What is our primary use case?
Rapid7 InsightCloudSec's main use case for our organization is to maintain our cloud security posture, and we typically depend on a platform named
AWS to monitor it and implement all the security features suggested by
Rapid7 InsightCloudSec.
Recently, we had a bunch of
AWS roles and
S3 bucket policies that were overly permissive, which were suggested by Rapid7 InsightCloudSec. After considering their suggestions, we limited the AWS policies and downsized all overly excessive permissions to only what's necessary.
We are also using Rapid7 InsightCloudSec for other use cases, such as managing the whole networking structure of our AWS account, including VPC, subnetting, and ensuring the whole cloud security posture aligns with how it should be.
What is most valuable?
Rapid7 InsightCloudSec's best features include the immediate suggestions and support provided, as well as real-time visibility across multiple cloud environments, risk-based prioritization, automated cloud compliance, policy enforcement, and best practices for
Infrastructure as Code security.
The automated compliance enforcement has helped our team significantly in cloud infrastructure entitlement management and maintaining the whole
IAM governance as well as the container and
Kubernetes security postures, plus conducting vulnerability assessments and generating comprehensive reports.
One of the best features is the agentless cloud-native vulnerability management plus cloud workload protection, as Rapid7 InsightCloudSec provides native vulnerability scanning for cloud workloads, containers, and VMs without needing an agent, simplifying deployment and reducing overhead.
It has positively impacted our organization by changing the whole efficiency, especially after updating our patching process to meet the CIS benchmark that was previously under-provisioned. This change uplifted our CIS compliance score. After implementing Rapid7 InsightCloudSec, we increased our CIS benchmark score from 48 to around 88 after addressing missing patches on some VM instances, indicating a significant positive impact.
What needs improvement?
I currently do not have any specific suggestions for improvements, as I am still exploring the full capabilities of Rapid7 InsightCloudSec, but I wish the UI and UX for reporting could be more straightforward, simplifying the process of creating matrices and dashboards.
For how long have I used the solution?
I have been working in my current field for the past three and a half years.
What do I think about the stability of the solution?
Rapid7 InsightCloudSec seems very stable, having been deployed in production systems without causing any issues.
What do I think about the scalability of the solution?
Rapid7 InsightCloudSec is scalable, as it effectively monitors resources regardless of how much we scale up.
How are customer service and support?
I interacted with customer support after an endpoint compromise incident, and they responded quickly and provided clear insights that were essential for resolving the situation.
I would rate customer support a nine, as there is always room for improvement, but they have been generally impressive.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
We previously used CyberArk and Sysdig, but we switched to Rapid7 InsightCloudSec for its comprehensive monitoring capabilities across our cloud security, as the previous solutions focused on specific areas and we needed a more general approach.
How was the initial setup?
I advise others considering Rapid7 InsightCloudSec to integrate it into their organization. While there may be upfront costs for setup, it pays off in long-term security benefits and risk reduction from breaches.
What was our ROI?
Rapid7 has provided us with a good return on investment, helping us plan migrations from outdated virtual machines to up-to-date, secure systems, which has led to savings in infrastructure costs and reduced the need for a large cybersecurity team.
What's my experience with pricing, setup cost, and licensing?
The pricing has been equivalent to the features provided. While it was not overly expensive, I do wish for more discounts for bulk purchases since we have implemented it widely across our cloud security posture. The setup cost was manageable, and the licensing process is seamless.
Which other solutions did I evaluate?
Before choosing Rapid7 InsightCloudSec, we did not evaluate other options thoroughly. While we had a few POC integrations with
Snyk, they were not as effective as Rapid7 InsightCloudSec.
What other advice do I have?
Everything is under control for the cloud security postures at this time. My overall review rating for Rapid7 InsightCloudSec is eight.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)