We use the solution to scan our internal OS and applications.
Technical Consultant at Yip Intsoi
Flexible, with good scanning, and rarely provides false positives
Pros and Cons
- "The most important aspect of the solution is that it rarely gives false positives, especially compared to other products. It provides very clear reports for our IT teams to look at."
- "There needs to be much clearer instructions surrounding scanning."
What is our primary use case?
How has it helped my organization?
The solution protects us from vulnerabilities. If it sees anything, it can tell us about the vulnerability and ranks it as critical or high risk. It allows us to take action immediately to protect our company from attacks.
What is most valuable?
The most important aspect of the solution is that it rarely gives false positives, especially compared to other products. It provides very clear reports for our IT teams to look at.
The solution has an excellent feature that scans for vulnerabilities that may affect the Windows operating system. It helps us avoid being affected by WannaCry or other malicious attacks of that nature. It's one of the most useful features that we have. We're able to see more vulnerabilities before they become an issue due to the fact that it's so protective. It's great at helping us avoid malware or ransomware.
What needs improvement?
The solution needs to improve its smart monitoring.
There needs to be much clearer instructions surrounding scanning.
As for new features, I can't think of anything that's lacking. It's pretty good overall in terms of feature offerings.
Buyer's Guide
Rapid7 InsightVM
May 2025

Learn what your peers think about Rapid7 InsightVM. Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
851,604 professionals have used our research since 2012.
For how long have I used the solution?
I've only been using the solution for half a year - approximately six months. It hasn't been too long.
What do I think about the stability of the solution?
The solution is very stable. There are no bugs or glitches that I have witnessed. The solution doesn't crash. It's very reliable.
What do I think about the scalability of the solution?
The solution is very flexible and very scalable. A company that needs to add it to their endpoints should have no issues doing so. I don't think there is a limit as to how many are possible.
Typically we deploy this solution to medium-sized enterprises in microfinance and insurance.
How are customer service and support?
I've been in contact with technical support in the past. they're very good. We're satisfied with the level or attention they give us and the information they share.
How was the initial setup?
The solution doesn't really have a complex setup. It's easy to set up and integrate with the endpoint. We install insights at our endpoints to help us collect vulnerability information from there.
We can also install it again and again and use active scanning to conduct vulnerability testing at the endpoints. It's very simple.
Deployment doesn't take long at all. Currently, we can deploy in around two or three days and then integrate it with the endpoint after we've gotten clear instructions from InsightVM.
The steps we choose for implementation are as follows: we first need to follow the instructions to install network communication, from the endpoint to InsightVM. Network communication from the endpoint will go to the scan engine and from the scan engine to the management console of Insight.
After we satisfy this, we start implementation and we start to deploy the engine to the endpoint. After that, we run a scan from the site configuration of each endpoint scope and we file the report displayed on the dashboard. Lastly, we export the report and provide it to the correct person that needs to be involved at the IT end of things.
In terms of the number of staff we use for deployment, from our side, we have two people to help manage everything. For the customer, we have four people to coordinate with the internal team. In total, we have six people involved with deployment. Our team includes a deployment engineer and from the customer's side, members of security operations.
What about the implementation team?
Normally, we have both the reseller and the vendor to assist with deployment. From the vendor, we just consult on the step and classify each endpoint. After that, we'll discuss next steps with our team. Currently, we have a distributor that provides this product to us. We work with the vendor and work with the reseller to deploy everything to the customer's systems.
What's my experience with pricing, setup cost, and licensing?
The solution offers flexible pricing.
What other advice do I have?
We're a partner of InsightVM.
We're most likely using the latest version of the solution, however, I'm not sure which exact version number it is.
We've deployed on-premises with a local scan engine.
I'd advise companies that are looking into vulnerability assessment or faster deployment, to check out InsightVM. It's easy to expand as necessary and offers flexibility in its pricing.
I'd rate the solution nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner

System Engineer at a tech services company with 201-500 employees
It's a good solution for capacity forecasting
Pros and Cons
- "I rate InsightVM eight out of 10 for ease of setup. It takes two or three engineers to deploy. The solution requires some maintenance. It's mainly cleaning up data."
What is our primary use case?
We use InsightVM for capacity forecasting.
For how long have I used the solution?
I've been working around, I don't know, it's about three years.
What do I think about the stability of the solution?
I rate Rapid7 nine out of 10 for stability.
What do I think about the scalability of the solution?
I rate Rapid7 nine out of 10 for scalability.
How are customer service and support?
I rate Rapid7 support nine out of 10.
How would you rate customer service and support?
Positive
How was the initial setup?
I rate InsightVM eight out of 10 for ease of setup. It takes two or three engineers to deploy. The solution requires some maintenance. It's mainly cleaning up data.
What other advice do I have?
I rate Rapid7 InsightVM 10 out of 10.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Rapid7 InsightVM
May 2025

Learn what your peers think about Rapid7 InsightVM. Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
851,604 professionals have used our research since 2012.
Cloud and Cyber-Security Technician at Software Productivity Group
It lets you scan your entire network for vulnerabilities, but it lacks patch management
Pros and Cons
- "I like Rapid7's scan optimization options."
- "Patch management is the only missing feature I can think of. Rapid7 detects vulnerabilities, but it should also help you manage patches."
What is our primary use case?
Rapid7 allows you to scan the entire network to discover information about devices, such as the type of operating system.
What is most valuable?
I like Rapid7's scan optimization options.
What needs improvement?
Patch management is the only missing feature I can think of. Rapid7 detects vulnerabilities, but it should also help you manage patches.
For how long have I used the solution?
I have used Rapid7 for about five months.
What do I think about the stability of the solution?
The product isn't stable. Sometimes I attempt to log in using the correct password, but I can't access the server. It tells me that the password is wrong, so I have to reboot the server to access it.
What's my experience with pricing, setup cost, and licensing?
We pay a monthly license.
What other advice do I have?
I rate Rapid7 InsightVM seven out of 10.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Vice President at INET Managed Services Co.,LTD.
Great scanning capabilities, fast, powerful, easy to access
Pros and Cons
- "It's easy to use. It's fast, it's a powerful easy to access tool."
- "The InsightVM cannot scan if we connect to our customer by the VPN."
What is most valuable?
InsightVM is good. It's easy to use. It's fast, it's a powerful, easy to access tool.
What needs improvement?
I have had some difficult problems with InsightVM. The InsightVM cannot scan if we connect to our customer by the VPN. I asked the Rapid7 support, they told me that the InsightVM can only work on the same network. We cannot use InsightVM by VPN. It also consumes a lot of memory. It would be good if they could resolve that.
For how long have I used the solution?
We worked with Rapid7 InsightVM for one year.
What do I think about the stability of the solution?
It is very stable, but it consumes a lot of memory.
What do I think about the scalability of the solution?
Scalability is good on the same network but not if you have to connect to another network.
How are customer service and technical support?
I think the support is okay. They responded very quickly, and it was sufficient.
How was the initial setup?
InsightVM is Window-based. It is easy to install and easy to use.
What about the implementation team?
It took us about half a day to set up. When we bought from the distributor in Thailand, the distributor sent an engineer to install and explain how to use it and how to customize the report.
Which other solutions did I evaluate?
My team uses a small tool such as Tenable Nessus and Rapid7 InsightVM, but when we use both tools and compared the report, Tenable Nessus is very easy to consolidate, to expand to our customer, but InsightVM is very difficult. We would have to cancel it to explain the daily part to our customers.
What other advice do I have?
I would recommend having the distributor help you to explain how this software works and to help with the details. I would rate it at an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
Assistant Engineer at Harel Mallac Technologies Ltd
Plenty of options, reliable, and simple installation
Pros and Cons
- "The solution is good because it has a lot of options."
- "The solution could improve by being more secure."
What is our primary use case?
We use Rapid7 InsightVM mostly for VM management.
What is most valuable?
The solution is good because it has a lot of options.
What needs improvement?
The solution could improve by being more secure.
For how long have I used the solution?
I have been using Rapid7 InsightVM for approximately one month.
What do I think about the stability of the solution?
The solution has been stable.
What do I think about the scalability of the solution?
Rapid7 InsightVM is scalable.
How are customer service and support?
I have not needed to contact the support at this time.
How was the initial setup?
The installation is simple, it took us approximately six hours.
What about the implementation team?
I did the implementation myself.
What other advice do I have?
I would recommend this solution to others.
I rate Rapid7 InsightVM a nine out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Infrastructure Security Architect at a comms service provider with 11-50 employees
Good site-level vulnerability scanning capability, and the dashboard is not difficult to manage
Pros and Cons
- "The most valuable feature is the site scanning, where we can provide a complete subnet and what it is we need to scan on those devices."
- "The reporting is a little bit tricky because it can be difficult to exactly pinpoint some of the assets to filter them and generate a report."
What is our primary use case?
We use Rapid7 for our vulnerability assessment. It scans the network, identifies all of the assets that are present, and then identifies all of the vulnerabilities due to non-patching those systems. Based on that, we can generate reports and make sure that those applications or servers are patched on both the operating system and application level.
What is most valuable?
The most valuable feature is the site scanning, where we can provide a complete subnet and what it is we need to scan on those devices. It will extract all of the information, including the rating and vulnerabilities, in all of the applications that are present, on each of those machines. This is quite relevant because if you have many applications on one server then you don't know if they are individually patched, or not.
The dashboard is not difficult to manage.
What needs improvement?
The reporting is a little bit tricky because it can be difficult to exactly pinpoint some of the assets to filter them and generate a report. Improving the filtering capability would make the reporting easier.
We would like to have penetration testing features built into Nexpose, as it is the next area that we are going to be concentrating on. We have not yet tried it, but it is on our roadmap.
For how long have I used the solution?
We have been using this solution for one year.
What do I think about the stability of the solution?
We have not had any issues with stability. For what we are using it for, it is okay, and we use it on a weekly basis.
What do I think about the scalability of the solution?
We have five people who are working with Nexpose and we have not yet needed to scale.
How are customer service and technical support?
We have been in touch with support on one or two occasions but I was not the person who dealt with them.
How was the initial setup?
The initial setup is not complex. As soon as you deploy, you start by opening all of the needed communication tools on all of the target systems. In our situation, we deployed gradually as opposed to doing everyone at the same time.
We have five people who have access to this solution and can maintain it. They do not work on it full-time but can do site scanning and generate reports when needed.
What about the implementation team?
A third-party was brought in to implement this solution. However, I have done some of the upgrades and I would say that it is straightforward enough that it is not necessary to bring in anybody else.
What other advice do I have?
My advice for anybody who is implementing this solution is to begin by clearly identifying infrastructure and the most critical assets. This tool will give you good visibility into the network and the assets, but it is only the starting point. It is really the input for the process that you have in place to follow up and patch the assets. Simply knowing that they are vulnerable is not good enough, so the right process has to be put into place before it will work effectively.
I would rate this solution an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Senior manager at Software Productivity Group
Affordable solution with an easy initial setup process
Pros and Cons
- "It is a stable solution."
- "They should improve the cybersecurity feature of the solution."
What is our primary use case?
We use the solution for vulnerability management of our on-cloud environments.
What is most valuable?
The solution provides all the required features for vulnerability management.
What needs improvement?
They should improve the cybersecurity feature of the solution.
For how long have I used the solution?
We have been using the solution for a month.
What do I think about the stability of the solution?
It is a stable solution. We can connect it with other platforms easily.
What do I think about the scalability of the solution?
We have four to five solution users in our organization.
How was the initial setup?
The solution's initial setup process is easy.
What's my experience with pricing, setup cost, and licensing?
The solution's license costs around $30 per month. It is less expensive compared to other competitors.
What other advice do I have?
I advise others to consider the number of IP addresses required to be scanned for their network while opting for Rapid7. I rate the solution as a nine.
Disclosure: My company has a business relationship with this vendor other than being a customer:
Senior Consultant at a tech services company with 11-50 employees
Good visibility in the event of an attack
Pros and Cons
- "When it comes to the process, installation is very easy and does not take long."
- "All products have room for increased security and Rapid7 InsightVM is no exception."
What is our primary use case?
The solution is similar to Tenable, but Rapid7 also comes with Insight - Detection and Response, which integrates with InsightVM. This alerts the customer in the event of an attack or updates him about the status of a vulnerability. The solution provides increased visibility in the environment when integrating between these two products.
What needs improvement?
All products have room for increased security and Rapid7 InsightVM is no exception. This is why I do not give a perfect score to any product on principle.
For how long have I used the solution?
We have been using Rapid7 InsightVM for a couple of months.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
The solution is scalable.
We have plans to increase its usage.
Which solution did I use previously and why did I switch?
I have some experience with Tenable Nessus, although I did not use it on a professional basis.
How was the initial setup?
When it comes to the process, installation is very easy and does not take long. As a matter of course, installing a VM and connecting to a portal is easy. That is all that is needed. Time-wise, this may take an hour. Once the portal and scanner are connected one can start getting the environment.
What's my experience with pricing, setup cost, and licensing?
The license is annual and this is the optimal approach when it comes to most software.
What other advice do I have?
The solution is hybrid, meaning that if installation is required it must be done on the environment itself, on-premises, the portal being cloud-based.
The solution has very good integration, so I see no need for improvements in this regard at present.
I have no issues with the stability, security, user interface, reporting, monitoring board or Techstar reports. These are all good.
The documentation is quite detailed and straightforward. It is provided to me via the internet.
Off the top of my head, I cannot think of anything needing improvement.
We have a single customer who is utilizing the solution, but he makes use of IDR, not IVM.
I would recommend the solution to others.
I rate Rapid7 InsightVM as an eight out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner

Buyer's Guide
Download our free Rapid7 InsightVM Report and get advice and tips from experienced pros
sharing their opinions.
Updated: May 2025
Product Categories
Risk-Based Vulnerability ManagementPopular Comparisons
Qualys VMDR
Tenable Security Center
Tenable Vulnerability Management
Microsoft Defender Vulnerability Management
Nucleus
Arctic Wolf Managed Risk
Cisco Vulnerability Management (formerly Kenna.VM)
SanerNow CyberHygiene Platform
Balbix BreachControl
SecureWorks Taegis VDR
Fortra's Vulnerability Management
Buyer's Guide
Download our free Rapid7 InsightVM Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions: