA could be better. Perhaps there could be some additional updates in the next phase that could integrate with it, so then you can proceed with the VT much easier.
For how long have I used the solution?
I've been using Rapid7 for about two years.
What do I think about the scalability of the solution?
From a scalability standpoint, it's good because they give you around 100%. If you want to increase your asset counts, for example, they give you permission for 100% above the limit that you pay for.
How are customer service and technical support?
Their support is very good. Technical support varies from person to person. Some cases have taken some time, but once it was escalated, everything was done well and the problem was solved. We've had some cases involving integration, remote sites, and some special configurations. They provided us with some support on all that.
How was the initial setup?
It's straightforward. Everything is like setting up Lego cubes. It doesn't take much time to deploy. The first deployment may take around an hour or two.
What's my experience with pricing, setup cost, and licensing?
The license could be a little bit cheaper. For all these features, you would expect to pay a little bit lower but around the same general price. Licenses are paid yearly. For some customers, we pay two years at a time, but mostly it's yearly.
What other advice do I have?
I would rate it nine out of 10.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Cyber Security Engineer at a manufacturing company with 5,001-10,000 employees
Good reporting, useful automation features, and has good technical support
Pros and Cons
- "It's a relevant management tool."
- "I would like to see more integration."
What is our primary use case?
We use this solution for our internal server for scanning. We can scan for vulnerabilities and locate them.
We also generate reports for the patching team. We assign tasks to the patching team.
What is most valuable?
It's a relevant management tool.
It has some useful automation features. The report generating and the scanning are very helpful.
What needs improvement?
It would be very helpful to have integration. There are many plugins that can be used for tasks that would help the visibility and be able to locate the exact problem.
I would like to see more integration.
I would also like to see more flexibility when scheduling the scans. We should be able to schedule scans when we want them to be scheduled. Currently, they have to be scheduled before a certain day of the week.
For how long have I used the solution?
I have been using Rapid7 InsightVm for six months during my internship.
What do I think about the stability of the solution?
Rapid7 InsightVM is a stable product.
What do I think about the scalability of the solution?
We have no issues with the scalability of this solution. We have a vulnerability management team of four who are using it, and in our organization, we have approximately 20 people, including management.
How are customer service and technical support?
Technical support is good.
Which solution did I use previously and why did I switch?
I have used Tenable Nessus previously for my personal projects. I used it for scanning for my projects in college.
How was the initial setup?
I was not involved in the installation. It was already installed previously.
What's my experience with pricing, setup cost, and licensing?
Licensing fees are paid on a yearly basis.
What other advice do I have?
I would recommend this solution to others, but more integration features would be more helpful.
I would rate Rapid7 InsightVM an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
CoFounder & Head of Technology at intuity
Professional support, absolutely stable, and easy to use and deploy
Pros and Cons
- "I really love the new platform. It is really easy to understand, use, and deploy."
- "It would be great to have a mobile application client. Currently, you have to use a mobile web browser on a device, but it is not similar to the desktop web browser in terms of user experience. It would be nice to have a mobile application to access the platform."
What is our primary use case?
We are using InsightVM for vulnerability management services. We use it for providing professional services to our customers, and we also use it for our internal use.
We do on-premises and cloud deployments.
What is most valuable?
I really love the new platform. It is really easy to understand, use, and deploy.
Their support is very professional and good at troubleshooting issues.
What needs improvement?
It would be great to have a mobile application client. Currently, you have to use a mobile web browser on a device, but it is not similar to the desktop web browser in terms of user experience. It would be nice to have a mobile application to access the platform.
It would be nice to have someone in the technical support team who speaks Italian.
For how long have I used the solution?
We have been in a partnership with Rapid7 for five years.
What do I think about the stability of the solution?
It is absolutely stable.
What do I think about the scalability of the solution?
It is scalable. We have 40 customers who are using this solution.
How are customer service and technical support?
Their technical support is great, but it would be nice to have someone in the technical support team who speaks Italian.
We speak Italian with Safeguy. So, sometimes, Safeguy's technical teams also help us.
How was the initial setup?
Its initial setup is easy and quick. We are typically able to deploy it in a couple of hours.
We have 15 certified and dedicated engineers to handle its deployment and maintenance.
What's my experience with pricing, setup cost, and licensing?
In some cases, we procure the licenses. In some cases, the customers directly buy the license from Rapid7.
What other advice do I have?
I would rate Rapid7 InsightVM a nine out of 10.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Head of Cybersecurity Assurance & Controls Director at a tech services company with 1,001-5,000 employees
Poor reporting, lacking in features, but the technical support is not bad
Pros and Cons
- "I have been in contact with technical support and they are not bad."
- "The reporting is very bad when you compare it with other vulnerability assessment tools."
What is our primary use case?
I primarily using Rapid7 for vulnerability assessment and reporting.
How has it helped my organization?
At this point, we are not happy with Rapid7.
What needs improvement?
The reporting is very bad when you compare it with other vulnerability assessment tools.
This product is for basic vulnerability assessments, only, and is lacking in features such as compliance, assessment, assets, inventory, and batch management.
For how long have I used the solution?
I have been using Rapid7 InsightVM for five years.
What do I think about the scalability of the solution?
I would say that the scalability is 50-50. It does not offer much in terms of being able to scale. We have approximately 3,000 users.
How are customer service and technical support?
I have been in contact with technical support and they are not bad.
What's my experience with pricing, setup cost, and licensing?
Comparing the price with the value that we receive, I am not happy with it.
Which other solutions did I evaluate?
We are currently looking to replace Rapid7 with another product.
Currently, we are working with Tenable Nessus and Qualys.
What other advice do I have?
I would rate this solution a five out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Owner at a tech services company with 1-10 employees
Understands and defends your network from vulnerabilities
Pros and Cons
- "I liked the dashboard on it. I could customize my dashboard with different widgets and different heat maps."
- "I would say that it improved our visibility, but it left things open."
What is our primary use case?
We used InsightVM mainly for vulnerability management. I thought it was a pretty interesting application. I'm a fan of Rapid7's Metasploit, so when I saw InsightVM I was like, "Let's see what else they have." I liked it up until we experienced some issues relating to scans. If I wanted to do mitigation, I needed to wait until the next scan was available or ran so that I could get to see if any indentations were made.
While I was in there, if I was searching for a specific vulnerability, sometimes it was hard to find the specific ones. In the dashboard, it'll tell you the results from the scans, and it will also tell you the vulnerabilities and it will rank them for risk. I would have liked to have been able to click on the vulnerability and it would take me to another area that just has the vulnerability with all the hosts. It wouldn't let you do that. You had to come back out of that window and go into another window and search for it. Well, you wouldn't get the same results as the number of hosts. I had to work a little bit harder to find exactly what I needed.
Within our organization, there were two of us using it. Both of us were IT analysts. One was an IT analyst III (which was me), and the other one was the IT analyst manager.
How has it helped my organization?
I would say that it improved our visibility, but it left things open.
What is most valuable?
I liked the dashboard on it. I could customize my dashboard with different widgets and different heat maps. I liked that. That was a feature I liked. If your manager had a different dashboard that they liked, and you tried to go into a meeting and they say, "Well, I think your numbers are wrong because my dashboard says this" Well, you couldn't rapidly say, "Here's the default dashboard for this for risk." Whereas, with Tenable, you could go through a dashboard just for risks, and say, "Hey, let's switch to this dashboard so we're seeing the same numbers without customization."
What needs improvement?
They just need to fix it to make it more fluid. If it shows you vulnerabilities, I want to be able to click on the vulnerability and drill down into the vulnerability. If it's rating it as a 10 and it says it's got 30 hosts in it for this vulnerability, I want to click on that vulnerability and get a separate report that says, "Here's the vulnerability specific and here's the host involved." That way I could export it and say, "Hey, this vulnerability's out there, it matches a CVE number that is critical, that Microsoft, Cisco, whatever, has put a patch out there, and here guys, here's what it is and here's the proof. Here's your host that's vulnerable. Here's a change request, fix it, send me back the proof that you fixed it, then allow me to rerun a scan specific to that, on-demand, to say 'Yes, boss, we have mitigated it.'"
I want to be able to just drill down on the reports. If it showing me there's a vulnerability and there's a said number of nodes that's vulnerable to it, I want to be able to drill down and export that list without having to come back out of it, going into my assets, trying to find the name of the vulnerability, which doesn't match what the dashboard says. To me, that was backward.
For how long have I used the solution?
I have used this solution for one year.
What do I think about the stability of the solution?
It was pretty stable. We didn't have any real hiccups, but it was stable. We didn't have any real hiccups there.
What do I think about the scalability of the solution?
As far as I know, it says it's scalable. I'm not sure if that company I used to work for had to scale it up or down.
How are customer service and technical support?
The tech support was very helpful. Actually, I knew a couple of them so it was very helpful.
I would give their tech support a rating of 10 — I knew them from using Metasploit and some other products. It was more of a, "Hey, I got this issue, how can you help me with it?" They'd point me and say, "Hey, check this out."
How was the initial setup?
I wasn't involved in the initial setup, so I can't comment on that.
What other advice do I have?
Do your proof of concepts if you can. Make sure you develop your risk strategy. That's important, because it's going to give you a risk number, it's going to give you critical: highs, mediums, but you need to understand what is the risk methodology that you're going to follow. Just because it says it's critical because of how many vulnerabilities you have, doesn't mean that you need to work on it right away.
For example, there was a vulnerability that had 2,000 nodes affected. It put it as a high-risk, whereby there was another vulnerability where there were only about 10 hosts affected — it put it at medium-risk. However, the high-risk one, because it had more nodes affected, did not have a POC associated with it. A novice person looking at it would say, "I need to work on these 1,000 vulnerabilities because it's a high-risk, and ignore the medium." Well, the medium one had an active POC on it. If you didn't have a person who understood how to read the report and what it's actually telling you, then you would say, "Hey, you know what, I'm going to use these, I'm going to cut my risk down because I got 1,000 nodes with this vulnerability and I'm going to put this chain out real quick and I'm going to reduce my risk real quick because of the numbers." Well, in my opinion, you didn't reduce your risk because you have 10 nodes out there with a vulnerability that's rated medium and it has a POC on it.
Overall, on a scale from one to ten, I would give this solution a rating of eight. I'm going to say that is because shame on Rapid7 for having such great applications, but then that little piece there that they know about hasn't been fixed. If I remember, if I go probably log back into the community, it's probably been asked a couple of times.
Which deployment model are you using for this solution?
Private Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Buyer's Guide
Download our free Rapid7 InsightVM Report and get advice and tips from experienced pros
sharing their opinions.
Updated: May 2025
Product Categories
Risk-Based Vulnerability ManagementPopular Comparisons
Qualys VMDR
Tenable Security Center
Tenable Vulnerability Management
Microsoft Defender Vulnerability Management
Nucleus
Arctic Wolf Managed Risk
Cisco Vulnerability Management (formerly Kenna.VM)
SanerNow CyberHygiene Platform
Balbix BreachControl
SecureWorks Taegis VDR
Fortra's Vulnerability Management
Buyer's Guide
Download our free Rapid7 InsightVM Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions: