List of Rapid7 InsightVM Customers
Boston, 2114, MA,
United States
Since 2010, our global team of researchers has been studying Rapid7 InsightVM customers around the world, aggregating massive amounts of data points that form the basis of our forecast assumptions and perhaps the rise and fall of certain vendors and their products on a quarterly basis.
Each quarter our research team identifies companies that have purchased Rapid7 InsightVM for Vulnerability Management from public (Press Releases, Customer References, Testimonials, Case Studies and Success Stories) and proprietary sources, including the customer size, industry, location, implementation status, partner involvement, LOB Key Stakeholders and related IT decision-makers contact details.
Companies using Rapid7 InsightVM for Vulnerability Management include: Scotiabank, a Canada based Banking and Financial Services organisation with 86746 employees and revenues of $24.55 billion, Metropolitan Transportation Authority (MTA), a United States based Transportation organisation with 70000 employees and revenues of $21.30 billion, TELUS Corporation, a Canada based Professional Services organisation with 111500 employees and revenues of $14.85 billion, Desjardins Group, a Canada based Insurance organisation with 57500 employees and revenues of $11.53 billion, SAIC, a United States based Professional Services organisation with 24000 employees and revenues of $7.70 billion and many others.
Contact us if you need a completed and verified list of companies using Rapid7 InsightVM, including the breakdown by industry (21 Verticals), Geography (Region, Country, State, City), Company Size (Revenue, Employees, Asset) and related IT Decision Makers, Key Stakeholders, business and technology executives responsible for the software purchases.
The Rapid7 InsightVM customer wins are being incorporated in our Enterprise Applications Buyer Insight and Technographics Customer Database which has over 100 data fields that detail company usage of software systems and their digital transformation initiatives. Apps Run The World wants to become your No. 1 technographic data source!
Apply Filters For Customers
| Logo | Customer | Industry | Empl. | Revenue | Country | Vendor | Application | Category | When | SI | Insight |
|---|---|---|---|---|---|---|---|---|---|---|---|
|
|
Baltimore Gas and Electric, a subsidiary of Exelon Corporation | Utilities | 3200 | $5.2B | United States | Rapid7 | Rapid7 InsightVM | Vulnerability Management | 2022 | n/a |
In 2022 Baltimore Gas and Electric implemented Rapid7 InsightVM as a core component of its Vulnerability Management program. The deployment was positioned to support the utility's security operations, IT remediation teams, and compliance processes under a centralized threat and vulnerability management function.
Rapid7 InsightVM was configured to deliver continuous vulnerability assessment, asset discovery, vulnerability prioritization, and enterprise reporting capabilities consistent with Vulnerability Management category expectations. Implementation activities emphasized configuration of scanning engines, tag-based asset classification, prioritized remediation workflows, and consolidated reporting to support stakeholder visibility and remediation tracking.
Integrations were developed and maintained between Rapid7 InsightVM and other assessment and reporting solutions used by the organization, including Qualys, Tenable.sc, Tenable.io, and reporting platforms such as Kenna Security, enabling consolidated enterprise vulnerability data pipelines. These integrations supported data ingestion, cross-tool correlation, and the generation of enterprise-level vulnerability analysis for cross-functional teams and third-party providers engaged in remediation activities.
Governance and operationalization included maintaining technical and operational documentation, prioritizing remediation activities, and facilitating collaboration between remediation teams and stakeholders. The program included knowledge transfer and team development practices to raise technical proficiency, and explicitly improved program effectiveness, maturity, and stakeholder awareness through structured reporting and process alignment.
|
|
|
Desjardins Group | Insurance | 57500 | $11.5B | Canada | Rapid7 | Rapid7 InsightVM | Vulnerability Management | 2018 | n/a |
In 2018, Desjardins Group deployed Rapid7 InsightVM as its Vulnerability Management platform. The implementation supported the Lévis security team and hybrid security analysts who ran daily application scanning and vulnerability triage activities.
Rapid7 InsightVM was configured to perform daily discovery and scanning, and it operated alongside SonarQube, ContrastSecurity, Kenna and Netsparker as detection sources. Functional capabilities implemented included vulnerability discovery, exception and false positive management, assignment of findings to stakeholders, and validation of remediation action plans, with security analysts producing guidelines, procedures and policies for security events.
Operational workflows integrated Rapid7 InsightVM outputs into vulnerability triage, risk assessment and remediation processes, with assignments and recommendations routed to application owners and development teams. Tactical penetration testing and verification used BurpSuite and manual exploitation techniques to validate InsightVM findings and to audit OWASP Top 10 issues, while static analysis results from SonarQube and dependency checks were correlated with vulnerability data. The technical environment referenced by security and development staff included IntelliJ, GitHub, Jira, Maven, Jenkins and Spring MVC for remediation and testing workflows.
Governance and risk practices explicitly used NIST framework elements for vulnerability management, and analysts referenced CVE identifiers, CVSS v3 scoring and ISO 31000 concepts when determining corrective or compensatory measures. Processes emphasized exception handling, false positive tuning and formal validation of action plan effectiveness and compliance.
|
|
|
East West Bank | Banking and Financial Services | 3350 | $2.9B | United States | Rapid7 | Rapid7 InsightVM | Vulnerability Management | 2020 | n/a |
In 2020, East West Bank implemented Rapid7 InsightVM for Vulnerability Management. The deployment was implemented to centralize vulnerability management and remediation practices across security engineering, DevSecOps, and risk management functions.
Rapid7 InsightVM was configured to support a shift from a CVE based triage model to a risk based vulnerability management approach, with the project explicitly using InsightVM together with Kenna security to prioritize and score vulnerabilities. Functional capabilities emphasized include continuous asset discovery and scanning, risk scoring and prioritization, and remediation tracking to drive coordinated fixes with DevOps and remediation teams.
The InsightVM deployment operated within a broader security toolset that included Splunk Cloud with Enterprise Security and Splunk UBA for incident response, Signal Sciences for runtime application protection, Data Theorem for API security, AttackIQ for attack simulation, Okta for MFA and SSO, and Netskope CASB for web and API policy enforcement. This positioned Rapid7 InsightVM as the vulnerability data source feeding risk prioritization and operational workflows alongside monitoring, identity, and CASB controls.
Governance changes accompanied the technical rollout, including formalized risk based triage workflows, collaboration with the risk management team to assess vendor and product risk, and routine review of compliance evidence such as ISO 27001 and SOC Type 2 certifications and network diagrams. The implementation focused on embedding Rapid7 InsightVM into security operations and DevSecOps remediation processes rather than on a point solution use case.
|
|
|
Exponent, Inc. | Professional Services | 1215 | $435M | United States | Rapid7 | Rapid7 InsightVM | Vulnerability Management | 2019 | n/a |
In 2019, Exponent, Inc. deployed Rapid7 InsightVM to standardize Vulnerability Management across its engineering and consulting operations. Exponent implemented Rapid7 InsightVM together with Rapid7 Managed Detection & Response to secure client data and provide continuous visibility across its distributed workforce and offices in the U.S., EU, and Asia.
The Rapid7 InsightVM implementation provided centralized asset discovery and consistent reporting as core functional capabilities, paired with vulnerability scanning and risk prioritization workflows typical of Vulnerability Management solutions. The configuration emphasized continuous visibility across distributed endpoints and office networks, and it incorporated automation for vulnerability detection and prioritized remediation ticketing to reduce manual triage effort.
Integration with Rapid7 Managed Detection & Response established a 24/7 SOC support model that extended operational coverage beyond periodic scans, enabling sustained monitoring and incident correlation as part of the Vulnerability Management program. Operational scope included security operations, IT operations, and compliance teams across Exponents regional offices, with centralized reporting used to align remediation workflows and client-facing security attestations.
Governance shifted toward standardized reporting and workflow orchestration to reduce manual monitoring burden and to help meet client security and compliance expectations. The combined InsightVM and Managed Detection & Response deployment delivered continuous visibility, centralized asset inventory, and around the clock SOC support as the primary outcomes reported by Exponent.
|
|
|
Metropolitan Transportation Authority (MTA) | Transportation | 70000 | $21.3B | United States | Rapid7 | Rapid7 InsightVM | Vulnerability Management | 2019 | n/a |
In 2019, the Metropolitan Transportation Authority (MTA) deployed Rapid7 InsightVM as part of its Vulnerability Management program. The deployment was managed through the enterprise security operations center and supported vulnerability scanning, scheduled assessments, and centralized reporting across network and endpoint inventories. Rapid7 InsightVM was used alongside Rapid7 Nexpose for enterprise network scanning and asset discovery.
Configuration work focused on authenticated and unauthenticated scanning, asset grouping, scheduled scan orchestration, risk scoring, and remediation tracking workflows. The implementation included consolidation of scan results into centralized dashboards and automated report generation for SOC analysts and management, with vulnerability prioritization aligned to operational risk workflows.
Integrations were implemented with multiple detection and analytics platforms that the MTA SOC operated, including Splunk ES, Exabeam Fusion SIEM, IBM QRadar, LogRhythm, Carbon Black and CrowdStrike EDRs, to enrich vulnerability context and support incident response. The vulnerability toolset was operated in a heterogeneous environment that also included Qualys, Tenable, Kenna Security and Nessus based scans, with scan outputs and findings fed into GNOSC and CyberComm ticketing and SOC triage processes. Automation and deployment leveraged infrastructure as code and CI CD patterns using Terraform, Ansible, Azure DevOps, Jenkins and Git to provision scanning assets and manage configuration drift.
Governance and operational procedures emphasized threat modeling and mapping to MITRE ATT&CK, with threat hunting and enrichment workflows linking EDR detections to exploit techniques and vulnerability data. The program aligned scanning and reporting to compliance and audit standards referenced by the security team, including NIST SP 800 53, FISMA and ISO 27001, and used Splunk best practice GRC patterns to support OWASP, CIS and DLP controls in remediation workflows.
|
|
|
|
Manufacturing | 11000 | $2.3B | United States | Rapid7 | Rapid7 InsightVM | Vulnerability Management | 2020 | n/a |
|
|
|
|
Banking and Financial Services | 5000 | $1.4B | United States | Rapid7 | Rapid7 InsightVM | Vulnerability Management | 2019 | n/a |
|
|
|
|
Professional Services | 24000 | $7.7B | United States | Rapid7 | Rapid7 InsightVM | Vulnerability Management | 2020 | n/a |
|
|
|
|
Banking and Financial Services | 86746 | $24.5B | Canada | Rapid7 | Rapid7 InsightVM | Vulnerability Management | 2023 | n/a |
|
|
|
|
Banking and Financial Services | 2500 | $658M | United States | Rapid7 | Rapid7 InsightVM | Vulnerability Management | 2018 | n/a |
|
Buyer Intent: Companies Evaluating Rapid7 InsightVM
Discover Software Buyers actively Evaluating Enterprise Applications
| Logo | Company | Industry | Employees | Revenue | Country | Evaluated | ||
|---|---|---|---|---|---|---|---|---|
| No data found | ||||||||