Talk to us
by Rapid7TechBag Intel Page

Rapid7 InsightVM

Risk-scored vulnerability management — Rapid7 InsightVM ranks findings 0–1000 on evidence of real exploitation, not theoretical CVSS, and Remediation Projects turn the list into assigned work with owners and deadlines. You host the console, so the scan data can stay in India.

Published from $1.62/asset/moActive Risk prioritisationYou host the console

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Gartner Peer Insights
~750 reviews in vulnerability assessment
4.3 / 5
PeerSpot
66 reviews, 87% would recommend
4.0 / 5
G2
listed as InsightVM (Nexpose), ~78 reviews
4.4 / 5
Forrester Wave 2025
Unified vulnerability management — not top tier
Strong Performer

Data residency & processing — confirm before the PoC

Where data lives

Your console — India if you choose

The Security Console and its database are hosted by YOU: on-premises, or in AWS Mumbai or Azure Central India. Your asset inventory, scan results and vulnerability database — a complete map of every weakness in your estate — can stay in country. This is the one Rapid7 product where the architecture gives you that answer.

Where it is processed

Some metadata still leaves India

The Rapid7 cloud layer provides dashboards, Remediation Projects, Goals and SLAs, the Executive Risk View and Active Risk scoring — and Rapid7 has no India region. Confirm in writing exactly what that layer holds before you rely on this as a regulatory answer.

Be precise here, because a comfortable answer is easy to reach and wrong. “The scan data stays in India” and “nothing leaves India” are different claims, and an auditor will probe the difference. TechBag obtains Rapid7’s written position on what the cloud platform layer holds as part of the quote. If your obligation requires that nothing at all leaves Indian jurisdiction, look at Qualys VMDR, which runs an India platform.

Quick answer

InsightVM is Rapid7's vulnerability management product. It scans servers, workstations, network devices, containers and cloud instances for known vulnerabilities and misconfigurations, scores what it finds, and tracks the fixing of it to a deadline. Its architecture is hybrid rather than pure SaaS, and this is the fact that shapes every other decision about it. You host a Security Console — a Windows or Linux server running a PostgreSQL database — plus one or more Scan Engines, while Rapid7's cloud platform layer adds dashboards, Remediation Projects, SLA goals and the Executive Risk View. Competitors such as Qualys removed the on-premises console years ago, and reviewers hold it against Rapid7. For Indian buyers facing data localisation pressure, that same architecture reads as an advantage: your scan data and vulnerability database sit on infrastructure you control, in India if you choose — which matters because a complete map of every weakness in your estate is about as sensitive as data gets. Findings are prioritised by Active Risk, a 0–1000 score weighting real-world exploitation evidence above theoretical severity, drawing on CISA's Known Exploited Vulnerabilities catalogue, Metasploit modules, ExploitDB, the AttackerKB community and Rapid7's own Project Lorelei honeypot network. A CVSS 9.8 with no working exploit can rank below a CVSS 7.5 that attackers are actively using. Note the timing: Rapid7 retired Real Risk, Temporal, TemporalPlus, Weighted and PCI ASV 2.0 scoring on 21 January 2026, and historical scores cannot be recalculated, so your trend data has a discontinuity at that point. The genuinely distinctive features are Scan Assistant, which achieves authenticated scanning without storing administrative credentials, and Remediation Projects with SLA goals, which turn a vulnerability list into assigned work with owners and deadlines — the part most vulnerability tools do badly. Rapid7 now describes InsightVM as the technology powering Exposure Command. It remains separately purchasable and is not end-of-life, but you will have to ask for a standalone quote specifically, because that is not what the sales motion leads with. Read more ↓ Show less ↑
Part 01 · Orient

The Microsoft platform family

This page covers Rapid7 InsightVM — the SIEM. The other pillars:

Quick facts

30-second orientation
Category
Risk-based vulnerability management
Vendor
Rapid7 — CEO Wael Mohamed (June 2026)
Deployment
HYBRID — self-hosted console plus Rapid7 cloud
Published price
From $1.62 per asset per month
Minimum tier
500 assets, annual subscription
Risk scoring
Active Risk, 0–1000 scale
Legacy scoring retired
21 January 2026 — no recalculation of history
Policy benchmarks
CIS · DISA STIG · USGCB
Certification
SCAP validated, USGCB certified by NIST
Agent limitation
Local checks only — no remote or unauthenticated checks
Data residency
YOURS — console and scan data on your infrastructure, India if you choose
Data processing
Cloud layer holds dashboards and Remediation Projects — confirm scope in writing
Console sizing
12 cores / 64 GB / 2 TB at 20,000 assets
Buy in India via
TechBag — INR, GST, standalone quote negotiated
Part 02 · Learn

Understand SIEM economics before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is it?

Risk-based vulnerability management for hybrid estates. Scans servers, workstations, network devices, containers and cloud instances, scores what it finds, and tracks the fixing to a deadline.

A two-copy SIEM architecture vs Elastic’s — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionNo / separate AI toolInsightVM
Detection basisRules you wrote in advanceBaselines, and deviation from them
Stolen credentialsNothing malformed to matchBehaviour is wrong, so it scores
Pricing axisPer GB ingested — grows on its ownPer monitored asset — grows with the estate
DeploymentCloud-only, or on-prem-onlyBoth, with a mature product each side
Existing SIEMRip and replaceAnalytics can augment what you have
InvestigationAnalyst queries for the timelineSmart Timelines assembled for them
Honest caveat—Two platforms post-merger — ask the roadmap
Best fit—Big volume, small team — or on-prem

The deployment-freedom answer — for the deepest out-of-the-box content, weigh Splunk (TechBag sells it).

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
Runs the database and UI

Security Console

Self-hosted management server

The core of the deployment, hosted by you on Windows Server or Linux with a PostgreSQL database. It defines sites, schedules scans, stores all asset and vulnerability data and generates reports. Sizing is substantial: twelve cores, 64 GB RAM and 2 TB storage at twenty thousand assets, rising to 256 GB and 8 TB at four hundred thousand. This is your capital cost, not Rapid7's.

02
Executes the actual scans

Scan Engine

Distributed scanner

Workers deployed across network segments that perform scanning and return results to the Console, holding data only temporarily. They connect either in standard mode on TCP 40814, where the Console initiates, or reverse mode on TCP 40815 for engines behind NAT. Rapid7 also operates Hosted Scan Engines for external perimeter scanning without you deploying infrastructure. Engine pools distribute load across large estates.

03
Assesses roaming assets

Rapid7 Agent

Persistent endpoint collector

The same agent used by Incident Command, installed once and collecting on its own schedule rather than only during scan windows. This solves the laptop problem: assets never on the network when a scan runs still get assessed. Its limitation is fundamental — it performs local checks only and cannot perform remote or unauthenticated network checks.

04
Enables authenticated scans safely

Scan Assistant

Credential-free authentication

A lightweight service on target hosts that establishes a trusted channel with the Scan Engine using ECDSA certificates and AES encryption, delivering authenticated scan results without storing or rotating administrative credentials. It also runs faster and lighter than credentialed scanning, particularly for policy assessment. It is dormant until a Scan Engine calls it, and complements rather than replaces the agent.

05
Dashboards and remediation workflow

Insight Platform

Cloud analytics layer

Rapid7's cloud, adding what the on-premises console lacks: live dashboards, Remediation Projects, Goals and SLAs, the Executive Risk View and Remediation Hub. Active Risk scoring and cross-product integration also live here. Reviewers report console-to-cloud synchronisation is not always fast, and feature parity between the two interfaces is imperfect.

One workspace where people meet, make, and share — work moving in one place, not emailed between tools.

Part 03 · Evaluate

Twelve capabilities. Draft, analyse, automate.

Sentinel collects, correlates and stores security telemetry — and the tier each table lands in is what sets your bill. Here are the five pieces that matter. Part of Defender XDR, managed in one portal, with Security Copilot AI.

Collect
Discovery

Asset discovery and inventory

Finds and catalogues devices across on-premises networks, cloud accounts and remote endpoints into one inventory.

Collect
Scanning

Authenticated network scanning

Logs into targets to enumerate installed software and configuration for accurate local vulnerability detection.

Collect
Scanning

Unauthenticated remote checks

Probes exposed network services from outside the host to find what an attacker without credentials would see.

Collect
Agent

Continuous agent assessment

Collects vulnerability data from laptops and roaming assets on its own schedule regardless of scan windows.

Collect
Credentials

Scan Assistant

Delivers authenticated scan depth using certificates instead of stored administrative credentials.

Collect
Cloud

Cloud connectors

Pulls asset inventory and configuration from AWS, Azure and GCP so cloud instances appear alongside on-premises assets.

Detect
Scoring

Active Risk prioritisation

Ranks vulnerabilities 0 to 1000 using live exploitation evidence rather than theoretical CVSS severity alone.

Detect
Intelligence

Exploit evidence feeds

Weights findings using CISA KEV, Metasploit, ExploitDB, AttackerKB and Rapid7 honeypot telemetry.

Detect
Policy

CIS and DISA STIG assessment

Tests operating system configuration against recognised hardening benchmarks with SCAP-validated, NIST-certified content.

Respond
Workflow

Remediation Projects

Assigns vulnerabilities to named owners and tracks live progress toward completion rather than producing a static list.

Respond
Workflow

Goals and SLAs

Sets measurable remediation deadlines by asset group and reports whether teams are meeting them.

Respond
Integration

Ticketing and automation

Creates Jira and ServiceNow tickets automatically and triggers actions such as scanning newly discovered assets.

See it, don’t just read it

Watch Microsoft Defender in action

Endpoint protection, XDR and Security Copilot.

Rapid7 (official)·Overview

Overview Video: InsightVM

Vulnerability management, demonstrated by Rapid7.

Rapid7 (official)·Workflow

Managing Remediation Activities in InsightVM

Remediation Projects in the console.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why InsightVM

AI works best where the work already happens.

Here’s what genuinely sets Elastic Security apart (and where Splunk or Sentinel may fit better).

01

Active Risk prioritises by what attackers actually exploit

Every vulnerability scanner produces more findings than any team can fix. The question is which twenty of the four thousand get attention this month, and CVSS answers it badly because it scores theoretical severity in isolation from the real world. Active Risk scores 0 to 1000 using evidence of actual exploitation: presence in CISA's Known Exploited Vulnerabilities catalogue, availability of a working Metasploit module, ExploitDB entries, AttackerKB community assessment, and observed attack traffic from Rapid7's Project Lorelei honeypot network. A CVSS 9.8 that nobody has ever exploited can rank below a CVSS 7.5 being used in the wild this week. The sources being named and public matters. You can explain to an auditor or a sceptical infrastructure manager exactly why a particular patch jumped the queue, which is a much easier conversation than defending a proprietary black-box score. Note that Rapid7 retired the older Real Risk model on 21 January 2026.

02

Remediation Projects turn findings into assigned work

The unglamorous truth of vulnerability management is that scanning is easy and fixing is hard, and the gap between them is organisational rather than technical. Most tools hand you a report and leave the negotiation with IT entirely to you. Remediation Projects assign specific vulnerabilities to named owners with live progress tracking, and Goals and SLAs express the standard as days allowed to remediate by asset group. Tickets flow automatically into Jira or ServiceNow, so the work appears in the systems infrastructure teams already use rather than in a security tool they will not open. For Indian buyers this maps directly onto regulatory expectation. RBI expects defined remediation timelines and evidence they are being met; SEBI's CSCRF expects demonstrable process. Being able to show a regulator that a critical finding was assigned within a day and closed within seven, with the audit trail, is worth more than another dashboard. One caveat: reviewers report the native Jira integration breaks with some regularity.

03

Scan Assistant removes the credential problem

Authenticated scanning gives far better results than unauthenticated scanning, because logging in reveals installed software and patch levels rather than guessing from network responses. The obstacle is that it traditionally requires storing privileged credentials in the scanner and rotating them across the estate, which security teams dislike and auditors question. Scan Assistant sidesteps this: a lightweight service on the target establishes a trusted channel with the Scan Engine using ECDSA certificates and AES encryption, delivering authenticated depth with no stored administrative credentials at all. It is also materially faster and lighter than credentialed scanning, particularly for policy assessment work. This is genuinely uncommon in the category, and for Indian organisations under RBI or SEBI scrutiny it removes an awkward conversation about privileged credential handling. It is dormant unless called by a Scan Engine, so it adds negligible attack surface.

04

The self-hosted console keeps your data in India

The most common criticism of InsightVM is that Rapid7 never moved to a pure cloud model — you must run a Security Console and a database. Qualys removed that burden years ago and reviewers hold it against Rapid7. For an Indian buyer under localisation pressure, the same fact reads differently. Your asset inventory, scan results and vulnerability database sit on infrastructure you control, which can be on-premises or in AWS Mumbai or Azure India. Rapid7 has no India data region, and for its cloud-only products that is a hard constraint. InsightVM is the one product in the portfolio where the architecture gives you a genuine answer, because the sensitive data — a complete map of every weakness in your estate — can stay in country. Be precise about what this does and does not solve. The cloud platform layer still handles dashboards and Remediation Projects, so some metadata leaves India. Confirm with Rapid7 in writing exactly what the platform layer holds before you rely on this for a regulatory answer.

05

The honest caveat: the console is heavy and the reporting is weak

Two limitations come up in nearly every honest review, and you should plan for both. The console is resource-hungry and can be temperamental. Rapid7's own sizing calls for twelve cores, 64 GB RAM and 2 TB of storage at twenty thousand assets, and 256 GB with 8 TB at four hundred thousand. Reviewers report the console running out of memory during simultaneous scans, report generation failing on memory pressure, and scheduled scans taking twenty hours where the same scan run manually completes in three or four. Scan duration on large estates is a recurring complaint, and Rapid7 ships a maximum-scan-duration setting largely because unresponsive devices are a known problem. Reporting is the other weak point. Users describe the report builder as inflexible and complex, and the common workaround is SQL Query Export, which requires someone who can write SQL against Rapid7's schema. Despite the Live Monitoring branding, reviewers say it is not genuinely real-time and that console-to-cloud synchronisation lags. Two more: false positives are reported particularly on Cisco network devices, and support response times draw consistent criticism.

06

The honest positioning

InsightVM is the right choice for a hybrid estate — meaningful on-premises infrastructure, network devices, some cloud — where remediation workflow matters as much as detection, and where keeping vulnerability data in India has regulatory value. Mid-market Indian organisations under RBI, SEBI or IRDAI supervision fit this profile well, and Rapid7 typically prices below Tenable and Qualys at the lower and middle tiers. It is the wrong choice in three cases. If you want minimal operational overhead, Qualys VMDR is cloud-native with no console to host, includes native patch management and is rated better on support. If your scanning requirements are broad and deep, Tenable has the largest plugin library in the market at over 219,000, a dedicated operational technology product, and a higher Gartner rating across nearly twice the review volume. If your estate is entirely cloud-native, Wiz will give you better coverage and faster time to value than any traditional scanner, InsightVM included. We sell all of them.

In the apps
Where people already work
Bundled in E5
Enterprise EDR, no extra seat
Grounded
In your M365 data
Proof, not promises

The numbers behind the platform

1000
Top of the Active Risk scale
InsightVM documentation
$1.162/asset/mo
Published price from 500 assets
Rapid7 pricing
~750 reviews
Gartner Peer Insights, vulnerability assessment
Gartner
219000+
Tenable plugins — the gap InsightVM concedes
Tenable
64 GB RAM
Console sizing at 20,000 assets — your capital cost
Rapid7 docs
2026
Real Risk retired 21 January; history not recalculable
Rapid7

What your Rapid7 InsightVM rollout looks like

Weeks 1–2Assess

Size the console properly

Twelve cores, 64 GB RAM and 2 TB at twenty thousand assets is Rapid7's own guidance, and under-sizing it is the commonest cause of the memory and scan-duration complaints in the reviews. Decide where it sits too — on-premises or an India cloud region — because that placement is your residency answer.

Weeks 2–5Deploy

Deploy engines and agents by segment

Place Scan Engines across network segments, using reverse mode for engines behind NAT. Roll out the agent for laptops and roaming assets that are never on the network during a scan window. Remember the agent does local checks only — you still need engines for exposed services and TLS misconfigurations.

Weeks 4–7Deploy

Turn on Scan Assistant before credentialed scanning

Reviewers rate credentialed scan configuration as one of InsightVM's harder tasks, which is precisely the argument for Scan Assistant. Certificates instead of stored administrative credentials, faster scans, and one fewer awkward conversation with your auditor.

Weeks 6–10Operate

Build Remediation Projects and SLA goals

This is where the product earns its price, and where most deployments stop short. Assign owners, set days-to-remediate by asset group, and wire the Jira or ServiceNow integration — then test that integration, because reviewers report it breaks with some regularity.

OngoingOperate

Expect a trend discontinuity at the scoring change

Real Risk and the other legacy models were retired on 21 January 2026 and historical scores cannot be recalculated. If you present risk reduction to a board or a regulator, prepare the explanation for the step change rather than being asked about it cold.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4.3
260+ reviews*
86% would recommend
Deployment flexibility4.8
Cost control4.6
Search & hunting4.5
Out-of-the-box content3.7
5
52%
4
32%
3
11%
2
4%
1
1%

Quick poll — what’s driving your evaluation?

Talk to an advisor
Banking
Active Risk let us argue for a patch order with evidence instead of opinion. The infrastructure team stopped pushing back.
Head of Security
Banking
IT Services
Remediation Projects put the work in Jira where our engineers actually live. That alone changed our close rate.
Security Manager
IT Services
Manufacturing
The console is a real server and it behaves like one. Budget the hardware properly or it will bite you during a big scan.
Infrastructure Lead
Manufacturing
Insurance
Scan Assistant meant we stopped storing domain admin credentials in a scanner. Our auditor was noticeably happier.
Compliance Manager
Insurance
Retail
Reporting is the weak point. We ended up writing SQL exports because the report builder could not do what we needed.
SOC Lead
Retail
Non-Banking Financial Company
Keeping scan data on our own console in Mumbai answered the localisation question that ruled out two other vendors.
CISO
Non-Banking Financial Company
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the endpoint-security (EDR/XDR) market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Endpoint-Security (EDR/XDR) Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
Rapid7This page

Mid-market platform — one agent, one contract.

Grid 02 · The architecture

In-App Integration × Estate Breadth

The grid nobody publishes — detection efficacy & agent maturity vs Microsoft-estate fit and TCO.

Point appsBest-of-breed suiteLegacy office suitesHeavy enterprise platforms
Rapid7This page

Breadth over depth — that is the deliberate trade.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Rapid7 InsightVM vs the field

The SIEM field — honest lanes; the edge is deployment freedom and one agent for logs and endpoint. Deepest content and talent pool? Splunk. We say so (and sell it).

DimensionRapid7TenableQualysCrowdStrikeMicrosoft
PositionMid-market platform: exposure, SIEM and MDR on one agentThe strongest scanner in the categoryCloud-native, lowest operational overheadThe endpoint and MDR benchmarkNear-free at the margin with E5
Pricing axisPer monitored asset — not per GB ingestedPer asset, quote-ledPer asset, reported ~$199–250/yr$25–45 per endpoint/month for Falcon CompleteBundled into E5 licensing
Vulnerability managementInsightVM — published price, Active Risk scoring219,000+ plugins, dedicated OT productCloud-native, native patching includedExposure module if you already run FalconWeak on non-Microsoft OS and network devices
SIEMChallenger in the 2025 MQ — not a LeaderNot a SIEM vendorNot a SIEM vendorFalcon Next-Gen SIEMSentinel — a Leader
MDRFrost Radar Leader; VM and unlimited IR bundled inNot an MDR vendorManaged services availableFalcon Complete — the benchmarkDefender Experts
DeploymentSIEM and MDR cloud-only; InsightVM console is yoursCloud or on-premisesCloud-native onlyCloud-native onlyAzure-hosted
India data residencyNO India region — InsightVM console is the exceptionRegion options; verify for your productIndia platform, Pune-engineeredVerify per productAzure India regions
The thing to plan aroundNo India region; agent mandatory; FY26 guided downPriced above Rapid7 at most tiersSupport quality rated well; scanning less deepThe most expensive option hereOnly economic if you already hold E5
Best fitMid-market wanting VM, SIEM and MDR from one vendorDeepest scanning, or operational technologyLowest operational overhead, native patchingBest-in-class endpoint and managed responseMicrosoft-standardised estates with E5
Strong Partial / add-on Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Does Rapid7 InsightVM fit you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose InsightVM if…

  • Remediation workflow matters as much as detection — assigned owners and deadlines, not a list
  • You want prioritisation grounded in real exploitation evidence you can show an auditor
  • Keeping vulnerability data in India has regulatory value — the console is yours
  • You want a published entry price rather than a quote-only negotiation

Choose Tenable if…

  • You need the deepest scanning coverage — 219,000+ plugins
  • You have operational technology or industrial environments
  • Dashboard flexibility and scan efficiency are your priorities

Choose Qualys if…

  • You want no console to host, patch and size — it is cloud-native
  • Native patch management matters rather than integrating out to SCCM
  • An India platform answers your residency question directly

Choose CrowdStrike if…

  • You already run Falcon, so there is no second agent to deploy
  • You want best-in-class endpoint detection and managed response
  • You can accept the premium — $25–45 per endpoint per month

Choose Microsoft if…

  • You hold E5 licences, which changes the economics entirely
  • Your estate is standardised on Microsoft 365 and Azure
  • Azure India regions answer a residency obligation Rapid7 cannot

Rapid7 InsightVM is one of 15 vulnerability management products TechBag carries. The SIEM & Log Management guide narrows them to a shortlist and shows the reasoning. →

Do the math

Users or gigabytes — which meter suits you?

Rapid7 meters per monitored asset; most rival SIEMs meter per gigabyte ingested. That is the comparison worth modelling, because it is the one that decides the deal. Move both sliders: the asset count you would license, and the daily ingest an ingest-priced SIEM would charge you for. The point is not the exact number — Rapid7 is quote-only — it is the shape: per-asset cost tracks headcount and hardware, which change slowly, while per-GB cost tracks how much you log, which only ever goes up. Indicative Indian-market rates.

750
25010,000
150
10 GB3,000 GB

If the saving reads zero, the ingest-priced SIEM is genuinely cheaper at your ratio and you should say so internally rather than force the comparison. The structural argument for per-asset pricing is not that it is always cheaper — it is that it stops the bill punishing you for collecting more, which is what makes teams under-log and miss things. Weigh that against the residency constraint before you decide.

An ingest-metered SIEM, at your GB/day
₹4,50,00,000
Saved vs an ingest-priced SIEM’s user meter
₹4,08,29,250
₹20,41,46,250 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

InsightVM carries one of the few published prices in this category: from $1.62 per asset per month at 500 assets, roughly $19 per asset per year, on an annual term. What the licence does not include is the infrastructure — you host a Security Console and a PostgreSQL database, and Rapid7’s own sizing calls for twelve cores, 64 GB RAM and 2 TB of storage at twenty thousand assets. Budget that explicitly, or a comparison against cloud-native Qualys is not a comparison. Ask for the standalone quote specifically; the sales motion leads with Exposure Command. TechBag quotes in INR with GST.

InsightVM

~$1.62/asset/month

Published, from 500 assets

  • Roughly $19 per asset per year at the entry band
  • Active Risk scoring and Remediation Projects included
  • Volume discounts above 500 assets

Your infrastructure

Your costnot Rapid7’s

The line buyers forget

  • 12 cores / 64 GB / 2 TB at 20,000 assets
  • 256 GB / 8 TB at 400,000 assets
  • Plus scan engines across your network segments

Exposure Command

Quotethe bundle

Only if you will use it

  • Adds Surface Command attack-surface discovery
  • Bundle discounts reported at 8–14% for two products
  • Buying a platform to use one component is how budgets are wasted

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every SIEM vendor

Take this into your next vendor call — including ours.

1
Console sizing

Have we budgeted the hardware Rapid7's own guidance calls for at our asset count?

2
Residency

Where will the Security Console sit, and does that satisfy our localisation obligation?

3
Cloud metadata

Have we confirmed IN WRITING what the Rapid7 cloud layer holds, given the console stays ours?

4
Coverage

Are we deploying scan engines as well as agents? Agent-only silently misses exposed network services.

5
Credentials

Will we use Scan Assistant rather than storing domain administrative credentials in the scanner?

6
Remediation

Who owns the fixing, and what days-to-remediate SLA applies to each asset group?

7
Integration

Have we tested the Jira or ServiceNow integration specifically? Reviewers report it breaking.

8
Scoring change

Can we explain the trend discontinuity from the January 2026 Real Risk retirement?

9
Reporting

Have we produced the exact reports our auditors demand, or will we need SQL Query Export?

10
Standalone

Have we asked for a standalone InsightVM quote, not just the Exposure Command bundle?

FAQ

Questions buyers ask

InsightVM carries one of the few published prices in this category: from $1.62 per asset per month at 500 assets, on an annual subscription, which works out to roughly $19 per asset per year. Volume discounts apply above that, and Rapid7 typically prices below Tenable and Qualys at the lower and middle tiers. The catch is not in the licence — it is the infrastructure the licence does not include. InsightVM is hybrid, not SaaS. You host a Security Console running a PostgreSQL database, and Rapid7's own sizing guidance calls for twelve cores, 64 GB of RAM and 2 TB of storage at twenty thousand assets, rising to 256 GB and 8 TB at four hundred thousand. You also host Scan Engines across your network segments. That is real capital and operational cost sitting on your side of the line, and it is the single most common omission when buyers compare InsightVM against Qualys VMDR, which is cloud-native with no console at all. Budget it explicitly or the comparison is not a comparison. Two other commercial points. Rapid7 now describes InsightVM as the technology powering Exposure Command, and its sales motion leads with the bundle — so if you want the standalone product, and it is not end-of-life, you must ask for that quote specifically. And on renewal, Rapid7 states around three percent annual uplift while customers commonly report seven to ten percent; fix it contractually in advance. Buying through TechBag you are invoiced in INR with GST, and we negotiate the asset band and the uplift on your behalf.

Ready to evaluate Rapid7 InsightVM?

Find out what you already run, work out which tier you actually need above the free one, or get an honest Elastic-vs-Splunk comparison — in INR/GST.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.