It's a vulnerability scanning tool utilized within the vulnerability management process. We employ it to conduct internal vulnerability assessments of company or organizational host IPs.
Information security engineer at Cyberisk
Comprehensive vulnerability management with robust set of features, making it highly effective for enhancing security posture and mitigating risks
Pros and Cons
- "The most valuable features are its reporting capabilities and the host discovery functionality."
- "There is a significant learning curve, that non-technical individuals, especially those not specialized in computer science or the information security industry, might face."
What is our primary use case?
How has it helped my organization?
It aids in enhancing the overall security posture within our organization. It uncovered numerous vulnerabilities that had been overlooked, which was quite beneficial.
What is most valuable?
The most valuable features are its reporting capabilities and the host discovery functionality.
What needs improvement?
The primary issue I encountered initially with this tool was related to configuration. There is a significant learning curve, that non-technical individuals, especially those not specialized in computer science or the information security industry, might face.
Buyer's Guide
Rapid7 InsightVM
April 2026
Learn what your peers think about Rapid7 InsightVM. Get advice and tips from experienced pros sharing their opinions. Updated: April 2026.
893,438 professionals have used our research since 2012.
For how long have I used the solution?
I have been working with it for six months.
What do I think about the stability of the solution?
I am satisfied with the stability provided.
How was the initial setup?
The initial setup went smoothly, but after completing it, I encountered difficulties when attempting to use features like the dashboard and the scan now option. Specifically, I faced challenges with scanning the host, which proved to be quite frustrating.
What about the implementation team?
The initial setup wasn't overly difficult, so it took me around one to two days due to troubleshooting issues. Overall deployment took about two to three days in total.
What other advice do I have?
I highly recommend Rapid7 as my experience with it is very positive. Overall, I would rate it eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Information Technology Security Specialist at Digitaltrack
Easy to use with good dashboards and decent reporting
Pros and Cons
- "We can create our own templates."
- "The authentication scan is not working."
What is our primary use case?
We primarily use the solution for scanning. It will support the agent and collect scanning information on particular hotspots.
What is most valuable?
We like that you can create your own inputs using the chat.
The integration capabilities are good.
It has good reporting.
We can create our own templates.
The dashboard is very easy to use for customers.
What needs improvement?
The firewall could be better.
We've had struggles with new scanning on Cisco routers. We have to do a lot of troubleshooting. The authentication scan is not working.
We'd like better risk levels for assets in terms of reporting.
For how long have I used the solution?
I've been using the solution since 2019. I've only used it for a few years at this point.
What do I think about the stability of the solution?
The solution is quite stable. It's reliable. There are no bugs or glitches. It doesn't crash or freeze. I'd rate the stability eight out of ten.
What do I think about the scalability of the solution?
The solution is scalable. It offers pretty high scalability. I'd rate it nine out of ten.
Our clients are medium to large-scale businesses.
How was the initial setup?
The initial setup is very easy. It is very customizable and easy to understand.
I'm not sure how long the deployment took. The POC took about 30 days to allow the clients to try it out. We requested a POC to test out some use cases.
What other advice do I have?
I'm a reseller.
I'm not sure which version of the solution I'm using. It might be version six or seven.
I'd recommend the solution to others.
I would rate the solution eight out of ten.
Which deployment model are you using for this solution?
Private Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Buyer's Guide
Rapid7 InsightVM
April 2026
Learn what your peers think about Rapid7 InsightVM. Get advice and tips from experienced pros sharing their opinions. Updated: April 2026.
893,438 professionals have used our research since 2012.
Cyber Security Architect at a healthcare company with 11-50 employees
Easily exposes misconfigurations, flaws, or security risks
Pros and Cons
- "The solution is automatically scheduled so it runs by itself."
- "The solution should include a tighter integration with third-party threat modeling and threat intelligence tools."
What is our primary use case?
Our company uses the solution to discover, identify, and patch vulnerabilities or disable certain services. The solution provides the patch recommendations that we implement via another tool.
Four team members manage the solution internally and for various clients who each have fifty users.
What is most valuable?
The solution helps to identify lots of misconfigurations, flaws, or security risks. Anything insecure is exposed easily.
The solution is automatically scheduled so it runs by itself.
What needs improvement?
The solution should include a tighter integration with third-party threat modeling and threat intelligence tools. Rapid7 is the solution's own threat intelligence platform but third-party platforms would be a great addition.
It would be nice to have patching capabilities built within the solution rather than using third-party products.
For how long have I used the solution?
I have been using the solution for three years.
What do I think about the stability of the solution?
The solution is extremely stable.
What do I think about the scalability of the solution?
The solution is easily scalable with the purchase of additional licenses.
How are customer service and support?
Technical support is extremely good and we get support quite fast. Technical support is rated a ten out of ten.
How would you rate customer service and support?
Positive
How was the initial setup?
The setup is very straightforward so I rate it a ten out of ten.
What about the implementation team?
We implement the solution for customers.
What's my experience with pricing, setup cost, and licensing?
The solution is a bit more reasonably priced than other products.
Which other solutions did I evaluate?
Most products in this category are similar with no real difference so it all comes down to price.
What other advice do I have?
It is important to have a strong patch management plan that prioritizes what and how you need to patch.
The solution does the vast majority of work but you need a proper system so you can take output to your operations team for patching. A good workflow between teams is important.
I rate the solution a ten out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Security Specialist at a financial services firm with 1,001-5,000 employees
Simple to install, user interface is both professional and user-friendly
Pros and Cons
- "This solution's most useful feature is that it is entirely a single-page application."
- "The drawback is that it is still not a fully SaaS solution, so you must deploy a console."
What is our primary use case?
We use Rapid7 InsightVM to increase vulnerability scanning, which is why we tried Qualys as well.
What is most valuable?
This solution's most useful feature is that it is entirely a single-page application.
The UI is both professional and user-friendly.
What needs improvement?
The drawback is that it is still not a fully SaaS solution, so you have to deploy a console.
For how long have I used the solution?
I have been working with Rapid7 InsightVM for six weeks.
What do I think about the stability of the solution?
Rapid7 InsightVM is stable.
What do I think about the scalability of the solution?
Rapid7 InsightVM is a scalable solution.
How are customer service and support?
We have two dedicated technicians to assist us.
Which solution did I use previously and why did I switch?
We are also testing Qualys. If you look at both options, I believe they are the same. Both are in the top market leader position.
Both tools have the same features. The most essential consideration in choosing one of those two experiences with it and whether it fits inside your business.
I can't decide, we are still in the comparison phases.
How was the initial setup?
It is very easy to set up.
It can be deployed in a matter of weeks.
What's my experience with pricing, setup cost, and licensing?
It is pretty expensive. It depends on what you consider pricey, however, if you only look at vulnerability management solutions, such as within VM or VMDR, there are, I suppose the prices are almost the same. But I believe you will discover that for yourself.
What other advice do I have?
Experiment with it and gain some experience with it.
I would rate Rapid7 InsightVM an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT Security Engineer at a financial services firm with 51-200 employees
Reliable, easy to set up, and has a good remediation feature
Pros and Cons
- "The solution scales well."
- "Overall, it's a nice tool."
- "There was functionality present previously, however, currently, we can't integrate directly with Jira Service Desk - only the cloud version."
- "There was functionality present previously, however, currently, we can't integrate directly with Jira Service Desk - only the cloud version."
What is our primary use case?
We primarily use the solution for vulnerability management and monitoring the progress of the remediation process.
What is most valuable?
The remediation feature has been quite useful.
It's easy to set up the solution.
It's stable.
The solution scales well.
What needs improvement?
The solution isn't missing any features, and I haven't noticed any shortcomings.
There was functionality present previously, however, currently, we can't integrate directly with Jira Service Desk - only the cloud version. That, or we must share to the internet on-prem Jira Service Desk. It's not easy for us since we use only the on-prem Service Desk service, and we don't straight to the internet for our service.
InsightVM can only directly connect to the internet. So, we can't use this integration and send tasks to our technical team from InsightVM. We, therefore, need better integration with Jira Service Desk.
What do I think about the stability of the solution?
The stability has been good overall. I would rate it five out of five in terms of reliability. The performance is good. There are no bugs or glitches, and it doesn't crash or freeze.
What do I think about the scalability of the solution?
The solution is suitable for big or small organizations. We have clients of different sizes using the product.
It's used at the engineering level, with security and administrators using it regularly.
I'd rate it five out of five in terms of the ease of scaling.
How was the initial setup?
The solution is straightforward to set up. I'd rate it four out of five in terms of ease of implementation.
We have one or two team members that can set up the solution.
How long it takes to deploy depends on the customer. For a small customer, it's less than one month or sometimes two weeks. For a big customer with many assets and services, it takes two or three months to deploy.
We only need to have one or two people on hand to handle maintenance tasks.
What's my experience with pricing, setup cost, and licensing?
The solution is not overly expensive.
What other advice do I have?
We use this solution for our clients.
We're dealing with the latest version of the product.
InsightVM is a solution based on on-prem infrastructure connected to the cloud service, so it's a hybrid solution.
Overall, it's a nice tool.
I'd rate the solution nine out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Security Solution Engineer II at a security firm with 501-1,000 employees
Easy to deploy, scalable, and helps in prioritizing the risks with risk scoring
Pros and Cons
- "The risk score that they provide makes it easier to find out the biggest risks. It helped the security officers to understand where the biggest risks are so that they can act on them. They can instruct their IT teams to give them a higher priority and mitigate them."
- "The risk score that they provide makes it easier to find out the biggest risks, helping the security officers understand where the biggest risks are so that they can act on them by instructing their IT teams to give them a higher priority and mitigate them."
- "It is still not a fully cloud-based solution. It will be helpful for customers if it is a complete cloud solution. It is a hybrid solution at the moment."
- "It is still not a fully cloud-based solution. It will be helpful for customers if it is a complete cloud solution."
How has it helped my organization?
A big vulnerability was discovered last year for jshell. We got a lot of questions from our customers about which services are vulnerable. We could give an answer in just a few minutes to the customers and also warn them.
What is most valuable?
The risk score that they provide makes it easier to find out the biggest risks. It helped the security officers to understand where the biggest risks are so that they can act on them. They can instruct their IT teams to give them a higher priority and mitigate them.
What needs improvement?
It is still not a fully cloud-based solution. It will be helpful for customers if it is a complete cloud solution. It is a hybrid solution at the moment.
For how long have I used the solution?
I have been working with this solution for two years. It is a cloud solution, and I have been using its latest version.
What do I think about the stability of the solution?
It is definitely stable.
What do I think about the scalability of the solution?
It is made for scalability. We use it to monitor our own company with 250 users. Day-to-day, three people are monitoring the environment.
How are customer service and support?
It is perfect. I would rate them a nine out of ten.
How would you rate customer service and support?
Positive
How was the initial setup?
It was straightforward. It took a couple of hours. I would rate it a nine out of ten in terms of ease of setup.
In terms of maintenance, it is all self-updating.
What was our ROI?
It is difficult to estimate the ROI. For our management, it is a really important tool. It helps us to understand if something is not going perfectly.
What's my experience with pricing, setup cost, and licensing?
Its licensing is yearly. Everything is included in the price for one year.
Which other solutions did I evaluate?
We checked other solutions. We went for it because it has a cloud platform inside, which integrates with our SIEM solution, and it has many more capabilities than other products.
What other advice do I have?
I would advise others to make sure that every asset in the environment is monitored by the tool. I see many customers who think they have full coverage of all assets, but they are missing a part of the network. In such a case, they will get an incorrect understanding of their security.
I would rate this solution a nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Service Delivery Manager at a security firm with 11-50 employees
Easy to deploy and flexible licensing but the reporting could be better
Pros and Cons
- "The product is scalable."
- "From a scanning perspective, it’s great."
- "The reporting could be better."
- "The reporting could be better."
What is our primary use case?
We primarily use the solution for vulnerability management.
What is most valuable?
From a scanning perspective, it’s great. The customization associated with each and every scan is very good. It actually provides functionality from a CIS control perspective as well.
It is easy to deploy.
The product is scalable.
The solution is very stable.
What needs improvement?
The reporting could be better.
We do not need any additional features.
For how long have I used the solution?
I’ve been using the solution for two years.
What do I think about the stability of the solution?
The solution is very stable. The reliability is good. There are no bugs or glitches. It doesn’t crash or freeze.
What do I think about the scalability of the solution?
The solution is absolutely scalable.
From a footprint perspective, there are about 780 servers. In totality, there's a license entitlement for about 1000 clients.
How are customer service and support?
Technical support has been accurate.
How would you rate customer service and support?
Neutral
How was the initial setup?
The solution is straightforward to set up and simple to deploy. It’s not overly complex. We only need one technical person to handle the setup process.
How long it takes to deploy depends on multiple instances whereby multiple factors, depending on client, on-prem, et cetera. Your average deployment time would be anything from three to five days.
What about the implementation team?
As partners, we can handle the implementation.
What was our ROI?
The ROI is fair to mild.
What's my experience with pricing, setup cost, and licensing?
The licensing is market-related.
The cost depends on the number of assets per annum.
It is very flexible. What's nice about it is, from a client's perspective, the environment can either grow and you can chew up, or it can shrink, and it meets whatever needs you have.
The licensing includes technical support.
What other advice do I have?
We’re partners.
We’re always using the latest version of the solution.
There's a mix of deployments. There's an on-prem deployment in certain customer areas. However, there's also a cloud deployment from the MSSV point of view as well.
The scanner is always on-prem. The majority of the scanners that we've deployed are on-prem. Although some of the consoles are selling cloud-deployed, other consoles would be on-prem.
I’d rate the solution seven out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Senior Manager Cyber Security Services & Solutions at Trillium
User-friendly and customizable with great risk scoring feature
Pros and Cons
- "InsightVM's most valuable feature is risk scoring, a formula based on different vectors like the ease of exploitation and the availability of the machine."
- "InsightVM is easy to use, has a well-defined dashboard, and can be customized according to your needs."
- "InsightVM could be improved by providing passive scanning as an option."
- "InsightVM could be improved by providing passive scanning as an option."
What is our primary use case?
InsightVM is mainly used for vulnerability management.
What is most valuable?
InsightVM's most valuable feature is risk scoring, a formula based on different vectors like the ease of exploitation and the availability of the machine. It can be customized according to the customer's needs - for example, if they have an asset that is more vulnerable, they can adjust the risk score according to their infrastructure. It also has a very robust dashboard system and good integration.
What needs improvement?
InsightVM could be improved by providing passive scanning as an option. They could also introduce license packages for fewer than 128 users for smaller organizations.
For how long have I used the solution?
I've been using InsightVM for almost five years.
What do I think about the stability of the solution?
InsightVM is stable.
What do I think about the scalability of the solution?
InsightVM has the option of implementing the scan engine separately, which helps with scalability.
How are customer service and support?
InsightVM's technical support is very good.
How would you rate customer service and support?
Positive
How was the initial setup?
InsightVM is easy to implement and deploy, even for small and medium businesses.
What's my experience with pricing, setup cost, and licensing?
InsightVM's licensing starts at a minimum of 128 IPs and can scale up to over 1,000.
What other advice do I have?
InsightVM is easy to use, has a well-defined dashboard, and can be customized according to your needs. You can also segregate your assets and define IP ranges. I would give InsightVM a rating of nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Integrator
Buyer's Guide
Download our free Rapid7 InsightVM Report and get advice and tips from experienced pros
sharing their opinions.
Updated: April 2026
Popular Comparisons
Microsoft Defender for Cloud
Checkmarx One
Qualys VMDR
Tenable Nessus
Orca Security
Tenable Security Center
Acunetix
Tenable Vulnerability Management
FortiCNAPP
Microsoft Defender Vulnerability Management
The NodeZero Platform by Horizon3.ai
Buyer's Guide
Download our free Rapid7 InsightVM Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
















