I use InsightVM for vulnerability scanning, to follow up that patching is done properly, and to control operational teams and ensure they're doing their job.
Head of Cyber security analysis at DNV Poland Sp. z o.o.
Company-saving vulnerability scanner that's easy to set up
Pros and Cons
- "InsightVM's best features are the vulnerability database and remediation steps."
- "InsightVM is getting a little stale and is in danger of falling behind its competitors."
What is our primary use case?
How has it helped my organization?
InsightVM lets me scan our environments and ensure that our operational teams are on top of patching.
What is most valuable?
InsightVM's best features are the vulnerability database and remediation steps.
What needs improvement?
InsightVM is getting a little stale and is in danger of falling behind its competitors. It's also becoming more complicated, and I prefer it to be kept simple. Its cloud coverage could also be stepped up.
Buyer's Guide
Rapid7 InsightVM
August 2025

Learn what your peers think about Rapid7 InsightVM. Get advice and tips from experienced pros sharing their opinions. Updated: August 2025.
865,295 professionals have used our research since 2012.
For how long have I used the solution?
I've been using InsightVM for ten years.
What do I think about the stability of the solution?
Insight VM is very stable.
What do I think about the scalability of the solution?
There used to be some problems with scaling InsightVM, but those limitations have been removed in newer versions.
How are customer service and support?
Rapid7's technical support is brilliant, responsive, and professional.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup was very easy and took a day to complete. I would rate the setup process five out of five.
What about the implementation team?
We used an in-house team.
What was our ROI?
Having a vulnerability scanner has saved us from cyber attacks a number of times, so we've gotten good ROI from Insight VM. I'd rate our ROI as five out of five.
What's my experience with pricing, setup cost, and licensing?
InsightVM is an expensive product, especially compared to its competitors, at around a million NOK per year. Support is included in the license for no extra cost. I would rate their pricing at one out of five.
What other advice do I have?
InsightVM has integration with Kubernetes, which no other solution has. I would give Insight VM a rating of eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Country Sales Lead at securic systems
Vulnerability management solution that has a good distribution network and support in Pakistan
Pros and Cons
- "Rapid7 have a good distribution network with good support and market presence."
- "Some of our customers want to be completely cloud based, and Rapid7 doesn't offer this as an option."
What needs improvement?
Their channel program and the process of their deal registration could be improved.
Some of our customers want to be completely cloud based, and Rapid7 doesn't offer this as an option.
For how long have I used the solution?
I have used this solution for one year.
What do I think about the stability of the solution?
This solution is fairly stable.
What do I think about the scalability of the solution?
This is a scalable solution suitable for large environments.
Which solution did I use previously and why did I switch?
We initially worked with Qualys and found that Qualys has a better reputation but it is expensive. Companies with bigger budgets and who would like a cloud solution, usually prefer Qualys. This is also because of the product maturity and the research they provide.
The challenge with Qualys is that they do not have any distributors in Pakistan. They do not have an on-premises product, which caters more towards the enterprise accounts in Pakistan. I prefer going with Rapid7 for this reason. Rapid7 have a good distribution network with good support and market presence.
What other advice do I have?
My advice is to explore many options and look at the integrations available. My personal experience is that only implementing vulnerability management doesn't solve all of the problems. We also needed evaluator integrations that provide preventative measures.
I would rate this solution an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer.
Buyer's Guide
Rapid7 InsightVM
August 2025

Learn what your peers think about Rapid7 InsightVM. Get advice and tips from experienced pros sharing their opinions. Updated: August 2025.
865,295 professionals have used our research since 2012.
IT Security Analyst at a financial services firm with 1,001-5,000 employees
Could be better on the cloud side and offer more reporting, overall - recommended to check other options
Pros and Cons
- "The feature that I have found most valuable is its dashboards."
- "There is room for improvement on its cloud side. In the next release I would like to see better reporting."
What is our primary use case?
We use it for vulnerability scanning.
What is most valuable?
The feature that I have found most valuable is its dashboards.
What needs improvement?
There is room for improvement on its cloud side.
In the next release I would like to see better reporting.
For how long have I used the solution?
I have been using Rapid7 InsightVM for seven years.
What do I think about the stability of the solution?
It is stable.
What do I think about the scalability of the solution?
Rapid7 InsightVM is scalable.
In my company, it is just my team of less than five people using it.
It requires one engineer for deployment and maintenance of the solution.
We do not have plans to increase the usage of the solution in the future.
How are customer service and support?
Their customer support is really bad. On a scale of 1 to 10 I would probably give it a 1.
How was the initial setup?
The initial cloud setup was difficult. It took months even though we worked with their professional services.
What about the implementation team?
We used a consultant to implement.
What was our ROI?
We had a good return, but it could be better.
What's my experience with pricing, setup cost, and licensing?
We pay 100,000 yearly.
What other advice do I have?
We are thinking about changing right now. We have always used Rapid7, but we are thinking about changing now.
My advice to anyone considering Rapid7 InsightVM is to look at the other vendors first.
On a scale of one to ten, I would give Rapid7 InsightVM a 3.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Professional services team lead at a tech services company with 1,001-5,000 employees
It performs well and is stable, but it is difficult to manage
Pros and Cons
- "The performance is good."
- "Rapid7 could be easier to manage."
What is our primary use case?
Rapid7 InsightVM, like Tenable, is used to enforce the vulnerability management lifecycle.
We identify the assets, scan them, prioritize them, and have a remediation plan in place to address any vulnerabilities that are discovered.
A remediator scan is performed to determine whether or not the discovered vulnerabilities have been patched.
What is most valuable?
The performance is good.
What needs improvement?
Rapid7 could be easier to manage. When you compare it to other similar solutions, it is a bit difficult to manage.
The reporting could be improved.
For how long have I used the solution?
I have been using Rapid7 InsightVM for two years.
At the time that it was used, I was using the latest version.
What do I think about the stability of the solution?
The installation is simple and quick; it only takes 10 minutes to complete.
Which solution did I use previously and why did I switch?
I have used Tenable SC and Tenable.io, and you cannot compare to Tenable SC or Tenable.io with any other vulnerability solution.
Tenable has that supremacy. It is very easy to manage and very easy to understand. You don't need any prior knowledge or experience to install it; you can do it on your own. You don't need any additional assistance or help through a search on how to install or scan your assets.
Tenable has a very powerful reporting engine but needs to be enhanced.
What other advice do I have?
Tenable is number one, Rapid7 comes second.
I would rate Rapid7 a six out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Information Security Officer at Umniah
It's smarter and more accurate from an application perspective
Pros and Cons
- "Using Rapid7, we can install a scan engine, we can do our VPN connections, and we can conduct internal scans of remote sites. We prefer the web application. It's smarter and more accurate from an application perspective."
- "The integration with other solutions like JIRA could be better. Perhaps there could be some additional updates in the next phase that could integrate with it, so then you can proceed with the VT much easier."
What is our primary use case?
We use a hybrid setup. Some dashboards and configurations are uploaded to the Cloud, and some of them are on-premises. The main engine is on-premises. We have about 12 customers and some of them are big companies.
What is most valuable?
There are a few main features that we are very happy with. Using Rapid7, we can install a scan engine, we can do our VPN connections, and we can conduct internal scans of remote sites. We prefer the web application. It's smarter and more accurate from an application perspective.
What needs improvement?
The integration with other solutions like JIRA could be better. Perhaps there could be some additional updates in the next phase that could integrate with it, so then you can proceed with the VT much easier.
For how long have I used the solution?
I've been using Rapid7 for about two years.
What do I think about the scalability of the solution?
From a scalability standpoint, it's good because they give you around 100%. If you want to increase your asset counts, for example, they give you permission for 100% above the limit that you pay for.
How are customer service and technical support?
Their support is very good. Technical support varies from person to person. Some cases have taken some time, but once it was escalated, everything was done well and the problem was solved. We've had some cases involving integration, remote sites, and some special configurations. They provided us with some support on all that.
How was the initial setup?
It's straightforward. Everything is like setting up Lego cubes. It doesn't take much time to deploy. The first deployment may take around an hour or two.
What's my experience with pricing, setup cost, and licensing?
The license could be a little bit cheaper. For all these features, you would expect to pay a little bit lower but around the same general price. Licenses are paid yearly. For some customers, we pay two years at a time, but mostly it's yearly.
What other advice do I have?
I would rate it nine out of 10.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Cyber Security Engineer at a manufacturing company with 5,001-10,000 employees
Good reporting, useful automation features, and has good technical support
Pros and Cons
- "It's a relevant management tool."
- "I would like to see more integration."
What is our primary use case?
We use this solution for our internal server for scanning. We can scan for vulnerabilities and locate them.
We also generate reports for the patching team. We assign tasks to the patching team.
What is most valuable?
It's a relevant management tool.
It has some useful automation features. The report generating and the scanning are very helpful.
What needs improvement?
It would be very helpful to have integration. There are many plugins that can be used for tasks that would help the visibility and be able to locate the exact problem.
I would like to see more integration.
I would also like to see more flexibility when scheduling the scans. We should be able to schedule scans when we want them to be scheduled. Currently, they have to be scheduled before a certain day of the week.
For how long have I used the solution?
I have been using Rapid7 InsightVm for six months during my internship.
What do I think about the stability of the solution?
Rapid7 InsightVM is a stable product.
What do I think about the scalability of the solution?
We have no issues with the scalability of this solution. We have a vulnerability management team of four who are using it, and in our organization, we have approximately 20 people, including management.
How are customer service and technical support?
Technical support is good.
Which solution did I use previously and why did I switch?
I have used Tenable Nessus previously for my personal projects. I used it for scanning for my projects in college.
How was the initial setup?
I was not involved in the installation. It was already installed previously.
What's my experience with pricing, setup cost, and licensing?
Licensing fees are paid on a yearly basis.
What other advice do I have?
I would recommend this solution to others, but more integration features would be more helpful.
I would rate Rapid7 InsightVM an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
CoFounder & Head of Technology at intuity
Professional support, absolutely stable, and easy to use and deploy
Pros and Cons
- "I really love the new platform. It is really easy to understand, use, and deploy."
- "It would be great to have a mobile application client. Currently, you have to use a mobile web browser on a device, but it is not similar to the desktop web browser in terms of user experience. It would be nice to have a mobile application to access the platform."
What is our primary use case?
We are using InsightVM for vulnerability management services. We use it for providing professional services to our customers, and we also use it for our internal use.
We do on-premises and cloud deployments.
What is most valuable?
I really love the new platform. It is really easy to understand, use, and deploy.
Their support is very professional and good at troubleshooting issues.
What needs improvement?
It would be great to have a mobile application client. Currently, you have to use a mobile web browser on a device, but it is not similar to the desktop web browser in terms of user experience. It would be nice to have a mobile application to access the platform.
It would be nice to have someone in the technical support team who speaks Italian.
For how long have I used the solution?
We have been in a partnership with Rapid7 for five years.
What do I think about the stability of the solution?
It is absolutely stable.
What do I think about the scalability of the solution?
It is scalable. We have 40 customers who are using this solution.
How are customer service and technical support?
Their technical support is great, but it would be nice to have someone in the technical support team who speaks Italian.
We speak Italian with Safeguy. So, sometimes, Safeguy's technical teams also help us.
How was the initial setup?
Its initial setup is easy and quick. We are typically able to deploy it in a couple of hours.
We have 15 certified and dedicated engineers to handle its deployment and maintenance.
What's my experience with pricing, setup cost, and licensing?
In some cases, we procure the licenses. In some cases, the customers directly buy the license from Rapid7.
What other advice do I have?
I would rate Rapid7 InsightVM a nine out of 10.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Head of Cybersecurity Assurance & Controls Director at a tech services company with 1,001-5,000 employees
Poor reporting, lacking in features, but the technical support is not bad
Pros and Cons
- "I have been in contact with technical support and they are not bad."
- "The reporting is very bad when you compare it with other vulnerability assessment tools."
What is our primary use case?
I primarily using Rapid7 for vulnerability assessment and reporting.
How has it helped my organization?
At this point, we are not happy with Rapid7.
What needs improvement?
The reporting is very bad when you compare it with other vulnerability assessment tools.
This product is for basic vulnerability assessments, only, and is lacking in features such as compliance, assessment, assets, inventory, and batch management.
For how long have I used the solution?
I have been using Rapid7 InsightVM for five years.
What do I think about the scalability of the solution?
I would say that the scalability is 50-50. It does not offer much in terms of being able to scale. We have approximately 3,000 users.
How are customer service and technical support?
I have been in contact with technical support and they are not bad.
What's my experience with pricing, setup cost, and licensing?
Comparing the price with the value that we receive, I am not happy with it.
Which other solutions did I evaluate?
We are currently looking to replace Rapid7 with another product.
Currently, we are working with Tenable Nessus and Qualys.
What other advice do I have?
I would rate this solution a five out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Buyer's Guide
Download our free Rapid7 InsightVM Report and get advice and tips from experienced pros
sharing their opinions.
Updated: August 2025
Product Categories
Risk-Based Vulnerability ManagementPopular Comparisons
Qualys VMDR
Tenable Security Center
Tenable Vulnerability Management
Microsoft Defender Vulnerability Management
Red Canary
Nucleus
Arctic Wolf Managed Risk
Cisco Vulnerability Management (formerly Kenna.VM)
SanerNow CyberHygiene Platform
Balbix BreachControl
SecureWorks Taegis VDR
Fortra's Vulnerability Management
Buyer's Guide
Download our free Rapid7 InsightVM Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions: