Rapid7 InsightVM / Exposure Command
Traditional enterprise VM
Security Console + distributed Scan Engines, now positioned as the VM engine inside Exposure Command.
- Not itemizedGov / FedRAMP
- No / integrationBuilt-in patch
- NoOpen source
- SaaS, On-premises (Security Console/engines)Deployment
- Classification
- Traditional enterprise vulnerability management, increasingly folded into Rapid7's broader Exposure Command.
- Discovery / scanning
- Official/Verified: Security Console creates sites, configures/runs scans, and manages vulnerability data; Scan Engines (distributable through the enterprise) perform the scans.
- Agent model
- Official/Verified: Rapid7 Agent / Insight Agent provides vulnerability assessment for remote assets outside normal network-scanning reach.
- Asset inventory
- Not itemized in source research.
- Risk prioritization
- Official/Verified: Active Risk (0–1000 scale) is the current recommended risk strategy, incorporating current CVSS data, threat intelligence, Rapid7 research, AttackerKB, Metasploit, ExploitDB, Project Lorelei, CISA KEV, and third-party dark-web sources. As of January 21, 2026, legacy strategies (RealRisk, Temporal, TemporalPlus, Weighted, PCI ASV 2.0) were deprecated.
- Remediation
- Official/Verified: Dedicated Remediation Projects group solutions, assign responsibility, track progress, aggregate risk by solution, and support verification via paired scan-engine validation scans. Patch execution is generally handled via integrations rather than a native InsightVM patch server.
- ITSM / ticketing integration
- Official/Verified: Jira and ServiceNow are explicitly referenced for remediation workflows.
- Cloud / container / OT coverage
- EVULNABLE Assessment: Broader cloud/exposure coverage is positioned through Exposure Command rather than InsightVM alone; confirm current container/OT scope directly with Rapid7.
- Data residency
- Official/Verified: Selectable data regions for certain Insight products — United States, Canada, Europe, Japan, and Australia.
- Pricing
- Published Price: starts at $1.62/asset/month at 500 assets (~$9,720/year for 500 assets before add-ons, services, taxes, or discounts).Verified against Rapid7's own pricing page as part of this tab's fact-check pass — matched.
- Time to initial data
- Estimated: Hours to days.
- Typical production rollout
- Estimated: 2–8 weeks — Security Console, distributed engines, agents, and remediation integrations add setup effort.
- Best-fit company size
- EVULNABLE Assessment: Mid-market through large enterprise.
- Potential limitations / evaluation considerations
- Not itemized in source research.
Last verified: August 27, 2026
