Risk-scored vulnerability management — Rapid7 InsightVM ranks findings 0–1000 on evidence of real exploitation, not theoretical CVSS, and Remediation Projects turn the list into assigned work with owners and deadlines. You host the console, so the scan data can stay in India.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Data residency & processing — confirm before the PoC
Where data lives
Your console — India if you choose
The Security Console and its database are hosted by YOU: on-premises, or in AWS Mumbai or Azure Central India. Your asset inventory, scan results and vulnerability database — a complete map of every weakness in your estate — can stay in country. This is the one Rapid7 product where the architecture gives you that answer.
Where it is processed
Some metadata still leaves India
The Rapid7 cloud layer provides dashboards, Remediation Projects, Goals and SLAs, the Executive Risk View and Active Risk scoring — and Rapid7 has no India region. Confirm in writing exactly what that layer holds before you rely on this as a regulatory answer.
Be precise here, because a comfortable answer is easy to reach and wrong. “The scan data stays in India” and “nothing leaves India” are different claims, and an auditor will probe the difference. TechBag obtains Rapid7’s written position on what the cloud platform layer holds as part of the quote. If your obligation requires that nothing at all leaves Indian jurisdiction, look at Qualys VMDR, which runs an India platform.
Quick answer
This page covers Rapid7 InsightVM — the SIEM. The other pillars:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
Risk-based vulnerability management for hybrid estates. Scans servers, workstations, network devices, containers and cloud instances, scores what it finds, and tracks the fixing to a deadline.
What consolidation actually replaces, dimension by dimension.
| Dimension | No / separate AI tool | InsightVM |
|---|---|---|
| Detection basis | Rules you wrote in advance | Baselines, and deviation from them |
| Stolen credentials | Nothing malformed to match | Behaviour is wrong, so it scores |
| Pricing axis | Per GB ingested — grows on its own | Per monitored asset — grows with the estate |
| Deployment | Cloud-only, or on-prem-only | Both, with a mature product each side |
| Existing SIEM | Rip and replace | Analytics can augment what you have |
| Investigation | Analyst queries for the timeline | Smart Timelines assembled for them |
| Honest caveat | — | Two platforms post-merger — ask the roadmap |
| Best fit | — | Big volume, small team — or on-prem |
The deployment-freedom answer — for the deepest out-of-the-box content, weigh Splunk (TechBag sells it).
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
The core of the deployment, hosted by you on Windows Server or Linux with a PostgreSQL database. It defines sites, schedules scans, stores all asset and vulnerability data and generates reports. Sizing is substantial: twelve cores, 64 GB RAM and 2 TB storage at twenty thousand assets, rising to 256 GB and 8 TB at four hundred thousand. This is your capital cost, not Rapid7's.
Workers deployed across network segments that perform scanning and return results to the Console, holding data only temporarily. They connect either in standard mode on TCP 40814, where the Console initiates, or reverse mode on TCP 40815 for engines behind NAT. Rapid7 also operates Hosted Scan Engines for external perimeter scanning without you deploying infrastructure. Engine pools distribute load across large estates.
The same agent used by Incident Command, installed once and collecting on its own schedule rather than only during scan windows. This solves the laptop problem: assets never on the network when a scan runs still get assessed. Its limitation is fundamental — it performs local checks only and cannot perform remote or unauthenticated network checks.
A lightweight service on target hosts that establishes a trusted channel with the Scan Engine using ECDSA certificates and AES encryption, delivering authenticated scan results without storing or rotating administrative credentials. It also runs faster and lighter than credentialed scanning, particularly for policy assessment. It is dormant until a Scan Engine calls it, and complements rather than replaces the agent.
Rapid7's cloud, adding what the on-premises console lacks: live dashboards, Remediation Projects, Goals and SLAs, the Executive Risk View and Remediation Hub. Active Risk scoring and cross-product integration also live here. Reviewers report console-to-cloud synchronisation is not always fast, and feature parity between the two interfaces is imperfect.
One workspace where people meet, make, and share — work moving in one place, not emailed between tools.
Sentinel collects, correlates and stores security telemetry — and the tier each table lands in is what sets your bill. Here are the five pieces that matter. Part of Defender XDR, managed in one portal, with Security Copilot AI.
Finds and catalogues devices across on-premises networks, cloud accounts and remote endpoints into one inventory.
Logs into targets to enumerate installed software and configuration for accurate local vulnerability detection.
Probes exposed network services from outside the host to find what an attacker without credentials would see.
Collects vulnerability data from laptops and roaming assets on its own schedule regardless of scan windows.
Delivers authenticated scan depth using certificates instead of stored administrative credentials.
Pulls asset inventory and configuration from AWS, Azure and GCP so cloud instances appear alongside on-premises assets.
Ranks vulnerabilities 0 to 1000 using live exploitation evidence rather than theoretical CVSS severity alone.
Weights findings using CISA KEV, Metasploit, ExploitDB, AttackerKB and Rapid7 honeypot telemetry.
Tests operating system configuration against recognised hardening benchmarks with SCAP-validated, NIST-certified content.
Assigns vulnerabilities to named owners and tracks live progress toward completion rather than producing a static list.
Sets measurable remediation deadlines by asset group and reports whether teams are meeting them.
Creates Jira and ServiceNow tickets automatically and triggers actions such as scanning newly discovered assets.
Endpoint protection, XDR and Security Copilot.
Vulnerability management, demonstrated by Rapid7.
Remediation Projects in the console.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets Elastic Security apart (and where Splunk or Sentinel may fit better).
Every vulnerability scanner produces more findings than any team can fix. The question is which twenty of the four thousand get attention this month, and CVSS answers it badly because it scores theoretical severity in isolation from the real world. Active Risk scores 0 to 1000 using evidence of actual exploitation: presence in CISA's Known Exploited Vulnerabilities catalogue, availability of a working Metasploit module, ExploitDB entries, AttackerKB community assessment, and observed attack traffic from Rapid7's Project Lorelei honeypot network. A CVSS 9.8 that nobody has ever exploited can rank below a CVSS 7.5 being used in the wild this week. The sources being named and public matters. You can explain to an auditor or a sceptical infrastructure manager exactly why a particular patch jumped the queue, which is a much easier conversation than defending a proprietary black-box score. Note that Rapid7 retired the older Real Risk model on 21 January 2026.
The unglamorous truth of vulnerability management is that scanning is easy and fixing is hard, and the gap between them is organisational rather than technical. Most tools hand you a report and leave the negotiation with IT entirely to you. Remediation Projects assign specific vulnerabilities to named owners with live progress tracking, and Goals and SLAs express the standard as days allowed to remediate by asset group. Tickets flow automatically into Jira or ServiceNow, so the work appears in the systems infrastructure teams already use rather than in a security tool they will not open. For Indian buyers this maps directly onto regulatory expectation. RBI expects defined remediation timelines and evidence they are being met; SEBI's CSCRF expects demonstrable process. Being able to show a regulator that a critical finding was assigned within a day and closed within seven, with the audit trail, is worth more than another dashboard. One caveat: reviewers report the native Jira integration breaks with some regularity.
Authenticated scanning gives far better results than unauthenticated scanning, because logging in reveals installed software and patch levels rather than guessing from network responses. The obstacle is that it traditionally requires storing privileged credentials in the scanner and rotating them across the estate, which security teams dislike and auditors question. Scan Assistant sidesteps this: a lightweight service on the target establishes a trusted channel with the Scan Engine using ECDSA certificates and AES encryption, delivering authenticated depth with no stored administrative credentials at all. It is also materially faster and lighter than credentialed scanning, particularly for policy assessment work. This is genuinely uncommon in the category, and for Indian organisations under RBI or SEBI scrutiny it removes an awkward conversation about privileged credential handling. It is dormant unless called by a Scan Engine, so it adds negligible attack surface.
The most common criticism of InsightVM is that Rapid7 never moved to a pure cloud model — you must run a Security Console and a database. Qualys removed that burden years ago and reviewers hold it against Rapid7. For an Indian buyer under localisation pressure, the same fact reads differently. Your asset inventory, scan results and vulnerability database sit on infrastructure you control, which can be on-premises or in AWS Mumbai or Azure India. Rapid7 has no India data region, and for its cloud-only products that is a hard constraint. InsightVM is the one product in the portfolio where the architecture gives you a genuine answer, because the sensitive data — a complete map of every weakness in your estate — can stay in country. Be precise about what this does and does not solve. The cloud platform layer still handles dashboards and Remediation Projects, so some metadata leaves India. Confirm with Rapid7 in writing exactly what the platform layer holds before you rely on this for a regulatory answer.
Two limitations come up in nearly every honest review, and you should plan for both. The console is resource-hungry and can be temperamental. Rapid7's own sizing calls for twelve cores, 64 GB RAM and 2 TB of storage at twenty thousand assets, and 256 GB with 8 TB at four hundred thousand. Reviewers report the console running out of memory during simultaneous scans, report generation failing on memory pressure, and scheduled scans taking twenty hours where the same scan run manually completes in three or four. Scan duration on large estates is a recurring complaint, and Rapid7 ships a maximum-scan-duration setting largely because unresponsive devices are a known problem. Reporting is the other weak point. Users describe the report builder as inflexible and complex, and the common workaround is SQL Query Export, which requires someone who can write SQL against Rapid7's schema. Despite the Live Monitoring branding, reviewers say it is not genuinely real-time and that console-to-cloud synchronisation lags. Two more: false positives are reported particularly on Cisco network devices, and support response times draw consistent criticism.
InsightVM is the right choice for a hybrid estate — meaningful on-premises infrastructure, network devices, some cloud — where remediation workflow matters as much as detection, and where keeping vulnerability data in India has regulatory value. Mid-market Indian organisations under RBI, SEBI or IRDAI supervision fit this profile well, and Rapid7 typically prices below Tenable and Qualys at the lower and middle tiers. It is the wrong choice in three cases. If you want minimal operational overhead, Qualys VMDR is cloud-native with no console to host, includes native patch management and is rated better on support. If your scanning requirements are broad and deep, Tenable has the largest plugin library in the market at over 219,000, a dedicated operational technology product, and a higher Gartner rating across nearly twice the review volume. If your estate is entirely cloud-native, Wiz will give you better coverage and faster time to value than any traditional scanner, InsightVM included. We sell all of them.
Twelve cores, 64 GB RAM and 2 TB at twenty thousand assets is Rapid7's own guidance, and under-sizing it is the commonest cause of the memory and scan-duration complaints in the reviews. Decide where it sits too — on-premises or an India cloud region — because that placement is your residency answer.
Place Scan Engines across network segments, using reverse mode for engines behind NAT. Roll out the agent for laptops and roaming assets that are never on the network during a scan window. Remember the agent does local checks only — you still need engines for exposed services and TLS misconfigurations.
Reviewers rate credentialed scan configuration as one of InsightVM's harder tasks, which is precisely the argument for Scan Assistant. Certificates instead of stored administrative credentials, faster scans, and one fewer awkward conversation with your auditor.
This is where the product earns its price, and where most deployments stop short. Assign owners, set days-to-remediate by asset group, and wire the Jira or ServiceNow integration — then test that integration, because reviewers report it breaks with some regularity.
Real Risk and the other legacy models were retired on 21 January 2026 and historical scores cannot be recalculated. If you present risk reduction to a board or a regulator, prepare the explanation for the step change rather than being asked about it cold.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“Active Risk let us argue for a patch order with evidence instead of opinion. The infrastructure team stopped pushing back.”
“Remediation Projects put the work in Jira where our engineers actually live. That alone changed our close rate.”
“The console is a real server and it behaves like one. Budget the hardware properly or it will bite you during a big scan.”
“Scan Assistant meant we stopped storing domain admin credentials in a scanner. Our auditor was noticeably happier.”
“Reporting is the weak point. We ended up writing SQL exports because the report builder could not do what we needed.”
“Keeping scan data on our own console in Mumbai answered the localisation question that ruled out two other vendors.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the endpoint-security (EDR/XDR) market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Mid-market platform — one agent, one contract.
The grid nobody publishes — detection efficacy & agent maturity vs Microsoft-estate fit and TCO.
Breadth over depth — that is the deliberate trade.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
The SIEM field — honest lanes; the edge is deployment freedom and one agent for logs and endpoint. Deepest content and talent pool? Splunk. We say so (and sell it).
| Dimension | Rapid7 | Tenable | Qualys | CrowdStrike | Microsoft |
|---|---|---|---|---|---|
| Position | Mid-market platform: exposure, SIEM and MDR on one agent | The strongest scanner in the category | Cloud-native, lowest operational overhead | The endpoint and MDR benchmark | Near-free at the margin with E5 |
| Pricing axis | Per monitored asset — not per GB ingested | Per asset, quote-led | Per asset, reported ~$199–250/yr | $25–45 per endpoint/month for Falcon Complete | Bundled into E5 licensing |
| Vulnerability management | InsightVM — published price, Active Risk scoring | 219,000+ plugins, dedicated OT product | Cloud-native, native patching included | Exposure module if you already run Falcon | Weak on non-Microsoft OS and network devices |
| SIEM | Challenger in the 2025 MQ — not a Leader | Not a SIEM vendor | Not a SIEM vendor | Falcon Next-Gen SIEM | Sentinel — a Leader |
| MDR | Frost Radar Leader; VM and unlimited IR bundled in | Not an MDR vendor | Managed services available | Falcon Complete — the benchmark | Defender Experts |
| Deployment | SIEM and MDR cloud-only; InsightVM console is yours | Cloud or on-premises | Cloud-native only | Cloud-native only | Azure-hosted |
| India data residency | NO India region — InsightVM console is the exception | Region options; verify for your product | India platform, Pune-engineered | Verify per product | Azure India regions |
| The thing to plan around | No India region; agent mandatory; FY26 guided down | Priced above Rapid7 at most tiers | Support quality rated well; scanning less deep | The most expensive option here | Only economic if you already hold E5 |
| Best fit | Mid-market wanting VM, SIEM and MDR from one vendor | Deepest scanning, or operational technology | Lowest operational overhead, native patching | Best-in-class endpoint and managed response | Microsoft-standardised estates with E5 |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Rapid7 InsightVM is one of 15 vulnerability management products TechBag carries. The SIEM & Log Management guide narrows them to a shortlist and shows the reasoning. →
Rapid7 meters per monitored asset; most rival SIEMs meter per gigabyte ingested. That is the comparison worth modelling, because it is the one that decides the deal. Move both sliders: the asset count you would license, and the daily ingest an ingest-priced SIEM would charge you for. The point is not the exact number — Rapid7 is quote-only — it is the shape: per-asset cost tracks headcount and hardware, which change slowly, while per-GB cost tracks how much you log, which only ever goes up. Indicative Indian-market rates.
If the saving reads zero, the ingest-priced SIEM is genuinely cheaper at your ratio and you should say so internally rather than force the comparison. The structural argument for per-asset pricing is not that it is always cheaper — it is that it stops the bill punishing you for collecting more, which is what makes teams under-log and miss things. Weigh that against the residency constraint before you decide.
InsightVM carries one of the few published prices in this category: from $1.62 per asset per month at 500 assets, roughly $19 per asset per year, on an annual term. What the licence does not include is the infrastructure — you host a Security Console and a PostgreSQL database, and Rapid7’s own sizing calls for twelve cores, 64 GB RAM and 2 TB of storage at twenty thousand assets. Budget that explicitly, or a comparison against cloud-native Qualys is not a comparison. Ask for the standalone quote specifically; the sales motion leads with Exposure Command. TechBag quotes in INR with GST.
Published, from 500 assets
The line buyers forget
Only if you will use it
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Have we budgeted the hardware Rapid7's own guidance calls for at our asset count?
Where will the Security Console sit, and does that satisfy our localisation obligation?
Have we confirmed IN WRITING what the Rapid7 cloud layer holds, given the console stays ours?
Are we deploying scan engines as well as agents? Agent-only silently misses exposed network services.
Will we use Scan Assistant rather than storing domain administrative credentials in the scanner?
Who owns the fixing, and what days-to-remediate SLA applies to each asset group?
Have we tested the Jira or ServiceNow integration specifically? Reviewers report it breaking.
Can we explain the trend discontinuity from the January 2026 Real Risk retirement?
Have we produced the exact reports our auditors demand, or will we need SQL Query Export?
Have we asked for a standalone InsightVM quote, not just the Exposure Command bundle?
Find out what you already run, work out which tier you actually need above the free one, or get an honest Elastic-vs-Splunk comparison — in INR/GST.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.