Compare Rapid7 InsightVM vs. Tenable SC

Rapid7 InsightVM is ranked 3rd in Vulnerability Management with 10 reviews while Tenable SC is ranked 5th in Vulnerability Management with 9 reviews. Rapid7 InsightVM is rated 8.2, while Tenable SC is rated 7.8. The top reviewer of Rapid7 InsightVM writes "Speed and quality of vulnerability scanning translates to reliable and timely results". On the other hand, the top reviewer of Tenable SC writes "Enables us to centralize and correlate all data and understand where the gaps are in our security posture". Rapid7 InsightVM is most compared with Tenable Nessus, Qualys VM and Tenable SC, whereas Tenable SC is most compared with Tenable.io Vulnerability Management, Tenable Nessus and Qualys VM. See our Rapid7 InsightVM vs. Tenable SC report.
Cancel
You must select at least 2 products to compare!
Most Helpful Review
Find out what your peers are saying about Rapid7 InsightVM vs. Tenable SC and other solutions. Updated: May 2020.
419,214 professionals have used our research since 2012.
Quotes From Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:

Pros
The scalability is good. The scalability is more than good because it can operate both as a standalone and it can be integrated as part of applications. So that really makes it a very, very versatile solution to have.For us, the most valuable aspect of the solution is the log-sequence feature.It can operate both as a standalone and it can be integrated with other applications, which makes it a very versatile solution to have.Our developers can run the attacks directly from their environments, desktops.The vulnerability scanning option for analyzing the security loopholes on the websites is the most valuable feature of this solution.The automated approach to these repetitive discovery attempts would take days to do manually and therefore it helps reduce the time needed to do an assessment.Their technical support has been very active. If I have an issue, I can reach out to them and get an answer pretty quick.We are able to create a report which shows the PCI DSS scoring and share it with the application teams. Then, they can correlate and see exactly what they need to fix, and why.

Read more »

This solution is very easy to use and easy to install.It's easy to use. It's fast, it's a powerful easy to access tool.There are many integrations with things like the VMware NSX that are great, the reporting is really solid.The most valuable feature is the site scanning, where we can provide a complete subnet and what it is we need to scan on those devices.We feel the interface is very good. It is very easy to use, even a nontechnical person can use it.The most valuable feature for us is the different types of reporting it provides.Rapid7 InsightVM has given us a practical view of the vulnerabilities present in our organization.It is stable and scalable.

Read more »

The scans are the most valuable aspect of this solution.The predictive prioritization features are pretty good. They do a lot of research and we trust the research that they do internally. They have knowledge of what's going on with many companies, where we only get a view into what's going on here. So the ability to get best practices out of them as part of this solution, is valuable to us.Tenable also helps us to focus resources on the vulnerabilities that are most likely to be exploited. And since it is continuously updated, it allows us to reevaluate quickly if there are new vulnerabilities found...This solution has a much lower rate of false positives compared to competing products.One of the most valuable features is their distributed scan model for allotting engines to work together as a pool and handle multiple scans at once, across multiple environments. Automatic scanning distribution is a distinguishing feature of their toolset.What is useful to me is being able to fulfill very customized scanning policies. In the clinical environment, because of vendor control, we can't perform credential-vulnerability scanning. And network scans, which I've done before, can cause a lot of impact. Being able to create very customized policies to be able to routinely scan and audit our clinical networks, while simultaneously not causing impact, is important to us.I think that this is a good solution for evaluating vulnerability in the network.We really love the Security Center dashboard. It basically performs vulnerability scanning and then outputs a vulnerability data.

Read more »

Cons
We want to see how much bandwidth usage it consumes. When we monitor traffic we have issues with the consumption and throttling of the traffic.The solution limits the number of scans. It would be much better if we could have unlimited scans.When monitoring the traffic we always have issues with the bandwidth consumption and the throttling of traffic.Tools that would allow us to work more efficiently with the mobile environment, with Android and iOS.In terms of what needs improvement, the way the licensing model is currently is not very convenient for us because initially, when we bought it, the licensing model was very flexible, but now it restricts us.It would be nice to have a feature to "retest" only a single vulnerability that the customer reports as patched, and delete it from the next scans since it has already been patched.You can't actually change your password after you've set it unless you go back into the administration account and you change it there. Thus, if you're locked out and don't remember your password, that's a thing.We have had issues during upgrades where their scans worked on some apps better with previous versions. Then, we had to work with their tech support, who were great, to get it fixed for the next version.

Read more »

It would be nice to have an additional feature that would provide reports on who has logged onto the console or who did what on the console.The InsightVM cannot scan if we connect to our customer by the VPN.Some difficulties with the online reporting and lack of integrations.The reporting is a little bit tricky because it can be difficult to exactly pinpoint some of the assets to filter them and generate a report.The reporting has room for improvement. You cannot customize any report. If I need a specific requirement, I have to create a new report for it.This solution integrates with another module in Metasploit, that doesn't exist in the other solutions. It is subscribed to on our roadmap, but we chose to implement both Nexppose and AppSpider.A definite improvement would be to make it easier to run ad-hoc scans without needing to assign the asset to a site or group.There are not enough templates, and the reporting is weak with this solution.

Read more »

The reporting needs a lot of work on the template.There's a lot of information being streamed out of the reports. What would be nice, and maybe we just haven't found it, would be more of an executive-type view. We still expect it to collect all this information, but we would like a feature that would allow us to show it to an executive or a director or someone like that and give them some type of high-level overview but not get into the nitty-gritty.The vulnerability scan does not work correctly until the access privileges are set by the system administrator.It's good at creating information, it's good creating dashboards, it's good at creating reports, but if you want to take that reporting metadata and put it into another tool, that is a little bit lacking.If I want to have a very low-managed scan policy, it's a lot of work to create something which is very basic. If I use a tool like Nmap, all I have to do is download it, install it, type in the command, and it's good to go. In Security Center, I have to go through a lot of work to create a policy that's very basic.The web application scanning area can be improved.A good plugin editor would be a good additional option for the Security Center.In terms of configuration, there is some level of flexibility that we are not able to achieve.

Read more »

Pricing and Cost Advice
The costs aren't very expensive. It costs around $3000 or $4000.All things considered, I think it has a good price/value ratio.The pricing and licensing are reasonable to a point. In order to run multiple scans at a time, we are going to have to purchase a 100 count license, which is an overkill. Though, compared to what we were paying for, the cost seems reasonable.When we looked at all other vendors and what they were asking for, to provide a third of what Acunetix was capable of doing, it was an easy decision... But now that it's coming to a cost where it's line with market value, it becomes more of a competition... Acunetix is raising the cost of licensing. It's 3.5 times what we were initially quoted.Acunetix was around the same price as all the other vendors we looked at, nothing special.

Read more »

Our licensing costs are somewhere around $40,000 annually. There are no additional fees.The license is IP based. How many IPs you are using to scan is the amount of the license you have to buy. The number of users doesn't matter; many users can use it or only person. It depends on the culture of the organization.This solution is expensive, but it's fine for us as we have an open budget for security solutions. Protection and having the system secured is more important.The price of the solution is less than the competitors.I do not have experience with the pricing of the solution.

Read more »

We pay around 60,000 on a yearly basis.We're a Fortune 500 company... our licensing costs [are] in the seven figures.Costing is pretty reasonable compared to the competition.The pricing is more than Nexpose.The licensing costs for this solution are approximately $100,000 US, and I think that covers everything.We're able to save because we don't have to employ more staff members to help wit ht he scheduling of the scans, running the reports or sending them out to the systems owners. That alone is a big ROI for us.It is slightly more expensive than other solutions in the same sphere.

Read more »

report
Use our free recommendation engine to learn which Vulnerability Management solutions are best for your needs.
419,214 professionals have used our research since 2012.
Top Comparisons
Compared 40% of the time.
Compared 18% of the time.
Compared 12% of the time.
Compared 23% of the time.
Compared 15% of the time.
Also Known As
AcuSensorInsightVM, NeXposeTenable Unified Security, Tenable SecurityCenter
Learn
Acunetix
Rapid7
Tenable Network Security
Overview

Acunetix Web Vulnerability Scanner is an automated web application security testing tool that audits your web applications by checking for vulnerabilities like SQL Injection, Cross site scripting, and other exploitable vulnerabilities.

Rapid7 InsightVM is the vulnerability assessment tool built for the modern web. InsightVM combines complete ecosystem visibility, an unparalleled understanding of the attacker mindset, and the agility of SecOps so you can act before impact.

Tenable SC consolidates and evaluates vulnerability data across the enterprise, prioritizing security risks and providing a clear view of your security posture. With SecurityCenter, get the visibility and context you need to effectively prioritize and remediate vulnerabilities, ensure compliance with IT security frameworks, standards and regulations, and take decisive action to ensure the effectiveness of your IT security program and reduce business risk.

Offer
Learn more about Acunetix Vulnerability Scanner
Learn more about Rapid7 InsightVM
Learn more about Tenable SC
Sample Customers
Joomla!, Digicure, Team Random, Credit Suisse, Samsung, Air New ZealandACS, Acosta, AllianceData, amazon.com, biogen idec, CBRE, CATERPILLAR, Deloitte, COACH, GameStop, IBMIBM, Sempra Energy, Microsoft, Apple, Adidas, Union Pacific
Top Industries
REVIEWERS
Financial Services Firm38%
Comms Service Provider13%
Energy/Utilities Company13%
Insurance Company13%
VISITORS READING REVIEWS
Software R&D Company40%
Comms Service Provider13%
Government10%
Media Company7%
REVIEWERS
Financial Services Firm29%
Insurance Company29%
Comms Service Provider14%
Government14%
VISITORS READING REVIEWS
Software R&D Company33%
Comms Service Provider9%
Media Company7%
Financial Services Firm7%
VISITORS READING REVIEWS
Software R&D Company43%
Government12%
Comms Service Provider11%
Media Company7%
Find out what your peers are saying about Rapid7 InsightVM vs. Tenable SC and other solutions. Updated: May 2020.
419,214 professionals have used our research since 2012.
We monitor all Vulnerability Management reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.