There are so many cases for InsightVM. It's used for customers that need the ICS compiler or if they need users to work from home right now. It allows them to manage assets from anywhere.
Network & Security Engineer at a comms service provider with 11-50 employees
Reliable, easy to set up, and has good active scan capabilities
Pros and Cons
- "It's very scalable."
- "We'd like the agent to cover more compliance issues."
What is our primary use case?
What is most valuable?
Using active scan is good.
If you have a history with the solution, the initial setup is easy.
The solution is stable and reliable.
It's very scalable.
What needs improvement?
The agent must be covered if the customer wants to do a combined thing. InsightVM cannot do that if they are using an agent. We'd like the agent to cover more compliance issues.
For how long have I used the solution?
I've been using the solution for three or four years.
Buyer's Guide
Rapid7 InsightVM
January 2026
Learn what your peers think about Rapid7 InsightVM. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,082 professionals have used our research since 2012.
What do I think about the stability of the solution?
The product is stable. There aren't bugs or glitches. It doesn't crash or freeze. It's reliable and the performance is good.
What do I think about the scalability of the solution?
If you want to scan more than 1,000 assets, then we need to show the requirement first. It will use the server with maximum CPU, and maximum RAM. The scalability is quite higher than on the previous one we used. It keeps getting better.
How was the initial setup?
Typically, the initial setup is easy. If a user has the experience, it is straightforward. However, if we work together with an organization that has never used it before, there's more configuration that needs to be done.
What other advice do I have?
We're working with the latest version of the solution, however, I cannot recall the exact version number.
While our clients are using a hybrid cloud, the customers still need to install on-premise. Your console right now is like a dashboard; it's moved to the cloud.
I'd advise users to try the solution. If they are using InsightVM they will be able to quickly understand what the vulnerabilities are on their assets.
I'd rate the solution eight out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Google
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Enterprise Security Architect at a energy/utilities company with 10,001+ employees
Provides good assessment, but the effectiveness of scans can be better
Pros and Cons
- "The assessment is most valuable."
- "Their customer support should be improved, and the effectiveness of scans also needs to be improved."
What is our primary use case?
We implemented it to scan all the assets. In terms of deployment, in my previous organization, it was deployed on-prem, but in my current organization, it is on the cloud.
What is most valuable?
The assessment is most valuable.
What needs improvement?
Their customer support should be improved, and the effectiveness of scans also needs to be improved.
For how long have I used the solution?
I am an implementor. I have been working with this product from time to time. I started working with it around 2016 for a project. After that, we implemented it in 2019 for another project. Currently, I am not using it, but it is being used in the organization.
What do I think about the stability of the solution?
Its stability is fine.
What do I think about the scalability of the solution?
Its scalability is okay. We have approximately 3,000 members. Every asset gets scanned. So, indirectly or directly, everyone is using this product.
We plan to keep using this tool. We don't want to get into another scanning tool right now. It has been selected as an enterprise tool, and we aren't going to move to another tool. Any new employees would get added to this tool.
How are customer service and support?
Their support could be better. I would rate them a three out of five.
Which solution did I use previously and why did I switch?
We were using Qualys. We switched because of the organization's standard.
How was the initial setup?
It is not complex. I would rate it a three out of five in terms of the ease of the setup.
What other advice do I have?
I would rate this solution a seven out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Rapid7 InsightVM
January 2026
Learn what your peers think about Rapid7 InsightVM. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,082 professionals have used our research since 2012.
Material Coordinator at a energy/utilities company with 1,001-5,000 employees
Useful reports, stable, and good vendor support
Pros and Cons
- "The reports in Rapid7 InsightVM are useful when compared to competitors."
- "Rapid7 InsightVM could be easier to use for those who are using it for the first time."
What is our primary use case?
We are using Rapid7 InsightVM to have a vulnerability assessment solution in our organization to overcome the audit points.
How has it helped my organization?
We are at the stage where we are deciding if the solution will be useful for us or not.
We generate the reports for our IT sessions and try to take the recommended actions. After the action is made, we generate another report to check if this action covers the vulnerability points or not.
What is most valuable?
The reports in Rapid7 InsightVM are useful when compared to competitors.
What needs improvement?
Rapid7 InsightVM could be easier to use for those who are using it for the first time.
The updates should be fixed in the next release.
For how long have I used the solution?
I have been using Rapid7 InsightVM for a few months.
What do I think about the stability of the solution?
The stability of Rapid7 InsightVM has been fine in the three months we have used it.
What do I think about the scalability of the solution?
We are using a virtual environment with Rapid7 InsightVM and we can expand it if we want.
We have approximately three people using this solution in my company. We use the solution weekly or monthly. We would increase the use of the solution if our tests go well.
How are customer service and support?
The support that we are receiving at this time is from our partner who handles the issue with the vendor if needed.
How was the initial setup?
The initial setup was not straightforward because it was our first time doing it.
We did a POC first and this took us two months to make the environment. After we received the license we went into production.
What about the implementation team?
We had a partner help us with the implementation of Rapid7 InsightVM.
We have an IT department that does the maintenance and support of Rapid7 InsightVM.
What's my experience with pricing, setup cost, and licensing?
We have an annual license to use Rapid7 InsightVM and if we want to extend it, we will possibly choose more than one year.
What other advice do I have?
I recommend this solution to others and for them to use a partner for the implementation. It can be difficult for the first time.
I rate Rapid7 InsightVM an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Owner at a computer software company with 11-50 employees
A stable enterprise solution that can automatically detect new devices and scan them for vulnerabilities
Pros and Cons
- "When you connect any new device to the network, Rapid7 has the ability to detect the new device immediately. It can scan that device to detect if it has any vulnerability. It tells you what is vulnerable and what has been misconfigured. It also tells you what is the risk of that misconfiguration or lack of patches and how to resolve the problem."
- "In terms of improvements, its price could be better. Our main issue with Rapid7 is that it is too expensive. You can only sell it to enterprise accounts. In terms of new features, Rapid7 came up with a product called InsightIDR a couple of years ago, which is a good SIEM solution. We expect that Rapid7 will work on some sort of integration between InsightVM and InsightIDR, where vulnerability or anomaly detected by InsightVM can be reported in InsightIDR in some sort of real-time. Rapid7 doesn't patch. For example, if you have a vulnerability, some products can scan and also do the patching, but Rapid7 does not do the patching. It would be nice if it can also patch."
What is our primary use case?
We are system integrators. Our clients normally use it to detect vulnerabilities in terms of a lack of patches in certain systems and databases. Its console can be installed on-premise or on the Rapid7 data center.
What is most valuable?
When you connect any new device to the network, Rapid7 has the ability to detect the new device immediately. It can scan that device to detect if it has any vulnerability.
It tells you what is vulnerable and what has been misconfigured. It also tells you what is the risk of that misconfiguration or lack of patches and how to resolve the problem.
What needs improvement?
In terms of improvements, its price could be better. Our main issue with Rapid7 is that it is too expensive. You can only sell it to enterprise accounts.
In terms of new features, Rapid7 came up with a product called InsightIDR a couple of years ago, which is a good SIEM solution. We expect that Rapid7 will work on some sort of integration between InsightVM and InsightIDR, where vulnerability or anomaly detected by InsightVM can be reported in InsightIDR in some sort of real-time.
Rapid7 doesn't patch. For example, if you have a vulnerability, some products can scan and also do the patching, but Rapid7 does not do the patching. It would be nice if it can also patch.
For how long have I used the solution?
We have been working with this solution for the last three years or so.
What do I think about the stability of the solution?
It has been stable. There is nothing that has caused any major damage to our customers. Normally, what happens is that when something goes wrong, the customer normally blames the tool first before admitting that they touched something or whatever the case may be.
What do I think about the scalability of the solution?
We have a couple of customers with various company sizes, and we haven't had any scalability issues. Rapid7 is pretty much an enterprise solution. We're talking about customers with more than 1500 nodes to scan.
How are customer service and technical support?
Their technical support is very good.
How was the initial setup?
I don't handle the installation, but it was not difficult to implement. The basic setup took us about four days or so.
Normally, for a product like this, the complexity of implementation is proportional to the size of the infrastructure that is going to be scanned and also how heterogeneous it is. An enterprise product like this is not like using a coffee maker. You need to have some knowledge of where you are installing it. You also need to have some knowledge of the technology that you are going to scan. You can't scan everything in the same way.
What's my experience with pricing, setup cost, and licensing?
Its price is too high. My only concern or issue with Rapid7 is its pricing.
Which other solutions did I evaluate?
Our clients evaluate Qualys, Tenable, and Rapid7. It doesn't really matter which one you choose. You cannot go wrong with all of these products. They have been very well ranked by Gartner. The main difference is probably the pricing.
What other advice do I have?
I would recommend this solution. I would rate Rapid7 InsightVM an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Security Specialist at a financial services firm with 1,001-5,000 employees
Simple to install, user interface is both professional and user-friendly
Pros and Cons
- "This solution's most useful feature is that it is entirely a single-page application."
- "The drawback is that it is still not a fully SaaS solution, so you must deploy a console."
What is our primary use case?
We use Rapid7 InsightVM to increase vulnerability scanning, which is why we tried Qualys as well.
What is most valuable?
This solution's most useful feature is that it is entirely a single-page application.
The UI is both professional and user-friendly.
What needs improvement?
The drawback is that it is still not a fully SaaS solution, so you have to deploy a console.
For how long have I used the solution?
I have been working with Rapid7 InsightVM for six weeks.
What do I think about the stability of the solution?
Rapid7 InsightVM is stable.
What do I think about the scalability of the solution?
Rapid7 InsightVM is a scalable solution.
How are customer service and support?
We have two dedicated technicians to assist us.
Which solution did I use previously and why did I switch?
We are also testing Qualys. If you look at both options, I believe they are the same. Both are in the top market leader position.
Both tools have the same features. The most essential consideration in choosing one of those two experiences with it and whether it fits inside your business.
I can't decide, we are still in the comparison phases.
How was the initial setup?
It is very easy to set up.
It can be deployed in a matter of weeks.
What's my experience with pricing, setup cost, and licensing?
It is pretty expensive. It depends on what you consider pricey, however, if you only look at vulnerability management solutions, such as within VM or VMDR, there are, I suppose the prices are almost the same. But I believe you will discover that for yourself.
What other advice do I have?
Experiment with it and gain some experience with it.
I would rate Rapid7 InsightVM an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT Security Engineer at a financial services firm with 51-200 employees
Reliable, easy to set up, and has a good remediation feature
Pros and Cons
- "The solution scales well."
- "There was functionality present previously, however, currently, we can't integrate directly with Jira Service Desk - only the cloud version."
What is our primary use case?
We primarily use the solution for vulnerability management and monitoring the progress of the remediation process.
What is most valuable?
The remediation feature has been quite useful.
It's easy to set up the solution.
It's stable.
The solution scales well.
What needs improvement?
The solution isn't missing any features, and I haven't noticed any shortcomings.
There was functionality present previously, however, currently, we can't integrate directly with Jira Service Desk - only the cloud version. That, or we must share to the internet on-prem Jira Service Desk. It's not easy for us since we use only the on-prem Service Desk service, and we don't straight to the internet for our service.
InsightVM can only directly connect to the internet. So, we can't use this integration and send tasks to our technical team from InsightVM. We, therefore, need better integration with Jira Service Desk.
What do I think about the stability of the solution?
The stability has been good overall. I would rate it five out of five in terms of reliability. The performance is good. There are no bugs or glitches, and it doesn't crash or freeze.
What do I think about the scalability of the solution?
The solution is suitable for big or small organizations. We have clients of different sizes using the product.
It's used at the engineering level, with security and administrators using it regularly.
I'd rate it five out of five in terms of the ease of scaling.
How was the initial setup?
The solution is straightforward to set up. I'd rate it four out of five in terms of ease of implementation.
We have one or two team members that can set up the solution.
How long it takes to deploy depends on the customer. For a small customer, it's less than one month or sometimes two weeks. For a big customer with many assets and services, it takes two or three months to deploy.
We only need to have one or two people on hand to handle maintenance tasks.
What's my experience with pricing, setup cost, and licensing?
The solution is not overly expensive.
What other advice do I have?
We use this solution for our clients.
We're dealing with the latest version of the product.
InsightVM is a solution based on on-prem infrastructure connected to the cloud service, so it's a hybrid solution.
Overall, it's a nice tool.
I'd rate the solution nine out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Service Delivery Manager at a security firm with 11-50 employees
Easy to deploy and flexible licensing but the reporting could be better
Pros and Cons
- "The product is scalable."
- "The reporting could be better."
What is our primary use case?
We primarily use the solution for vulnerability management.
What is most valuable?
From a scanning perspective, it’s great. The customization associated with each and every scan is very good. It actually provides functionality from a CIS control perspective as well.
It is easy to deploy.
The product is scalable.
The solution is very stable.
What needs improvement?
The reporting could be better.
We do not need any additional features.
For how long have I used the solution?
I’ve been using the solution for two years.
What do I think about the stability of the solution?
The solution is very stable. The reliability is good. There are no bugs or glitches. It doesn’t crash or freeze.
What do I think about the scalability of the solution?
The solution is absolutely scalable.
From a footprint perspective, there are about 780 servers. In totality, there's a license entitlement for about 1000 clients.
How are customer service and support?
Technical support has been accurate.
How would you rate customer service and support?
Neutral
How was the initial setup?
The solution is straightforward to set up and simple to deploy. It’s not overly complex. We only need one technical person to handle the setup process.
How long it takes to deploy depends on multiple instances whereby multiple factors, depending on client, on-prem, et cetera. Your average deployment time would be anything from three to five days.
What about the implementation team?
As partners, we can handle the implementation.
What was our ROI?
The ROI is fair to mild.
What's my experience with pricing, setup cost, and licensing?
The licensing is market-related.
The cost depends on the number of assets per annum.
It is very flexible. What's nice about it is, from a client's perspective, the environment can either grow and you can chew up, or it can shrink, and it meets whatever needs you have.
The licensing includes technical support.
What other advice do I have?
We’re partners.
We’re always using the latest version of the solution.
There's a mix of deployments. There's an on-prem deployment in certain customer areas. However, there's also a cloud deployment from the MSSV point of view as well.
The scanner is always on-prem. The majority of the scanners that we've deployed are on-prem. Although some of the consoles are selling cloud-deployed, other consoles would be on-prem.
I’d rate the solution seven out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Senior Manager Cyber Security Services & Solutions at a tech vendor with 11-50 employees
User-friendly and customizable with great risk scoring feature
Pros and Cons
- "InsightVM's most valuable feature is risk scoring, a formula based on different vectors like the ease of exploitation and the availability of the machine."
- "InsightVM could be improved by providing passive scanning as an option."
What is our primary use case?
InsightVM is mainly used for vulnerability management.
What is most valuable?
InsightVM's most valuable feature is risk scoring, a formula based on different vectors like the ease of exploitation and the availability of the machine. It can be customized according to the customer's needs - for example, if they have an asset that is more vulnerable, they can adjust the risk score according to their infrastructure. It also has a very robust dashboard system and good integration.
What needs improvement?
InsightVM could be improved by providing passive scanning as an option. They could also introduce license packages for fewer than 128 users for smaller organizations.
For how long have I used the solution?
I've been using InsightVM for almost five years.
What do I think about the stability of the solution?
InsightVM is stable.
What do I think about the scalability of the solution?
InsightVM has the option of implementing the scan engine separately, which helps with scalability.
How are customer service and support?
InsightVM's technical support is very good.
How would you rate customer service and support?
Positive
How was the initial setup?
InsightVM is easy to implement and deploy, even for small and medium businesses.
What's my experience with pricing, setup cost, and licensing?
InsightVM's licensing starts at a minimum of 128 IPs and can scale up to over 1,000.
What other advice do I have?
InsightVM is easy to use, has a well-defined dashboard, and can be customized according to your needs. You can also segregate your assets and define IP ranges. I would give InsightVM a rating of nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Integrator
Buyer's Guide
Download our free Rapid7 InsightVM Report and get advice and tips from experienced pros
sharing their opinions.
Updated: January 2026
Popular Comparisons
Microsoft Defender for Cloud
Qualys VMDR
Tenable Nessus
Tenable Security Center
Orca Security
Tenable Vulnerability Management
Acunetix
FortiCNAPP
Microsoft Defender Vulnerability Management
The NodeZero Platform by Horizon3.ai
Red Canary
Buyer's Guide
Download our free Rapid7 InsightVM Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:

















