Rapid7 InsightIDR a Great Solution for an SMB
April 15, 2022

Rapid7 InsightIDR a Great Solution for an SMB

Anonymous | TrustRadius Reviewer
Score 10 out of 10
Vetted Review
Verified User

Overall Satisfaction with Rapid7 InsightIDR

We use Rapid7 as our SIEM solution. It provides us the network monitoring and detection capabilities without having to bring in an in-house SIEM technology and the FTE support required for such an implementation. Our network is spread across the US with over 60 offices spanning three time zones. We are an SMB with over 1,400 employees.
  • Timely Detection of Abnormal Behavior
  • Host Isolation
  • Collection of Network Devices Logs
  • Threat Intelligence Source
  • User Behavior and Analytics
  • Cost Effective
  • Staff Augmentation
  • Tamper Proofing Agent Against Bad Actors
  • Log Searching
  • Integration with Other Security Technologies
  • Behavior Analytics
  • Host Isolation
  • Timely Alerting
  • HelpDesk Support
  • Cost
  • Savings has come from not having to hire FTE's to support a SIEM
  • Provided defense in depth as an additional endpoint agent with our EDR
  • Kept ransomware and other malicious activity out of our network
Many of the top-tier providers of this technology do a comparable job. However, we selected Rapid7 because of their reputation in the area of user behavior analytics, cost, # of SOC locations (due to our selection of their MDR service), support, company growth in other areas and other criteria. Rapid7 started off in the vulnerability management space and own the Metasploit Project. Understanding these two areas are critical in being able to address the InsightIDR threat detection area.

Do you think Rapid7 InsightIDR delivers good value for the price?

Yes

Are you happy with Rapid7 InsightIDR's feature set?

Yes

Did Rapid7 InsightIDR live up to sales and marketing promises?

Yes

Did implementation of Rapid7 InsightIDR go as expected?

Yes

Would you buy Rapid7 InsightIDR again?

Yes

InsightIDR is well suited for SMBs that do not have the resources to bring in an on-prem SIEM. After the initial configuration is completed, which the Rapid7 team was very good at assisting us on, the upkeep of the SIEM in the cloud is mainly done by them. Then after the "tuning" is done and the noise of the benign network traffic is muted, then only the true alerts can be investigated for malicious intentions. It has been a great tool for us to identify malicious activity. The technology also allows us to isolate hosts on-the-fly.