Rapid7 InsightVM Other Advice

DA
Cyber ​​Security Analyst at a tech services company with 1-10 employees

I give the solution eight out of ten.

View full review »
Shakeel Ahmad - PeerSpot reviewer
Sr Cyber Security Consultant at Google

I recommend the solution from the reporting side but am not sure I recommend it from the scanning side. The issue with firewalls needs to be fixed and then I will definitely recommend the solution. 

I rate the solution a seven out of ten. 

View full review »
RW
IT Security Architect at a government with 1,001-5,000 employees

It's important to take the time to have a full understanding of how schemes are scheduled, how sites and asset groups are set up and make sure it's done upfront. It's a big help. If you remove an old site and recreate it with small differences you lose some of the data associated with the old site. Getting the organization sorted from the beginning would be the biggest piece of advice.

It's very important to know what your environment is made up of. People often leave companies without documenting things and there's a lot that not everybody knows about because it was in the back of someone's mind. We now have a great repository of information on what's active on our network, what's installed on it, how all of those systems are interacting, and really having that visibility is great. One of the big lessons we were able to get value from immediately was really just having good visibility of what's in our environment.

It's a very solid product, reporting is great, it's reliable. We have a lot of faith in the results it gives us. At least once a week, I get a notification with some great new features that they've added that I didn't really even know I wanted, but now I have it and can't imagine life without it. 

The product is cloud-based, but with an on-prem portion, but it all auto-updates. The actual scanning engine and all of that is on-prem for us. It's a SaaS solution, it's not one where we are running our own servers. It's provided as a service for us on the cloud. The on-premises stuff that we're running is just virtual machines on our VMware environment.

I would rate this product an eight out of 10. 

View full review »
Buyer's Guide
Rapid7 InsightVM
April 2024
Learn what your peers think about Rapid7 InsightVM. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
768,578 professionals have used our research since 2012.
Christian Kyony - PeerSpot reviewer
Senior Security Engineer at DRS

I would rate it 8 out of 10. 

View full review »
SonNguyen3 - PeerSpot reviewer
Technical Manager at a computer software company with 11-50 employees

Overall, I would rate the solution an eight out of ten.

View full review »
Andrei Bigdan - PeerSpot reviewer
Executive Manager at B2B-Solutions LLC

I prioritize vulnerabilities in InsightVM by first focusing on customer-facing systems at our perimeter, which helps me quickly identify and address any security risks. Then, I utilize the cloud-based engine to scan internal networks and ensure comprehensive coverage without the need for complex on-premise solutions, making it easy to manage from my notebook connected to the internet.

Additionally, in InsightVM, we prioritize vulnerabilities by utilizing comprehensive data sources like the NVD and Rapid7's specialized risk calculation methods. The solution provides detailed information, including exploitability and impact, and evaluates whether vulnerabilities could be exploited in specific environments like NetApp.

I would recommend InsightVM to others. Overall, I would rate the product as an eight out of ten.

View full review »
JonathanShilling - PeerSpot reviewer
System Analyst II at a energy/utilities company with 1,001-5,000 employees

I recommend reviewing the documentation and studying the built-in reports because they are a valuable resource. It's a great product that reports everything that's wrong with a system, providing detailed and high-level reports. 

I rate the solution nine out of 10. 

View full review »
AP
IRM Technical Consultant at Shell

I would rate this solution a seven out of ten.

View full review »
UdayaSri Kariyawasam - PeerSpot reviewer
Engineering Lead - DevOps at Persistent Systems

I recommend doing a comparison of Qualys, Rapid7, and Nessus. Because the scope is different from company to company and cluster to cluster, it would be good to research each product and decide according to your needs.

If I were to rate Rapid7 InsightVM, I would rate it at seven on a scale from one to ten.

View full review »
DS
Cyber Security Architect at a healthcare company with 11-50 employees

It is important to have a strong patch management plan that prioritizes what and how you need to patch. 

The solution does the vast majority of work but you need a proper system so you can take output to your operations team for patching. A good workflow between teams is important. 

I rate the solution a ten out of ten. 

View full review »
AD
IT Manager at a aerospace/defense firm with 10,001+ employees

The solution works well. I recommend it to others and rate it as an eight.

View full review »
Agustinus DWIJOKO - PeerSpot reviewer
Network & Security Engineer at PT. Centrin Online Prima

We're working with the latest version of the solution, however, I cannot recall the exact version number.

While our clients are using a hybrid cloud, the customers still need to install on-premise. Your console right now is like a dashboard; it's moved to the cloud.

I'd advise users to try the solution. If they are using InsightVM they will be able to quickly understand what the vulnerabilities are on their assets.

I'd rate the solution eight out of ten.

View full review »
ES
Owner at Sidif Del Caribe Corporation

I would recommend this solution. I would rate Rapid7 InsightVM an eight out of ten.

View full review »
ME
Chief Executive Officer at a outsourcing company with 11-50 employees

I believe they see us as resellers because we resell it, but when we use it for professional services, they regard us as partners. They use both terms in the same sentence.

We support it.

I strongly recommend it. It's a good product. 

It's only the backend support that needs to be improved. However, there isn't very much that has room for improvement in the product right now.

They are not flawless. We have had problems here and there, but overall, I would rate Rapid7 InsightVM an eight out of ten.

View full review »
HW
Marketing Expert at a comms service provider with 51-200 employees

My company uses Rapid7 InsightVM to identify and assess vulnerabilities.

The product has improved our company's vulnerability remediation process. The tool finds vulnerabilities by scanning devices and networks. The solution is also useful in the area of database scanning.

The product area I find to be valuable in vulnerability management workflow stems from many aspects, like reporting, which is very useful. Rapid7 InsightVM's integration with Jira is also very effective and useful for end users. The coverage of the vulnerability offered by the product is very good. The GUI for Japanese users is good.

The product's integration capabilities have improved my company's security posture, as many other systems can be integrated with it. The export feature of the product helps users deal with other products like ServiceNow or Splunk.

The product is more useful for scanning than for its real-time visibility, but I can say that its functionalities come very close to real-time features. The product scans every six hours.

In large and diverse environments, the performance and the scalability of the product are not bad.

The product is easy to understand, making it good for companies that doesn't have much expertise in the area of security. It is an easy to use product. The product also provides a GUI in Japanese, while taking care of the reporting part efficiently, making it very convenient for the end users in Japan.

I rate the product's capacity to offer ease of use an eight out of ten.

I rate the overall tool a six to seven out of ten.

View full review »
KM
Head of Cyber security analysis at DNV Poland Sp. z o.o.

InsightVM has integration with Kubernetes, which no other solution has. I would give Insight VM a rating of eight out of ten.

View full review »
SH
Head of Cyber Security at a tech services company with 51-200 employees

Since the product is cloud-based, there's no maintenance. Whatever the information or the customization of the customer needs to be confirmed. The hardware needs maintenance.

Overall, I rate the solution a six out of ten.

View full review »
TW
Cybersecurity Consultant at a wholesaler/distributor with 51-200 employees

I'm a partner, not a customer.

I've been using the solution's latest version and updating it often. 

I'd advise people to use the product as a vulnerability scanner and as a remediation tool. They should look at the whole brand and see if any of their other products can integrate with the scanner. 

I would rate the solution nine out of ten.

View full review »
BV
Security Specialist at a financial services firm with 1,001-5,000 employees

Experiment with it and gain some experience with it.

I would rate Rapid7 InsightVM an eight out of ten.

View full review »
it_user1152534 - PeerSpot reviewer
Information Security Senior Expert (Founding member, African Cybersecurity Center) at a financial services firm with 10,001+ employees

Rapid 7 is a leading solution that has been implemented in many companies.

In Nexpose you have the console and the app assistant for Rapid 7. The design can be implemented in all of the segments of the network to scan, perform the scale of the scan, perform the reporting, generate the reports, and send it to the central console.

I would suggest that customers acquire this solution.

In addition to management, we are subscribed to the security dispense team and the company emergency dispense team. We always receive the bulletins, so we are always aware of the vulnerabilities.

I appreciate this solution. All of the features that are included are enough for me.

This is an excellent solution and I would rate it a ten out of ten.

View full review »
MuhammadMurtaza - PeerSpot reviewer
Information security engineer at CYBERISK

I highly recommend Rapid7 as my experience with it is very positive. Overall, I would rate it eight out of ten.

View full review »
KW
IT Security Engineer

We use this solution for our clients.

We're dealing with the latest version of the product.

InsightVM is a solution based on on-prem infrastructure connected to the cloud service, so it's a hybrid solution.

Overall, it's a nice tool. 

I'd rate the solution nine out of ten. 

View full review »
Muhammad Ali Aziz - PeerSpot reviewer
Senior Manager Cyber Security Services & Solutions at Trillium

InsightVM is easy to use, has a well-defined dashboard, and can be customized according to your needs. You can also segregate your assets and define IP ranges. I would give InsightVM a rating of nine out of ten.

View full review »
Khizar Butt - PeerSpot reviewer
Country Sales Lead at securic systems

My advice is to explore many options and look at the integrations available. My personal experience is that only implementing vulnerability management doesn't solve all of the problems. We also needed evaluator integrations that provide preventative measures.

I would rate this solution an eight out of ten. 

View full review »
LM
Information Security Officer at Umniah

I would rate it nine out of 10.

View full review »
JS
Director of Information Technology at a government with 201-500 employees

The company I worked for was just a customer and I was just an end-user. There was no business relationship between the two companies that I was aware of.

The company is considering moving from on-premises to the cloud.

I am unsure of which version of the solution is being used currently. I'm no longer at the company where I used the product.

While the solution worked well, I have never compared other solutions, so I don't know if it's best in class or not.

I'd rate the solution six out of ten.

View full review »
ZR
Senior Security Analyst at a financial services firm with 1,001-5,000 employees

I would recommend the product. The product is very good.

I would rate the product between a nine and a nine point five (out of 10).

View full review »
FH
Senior manager at Software Productivity Group

I advise others to consider the number of IP addresses required to be scanned for their network while opting for Rapid7. I rate the solution as a nine.

View full review »
BR
Security Solution Engineer II at a security firm with 501-1,000 employees

I would advise others to make sure that every asset in the environment is monitored by the tool. I see many customers who think they have full coverage of all assets, but they are missing a part of the network. In such a case, they will get an incorrect understanding of their security.

I would rate this solution a nine out of ten.

View full review »
SK
Service Delivery Manager at a security firm with 11-50 employees

We’re partners.

We’re always using the latest version of the solution.

There's a mix of deployments. There's an on-prem deployment in certain customer areas. However, there's also a cloud deployment from the MSSV point of view as well.

The scanner is always on-prem. The majority of the scanners that we've deployed are on-prem. Although some of the consoles are selling cloud-deployed, other consoles would be on-prem.

I’d rate the solution seven out of ten.

View full review »
DM
Security Analyst at Zavarovalnica Triglav dd

My advice would be to just use it. 


As a whole, it's a pretty good product. I don't have any problem with it.

If they had the audit reporting then I would rate it a ten out of ten, but as it is now, I would rate this solution a nine out of then.

View full review »
JV
Cyber Security Engineer at a manufacturing company with 5,001-10,000 employees

I would recommend this solution to others, but more integration features would be more helpful.

I would rate Rapid7 InsightVM an eight out of ten.

View full review »
DB
CoFounder & Head of Technology at intuity

I would rate Rapid7 InsightVM a nine out of 10.

View full review »
PR
Information Security Manager at a educational organization with 5,001-10,000 employees

Take a test drive. If you don't test drive it, how do you know you're going to like it or if it even works. Would you buy a car without test driving it? Absolutely not. In this case, it’s a sales contract. It's a service for one to three years. Backing out of it is pretty much impossible.

I rate it at eight out of 10. It just works. We haven't had any trouble with it. We've had good support. What's not to like? But it's an eight because the software that can be purchased is not the ultimate software. It's hard to give anybody a 10.

View full review »
AA
Material Coordinator at a energy/utilities company with 1,001-5,000 employees

I recommend this solution to others and for them to use a partner for the implementation. It can be difficult for the first time.

I rate Rapid7 InsightVM an eight out of ten.

View full review »
FA
Head of Cybersecurity Assurance & Controls Director at a tech services company with 1,001-5,000 employees

I would rate this solution a five out of ten.

View full review »
JE
Information Technology Security Specialist at Digitaltrack

I'm a reseller. 

I'm not sure which version of the solution I'm using. It might be version six or seven. 

I'd recommend the solution to others. 

I would rate the solution eight out of ten. 

View full review »
MH
Owner at a tech services company with 1-10 employees

Do your proof of concepts if you can. Make sure you develop your risk strategy. That's important, because it's going to give you a risk number, it's going to give you critical: highs, mediums, but you need to understand what is the risk methodology that you're going to follow. Just because it says it's critical because of how many vulnerabilities you have, doesn't mean that you need to work on it right away.

For example, there was a vulnerability that had 2,000 nodes affected. It put it as a high-risk, whereby there was another vulnerability where there were only about 10 hosts affected — it put it at medium-risk. However, the high-risk one, because it had more nodes affected, did not have a POC associated with it. A novice person looking at it would say, "I need to work on these 1,000 vulnerabilities because it's a high-risk, and ignore the medium." Well, the medium one had an active POC on it. If you didn't have a person who understood how to read the report and what it's actually telling you, then you would say, "Hey, you know what, I'm going to use these, I'm going to cut my risk down because I got 1,000 nodes with this vulnerability and I'm going to put this chain out real quick and I'm going to reduce my risk real quick because of the numbers." Well, in my opinion, you didn't reduce your risk because you have 10 nodes out there with a vulnerability that's rated medium and it has a POC on it.

Overall, on a scale from one to ten, I would give this solution a rating of eight. I'm going to say that is because shame on Rapid7 for having such great applications, but then that little piece there that they know about hasn't been fixed. If I remember, if I go probably log back into the community, it's probably been asked a couple of times.

View full review »
PD
Assistant Engineer at Harel Mallac Technologies Ltd

I would recommend this solution to others.

I rate Rapid7 InsightVM a nine out of ten.

View full review »
it_user988146 - PeerSpot reviewer
Director of Cyber Security (CISO) at a marketing services firm with 201-500 employees

I had implemented InsightVM before at another company. I liked it when we were using it there which is why it ended up here. I have also had previous experience with Qualys. I did not have the time or the luxury to sit back and do a full analysis, RFI (Request for Information) and RFP (Request for Proposal) when we had to bring on the solution. We are not the CIA (Central Intelligence Agency), we are not the NSA (National Security Agency). We do not need any sophisticated solution or anything like that. We just needed something we could bring in, get online fairly quickly, and get running to do reports. Rapid7 InsightsVM fit the bill.  

On a scale of one to ten (where one is the worst and ten is the best), I would rate Rapid7 InsightVM as probably about an eight-out-of-ten. It gets an eight rather than scoring higher just because of some of the other stuff that I wish we had.  

View full review »
Khaoula Saidi - PeerSpot reviewer
Cloud and Cyber-Security Technician at Software Productivity Group

I rate Rapid7 InsightVM seven out of 10.

View full review »
it_user1336563 - PeerSpot reviewer
Technical Consultant at Yip Intsoi

We're a partner of InsightVM.

We're most likely using the latest version of the solution, however, I'm not sure which exact version number it is.

We've deployed on-premises with a local scan engine.

I'd advise companies that are looking into vulnerability assessment or faster deployment, to check out InsightVM. It's easy to expand as necessary and offers flexibility in its pricing.

I'd rate the solution nine out of ten.

View full review »
GN
Security Engineer at a computer software company with 51-200 employees

If your company has the budget for this product, I would recommend it. 

I rate the solution seven out of 10. 

View full review »
FA
Senior Consultant at a tech services company with 11-50 employees

The solution is hybrid, meaning that if installation is required it must be done on the environment itself, on-premises, the portal being cloud-based. 

The solution has very good integration, so I see no need for improvements in this regard at present. 

I have no issues with the stability, security, user interface, reporting, monitoring board or Techstar reports. These are all good. 

The documentation is quite detailed and straightforward. It is provided to me via the internet. 

Off the top of my head, I cannot think of anything needing improvement.

We have a single customer who is utilizing the solution, but he makes use of IDR, not IVM.

I would recommend the solution to others.

I rate Rapid7 InsightVM as an eight out of ten. 

View full review »
TJ
IT Security Analyst at a financial services firm with 1,001-5,000 employees

We are thinking about changing right now. We have always used Rapid7, but we are thinking about changing now.

My advice to anyone considering Rapid7 InsightVM is to look at the other vendors first.

On a scale of one to ten, I would give Rapid7 InsightVM a 3.

View full review »
IS
Enterprise ICT Security Architect at a tech services company with 1-10 employees

Overall, this is a product that I am very satisfied with.

I would rate this solution an eight out of ten.

View full review »
PJ
Vice President at INET Managed Services Co.,LTD.

I would recommend having the distributor help you to explain how this software works and to help with the details. I would rate it at an eight out of ten.

View full review »
MF
Infrastructure Security Architect at a comms service provider with 11-50 employees

My advice for anybody who is implementing this solution is to begin by clearly identifying infrastructure and the most critical assets. This tool will give you good visibility into the network and the assets, but it is only the starting point. It is really the input for the process that you have in place to follow up and patch the assets. Simply knowing that they are vulnerable is not good enough, so the right process has to be put into place before it will work effectively.

I would rate this solution an eight out of ten.

View full review »
Smriti Rani - PeerSpot reviewer
System Engineer at a tech services company with 201-500 employees

I rate Rapid7 InsightVM 10 out of 10.

View full review »
it_user121395 - PeerSpot reviewer
ITSM & AntiFraud Consultant with 51-200 employees

Nexpose is one of the best solution on the market with very good development. One of it's key features was the On-Premise installation and Community Edition. Also it integrates flawless with Metasploit.

View full review »
ME
Senior Cyber Security Specialist at a tech services company with 1,001-5,000 employees

Tenable is number one, Rapid7 comes second.

I would rate Rapid7 a six out of ten.

View full review »
it_user606432 - PeerSpot reviewer
Works at a insurance company with 501-1,000 employees

Users need to customize the policy compliance in order to optimize usage.

View full review »
AJ
Security Consultant at a tech vendor with 11-50 employees

I rate Rapid7 InsightVM an eight out of ten.

View full review »
Buyer's Guide
Rapid7 InsightVM
April 2024
Learn what your peers think about Rapid7 InsightVM. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
768,578 professionals have used our research since 2012.