I use the solution in my company for cybersecurity purposes.
External reviews
External reviews are not included in the AWS star rating for the product.
Easy to implement and is suitable for enterprise-sized businesses
What is our primary use case?
What is most valuable?
The most valuable features of the solution are the agent and the scanning.
What needs improvement?
I think the improvement in the tool should be to provide a better update to users because sometimes the information within the cloud and the scanner are not synchronized very fast.
For example, like, when we upgrade to a patch with the devices, it should be able to make it up to date right away, but it takes more than hours to update in the portal. We need to then do a rescan manually.
For how long have I used the solution?
I have been using Rapid7 InsightVM for six years. I am just a customer of the tool.
What do I think about the stability of the solution?
Stability-wise, I rate the solution a nine out of ten.
What do I think about the scalability of the solution?
The scalability of the product is very good. Scalability-wise, I rate the solution a nine out of ten.
In my organization, around five people use the product.
The product is used most of the time in my company.
I may plan to increase the use of the solution in the future if my business grows.
How are customer service and support?
I rate the technical support an eight out of ten.
Sometimes when I submit a case to Rapid7's support team, it takes them a very long time to provide a resolution. It is not very smooth.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I have experience with Nessus and GFI LanGuard. I started using Rapid7 InsightVM since I used some other products in the past. I think Rapid7 bought the company whose tool I was using. Rapid7 purchased a tool with a network sensor, after which the company offered our organization the use of Rapid7.
How was the initial setup?
As I had managed the tool's initial setup phase in my previous company, it would be easy for me. For the first-time user of the app, I think because the tool has an onboarding process, it should be very straightforward.
Regarding the product's deployment phase, I have all the instructions from Dell, and I can do everything by myself based on the documentation. The process may take a long time because I need to fix an appointment with Rapid7's team to start the onboarding process. Sometimes, it took at least four weeks to have an appointment. After I have an appointment, during the onboarding, the tool's team just does the syncing part, and then I follow all the steps to make sure everything is in place.
The solution is deployed on a combination, so even though the solution is deployed on the cloud, we have a console, so it is on-premise. It's like a combination consisting of a console and a cloud. Rapid7 has its own cloud.
The solution can be deployed in a month.
What about the implementation team?
The product's deployment was carried out with the help of my company's in-house team, and I mostly managed it myself.
What was our ROI?
The product has helped with cost-savings. The tool is used to manage areas like updating and monitoring everything. It is good to have an outstanding cybersecurity defense system instead of having to fix a problem when somebody has to deal with high vulnerabilities due to ransomware.
What's my experience with pricing, setup cost, and licensing?
The tool's price is neither too high nor too low. My company needs to pay 65,000 per year. There are no additional costs apart from the licensing fees attached to the solution.
Which other solutions did I evaluate?
I tried some tools and compared some other products with Rapid7 InsightVM. I considered Tenable Nessus against Rapid7 InsightVM. Tenable Nessus only has a real-time scanner, so it is not a complete solution.
What other advice do I have?
Rapid7 InsightVM fits into our organization's overall security posture in a critical manner.
Most of the features of Rapid7 InsightVM are helpful for identifying and managing vulnerabilities. The reporting part is very useful.
The live monitoring feature in Rapid7 InsightVM has enhanced your security measures in a very critical manner. With Rapid7 and InsightVM, the measurements are critical because we are based on the report, so we know exactly what endpoint or device needs to be patched. Based on the agent and report, we can identify what device we need to handle critically based on the priority.
My company does not have to meet any compliance requirements. In the previous company, there was a need to meet some compliance requirements.
The tool is easy to implement, but you need to have a team to work, and keep it up to date. I wouldn't recommend it for one or two people.
I recommend the product to others.
The product is more suitable for enterprise-sized businesses.
I think the tool doesn't have an AI feature.
I rate the overall tool a nine out of ten.
Nexpose is an excellent tool that helps identify vulnerabilities.
It integrates seamlessly with various other security tools and systems, such as SIEMs, ticketing systems, and DevOps tools, facilitating a more streamlined security workflow.
The tool supports automated remediation workflows, which can significantly reduce the time and effort required to address vulnerabilities.
Cost is very high to compair to other tool.
Some users have experienced false positives in the scan results, which can lead to unnecessary remediation efforts and wasted resources.
The detailed compliance reporting and helps organizations ensure they meet various regulatory standards such as PCI-DSS, GDPR, and HIPAA.
Useful to identify and assess vulnerabilities but needs to provide a pure cloud-based version
What needs improvement?
The product is not a cloud solution. The tool can only be used as a hybrid solution, meaning it can be used on the cloud and on an on-premises deployment model. There are certain limitations because of the product being used on a hybrid model. Rapid7 InsightVM doesn't offer a solution purely in the cloud.
Competitors of Rapid7 InsightVM, like Tenable.io and Qualys, offer pure cloud solutions.
For how long have I used the solution?
I have been using Rapid7 InsightVM for seven or eight years. My company serves as a distributor of the tool.
What do I think about the stability of the solution?
Sometimes, there were certain parts and programs of the product about which the customer used to complain.
Stability-wise, I rate the solution a six to seven out of ten.
What do I think about the scalability of the solution?
It is a highly scalable solution. One of my company's customers uses the tool on 1,30,000 devices.
My company deals with clients who own small as well as enterprise-sized businesses.
How are customer service and support?
In the past, the support offered for the product was good. Unfortunately, over a period of time, the support offered has become poor.
I rate the technical support a four to five out of ten.
How would you rate customer service and support?
Neutral
How was the initial setup?
The product's initial setup phase was very easy.
The solution can be deployed in a few hours. The time required depends on the scale of the deployment. If there are 1,000 or 10,000 deployments to be done, then it takes time. If the customer provides a Q&A to calculate the design of the network, then the process becomes easier. If the customer does not know about their network, then the deployment process takes time since our company has to discuss several things with them before starting the process.
What's my experience with pricing, setup cost, and licensing?
The product is cheaper than the other similar tools available in the market.
What other advice do I have?
My company uses Rapid7 InsightVM to identify and assess vulnerabilities.
The product has improved our company's vulnerability remediation process. The tool finds vulnerabilities by scanning devices and networks. The solution is also useful in the area of database scanning.
The product area I find to be valuable in vulnerability management workflow stems from many aspects, like reporting, which is very useful. Rapid7 InsightVM's integration with Jira is also very effective and useful for end users. The coverage of the vulnerability offered by the product is very good. The GUI for Japanese users is good.
The product's integration capabilities have improved my company's security posture, as many other systems can be integrated with it. The export feature of the product helps users deal with other products like ServiceNow or Splunk.
The product is more useful for scanning than for its real-time visibility, but I can say that its functionalities come very close to real-time features. The product scans every six hours.
In large and diverse environments, the performance and the scalability of the product are not bad.
The product is easy to understand, making it good for companies that doesn't have much expertise in the area of security. It is an easy to use product. The product also provides a GUI in Japanese, while taking care of the reporting part efficiently, making it very convenient for the end users in Japan.
I rate the product's capacity to offer ease of use an eight out of ten.
I rate the overall tool a six to seven out of ten.
Better than most of the products in the market, but not the best
Reporting
Dashboards
Tons of threat intelligence and research data integrated with the product by Rapid7. Stuff like Metasploit DB, AttackerKB and project Heisenberg are some of the best integrations.
Remediation Projects
Risk Scoring - the new Active Risk Scoring is awesome.
Scan Assistant (probably the best service for vuln scanning)
Native Jira integration is not really native. Breaks all the time.
Sometimes it takes days to identify some vulnerabilities which is a major drawback especially for critical vulnerabilities (Jetbrains TeamCity CVSS10 vuln is one example, took it 3 days to identify vulnerable assets)
Too much administrative efforts to setup stuff.
Particularly useful for focusing on customer-facing systems and offers excellent scalability
What is our primary use case?
With InsightVM, I continuously monitor my network by setting up regular scans to identify vulnerabilities in real-time. It IS particularly useful for focusing on customer-facing systems at our perimeter, helping me prioritize and quickly address any security risks.
What is most valuable?
InsightVM offers a robust platform for identifying, prioritizing, and addressing vulnerabilities across an organization's IT infrastructure.
What needs improvement?
One area I would like to improve in InsightVM is its integration with other solutions, particularly for better compatibility with upcoming tools we plan to adopt. Enhanced functionality for budget management or change management databases could also be beneficial.
For how long have I used the solution?
I have been working with InsightVM for over two years.
What do I think about the stability of the solution?
I would rate the stability of the solution as a nine out of ten.
What do I think about the scalability of the solution?
InsightVM's scalability is top-notch and I would rate it a solid nine out of ten. Being a cloud-based solution, it effortlessly adjusts to accommodate varying needs and can easily scale from small to large environments.
How are customer service and support?
Rapid7's technical support is highly responsive and helpful. I would rate them as a nine out of ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I chose Rapid7 over Tenable Nessus because of its better performance, comprehensive functionality, and stronger support for operating systems and services. While Tenable Nessus may be cheaper, it lacks integration with other features and is more suited for SMBs rather than enterprises.
How was the initial setup?
Implementing InsightVM was straightforward. Setting it up to scan external networks at the perimeter was effortless; I just needed to create a cloud account and start using the solution. For internal network scanning, I installed the software on my notebook, which took about five to ten minutes for a single version setup, but it is important to note that it doesn't support Windows platforms.
What's my experience with pricing, setup cost, and licensing?
InsightVM's pricing can vary depending on the coverage needed. While it may not be the cheapest option, purchasing an unlimited license could be cost-effective for larger environments. For smaller needs, it might be more expensive compared to competitors. I would rate the affordability of the product at a four out of ten.
What other advice do I have?
I prioritize vulnerabilities in InsightVM by first focusing on customer-facing systems at our perimeter, which helps me quickly identify and address any security risks. Then, I utilize the cloud-based engine to scan internal networks and ensure comprehensive coverage without the need for complex on-premise solutions, making it easy to manage from my notebook connected to the internet.
Additionally, in InsightVM, we prioritize vulnerabilities by utilizing comprehensive data sources like the NVD and Rapid7's specialized risk calculation methods. The solution provides detailed information, including exploitability and impact, and evaluates whether vulnerabilities could be exploited in specific environments like NetApp.
I would recommend InsightVM to others. Overall, I would rate the product as an eight out of ten.
Master in Vulnerability Management
A vulnerability management solution that is great for managing video equipment
What is our primary use case?
We handle a lot of video equipment and Rapid7 InsightVM helps us to scan subnets, around 150,000 of them.
How has it helped my organization?
Rapid7 InsightVM is more focused on proactive liability management. However, when there's an incident, our team can handle it, but it's not a top priority for me. I think having another solution, like a response automation tool, would be more helpful. Vulnerability management can't prevent incidents once they're in progress, but it's essential to prevent them before they happen.
What is most valuable?
The remediation project is pretty effective because it allows us to choose specific assets and set limitations on them for a certain period which allows us to track and follow up on those limitations.
However, when it comes to real-time monitoring and live dashboards, InsightVM doesn't quite fit the bill. It's not a real-time solution and is not instant.
What needs improvement?
Rapid7 InsightVM, has impressive capabilities, especially when it comes to managing video equipment. However, we've noticed that Rapid7 also offers a cloud solution called CloudSec, and we don't have that. We think it would be better if InsightVM had all the features for both on-premise and cloud management.
For how long have I used the solution?
I have been using Rapid7 InsightVM for the past 6 years.
What do I think about the stability of the solution?
I would rate it nine out of ten, especially when it is deployed on Linux Box.
What do I think about the scalability of the solution?
It is very scalable and I would rate it ten out of ten.
How was the initial setup?
As for deployment time, it varies based on the size of the organization and network sensitivity. For example, in a bank, scans might only happen at specific times, like during the night. Generally, deployment can be quick, but there are many factors to consider. You install the console and the scan engine, and then configure them based on network complexity. Scans themselves take less than 20-30 minutes, but the non-technical aspects, like setting up profiles and firewall rules, can take more time.I would rate it 8 out of 10.
What other advice do I have?
I would rate it 8 out of 10.
Comprehensive vulnerability management with robust set of features, making it highly effective for enhancing security posture and mitigating risks
What is our primary use case?
It's a vulnerability scanning tool utilized within the vulnerability management process. We employ it to conduct internal vulnerability assessments of company or organizational host IPs.
How has it helped my organization?
It aids in enhancing the overall security posture within our organization. It uncovered numerous vulnerabilities that had been overlooked, which was quite beneficial.
What is most valuable?
The most valuable features are its reporting capabilities and the host discovery functionality.
What needs improvement?
The primary issue I encountered initially with this tool was related to configuration. There is a significant learning curve, that non-technical individuals, especially those not specialized in computer science or the information security industry, might face.
For how long have I used the solution?
I have been working with it for six months.
What do I think about the stability of the solution?
I am satisfied with the stability provided.
How was the initial setup?
The initial setup went smoothly, but after completing it, I encountered difficulties when attempting to use features like the dashboard and the scan now option. Specifically, I faced challenges with scanning the host, which proved to be quite frustrating.
What about the implementation team?
The initial setup wasn't overly difficult, so it took me around one to two days due to troubleshooting issues. Overall deployment took about two to three days in total.
What other advice do I have?
I highly recommend Rapid7 as my experience with it is very positive. Overall, I would rate it eight out of ten.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Easy deployment, but technical support could respond faster
What is our primary use case?
The core domain use of the solution is verification, scanning, and finding out the vulnerabilities in real time.
How has it helped my organization?
The ease of deployment and configuration allows users to onboard quickly, aligning smoothly with various functionalities.
What is most valuable?
The data sheet is good in pricing and promises. The customers are very price-conscious. You have to satisfy technical requirements. This combo makes the product valuable and usable.
What needs improvement?
Two things are consistent. The rest of the things run fine. The technical side does not respond quickly. They take a lot of time. The priority should be to respond to the customer to serve the customer.
For how long have I used the solution?
I have been using Rapid7 InsightVM for more than three years.
What do I think about the stability of the solution?
The solution’s stability is good. It keeps on running. There are no system complaints.
What do I think about the scalability of the solution?
The solution’s scalability is linked to the new scope and the cost.
Which solution did I use previously and why did I switch?
We are actively seeking alternatives. If you can offer a better solution, superior after-sales service, and overall better everything, we would like to explore what you have to offer.
How was the initial setup?
The initial setup is not so complex. It is quickly deployable configurable and integrated with your existing setup.
The common process for Rapid7 InsightVM involves comparing it against their standard procedures to ensure compliance with the required licenses and resources. Users download the necessary files and initiate/reactivate licenses. Certain configurations are also set up. This process typically takes two to three days for the department, but we usually allocate a week for completion.
Our team feels enabled enough after completing the training session on Rapid7 InsightVM. We conduct our tests independently, and whenever we need support, we seek assistance directly from Rapid7. This process isn't overly complex or time-consuming. We ensure thorough preparation by gathering all necessary information, addressing internet concerns, and informing the customer. Once fully prepared, we proceed forward.
What's my experience with pricing, setup cost, and licensing?
The solution’s pricing is good because the value proposition delivers a report box. It is not very costly.
What other advice do I have?
Since the product is cloud-based, there's no maintenance. Whatever the information or the customization of the customer needs to be confirmed. The hardware needs maintenance.
Overall, I rate the solution a six out of ten.
"One of the Best tool for Vulnerability Management"
is also very cool and helps alot in easily go throught the stats.