Try our new research platform with insights from 80,000+ expert users

Rapid7 InsightVM vs SecurityScorecard comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
6.0
Rapid7 InsightVM is praised as a cost-effective cybersecurity tool for preventing attacks and enhancing system defenses.
Sentiment score
6.1
SecurityScorecard enhances security visibility and efficiency, improving scores and reducing premiums, yielding 176% ROI over three years.
This resulting in a lower insurance premium cost for us and considerable cost savings overall, which made our management very pleased with the progress.
Application security engineer at a media company with 51-200 employees
The biggest benefit is visibility, allowing organizations to understand their risks, vulnerabilities, and potential threats.
Regional Director at a tech services company with 51-200 employees
We have seen a clear return on investment, and in terms of the metrics, the time saver is in the reduction of time spent.
SOC analyst at BUSINESS IT
 

Customer Service

Sentiment score
6.7
Rapid7 InsightVM receives positive customer service reviews, with praise for quality but suggestions to improve response times.
Sentiment score
7.4
SecurityScorecard's customer support is knowledgeable and available 24/7, but users report delayed response times despite improvements.
Support is not available promptly, especially when issues are escalated to another region.
Head Of Cyber Security at Super Secure
Sometimes support requests coincide with holidays in their support region, causing slight delays.
Professional services team lead at a tech services company with 1,001-5,000 employees
I cannot comment specifically regarding the support part because I have never needed Rapid7 support for the InsightVM solution as it is very stable.
Senior Manager - Pre-Sales at Trillium Information Security Systems
They need better organization to support their customer volume.
Regional Director at a tech services company with 51-200 employees
they continue to assist us with bi-monthly sync-up calls whenever we face issues with the platform regarding risk and how to improve our security score
Application security engineer at a media company with 51-200 employees
I would rate the customer support for SecurityScorecard nine out of 10.
Technical Lead at M.TECH Solutions India Pvt. Ltd.
 

Scalability Issues

Sentiment score
7.5
Rapid7 InsightVM is highly scalable, seamlessly integrates expansions, and is praised for handling diverse environments and client infrastructures.
Sentiment score
6.3
SecurityScorecard offers a scalable, adaptable service ideal for medium to large enterprises, though not suited for Fortune 500 firms.
Scalability in the Rapid7 InsightVM solution is straightforward.
Senior Manager - Pre-Sales at Trillium Information Security Systems
Rapid7 InsightVM is recommended for large-scale companies with more than 30,000 users.
Enterprise Security Architect at a energy/utilities company with 10,001+ employees
According to the environment requirements, we can scale the solution as needed.
Professional services team lead at a tech services company with 1,001-5,000 employees
The product is suitable for medium to large businesses, typically with a revenue range from $200 million to a couple of billion dollars.
Regional Director at a tech services company with 51-200 employees
My experience with SecurityScorecard is that it is highly scalable and can handle more vendors or users as my organization grows.
SOC analyst at BUSINESS IT
 

Stability Issues

Sentiment score
8.1
Rapid7 InsightVM is highly stable, with minimal issues quickly resolved, and users frequently rate its reliability highly.
Sentiment score
8.2
SecurityScorecard is highly stable, rated 9/10, with 99.99% uptime, appreciated for performance speed and reliable browser extension.
We have not faced any issues with stability, and I would rate it a nine out of ten.
Professional services team lead at a tech services company with 1,001-5,000 employees
The stability of Rapid7 InsightVM is excellent.
0 at a tech vendor with 5,001-10,000 employees
There have been some challenges, especially with support response times, which affect stability.
Head Of Cyber Security at Super Secure
I find SecurityScorecard stable for our organization, as I have not encountered any downtime.
Application security engineer at a media company with 51-200 employees
 

Room For Improvement

Rapid7 InsightVM needs improvements in reporting, integrations, UI, and support, with enhanced cloud capabilities and customization options.
SecurityScorecard requires better responsiveness, remediation guidance, integration, customization, pricing, insights, accuracy, interface, mobile capabilities, and third-party risk management.
Having the ability to build our own audit file, similar to a feature in Tenable, would be beneficial.
Professional services team lead at a tech services company with 1,001-5,000 employees
The major improvement needed is prompt support.
Head Of Cyber Security at Super Secure
The current process requires manually telling IT teams to remediate vulnerabilities, and then they update the status of these vulnerabilities in the platform.
Senior Manager - Pre-Sales at Trillium Information Security Systems
If SecurityScorecard could improve anything, it would be making sure the algorithm pulls the right data for the right domain.
IT operations risk analyst at a energy/utilities company with 10,001+ employees
There is a need for more active rather than passive third-party risk management features to truly mitigate risks.
Regional Director at a tech services company with 51-200 employees
SecurityScorecard could enhance some of the integrations based on AI platforms, where I could receive suggestions from the AI tool regarding why SecurityScorecard rates specific issues as critical or high.
Application security engineer at a media company with 51-200 employees
 

Setup Cost

Rapid7 InsightVM is asset-based, scalable, and flexible with costs between $40,000-$100,000, considered competitive despite higher pricing.
SecurityScorecard's mid-range pricing and flexible setup attract enterprises, offering transparency and support, though international cost varies.
Rapid7 InsightVM is expensive, possibly one of the highest in pricing among similar products.
0 at a tech vendor with 5,001-10,000 employees
Pricing is reasonable and competitive compared to other solutions in the market.
Head Of Cyber Security at Super Secure
I would rate the pricing for Rapid7 InsightVM as eight out of ten.
Enterprise Security Architect at a energy/utilities company with 10,001+ employees
There are more expensive and cheaper options available.
Regional Director at a tech services company with 51-200 employees
I expected slightly lower pricing.
Application security engineer at a media company with 51-200 employees
Pricing is acceptable as per the Indian market.
Technical Lead at M.TECH Solutions India Pvt. Ltd.
 

Valuable Features

Rapid7 InsightVM excels with comprehensive scanning, robust reporting, ease of use, and dynamic integration, boosting effective vulnerability management.
SecurityScorecard provides continuous monitoring, risk management, and visual insights, improving compliance and security conversations with stakeholders and vendors.
It's based on the CVSS risk scoring system, which is well-recognized and effective.
Professional services team lead at a tech services company with 1,001-5,000 employees
The dashboard is excellent as it helps in visualizing our vulnerability management data.
Manager at a financial services firm with 5,001-10,000 employees
We have integrated our SIEM solutions and antivirus with each other through Rapid7.
0 at a tech vendor with 5,001-10,000 employees
It combines threat intel data with vulnerability information to increase risk ratings and provides insights into third-party supply chain risks.
Regional Director at a tech services company with 51-200 employees
I particularly value the Jira integration, so any issue identified as part of the threat intel activity can be directly updated through our Jira.
Application security engineer at a media company with 51-200 employees
It converts complex security issues into business-friendly language, which helps executives and the board understand cyber risk.
Technical Lead at M.TECH Solutions India Pvt. Ltd.
 

Categories and Ranking

Rapid7 InsightVM
Average Rating
8.0
Reviews Sentiment
6.9
Number of Reviews
66
Ranking in other categories
Vulnerability Management (7th), Risk-Based Vulnerability Management (3rd)
SecurityScorecard
Average Rating
8.2
Reviews Sentiment
6.5
Number of Reviews
13
Ranking in other categories
IT Vendor Risk Management (1st), AI Legal & Compliance (3rd), AI Procurement & Supply Chain (2nd)
 

Mindshare comparison

While both are Security Software solutions, they serve different purposes. Rapid7 InsightVM is designed for Risk-Based Vulnerability Management and holds a mindshare of 10.8%, down 13.3% compared to last year.
SecurityScorecard, on the other hand, focuses on IT Vendor Risk Management, holds 7.9% mindshare, down 11.3% since last year.
Risk-Based Vulnerability Management Market Share Distribution
ProductMarket Share (%)
Rapid7 InsightVM10.8%
Qualys VMDR12.5%
Tenable Security Center9.0%
Other67.7%
Risk-Based Vulnerability Management
IT Vendor Risk Management Market Share Distribution
ProductMarket Share (%)
SecurityScorecard7.9%
OneTrust GRC8.3%
Bitsight7.2%
Other76.6%
IT Vendor Risk Management
 

Featured Reviews

FL
Senior Manager - Pre-Sales at Trillium Information Security Systems
Offers robust compliance features but needs improved automation in remediation
The automation capability remediation needs improvement. The current process requires manually telling IT teams to remediate vulnerabilities, and then they update the status of these vulnerabilities in the platform. This basic feature that Rapid7 calls an automated remediation process is actually manual. We can update the status of vulnerabilities in the Rapid7 InsightVM platform and collectively see how many vulnerabilities we have identified and how many are remediated by our IT team. More automation in the remediation feature is a basic demand from many customers. The remediation part and vulnerability identification of network devices or rigid devices are not currently supported by Rapid7 InsightVM. More integration and automation are the two areas Rapid7 needs to improve in their product.
AG
Application security engineer at a media company with 51-200 employees
Vendor risk monitoring has strengthened our security posture and reduced insurance costs
In terms of improvements, I feel SecurityScorecard could enhance some of the integrations based on AI platforms, where I could receive suggestions from the AI tool regarding why SecurityScorecard rates specific issues as critical or high. Details on the technical mitigation would help my non-technical teams understand the security issues better. I think improvements could be made on the reporting side as well, such as the ability to download customizable reports. While SecurityScorecard offers various kinds of reports now, they are limited to predefined formats. Having the ability to choose specific fields for an automated report would be very helpful.
report
Use our free recommendation engine to learn which Risk-Based Vulnerability Management solutions are best for your needs.
881,665 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
12%
Manufacturing Company
10%
Computer Software Company
9%
Government
6%
Financial Services Firm
13%
Manufacturing Company
11%
Computer Software Company
10%
Insurance Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business29
Midsize Enterprise14
Large Enterprise25
By reviewers
Company SizeCount
Small Business7
Midsize Enterprise5
Large Enterprise3
 

Questions from the Community

How would you choose between Rapid7 InsightVM and Tenable Nessus?
You have full visibility across cloud, network, virtual, and containerized infrastructures with Rapid7 Insight VM. You can easily prioritize vulnerabilities using attacker analytics. Overall, Rapid...
What do you like most about Rapid7 InsightVM?
The product's initial setup phase was very easy.
What is your experience regarding pricing and costs for Rapid7 InsightVM?
My experience with pricing, setup cost, and licensing for Rapid 7 is that they are generally pretty good in terms of their pricing, their setup cost is reasonable, and licensing is among the easier...
What do you like most about SecurityScorecard?
One of its most effective features for risk identification is its enterprise-ready automation for third-party risk measurements.
What is your experience regarding pricing and costs for SecurityScorecard?
I have seen a return on investment with SecurityScorecard as it is easy to use and has saved us some time, so we do not need to do the scans on our own.
What needs improvement with SecurityScorecard?
I suggest that SecurityScorecard could be improved by giving a little more specifics on how the scanning works and how you are able to detect those IPs, including more details on the privacy side a...
 

Also Known As

InsightVM, NeXpose
No data available
 

Overview

 

Sample Customers

ACS, Acosta, AllianceData, amazon.com, biogen idec, CBRE, CATERPILLAR, Deloitte, COACH, GameStop, IBM
TriNet, USAA, Zurich, Gilt Groupe, McGraw Hill Financial
Find out what your peers are saying about Qualys, Tenable, Rapid7 and others in Risk-Based Vulnerability Management. Updated: January 2026.
881,665 professionals have used our research since 2012.