We implemented it to scan all the assets. In terms of deployment, in my previous organization, it was deployed on-prem, but in my current organization, it is on the cloud.
Enterprise Security Architect at a energy/utilities company with 10,001+ employees
Provides good assessment, but the effectiveness of scans can be better
Pros and Cons
- "The assessment is most valuable."
- "We plan to keep using this tool, and we don't want to get into another scanning tool right now because it has been selected as an enterprise tool."
- "Their customer support should be improved, and the effectiveness of scans also needs to be improved."
What is our primary use case?
What is most valuable?
The assessment is most valuable.
What needs improvement?
Their customer support should be improved, and the effectiveness of scans also needs to be improved.
For how long have I used the solution?
I am an implementor. I have been working with this product from time to time. I started working with it around 2016 for a project. After that, we implemented it in 2019 for another project. Currently, I am not using it, but it is being used in the organization.
Buyer's Guide
Rapid7 InsightVM
July 2026
Learn what your peers think about Rapid7 InsightVM. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
908,800 professionals have used our research since 2012.
What do I think about the stability of the solution?
Its stability is fine.
What do I think about the scalability of the solution?
Its scalability is okay. We have approximately 3,000 members. Every asset gets scanned. So, indirectly or directly, everyone is using this product.
We plan to keep using this tool. We don't want to get into another scanning tool right now. It has been selected as an enterprise tool, and we aren't going to move to another tool. Any new employees would get added to this tool.
How are customer service and support?
Their support could be better. I would rate them a three out of five.
Which solution did I use previously and why did I switch?
We were using Qualys. We switched because of the organization's standard.
How was the initial setup?
It is not complex. I would rate it a three out of five in terms of the ease of the setup.
What other advice do I have?
I would rate this solution a seven out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Material Coordinator at a energy/utilities company with 1,001-5,000 employees
Useful reports, stable, and good vendor support
Pros and Cons
- "The reports in Rapid7 InsightVM are useful when compared to competitors."
- "Rapid7 InsightVM could be easier to use for those who are using it for the first time."
What is our primary use case?
We are using Rapid7 InsightVM to have a vulnerability assessment solution in our organization to overcome the audit points.
How has it helped my organization?
We are at the stage where we are deciding if the solution will be useful for us or not.
We generate the reports for our IT sessions and try to take the recommended actions. After the action is made, we generate another report to check if this action covers the vulnerability points or not.
What is most valuable?
The reports in Rapid7 InsightVM are useful when compared to competitors.
What needs improvement?
Rapid7 InsightVM could be easier to use for those who are using it for the first time.
The updates should be fixed in the next release.
For how long have I used the solution?
I have been using Rapid7 InsightVM for a few months.
What do I think about the stability of the solution?
The stability of Rapid7 InsightVM has been fine in the three months we have used it.
What do I think about the scalability of the solution?
We are using a virtual environment with Rapid7 InsightVM and we can expand it if we want.
We have approximately three people using this solution in my company. We use the solution weekly or monthly. We would increase the use of the solution if our tests go well.
How are customer service and support?
The support that we are receiving at this time is from our partner who handles the issue with the vendor if needed.
How was the initial setup?
The initial setup was not straightforward because it was our first time doing it.
We did a POC first and this took us two months to make the environment. After we received the license we went into production.
What about the implementation team?
We had a partner help us with the implementation of Rapid7 InsightVM.
We have an IT department that does the maintenance and support of Rapid7 InsightVM.
What's my experience with pricing, setup cost, and licensing?
We have an annual license to use Rapid7 InsightVM and if we want to extend it, we will possibly choose more than one year.
What other advice do I have?
I recommend this solution to others and for them to use a partner for the implementation. It can be difficult for the first time.
I rate Rapid7 InsightVM an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Rapid7 InsightVM
July 2026
Learn what your peers think about Rapid7 InsightVM. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
908,800 professionals have used our research since 2012.
IT Security Analyst at a financial services firm with 1,001-5,000 employees
Could be better on the cloud side and offer more reporting, overall - recommended to check other options
Pros and Cons
- "The feature that I have found most valuable is its dashboards."
- "There is room for improvement on its cloud side. In the next release I would like to see better reporting."
- "Their customer support is really bad. On a scale of 1 to 10 I would probably give it a 1."
What is our primary use case?
We use it for vulnerability scanning.
What is most valuable?
The feature that I have found most valuable is its dashboards.
What needs improvement?
There is room for improvement on its cloud side.
In the next release I would like to see better reporting.
For how long have I used the solution?
I have been using Rapid7 InsightVM for seven years.
What do I think about the stability of the solution?
It is stable.
What do I think about the scalability of the solution?
Rapid7 InsightVM is scalable.
In my company, it is just my team of less than five people using it.
It requires one engineer for deployment and maintenance of the solution.
We do not have plans to increase the usage of the solution in the future.
How are customer service and support?
Their customer support is really bad. On a scale of 1 to 10 I would probably give it a 1.
How was the initial setup?
The initial cloud setup was difficult. It took months even though we worked with their professional services.
What about the implementation team?
We used a consultant to implement.
What was our ROI?
We had a good return, but it could be better.
What's my experience with pricing, setup cost, and licensing?
We pay 100,000 yearly.
What other advice do I have?
We are thinking about changing right now. We have always used Rapid7, but we are thinking about changing now.
My advice to anyone considering Rapid7 InsightVM is to look at the other vendors first.
On a scale of one to ten, I would give Rapid7 InsightVM a 3.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Professional services team lead at a tech services company with 1,001-5,000 employees
It performs well and is stable, but it is difficult to manage
Pros and Cons
- "The performance is good."
- "Rapid7 could be easier to manage."
- "Rapid7 could be easier to manage. When you compare it to other similar solutions, it is a bit difficult to manage."
What is our primary use case?
Rapid7 InsightVM, like Tenable, is used to enforce the vulnerability management lifecycle.
We identify the assets, scan them, prioritize them, and have a remediation plan in place to address any vulnerabilities that are discovered.
A remediator scan is performed to determine whether or not the discovered vulnerabilities have been patched.
What is most valuable?
The performance is good.
What needs improvement?
Rapid7 could be easier to manage. When you compare it to other similar solutions, it is a bit difficult to manage.
The reporting could be improved.
For how long have I used the solution?
I have been using Rapid7 InsightVM for two years.
At the time that it was used, I was using the latest version.
What do I think about the stability of the solution?
The installation is simple and quick; it only takes 10 minutes to complete.
Which solution did I use previously and why did I switch?
I have used Tenable SC and Tenable.io, and you cannot compare to Tenable SC or Tenable.io with any other vulnerability solution.
Tenable has that supremacy. It is very easy to manage and very easy to understand. You don't need any prior knowledge or experience to install it; you can do it on your own. You don't need any additional assistance or help through a search on how to install or scan your assets.
Tenable has a very powerful reporting engine but needs to be enhanced.
What other advice do I have?
Tenable is number one, Rapid7 comes second.
I would rate Rapid7 a six out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Information Security Officer at Umniah
It's smarter and more accurate from an application perspective
Pros and Cons
- "Using Rapid7, we can install a scan engine, we can do our VPN connections, and we can conduct internal scans of remote sites. We prefer the web application. It's smarter and more accurate from an application perspective."
- "The integration with other solutions like JIRA could be better. Perhaps there could be some additional updates in the next phase that could integrate with it, so then you can proceed with the VT much easier."
- "The integration with other solutions like JIRA could be better."
What is our primary use case?
We use a hybrid setup. Some dashboards and configurations are uploaded to the Cloud, and some of them are on-premises. The main engine is on-premises. We have about 12 customers and some of them are big companies.
What is most valuable?
There are a few main features that we are very happy with. Using Rapid7, we can install a scan engine, we can do our VPN connections, and we can conduct internal scans of remote sites. We prefer the web application. It's smarter and more accurate from an application perspective.
What needs improvement?
The integration with other solutions like JIRA could be better. Perhaps there could be some additional updates in the next phase that could integrate with it, so then you can proceed with the VT much easier.
For how long have I used the solution?
I've been using Rapid7 for about two years.
What do I think about the scalability of the solution?
From a scalability standpoint, it's good because they give you around 100%. If you want to increase your asset counts, for example, they give you permission for 100% above the limit that you pay for.
How are customer service and technical support?
Their support is very good. Technical support varies from person to person. Some cases have taken some time, but once it was escalated, everything was done well and the problem was solved. We've had some cases involving integration, remote sites, and some special configurations. They provided us with some support on all that.
How was the initial setup?
It's straightforward. Everything is like setting up Lego cubes. It doesn't take much time to deploy. The first deployment may take around an hour or two.
What's my experience with pricing, setup cost, and licensing?
The license could be a little bit cheaper. For all these features, you would expect to pay a little bit lower but around the same general price. Licenses are paid yearly. For some customers, we pay two years at a time, but mostly it's yearly.
What other advice do I have?
I would rate it nine out of 10.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Cyber Security Engineer at a manufacturing company with 5,001-10,000 employees
Good reporting, useful automation features, and has good technical support
Pros and Cons
- "It's a relevant management tool."
- "The report generating and the scanning are very helpful."
- "I would like to see more integration."
What is our primary use case?
We use this solution for our internal server for scanning. We can scan for vulnerabilities and locate them.
We also generate reports for the patching team. We assign tasks to the patching team.
What is most valuable?
It's a relevant management tool.
It has some useful automation features. The report generating and the scanning are very helpful.
What needs improvement?
It would be very helpful to have integration. There are many plugins that can be used for tasks that would help the visibility and be able to locate the exact problem.
I would like to see more integration.
I would also like to see more flexibility when scheduling the scans. We should be able to schedule scans when we want them to be scheduled. Currently, they have to be scheduled before a certain day of the week.
For how long have I used the solution?
I have been using Rapid7 InsightVm for six months during my internship.
What do I think about the stability of the solution?
Rapid7 InsightVM is a stable product.
What do I think about the scalability of the solution?
We have no issues with the scalability of this solution. We have a vulnerability management team of four who are using it, and in our organization, we have approximately 20 people, including management.
How are customer service and technical support?
Technical support is good.
Which solution did I use previously and why did I switch?
I have used Tenable Nessus previously for my personal projects. I used it for scanning for my projects in college.
How was the initial setup?
I was not involved in the installation. It was already installed previously.
What's my experience with pricing, setup cost, and licensing?
Licensing fees are paid on a yearly basis.
What other advice do I have?
I would recommend this solution to others, but more integration features would be more helpful.
I would rate Rapid7 InsightVM an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
CoFounder & Head of Technology at intuity
Professional support, absolutely stable, and easy to use and deploy
Pros and Cons
- "I really love the new platform. It is really easy to understand, use, and deploy."
- "It would be great to have a mobile application client. Currently, you have to use a mobile web browser on a device, but it is not similar to the desktop web browser in terms of user experience. It would be nice to have a mobile application to access the platform."
- "It would be great to have a mobile application client."
What is our primary use case?
We are using InsightVM for vulnerability management services. We use it for providing professional services to our customers, and we also use it for our internal use.
We do on-premises and cloud deployments.
What is most valuable?
I really love the new platform. It is really easy to understand, use, and deploy.
Their support is very professional and good at troubleshooting issues.
What needs improvement?
It would be great to have a mobile application client. Currently, you have to use a mobile web browser on a device, but it is not similar to the desktop web browser in terms of user experience. It would be nice to have a mobile application to access the platform.
It would be nice to have someone in the technical support team who speaks Italian.
For how long have I used the solution?
We have been in a partnership with Rapid7 for five years.
What do I think about the stability of the solution?
It is absolutely stable.
What do I think about the scalability of the solution?
It is scalable. We have 40 customers who are using this solution.
How are customer service and technical support?
Their technical support is great, but it would be nice to have someone in the technical support team who speaks Italian.
We speak Italian with Safeguy. So, sometimes, Safeguy's technical teams also help us.
How was the initial setup?
Its initial setup is easy and quick. We are typically able to deploy it in a couple of hours.
We have 15 certified and dedicated engineers to handle its deployment and maintenance.
What's my experience with pricing, setup cost, and licensing?
In some cases, we procure the licenses. In some cases, the customers directly buy the license from Rapid7.
What other advice do I have?
I would rate Rapid7 InsightVM a nine out of 10.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Owner at Sidif Del Caribe Corporation
A stable enterprise solution that can automatically detect new devices and scan them for vulnerabilities
Pros and Cons
- "When you connect any new device to the network, Rapid7 has the ability to detect the new device immediately. It can scan that device to detect if it has any vulnerability. It tells you what is vulnerable and what has been misconfigured. It also tells you what is the risk of that misconfiguration or lack of patches and how to resolve the problem."
- "When you connect any new device to the network, Rapid7 has the ability to detect the new device immediately."
- "In terms of improvements, its price could be better. Our main issue with Rapid7 is that it is too expensive. You can only sell it to enterprise accounts. In terms of new features, Rapid7 came up with a product called InsightIDR a couple of years ago, which is a good SIEM solution. We expect that Rapid7 will work on some sort of integration between InsightVM and InsightIDR, where vulnerability or anomaly detected by InsightVM can be reported in InsightIDR in some sort of real-time. Rapid7 doesn't patch. For example, if you have a vulnerability, some products can scan and also do the patching, but Rapid7 does not do the patching. It would be nice if it can also patch."
- "In terms of improvements, its price could be better. Our main issue with Rapid7 is that it is too expensive."
What is our primary use case?
We are system integrators. Our clients normally use it to detect vulnerabilities in terms of a lack of patches in certain systems and databases. Its console can be installed on-premise or on the Rapid7 data center.
What is most valuable?
When you connect any new device to the network, Rapid7 has the ability to detect the new device immediately. It can scan that device to detect if it has any vulnerability.
It tells you what is vulnerable and what has been misconfigured. It also tells you what is the risk of that misconfiguration or lack of patches and how to resolve the problem.
What needs improvement?
In terms of improvements, its price could be better. Our main issue with Rapid7 is that it is too expensive. You can only sell it to enterprise accounts.
In terms of new features, Rapid7 came up with a product called InsightIDR a couple of years ago, which is a good SIEM solution. We expect that Rapid7 will work on some sort of integration between InsightVM and InsightIDR, where vulnerability or anomaly detected by InsightVM can be reported in InsightIDR in some sort of real-time.
Rapid7 doesn't patch. For example, if you have a vulnerability, some products can scan and also do the patching, but Rapid7 does not do the patching. It would be nice if it can also patch.
For how long have I used the solution?
We have been working with this solution for the last three years or so.
What do I think about the stability of the solution?
It has been stable. There is nothing that has caused any major damage to our customers. Normally, what happens is that when something goes wrong, the customer normally blames the tool first before admitting that they touched something or whatever the case may be.
What do I think about the scalability of the solution?
We have a couple of customers with various company sizes, and we haven't had any scalability issues. Rapid7 is pretty much an enterprise solution. We're talking about customers with more than 1500 nodes to scan.
How are customer service and technical support?
Their technical support is very good.
How was the initial setup?
I don't handle the installation, but it was not difficult to implement. The basic setup took us about four days or so.
Normally, for a product like this, the complexity of implementation is proportional to the size of the infrastructure that is going to be scanned and also how heterogeneous it is. An enterprise product like this is not like using a coffee maker. You need to have some knowledge of where you are installing it. You also need to have some knowledge of the technology that you are going to scan. You can't scan everything in the same way.
What's my experience with pricing, setup cost, and licensing?
Its price is too high. My only concern or issue with Rapid7 is its pricing.
Which other solutions did I evaluate?
Our clients evaluate Qualys, Tenable, and Rapid7. It doesn't really matter which one you choose. You cannot go wrong with all of these products. They have been very well ranked by Gartner. The main difference is probably the pricing.
What other advice do I have?
I would recommend this solution. I would rate Rapid7 InsightVM an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Owner at a tech services company with 1-10 employees
Understands and defends your network from vulnerabilities
Pros and Cons
- "I liked the dashboard on it. I could customize my dashboard with different widgets and different heat maps."
- "I would say that it improved our visibility, but it left things open."
What is our primary use case?
We used InsightVM mainly for vulnerability management. I thought it was a pretty interesting application. I'm a fan of Rapid7's Metasploit, so when I saw InsightVM I was like, "Let's see what else they have." I liked it up until we experienced some issues relating to scans. If I wanted to do mitigation, I needed to wait until the next scan was available or ran so that I could get to see if any indentations were made.
While I was in there, if I was searching for a specific vulnerability, sometimes it was hard to find the specific ones. In the dashboard, it'll tell you the results from the scans, and it will also tell you the vulnerabilities and it will rank them for risk. I would have liked to have been able to click on the vulnerability and it would take me to another area that just has the vulnerability with all the hosts. It wouldn't let you do that. You had to come back out of that window and go into another window and search for it. Well, you wouldn't get the same results as the number of hosts. I had to work a little bit harder to find exactly what I needed.
Within our organization, there were two of us using it. Both of us were IT analysts. One was an IT analyst III (which was me), and the other one was the IT analyst manager.
How has it helped my organization?
I would say that it improved our visibility, but it left things open.
What is most valuable?
I liked the dashboard on it. I could customize my dashboard with different widgets and different heat maps. I liked that. That was a feature I liked. If your manager had a different dashboard that they liked, and you tried to go into a meeting and they say, "Well, I think your numbers are wrong because my dashboard says this" Well, you couldn't rapidly say, "Here's the default dashboard for this for risk." Whereas, with Tenable, you could go through a dashboard just for risks, and say, "Hey, let's switch to this dashboard so we're seeing the same numbers without customization."
What needs improvement?
They just need to fix it to make it more fluid. If it shows you vulnerabilities, I want to be able to click on the vulnerability and drill down into the vulnerability. If it's rating it as a 10 and it says it's got 30 hosts in it for this vulnerability, I want to click on that vulnerability and get a separate report that says, "Here's the vulnerability specific and here's the host involved." That way I could export it and say, "Hey, this vulnerability's out there, it matches a CVE number that is critical, that Microsoft, Cisco, whatever, has put a patch out there, and here guys, here's what it is and here's the proof. Here's your host that's vulnerable. Here's a change request, fix it, send me back the proof that you fixed it, then allow me to rerun a scan specific to that, on-demand, to say 'Yes, boss, we have mitigated it.'"
I want to be able to just drill down on the reports. If it showing me there's a vulnerability and there's a said number of nodes that's vulnerable to it, I want to be able to drill down and export that list without having to come back out of it, going into my assets, trying to find the name of the vulnerability, which doesn't match what the dashboard says. To me, that was backward.
For how long have I used the solution?
I have used this solution for one year.
What do I think about the stability of the solution?
It was pretty stable. We didn't have any real hiccups, but it was stable. We didn't have any real hiccups there.
What do I think about the scalability of the solution?
As far as I know, it says it's scalable. I'm not sure if that company I used to work for had to scale it up or down.
How are customer service and technical support?
The tech support was very helpful. Actually, I knew a couple of them so it was very helpful.
I would give their tech support a rating of 10 — I knew them from using Metasploit and some other products. It was more of a, "Hey, I got this issue, how can you help me with it?" They'd point me and say, "Hey, check this out."
How was the initial setup?
I wasn't involved in the initial setup, so I can't comment on that.
What other advice do I have?
Do your proof of concepts if you can. Make sure you develop your risk strategy. That's important, because it's going to give you a risk number, it's going to give you critical: highs, mediums, but you need to understand what is the risk methodology that you're going to follow. Just because it says it's critical because of how many vulnerabilities you have, doesn't mean that you need to work on it right away.
For example, there was a vulnerability that had 2,000 nodes affected. It put it as a high-risk, whereby there was another vulnerability where there were only about 10 hosts affected — it put it at medium-risk. However, the high-risk one, because it had more nodes affected, did not have a POC associated with it. A novice person looking at it would say, "I need to work on these 1,000 vulnerabilities because it's a high-risk, and ignore the medium." Well, the medium one had an active POC on it. If you didn't have a person who understood how to read the report and what it's actually telling you, then you would say, "Hey, you know what, I'm going to use these, I'm going to cut my risk down because I got 1,000 nodes with this vulnerability and I'm going to put this chain out real quick and I'm going to reduce my risk real quick because of the numbers." Well, in my opinion, you didn't reduce your risk because you have 10 nodes out there with a vulnerability that's rated medium and it has a POC on it.
Overall, on a scale from one to ten, I would give this solution a rating of eight. I'm going to say that is because shame on Rapid7 for having such great applications, but then that little piece there that they know about hasn't been fixed. If I remember, if I go probably log back into the community, it's probably been asked a couple of times.
Which deployment model are you using for this solution?
Private Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Director of Cyber Security (CISO) at a marketing services firm with 201-500 employees
Broad capabilities make this scanning solution able to cover a lot of ground
Pros and Cons
- "It is good and fits well with pretty much all of our use case needs."
- "You can bring in and get online to do reports fairly quickly,"
- "Rapid7 gave us the ability to do a lot of that, and it was not a cumbersome tool to implement."
- "The product does not have the capability to do dynamic scanning of non-web applications."
- "Reporting could be expanded."
- "There are end-user needs and expectations that are being overlooked in the development that could be addressed by appointing a customer advisory board."
- "I do not like the fact that as a vulnerability scanner, this product has a fault to a certain extent."
What is our primary use case?
In our first use case, we wanted to map the solution back to our NIS (Network and Information Systems) framework and the CIS (Center for Internet Security that publishes Critical Security Controls). That is the first part. The second part of this same use case is that we wanted to do continuous vulnerability scanning. That is we wanted to scan the complete network every month at a minimum. What we are finding out in practice is that we are scanning every week because of our network and the size of it. In the end, we are able to get even more aggressive than our original position.
The next use case was we wanted to identify the assets that were in our environment. We can identify how many servers we have, we have identified how many desktops and laptops we have got, et cetera. To that point is where we were looking at pretty good.
Our next use case was the obvious next step where we wanted to identify vulnerabilities. That meant identifying all the vulnerabilities from critical all the way down to the low. We needed to know what they were and how many. Also, we wanted to know how many are unique versus how many there are in total.
We also wanted to get away from tracking vulnerabilities on spreadsheets. It was incredibly cumbersome, incredibly hard to do, and it was not efficient. The IT guys kept telling me that they did not know how to fix certain issues. So I thought we needed to do CVSS ( Common Vulnerability Scoring System) on it. They were a bit resistant to that idea. Well, I was not about to start doing that for them. So InsightVM gives us the ability now to track the issues and communicate how the remediation should occur to fix vulnerabilities.
Then the last thing is we wanted was to have a dashboard for management. We had to have a dashboard to be able to have a CIO (Chief Information Officer) log in and find out where we sit with things. Like where do we sit with remediation where are we failing to make expected progress and things of that nature.
Rapid7 gave us the ability to do a lot of that, and it was not a cumbersome tool to implement. It is good and fits well with pretty much all of our use case needs. It only falls short in a couple of spots.
What needs improvement?
Now that we have been using it, I think there are some things Rapid7 needs to consider and address in improving InsightsVM. I think the reporting piece has room for improvement. While they have a lot of reporting, and some of the reporting is really good, there are some things that I think they can do better on. They need to add some categories that are not covered and expand a few things that have only surface coverage.
I would love to be on a customer advisory board so that I could provide feedback to them and show them what their solution does not do. For example, I could point out things that I can not do with a widget on the dashboard that I would expect it to be able to do. Things like that might help them improve the product from a real user's perspective. That could amount to a lot of different things, but ideally, it would focus on your most common issues.
There were a couple of things I know that the security analyst and I were looking at and we were wondering why Rapid7 would choose to implement it that way. Like if they did not include something we needed as part of a report, we could not do what we expected when running the report. That is a little frustrating. I would say that they need to spend some more time evaluating enhancements suggested by customers so that they can get those things implemented and round out the user experience. That is the reason why I think a CAB (Customer Advisory Board) is important for vendors like Rapid7.
For how long have I used the solution?
We rolled it out in our operations between June and September. So we have been using it since June of 2020.
What do I think about the scalability of the solution?
I do not know at this point just how scalable this solution is. We bought it for an enterprise solution, so our enterprise need is getting solved. I do not know how much scaling we have to do on top of that. I do not like the fact that as a vulnerability scanner, this product has a fault to a certain extent. We want to be able to scan applications dynamically and this solution does not give us that ability. It does for web apps. But if you are a company that does not have a lot of web apps, something is getting left uncovered.
Let's say you have a third-party app. You go to that third-party developer and you ask if they have ever done a security attestation on the application. They look at you and like they have no idea what the heck you are talking about and they have no idea what that means. It would be good, in that case, to be able to take the Rapid7 product and point it at that third-party app and scan it dynamically. That way you can get code vulnerabilities or functional vulnerabilities. What would otherwise be a problem is something you could identify and isolate. If Rapid7 looked at the scripting and identified a secret injection attack at line 1,141 — or something to that effect — it could be vetted. It does do that, but it only does that on web applications. Why stop there?
In order to solve that issue, you have to go out and buy another third-party product that allows you to scan the application to do dynamic or static vulnerability scanning on the application. I do not like that omission because I had that capability with Qualys. We could take Qualys and we could point it at an application and get dynamic scanning reports from it. It told us a line that needed to be fixed and everything.
I have not yet gotten into the bowels of that discussion with Rapid7, but I want to. What I did find out about it is our current setup does not cover that type of potential application vulnerability. It does allow for some scanning of web applications, but we are not a company that has a lot of web applications. We are not a retail organization. We do not sell anything. We do have web applications, but they are mainly used for marketing.
We probably have close to a dozen people in our organization who are currently interfacing in some way with Rapid7 InsightVM. That part is scalable. The utility does have those certain limitations, however.
How are customer service and technical support?
We have a client service manager for Rapid7 tech support. He is an appointed customer service manager where we have him for the first year. We are working with him to identify things, correct things, implement, attune, and things like that. Because of that relationship, I do not have a need to call their regular tech support right now. We just worked through the service manager.
Which solution did I use previously and why did I switch?
I have had some previous experience with Qualys and using Rapid7 now is really a matter of what I chose to bring on based on my personal user experience. Each has its own advantages and neither is a bad product.
How was the initial setup?
The initial installation and setup were pretty much straightforward. We did run into an issue with credentialing. We ended up working through that and got that correct.
I think it was done fairly quickly overall. When we ran into that credentialing issue, we spent about three weeks or so — almost a month — working through that. The issue meant involving some guys from some of the other IT teams and getting them into the mix to help us out.
What other advice do I have?
I had implemented InsightVM before at another company. I liked it when we were using it there which is why it ended up here. I have also had previous experience with Qualys. I did not have the time or the luxury to sit back and do a full analysis, RFI (Request for Information) and RFP (Request for Proposal) when we had to bring on the solution. We are not the CIA (Central Intelligence Agency), we are not the NSA (National Security Agency). We do not need any sophisticated solution or anything like that. We just needed something we could bring in, get online fairly quickly, and get running to do reports. Rapid7 InsightsVM fit the bill.
On a scale of one to ten (where one is the worst and ten is the best), I would rate Rapid7 InsightVM as probably about an eight-out-of-ten. It gets an eight rather than scoring higher just because of some of the other stuff that I wish we had.
Which deployment model are you using for this solution?
Private Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Rapid7 InsightVM Report and get advice and tips from experienced pros
sharing their opinions.
Updated: July 2026
Popular Comparisons
Microsoft Defender for Cloud
Checkmarx One
Qualys VMDR
Orca Security
Tenable Nessus
FortiCNAPP
Acunetix
Tenable Security Center
Tenable Vulnerability Management
The NodeZero Platform by Horizon3.ai
Rapid7 Metasploit
Ivanti Autonomous Endpoint Management
Buyer's Guide
Download our free Rapid7 InsightVM Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
















