No more typing reviews! Try our Samantha, our new voice AI agent.

Proofpoint Insider Threat Management vs Rapid7 InsightIDR comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Feb 4, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Proofpoint Insider Threat M...
Ranking in User Entity Behavior Analytics (UEBA)
7th
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
6
Ranking in other categories
User Activity Monitoring (3rd), Insider Risk Management (4th)
Rapid7 InsightIDR
Ranking in User Entity Behavior Analytics (UEBA)
11th
Average Rating
8.4
Reviews Sentiment
7.1
Number of Reviews
33
Ranking in other categories
Security Information and Event Management (SIEM) (24th), Endpoint Detection and Response (EDR) (34th), Threat Deception Platforms (4th), Extended Detection and Response (XDR) (19th)
 

Mindshare comparison

As of August 2026, in the User Entity Behavior Analytics (UEBA) category, the mindshare of Proofpoint Insider Threat Management is 5.4%, up from 5.4% compared to the previous year. The mindshare of Rapid7 InsightIDR is 4.6%, down from 9.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
User Entity Behavior Analytics (UEBA) Mindshare Distribution
ProductMindshare (%)
Proofpoint Insider Threat Management5.4%
Rapid7 InsightIDR4.6%
Other90.0%
User Entity Behavior Analytics (UEBA)
 

Featured Reviews

reviewer1271289 - PeerSpot reviewer
Cyber Security Leader at a tech services company with 201-500 employees
Good value, easy to use, and easy to deploy
In terms of what can be improved, that is a question I think the end users can tell you better. I'm not the end-user for this system. However, I can say that it needs to be more scalable. I think they already have a good value proposition in terms of being a hybrid model, and the reporting is okay, as well. It could have better integration with other SIEMs, but this integration has to come from the SIEM side, not ObserveIT.
Prajwal Chougale - PeerSpot reviewer
System Analyst at a tech services company with 51-200 employees
Centralized threat hunting has improved alert accuracy and simplifies incident investigations
I would say there are two areas for improvement: the reporting dashboard that provides insights or reports weekly or monthly lacks detailed information about how logs are being ingested. While the details are there, they could be more concise and easier to understand for any level of authority. The second area is alert tuning; compared to Microsoft Sentinel, Rapid7 InsightIDR provides fewer alerts with more static alert functionality and lacks dynamic alerting exposures. There could be improvements to learn from past alert activities for more dynamic alert configurations. These two areas are the main areas for improvement; everything else is good.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Customer Service: The ObserveIT professional services team has been excellent, extremely engaged and genuinely concerned with our success."
"It resolved security issues of the organization by providing audit reports and records to our customers."
"ObserveIT is small, easy to use, easy to deploy, and is not complicated, so it's more generally suited for only SMBs. It's a good value with a cheaper price."
"Meta data search Alert generation."
"Overall, it gives a consistent and really good return on investment."
"Record videos that have a very small file size Management interface is very convenient and intuitive"
"All my clients are very pleased with this product as it helps them to keep track of what partners and employees are doing on the servers."
"Rapid7 InsightIDR integrates well with other solutions. It's also easy to configure because Rapid7 InsightIDR has a lot of instructions posted on their website that customers can follow if they need to get the source log."
"The solution provides satisfying native integration features"
"It is a very stable solution."
"The solution is easy to use, and the interface is intuitive."
"Very intuitive and easy to set up."
"I like the tool's user analysis feature."
"Log search allows us to dive deep into aggregated logs and query all event types at once.​"
"We were able to identify criminals attempting to login from China and put a stop on their IP locations."
 

Cons

"The tool is still not providing records of tunnels established - we would like to see it in future versions."
"Ticketing and issue management. Based on the new system, one needs to go through the sales people."
"ObserveIT is not scalable and it's not for the medium to large corporations. It's for the smaller environments. For the larger corporations, we have other scalable solutions."
"OCR capability, support for Mainframe, Ticketing and Incident workflow."
"I had some problems with an instance of ObserveIT in a Proof of Concept, when I installed ObserveIT with an SQL Express instance and the DB used all provisioned space."
"I would like the ability to adjust the threshold of certain existing alerts. Currently the only option is to change the notifications or create my own alert."
"The main problem lies in the processes within the client's operating systems."
"One of the things that could be better is digital forensics. It is there, but it can be better. They could provide more on the endpoint detection level."
"The product allows us to make only 30 custom rules."
"One thing that springs to mind is easier API integration with ITSMs. We are evaluating a new ITSM and I would like to have InsightIDR create a ticket when an attack is identified, and the ticket would be closed in InsightIDR when the ITSM resolution is completed. This would take out the "single point of failure" we currently have, if the email recipient is somehow absent, in recording the risk appetite for the incident and the actions taken to mitigate or not."
"Rapid7 doesn't integrate well with all our security tools from various vendors, so we plan to switch. Many of our solutions work with Rapid7, but some do not. We are already searching for a replacement already."
"Sometimes, it is hard to get the right queries to use. Currently, the tool lacks a pre-made set of queries."
"Rapid7's customer support is awful. They didn't respond at all."
 

Pricing and Cost Advice

Information not available
"It is more reasonably priced than other vendors."
"Rapid7 InsightIDR's pricing is reasonable but we have challenges with the Minimum Order Quantity. It is not reasonable for customers who have less than one hundred devices. If they can reduce Minimum Order Quantity, it is good. You have to pay around 5000-6000 dollars per year for the product. The pricing includes maintenance and support costs."
"​Accurately predict your licensing counts as this is a subscription based product.​"
"It is on a yearly basis. For our own company, for about 250 users, it was 16,000 euros a year."
"Rapid7 InsightIDR is priced very well and is cost-effective."
"The team is very willing to work with companies. My suggestion is to call the Rapid7 sales department and see how they can help.​"
"Rapid7 InsightIDR is a cheaply priced product. On a scale of one to ten, where one is very expensive, and ten is very cheap, I rate the product's price at seven or eight."
"​I am sure that there are cheaper products out there, but none that meet so many of our needs whilst maintaining stability and usability.​"
report
Use our free recommendation engine to learn which User Entity Behavior Analytics (UEBA) solutions are best for your needs.
909,099 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Construction Company
11%
Media Company
8%
Comms Service Provider
8%
Performing Arts
8%
Manufacturing Company
9%
Financial Services Firm
9%
Comms Service Provider
7%
Computer Software Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
By reviewers
Company SizeCount
Small Business22
Midsize Enterprise5
Large Enterprise6
 

Questions from the Community

Looking for recommendations and a pros/cons template for software to detect insider threats
In addition to responsesfrom Xavier Suriol and reviewer1324719, also consider ObserveIT from Proofpoint.
Looking for recommendations and a pros/cons template for software to detect insider threats
Hello All,I hope you had a merry Christmas.In this case it is as simple as it is.Just take Proofpoint ObserveIT - many companies in the public and financial sector have been using it for years.By ...
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What is your experience regarding pricing and costs for Rapid7 InsightIDR?
My experience with pricing, setup costs, and licensing has been very positive; it is cost-effective and offers great value for the money. We bought the licensing through an agent, and the setup was...
What needs improvement with Rapid7 InsightIDR?
I would say there are two areas for improvement: the reporting dashboard that provides insights or reports weekly or monthly lacks detailed information about how logs are being ingested. While the ...
 

Also Known As

ObserveIT
InsightIDR
 

Overview

 

Sample Customers

Coca Cola, Allianz, Premiere League, Xerox, AIG, Cigna, Starbucks, Revlon, Toshiba, Nissan and more.
Liberty Wines, Pioneer Telephone, Visier
Find out what your peers are saying about Proofpoint Insider Threat Management vs. Rapid7 InsightIDR and other solutions. Updated: August 2026.
909,099 professionals have used our research since 2012.