Best Risk-Based Vulnerability Management Software - Page 2

How Many Risk-Based Vulnerability Management Software Products Does G2 Track?

Total Products under this Category: 215

Category Stats (Sep 2026)

  • Average Rating: 4.5/5 (↓0.01 vs Aug 2026) The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: Ethiack (+0.86%) - Among all products in this category, Ethiack recorded the largest rating increase compared to last month

Last updated: September 15, 2026

How Does G2 Rank Risk-Based Vulnerability Management Software Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 5,400+ Authentic Reviews
  • 215+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Risk-Based Vulnerability Management Software

G2 Grid® for Risk-Based Vulnerability Management Software plotting products by satisfaction and market presence

Highlighted products: Ivanti Autonomous Endpoint Management, Arctic Wolf, Tenable Vulnerability Management, RiskProfiler - External Threat Exposure Management, YesWeHack, Check Point Exposure Management, H1 Platform, and Pentera.

Underlying data: [Grid® JSON](https://www.g2.com/categories/risk-based-vulnerability-management/grids.json?focus%5B%5D=ivanti-autonomous-endpoint-management&focus%5B%5D=arctic-wolf&focus%5B%5D=tenable-vulnerability-management&focus%5B%5D=riskprofiler-external-threat-exposure-management&focus%5B%5D=yeswehack&focus%5B%5D=check-point-exposure-management&focus%5B%5D=h1-platform&focus%5B%5D=pentera)

Bitsight

Bitsight is the global leader in cyber risk intelligence, leveraging advanced AI to empower organizations with precise insights derived from the industry’s most extensive external cybersecurity dataset. With more than 3,500 customers and over 68,000 organizations active on its platform, Bitsight delivers real-time visibility into cyber risk and threat exposure, enabling teams to rapidly identify vulnerabilities, detect emerging threats, prioritize remediation, and mitigate risks across their extended attack surface. Bitsight proactively uncovers security gaps across infrastructure, cloud environments, digital identities, and third- and fourth-party ecosystems. From security operations and governance teams to executive boardrooms, Bitsight provides the unified intelligence backbone required to confidently manage cyber risk and address exposures before they impact performance.

Average Rating: 4.5/5.0

Total Reviews: 76

How Do G2 Users Rate Bitsight?

  • Has the product been a good partner in doing business?: 9.3/10 (Category avg: 9.2/10)
  • Reporting: 7.4/10 (Category avg: 8.8/10)
  • Vulnerability Intelligence: 7.4/10 (Category avg: 8.7/10)
  • Risk-Prioritization: 7.9/10 (Category avg: 8.8/10)

Who Is the Company Behind Bitsight?

  • Seller: Bitsight
  • Company Website:
  • Year Founded: 2011
  • HQ Location: Boston, MA
  • Twitter: @BitSight
    4,503 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    694 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Hospital & Health Care
  • Company Size: 71% Large, 24% Medium

What Do G2 Reviewers Say About Bitsight?

AI-generated summary from verified user reviews

Pros
  • Users value the comprehensive security posture that Bitsight provides for both their organization and suppliers.
  • Users value Bitsight for its comprehensive risk assessment, enabling effective management of cyber risks and third-party suppliers.
  • Users appreciate the intuitive interface of Bitsight, finding it user-friendly and easy to navigate for daily tasks.
  • Users value the intuitive interface and comprehensive insights provided by Bitsight, enhancing security management efficiency.
  • Users commend Bitsight's fantastic customer support, recognizing their knowledge, responsiveness, and intuitive assistance.
Cons
  • Users express frustration over the missing features in Bitsight, particularly regarding questionnaire management and transparency in scoring.
  • Users express concerns about the lack of clarity in Bitsight's findings and scoring methodology, affecting overall trust.
  • Users experience poor customer support and inadequate documentation, hindering effective use of the Bitsight platform.
  • Users face poor notifications from BitSight, with alerts often delayed and historical breaches not reflecting current vulnerabilities.
  • Users experience slow loading times and timeouts that hinder workflow and overall satisfaction with Bitsight.

What Are Recent G2 Reviews of Bitsight?

What Are G2 Users Discussing About Bitsight?

Cisco Vulnerability Management (formerly Kenna.VM)

Cisco Vulnerability Management (formerly Kenna.VM), the original SaaS risk-based vulnerability management platform, prioritizes vulnerabilities that pose a real risk, enabling Security and IT teams to focus their limited resources and remediate more efficiently. Cisco’s data science-driven prioritization evaluates both enterprise data and a wealth of data on real-world exploit activity and translates that context into actionable intelligence to guide remediation.

Average Rating: 4.3/5.0

Total Reviews: 200

How Do G2 Users Rate Cisco Vulnerability Management (formerly Kenna.VM)?

  • Has the product been a good partner in doing business?: 8.9/10 (Category avg: 9.2/10)
  • Reporting: 8.5/10 (Category avg: 8.8/10)
  • Vulnerability Intelligence: 8.7/10 (Category avg: 8.7/10)
  • Risk-Prioritization: 9.1/10 (Category avg: 8.8/10)

Who Is the Company Behind Cisco Vulnerability Management (formerly Kenna.VM)?

  • Seller: Cisco
  • Year Founded: 1984
  • HQ Location: San Jose, CA
  • Twitter: @Cisco
    720,366 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    95,294 employees on LinkedIn®
  • Ownership: NASDAQ:CSCO

Who Uses This Product?

  • Who Uses This: Software Engineer
  • Top Industries: Information Technology and Services, Financial Services
  • Company Size: 76% Large, 17% Medium

What Are Recent G2 Reviews of Cisco Vulnerability Management (formerly Kenna.VM)?

What Are G2 Users Discussing About Cisco Vulnerability Management (formerly Kenna.VM)?

Semperis Purple Knight

Community-driven hybrid Active Directory security assessment tool. Purple Knight is an identity system security assessment tool used by thousands of organizations to quickly identify vulnerabilities in AD, Entra ID, and Okta environments and receive prioritized, expert remediation guidance.

Average Rating: 4.7/5.0

Total Reviews: 11

How Do G2 Users Rate Semperis Purple Knight?

  • Has the product been a good partner in doing business?: 8.9/10 (Category avg: 9.2/10)
  • Reporting: 8.7/10 (Category avg: 8.8/10)
  • Vulnerability Intelligence: 8.2/10 (Category avg: 8.7/10)
  • Risk-Prioritization: 8.0/10 (Category avg: 8.8/10)

Who Is the Company Behind Semperis Purple Knight?

  • Seller: Semperis
  • Company Website:
  • Year Founded: 2015
  • HQ Location: Hoboken, New Jersey
  • Twitter: @SemperisTech
    10,074 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    693 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 45% Medium, 45% Small

What Do G2 Reviewers Say About Semperis Purple Knight?

AI-generated summary from verified user reviews

Pros
  • Users value the immediate, prioritized security insights from Semperis Purple Knight, enhancing their Active Directory protection effectively.
  • Users find the ease of use of Semperis Purple Knight invaluable for quickly assessing security vulnerabilities in Active Directory.
  • Users appreciate the immediate, prioritized insights from Semperis Purple Knight, enabling swift identification of critical security gaps.
  • Users value the immediate actionable insights offered by Semperis Purple Knight, quickly identifying critical Active Directory security gaps.
  • Users appreciate the ease of implementation of Semperis Purple Knight, making setup and integration straightforward and efficient.
Cons
  • Users find the limited information management capabilities of Semperis Purple Knight to be a significant drawback.
  • Users express concern over the lack of automation in remediation, requiring manual intervention for issues identified by the tool.
  • Users find the difficult learning curve due to overwhelming reports that require expert knowledge for effective use.
  • Users struggle with the difficult setup for Semperis Purple Knight, facing challenges in manual configurations for hybrid environments.
  • Users express concerns about inadequate reporting, citing basic reports and no real-time monitoring as significant drawbacks.

What Are Recent G2 Reviews of Semperis Purple Knight?

ZeroFox

ZeroFox is the solution used to illuminate threat actor intent, mitigate threats and exposures, remove threats from the internet, and preemptively safeguard your reputation. ZeroFox uniquely fuses the core capabilities of Cyber Threat Intelligence, Brand and Domain Protection, Attack Surface Intelligence, Executive Protection and Physical Security Intelligence in one platform packed with intelligence you’ll actually use. ZeroFox defends your business from the everyday attacks that impact revenue, erode trust, and frustrate teams by: Discovering exposed assets, brands, domains, accounts, and emerging threats Validating the risks that matter most to you and your digital estate Disrupting attacks before they harm your business, your customers, and your people Our continuous cycle—Discover, Validate, Disrupt—delivers outcomes and helps organizations achieve deeper threat contextualization, faster detection and response times, and longer-term cost savings by anticipating, understanding, and mitigating external digital threats at scale. Join thousands of customers, including some of the largest public sector organizations and leaders in finance, media, technology, retail, and healthcare, and let ZeroFox deliver timely, personal, and usable intelligence so you can stay ahead of what’s next and reclaim what’s right.

Average Rating: 4.4/5.0

Total Reviews: 169

How Do G2 Users Rate ZeroFox?

  • Has the product been a good partner in doing business?: 9.2/10 (Category avg: 9.2/10)
  • Reporting: 9.0/10 (Category avg: 8.8/10)
  • Vulnerability Intelligence: 8.8/10 (Category avg: 8.7/10)
  • Risk-Prioritization: 9.0/10 (Category avg: 8.8/10)

Who Is the Company Behind ZeroFox?

  • Seller: ZeroFox
  • Company Website:
  • Year Founded: 2013
  • HQ Location: Baltimore, MD
  • Twitter: @ZeroFOX
    5,205 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    856 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Cyber Security Analyst
  • Top Industries: Financial Services, Banking
  • Company Size: 50% Large, 28% Medium

What Do G2 Reviewers Say About ZeroFox?

AI-generated summary from verified user reviews

Pros
  • Users value the ease of use in ZeroFox, appreciating smooth onboarding and effortless setup for brand protection.
  • Users value ZeroFox for its effective scam site detection and exceptional brand protection, enhancing overall security effortlessly.
  • Users value the real-time threat visibility ZeroFox provides, enhancing external security across various digital platforms.
  • Users value the quick and effective alert notifications from ZeroFox, enhancing their daily operational efficiency and response.
  • Users value ZeroFox for its effective scam site detection, significantly enhancing their security against threats.
Cons
  • Users express frustration with inefficient alerts from ZeroFox, as takedowns may take too long or remain incomplete.
  • Users experience false alarms from ZeroFox, leading to time-consuming manual reviews of repetitive alerts.
  • Users experience slow performance with ZeroFox, including delays in alert reporting and slow UI loading times.
  • Users experience frequent false positive alerts with ZeroFox, leading to time-consuming manual reviews and inefficiencies.
  • Users experience an inefficient alert system with delays and false positives affecting timely threat response.

What Are Recent G2 Reviews of ZeroFox?

What Are G2 Users Discussing About ZeroFox?

SecOps Solution

SecOps Solution is a next-gen, agentless patch and vulnerability management platform that helps organizations fix vulnerabilities fast — without agents, manual effort, or complex setups. We automate patching across operating systems and third-party applications, including remote and on-prem devices — all in a fraction of the time traditional tools take.

Average Rating: 4.8/5.0

Total Reviews: 49

How Do G2 Users Rate SecOps Solution?

  • Has the product been a good partner in doing business?: 9.3/10 (Category avg: 9.2/10)
  • Reporting: 9.7/10 (Category avg: 8.8/10)
  • Vulnerability Intelligence: 9.7/10 (Category avg: 8.7/10)
  • Risk-Prioritization: 9.7/10 (Category avg: 8.8/10)

Who Is the Company Behind SecOps Solution?

  • Seller: SecOps Solution
  • Year Founded: 2021
  • HQ Location: Mountain View, California, USA
  • Twitter: @secopsolution
    35 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    7 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software, Financial Services
  • Company Size: 62% Small, 35% Medium

What Do G2 Reviewers Say About SecOps Solution?

AI-generated summary from verified user reviews

Pros
  • Users value the intuitive centralized dashboard of SecOps Solution, which simplifies vulnerability and patch management processes effortlessly.
  • Users value the responsive customer support of SecOps Solution, ensuring guidance and assistance throughout their processes.
  • Users value the detailed patch testing environment of SecOps Solution, boosting confidence in updates and reporting.
  • Users value the detailed reporting features of SecOps Solution, enhancing communication and compliance with stakeholders.
  • Users value the reporting efficiency of SecOps Solution, enabling clear communication and aiding compliance audits effectively.

What Are Recent G2 Reviews of SecOps Solution?

What Are G2 Users Discussing About SecOps Solution?

PlexTrac

PlexTrac is the leading AI-powered platform for pentest reporting and threat exposure management, trusted by Fortune 500 companies and top security providers. Built to help cybersecurity teams continuously manage and reduce threat exposure, PlexTrac centralizes security data, streamlines reporting, prioritizes risk, and automates remediation workflows—empowering teams to drive measurable risk reduction. The platform is ideal for enterprises & service providers looking to deliver a Continuous Threat Exposure Management (CTEM) framework across their business. With our suite of solutions, you can consolidate security data from tools and manual testing, automatically prioritize risks based on business impact, and automate remediation and retesting workflows for ongoing, more effective threat management.

Average Rating: 4.8/5.0

Total Reviews: 15

How Do G2 Users Rate PlexTrac?

  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 9.2/10)
  • Reporting: 9.9/10 (Category avg: 8.8/10)
  • Vulnerability Intelligence: 6.9/10 (Category avg: 8.7/10)
  • Risk-Prioritization: 9.6/10 (Category avg: 8.8/10)

Who Is the Company Behind PlexTrac?

  • Seller: PlexTrac
  • Company Website:
  • Year Founded: 2016
  • HQ Location: Boise, Idaho
  • Twitter: @plextrac
    1,648 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    84 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Consulting
  • Company Size: 40% Large, 40% Small

What Do G2 Reviewers Say About PlexTrac?

AI-generated summary from verified user reviews

Pros
  • Users praise the intuitive and customizable platform of PlexTrac, enhancing efficiency in security reporting and collaboration.
  • Users praise the exceptional customer support from PlexTrac, noting their responsiveness and willingness to assist with inquiries.
  • Users find PlexTrac's ease of use beneficial, thanks to its intuitive UI and seamless integration features.
  • Users appreciate the reporting efficiency of PlexTrac, enabling streamlined processes and enhanced organization in their workflow.
  • Users value the seamless integrations of PlexTrac, significantly enhancing efficiency in reporting and security assessments.
Cons
  • Users face missing features in PlexTrac's on-premise version compared to the SaaS offering, affecting overall functionality.
  • Users note that complexity in report formatting can be finicky, requiring extra effort for optimal results.
  • Users find the complex setup of PlexTrac challenging initially, requiring time to adapt before reaping its benefits.
  • Users find the difficult learning curve of PlexTrac challenging, despite the team's supporting availability.
  • Users seek improved reporting capabilities for Threat Hunting and Incident Response within PlexTrac to enhance usability.

What Are Recent G2 Reviews of PlexTrac?

Armis

Armis is THE cyber exposure management and security solution designed to help organizations protect their entire attack surface and manage cyber risk exposure in real time. In an era where traditional perimeter defenses are becoming increasingly ineffective, Armis provides a comprehensive approach to cybersecurity that enables organizations to continuously monitor, secure, and manage all critical assets, whether on-premises or in the cloud. Armis' target audience includes a wide range of organizations, from Fortune 100, 200, and 500 companies to national governments and local entities. These organizations face unique challenges in safeguarding their critical infrastructure and sensitive data against evolving cyber threats. Armis is particularly beneficial for industries that rely heavily on connected devices and IoT (Internet of Things) technologies, as it offers visibility and protection across diverse environments. This capability is essential for organizations aiming to maintain operational continuity and protect their reputations in a landscape where cyber incidents can have far-reaching consequences. Key features of Armis include real-time visibility into all connected devices, automated risk assessment, and continuous monitoring of network activity. The platform uses advanced machine learning algorithms to detect anomalies and potential threats, allowing organizations to respond swiftly to emerging risks. Additionally, Armis seamlessly integrates with existing security tools, enhancing security posture without disrupting current workflows. This interoperability is crucial for organizations looking to strengthen their defenses without overhauling their entire security infrastructure. The benefits of using Armis extend beyond mere compliance; they encompass a proactive approach to cybersecurity that empowers organizations to anticipate and mitigate risks before they escalate into significant incidents. By providing a unified view of the attack surface, Armis enables security teams to prioritize their efforts and allocate resources effectively. This strategic focus not only enhances security measures, but also fosters a culture of cybersecurity awareness throughout the organization, ultimately contributing to a more resilient operational framework. In summary, Armis stands out in the cybersecurity landscape by offering a holistic solution that addresses the complexities of modern threats. Its ability to provide real-time insights and automate risk management processes makes it an invaluable tool for organizations striving to protect their critical assets and maintain a secure environment in an increasingly interconnected world.

Average Rating: 4.3/5.0

Total Reviews: 19

How Do G2 Users Rate Armis?

  • Has the product been a good partner in doing business?: 8.5/10 (Category avg: 9.2/10)
  • Reporting: 9.3/10 (Category avg: 8.8/10)
  • Vulnerability Intelligence: 8.6/10 (Category avg: 8.7/10)
  • Risk-Prioritization: 7.9/10 (Category avg: 8.8/10)

Who Is the Company Behind Armis?

  • Seller: ServiceNow
  • Company Website:
  • Year Founded: 2004
  • HQ Location: Santa Clara, CA
  • Twitter: @servicenow
    55,548 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    35,078 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Hospital & Health Care
  • Company Size: 53% Large, 26% Small

What Do G2 Reviewers Say About Armis?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the intuitive interface of Armis, which makes accessing insights and managing tasks effortless.
  • Users value Armis for its effective asset management, providing clear insights and risk assessments in real-time.
  • Users appreciate Armis for its intuitive and user-friendly interface, making it easy to manage system risks and insights.
  • Users value the deep visibility Armis offers, providing comprehensive insights and context into their network environments.
  • Users praise the responsive customer support of Armis, enhancing their overall experience and problem-solving capabilities.
Cons
  • Users report integration issues with Armis, making it challenging to configure for reliable information.
  • Users find the additional costs for add-on modules to be quite high, impacting overall satisfaction with Armis.
  • Users find the complex setup challenging, requiring effort to configure integrations and additional modules that are expensive.
  • Users find the difficult setup of Armis frustrating, though integrations work well once configured.
  • Users experience excessive notifications from Armis, finding the initial alert noise overwhelming and requiring further integration.

What Are Recent G2 Reviews of Armis?

What Are G2 Users Discussing About Armis?

Microsoft Defender Vulnerability Management

Defender Vulnerability Management delivers asset visibility, intelligent assessments, and built-in remediation tools for Windows, macOS, Linux, Android, iOS, and network devices. Leveraging Microsoft threat intelligence, breach likelihood predictions, business contexts, and devices assessments, Defender Vulnerability Management rapidly and continuously prioritizes the biggest vulnerabilities on your most critical assets and provides security recommendations to mitigate risk. Reduce risk with continuous vulnerability assessment, risk-based prioritization, and remediation. Defender Vulnerability Management is available for cloud workloads and endpoints. Defender for Endpoint Plan 2 customers can access advanced vulnerability management capabilities with the Defender Vulnerability Management add-on, now generally available.

Average Rating: 4.4/5.0

Total Reviews: 34

How Do G2 Users Rate Microsoft Defender Vulnerability Management?

  • Has the product been a good partner in doing business?: 8.6/10 (Category avg: 9.2/10)
  • Reporting: 8.7/10 (Category avg: 8.8/10)
  • Vulnerability Intelligence: 8.8/10 (Category avg: 8.7/10)
  • Risk-Prioritization: 8.8/10 (Category avg: 8.8/10)

Who Is the Company Behind Microsoft Defender Vulnerability Management?

  • Seller: Microsoft
  • Year Founded: 1975
  • HQ Location: Redmond, Washington
  • Twitter: @microsoft
    13,091,739 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    232,750 employees on LinkedIn®
  • Ownership: MSFT

Who Uses This Product?

  • Top Industries: Computer & Network Security
  • Company Size: 41% Small, 35% Large

What Are Recent G2 Reviews of Microsoft Defender Vulnerability Management?

Edgescan

What Is Edgescan? Edgescan is a cybersecurity company that helps organizations proactively identify, validate, and prioritize vulnerabilities across their applications, API’s and digital landscape. The company specializes in continuous vulnerability assessment, automated penetration testing, Attack Surface Management and Penetration Testing as a Service (PTaaS). Edgescan also delivers Autonomous Penetration Testing via "Edgescan Atomic". Atomic is an AI powered autonomous penetration testing capability available exclusively to Edgescan customers. Each Atomic Attack Credit provides an autonomous penetration test, allowing organizations to perform an additional autonomous penetration test when required Atomic complements PTaaS by providing another way to assess security as environments evolve. (Supercharge your security with AI) Edgescan combines advanced automation with certified security experts, including professionals holding credentials such as CREST and OSCP, to deliver highly accurate and actionable security testing. This hybrid approach allows organizations to move beyond traditional point-in-time penetration tests and operate a continuous proactive cybersecurity program. The Edgescan platform is designed primarily for web application and API security, enabling organizations to continuously assess their attack surface and identify vulnerabilities throughout the development lifecycle but also delivers “full stack” coverage to detect host layer CVE’s. With a client retention rate of over 90%, Edgescan has built long-term partnerships by delivering measurable improvements in security efficiency, risk visibility, and vulnerability management. Key Features and Capabilities of Edgescan Automated Penetration Testing Edgescan uses intelligent automation to continuously assess applications, APIs, hosts, and cloud environments for vulnerabilities. This enables frequent, scalable security testing across modern and distributed architectures. Human‑Validated Testing Findings are reviewed and manually validated by certified security experts to eliminate false positives and provide deeper insight into real‑world exploitability. Each result is accurate, contextual, and actionable. Penetration Testing as a Service (PTaaS) Edgescan’s PTaaS model extends beyond automated testing by allowing expert testers to focus on vulnerabilities that require human analysis, including: • Business logic flaws • Authentication and authorization weaknesses • Context-dependent exposures • Complex attack chains and privilege escalation paths Cyber Analytics and AI‑Assisted Validation AI-driven analysis enhances detection, verifies exploitability, and increases accuracy. This reduces noise and gives security teams a clearer picture of genuine threats. Integrated Threat Intelligence Edgescan correlates vulnerabilities with real-world threat intelligence, including known exploits and ransomware activity to help organizations prioritize the most dangerous exposures first. Risk‑Based Prioritization Findings are prioritized based on exploitability, severity, threat context, and business impact, ensuring teams focus on the issues that matter most. Primary Value: What Edgescan Solves for Clients Edgescan enables organizations to shift from reactive vulnerability management to a continuous, proactive security model. Traditional scanners and periodic penetration tests frequently produce large volumes of unvalidated findings. This creates noise and forces security teams to spend hours determining which issues are real and critical. Edgescan solves this by combining: Automation for continuous testing Human expertise for validation and complex analysis Cyber analytics and AI for accuracy and prioritization Key Benefits Significant efficiency gains: reducing thousands of hours spent on manual validation. Higher accuracy, thanks to expert‑validated findings and reduced false positives. Clear prioritization, using threat intelligence and ransomware insights to highlight the highest‑risk exposures. Continuous security improvement, enabling rapid detection, faster remediation, and scalable vulnerability management. By unifying automation, human expertise, AI, and threat intelligence, Edgescan empowers organizations to maintain a continuous cybersecurity program that strengthens overall security posture while dramatically reducing operational burden.

Average Rating: 4.6/5.0

Total Reviews: 58

How Do G2 Users Rate Edgescan?

  • Has the product been a good partner in doing business?: 9.1/10 (Category avg: 9.2/10)
  • Reporting: 9.0/10 (Category avg: 8.8/10)
  • Vulnerability Intelligence: 9.2/10 (Category avg: 8.7/10)
  • Risk-Prioritization: 9.5/10 (Category avg: 8.8/10)

Who Is the Company Behind Edgescan?

  • Seller: Edgescan
  • Company Website:
  • Year Founded: 2017
  • HQ Location: Dublin, Dublin
  • Twitter: @edgescan
    2,256 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    90 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 38% Large, 28% Medium

What Do G2 Reviewers Say About Edgescan?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the ease of use of Edgescan, highlighting its intuitive interface and straightforward navigation.
  • Users value the automated vulnerability detection features of Edgescan for efficient risk assessment and remediation support.
  • Users value the excellent customer support from Edgescan, noting their responsiveness and proactivity in addressing queries.
  • Users value the detailed vulnerability identification from Edgescan, enabling effective risk management and threat mitigation strategies.
  • Users value Edgescan for its intuitive interface and comprehensive functionality that streamlines security assessments and support.
Cons
  • Users find the complex UI of Edgescan challenging, often requiring guidance to navigate key functions effectively.
  • Users find limited customization options frustrating, particularly with filtering systems and administrative functionalities.
  • Users find the poor interface design of Edgescan challenging, causing navigation and task completion difficulties.
  • Users experience slow performance with Edgescan as manual reviews lead to longer scan completion times.
  • Users find the user interface challenging and unintuitive, leading to difficulties in navigation and task completion.

What Are Recent G2 Reviews of Edgescan?

What Are G2 Users Discussing About Edgescan?

Bugcrowd

Bugcrowd frees organizations with a low tolerance for risk from chronic talent shortages, noisy tools that breed false positives, and the fear of critical hidden or emerging vulnerabilities. Our SaaS platform provides access to the unlimited capacity and skills of the global ethical hacker/pentester community for deeper, proactive risk reduction and faster regulatory compliance. With 12+ years of experience and 1200+ customers in every industry (including OpenAI, National Australia Bank, Indeed, USAA, Twilio, and CISA), we know what long-term with crowdsourced security looks like.

Average Rating: 4.3/5.0

Total Reviews: 60

How Do G2 Users Rate Bugcrowd?

  • Has the product been a good partner in doing business?: 9.4/10 (Category avg: 9.2/10)
  • Reporting: 8.6/10 (Category avg: 8.8/10)
  • Vulnerability Intelligence: 8.3/10 (Category avg: 8.7/10)
  • Risk-Prioritization: 8.1/10 (Category avg: 8.8/10)

Who Is the Company Behind Bugcrowd?

  • Seller: Bugcrowd
  • Year Founded: 2012
  • HQ Location: San Francisco, CA
  • Twitter: @Bugcrowd
    199,211 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    3,858 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer & Network Security
  • Company Size: 34% Large, 33% Small

What Do G2 Reviewers Say About Bugcrowd?

AI-generated summary from verified user reviews

Pros
  • Users commend Bugcrowd for its high-quality reporting processes, enabling efficient and transparent vulnerability submissions and feedback.
  • Users commend the ease of use of Bugcrowd, fostering a seamless experience for ethical hacking and vulnerability reporting.
  • Users commend Bugcrowd for its exceptional customer support, highlighting responsiveness and a cooperative attitude from the team.
  • Users appreciate the consistent and transparent communication from Bugcrowd, enhancing their overall research experience.
  • Users appreciate Bugcrowd for its thorough vulnerability detection, enhancing security through a strong community and efficient management.
Cons
  • Users often face poor customer support, with slow responses and inconsistencies that hinder the overall experience.
  • Users experience slow performance with triage and response times, complicating their ability to work efficiently on Bugcrowd.
  • Users experience slow triaging and inconsistent communication from Bugcrowd, leading to frustration during the bug reporting process.
  • Users find inadequate reporting can delay remediation and frustrate timely responses, impacting the overall efficiency of Bugcrowd.
  • Users find the learning curve steep for Bugcrowd, with complex setups and insufficient guidance for beginners.

What Are Recent G2 Reviews of Bugcrowd?

InsightVM (Nexpose)

InsightVM is Rapid7’s vulnerability risk management offering that advances security through cross-department clarity, a deeper understanding of risk, and measurable progress. By informing and aligning technical teams, security teams can remediate vulnerabilities and build Security into the core of the organization. With InsightVM, security teams can: Gain Clarity Into Risk and Across Teams Better understand the risk in your modern environment so you can work in lockstep with technical teams. Extend Security’s Influence Align traditionally siloed teams and drive impact with the shared view and common language of InsightVM. See Shared Progress Take a proactive approach to security with tracking and metrics that create accountability and recognize progress.

Average Rating: 4.4/5.0

Total Reviews: 72

How Do G2 Users Rate InsightVM (Nexpose)?

  • Has the product been a good partner in doing business?: 9.3/10 (Category avg: 9.2/10)
  • Reporting: 8.5/10 (Category avg: 8.8/10)
  • Vulnerability Intelligence: 9.1/10 (Category avg: 8.7/10)
  • Risk-Prioritization: 8.5/10 (Category avg: 8.8/10)

Who Is the Company Behind InsightVM (Nexpose)?

  • Seller: Rapid7
  • Year Founded: 2000
  • HQ Location: Boston, MA
  • Twitter: @rapid7
    124,405 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    8,746 employees on LinkedIn®
  • Ownership: NASDAQ:RPD

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer & Network Security
  • Company Size: 51% Large, 33% Medium

What Do G2 Reviewers Say About InsightVM (Nexpose)?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the automation capabilities of InsightVM, significantly reducing time and effort to address vulnerabilities.
  • Users benefit from real-time vulnerability identification, enhancing network security through continuous monitoring and immediate detection.
  • Users find asset management features of InsightVM invaluable for effective tracking and categorization of vital assets.
  • Users value InsightVM's clear risk scoring and live dashboards for managing asset exposure effectively and prioritizing risks.
  • Users appreciate the effective prioritization of risks and vulnerabilities with InsightVM’s actionable dashboards and asset tagging.
Cons
  • Users find the complexity of setup and maintenance a challenge, impacting usability and initial experiences.
  • Users experience performance issues with scans and dashboards, finding them cumbersome at scale and support slow to respond.
  • Users face resource limitations with InsightVM, requiring careful management and optimization for optimal performance.
  • Users note that memory consumption can peak, requiring careful management for optimal performance with InsightVM.
  • Users find the time-consuming resource tracking in InsightVM can be tedious, especially when optimizing functionalities.

What Are Recent G2 Reviews of InsightVM (Nexpose)?

What Are G2 Users Discussing About InsightVM (Nexpose)?

SAFE

SAFE has reinvented cyber risk management with Agentic AI. The company helps CISOs, TPRM, and GRC leaders become strategic business partners by automating the understanding, prioritization and management of cyber risk—accelerating AI adoption and digital transformation. SAFE is the #1 platform to unify the management of all cyber risks—enterprise, third-party, and AI-related—and deliver autonomous cyber risk management through a fleet of specialized AI agents. Its platform replaces manual effort with agentic automation, backed by the world’s most trusted risk standards. Trusted by hundreds of global organizations, SAFE has more than doubled revenue three years in a row and raised $100M+ to fuel the future of cyber risk automation.

Average Rating: 4.4/5.0

Total Reviews: 59

How Do G2 Users Rate SAFE?

  • Has the product been a good partner in doing business?: 8.5/10 (Category avg: 9.2/10)
  • Reporting: 7.4/10 (Category avg: 8.8/10)
  • Vulnerability Intelligence: 8.1/10 (Category avg: 8.7/10)
  • Risk-Prioritization: 8.8/10 (Category avg: 8.8/10)

Who Is the Company Behind SAFE?

  • Seller: Safe Security
  • Year Founded: 2012
  • HQ Location: Palo Alto, US
  • Twitter: @safecrq
    3,248 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    1,258 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Hospital & Health Care
  • Company Size: 73% Large, 13% Medium

What Do G2 Reviewers Say About SAFE?

AI-generated summary from verified user reviews

Pros
  • Users value the automated risk insights of SAFE, enabling timely and effective decision-making in cybersecurity.
  • Users praise SAFE Security for its responsive and knowledgeable customer support, making onboarding and troubleshooting effortless.
  • Users value SAFE's powerful data integrations and quantified risk analysis features for informed decision-making and efficient operations.
  • Users appreciate the seamless integrations of SAFE, enhancing automation and providing clear risk insights effortlessly.
  • Users appreciate the ease of use of SAFE, which simplifies risk assessment and enhances operational efficiency.
Cons
  • Users find the reporting and customization features lacking, limiting usability and efficiency in various tasks.
  • Users note the need for improved information management in SAFE, often seeking clarity and granularity in data presentation.
  • Users face integration issues with SAFE, limiting data use and complicating its functionality for smaller teams.
  • Users experience limited customization in SAFE, hindering integration depth and overall usability adjustments.
  • Users find the confusing interface of SAFE overwhelming, making navigation and understanding difficult initially.

What Are Recent G2 Reviews of SAFE?

What Are G2 Users Discussing About SAFE?

SecureFlag

SecureFlag is a Developer Security Enablement Platform designed to assist organizations in mitigating application risk throughout the software development lifecycle (SDLC). By integrating automated threat modeling with practical secure coding training, SecureFlag addresses critical vulnerabilities that arise from insecure design decisions and inadequate secure coding skills among development teams. This platform empowers enterprises to identify potential security threats early in the design phase and cultivate a culture of secure coding, ultimately enhancing the overall security posture of their applications. Targeted primarily at enterprise engineering and application security teams, SecureFlag serves as a comprehensive solution for organizations looking to strengthen their security frameworks. The platform effectively tackles two fundamental issues: the need for proactive security measures during the design phase and the necessity for ongoing education in secure coding practices. By providing tools that facilitate early detection of vulnerabilities and hands-on training, SecureFlag enables teams to create more secure applications while fostering a knowledgeable workforce capable of addressing security challenges. One of the standout features of SecureFlag is its automated threat modeling tool powered by AI, ThreatCanvas. This innovative solution automates the generation of threat models during the design stage, allowing teams to visualize security risks before any code is written. This proactive approach reduces reliance on manual processes and ensures that security considerations are consistently integrated into design decisions as systems evolve. Additionally, SecureFlag's secure coding training platform offers hands-on labs in real development environments, allowing developers, DevOps, Cloud, and QA engineers to practice defensive programming in real-world scenarios. This practical training is designed to replace traditional multiple-choice assessments, providing immediate feedback on code changes and fostering skill development over time. SecureFlag also emphasizes compliance and integration, mapping its training and threat modeling capabilities to various industry standards such as PCI DSS, ISO 27001, SOC 2, HIPAA, and ASVS. This feature includes exportable evidence packs for audits, simplifying the compliance process for organizations. Furthermore, SecureFlag seamlessly integrates with popular developer workflows through tools like Jira and GitHub, enabling teams to address security issues within their existing engineering processes. The platform’s AppSec team dashboards provide continuous visibility into skill coverage, risk reduction, and training adoption, allowing organizations to track their progress and make informed decisions regarding their security initiatives. With over 300 organizations across more than 30 countries utilizing SecureFlag, the platform has demonstrated measurable outcomes in enhancing security and engineering efficiency. Users have reported a 27% reduction in the time required to fix vulnerabilities, a 21% decrease in new security tickets, and an average savings of 3,600 developer hours per 100 engineers annually. SecureFlag is also recognized as an OWASP Partner, providing valuable training resources for OWASP members alongside its enterprise offerings, further solidifying its commitment to advancing secure software development practices.

Average Rating: 4.8/5.0

Total Reviews: 43

How Do G2 Users Rate SecureFlag?

  • Has the product been a good partner in doing business?: 9.8/10 (Category avg: 9.2/10)
  • Risk-Prioritization: 10.0/10 (Category avg: 8.8/10)

Who Is the Company Behind SecureFlag?

  • Seller: SecureFlag
  • Company Website:
  • HQ Location: London, United Kingdom
  • LinkedIn® Page: www.linkedin.com
    71 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Financial Services, Computer Software
  • Company Size: 47% Medium, 28% Large

What Are Recent G2 Reviews of SecureFlag?

DeCYFIR by CYFIRMA

DeCYFIR is an AI-powered preemptive External Threat Landscape Management platform engineered to help organizations predict and prevent cyberattacks before they occur. Adopting a hacker's perspective, it delivers early warnings, prioritized insights, and actionable intelligence across the full external threat landscape. Built on a proprietary 9-pillar architecture — spanning Attack Surface Discovery & Intelligence, Vulnerability Intelligence & Threat Prioritization, Brand & Online Exposure Management, Digital Risk & Identity Protection, Third Party Risk Management, Situational Awareness & Emerging Threats, Predictive Threat Intelligence, Threat Adaptive Awareness & Training, and Sector Tailored Deception Intelligence. DeCYFIR correlates signals across all pillars to cut through noise, surface what is truly critical, and empower security teams to stay decisively ahead of emerging threats.

Average Rating: 4.8/5.0

Total Reviews: 49

How Do G2 Users Rate DeCYFIR by CYFIRMA?

  • Has the product been a good partner in doing business?: 9.4/10 (Category avg: 9.2/10)
  • Reporting: 10.0/10 (Category avg: 8.8/10)
  • Vulnerability Intelligence: 10.0/10 (Category avg: 8.7/10)
  • Risk-Prioritization: 10.0/10 (Category avg: 8.8/10)

Who Is the Company Behind DeCYFIR by CYFIRMA?

  • Seller: CYFIRMA
  • Year Founded: 2017
  • HQ Location: Singapore, SG
  • Twitter: @cyfirma
    1,002 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    135 employees on LinkedIn®
  • Phone: marketing@cyfirma.com

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer & Network Security
  • Company Size: 53% Medium, 24% Large

What Do G2 Reviewers Say About DeCYFIR by CYFIRMA?

AI-generated summary from verified user reviews

Pros
  • Users value the thorough threat detection capabilities of DeCYFIR, enhancing cybersecurity measures against potential attacks.
  • Users value the informative threat intelligence from DeCYFIR, aiding in proactive prevention of cyber incidents.
  • Users value DeCYFIR for its contextual and predictive intelligence, enhancing threat visibility and strategic risk management.
  • Users value DeCYFIR's comprehensive threat intelligence features, enhancing proactive defense against cyber threats effectively.
  • Users value the advanced security insights from DeCYFIR, enhancing their ability to prevent and respond to threats.
Cons
  • Users find DeCYFIR not user-friendly, citing a confusing UI and technical complexity for less experienced individuals.
  • Users find DeCYFIR's interface to be complex and overwhelming, particularly for those unfamiliar with threat intelligence workflows.
  • Users find DeCYFIR's learning curve daunting, as its complexity may overwhelm new users without proper training.
  • Users find the platform's limited customization options challenging, impacting their overall user experience.
  • Users find DeCYFIR's complex setup challenging, particularly for newcomers and those needing customized dashboards or API integration.

What Are Recent G2 Reviews of DeCYFIR by CYFIRMA?

Qualys VMDR

Qualys VMDR is an all-in-one risk-based vulnerability management solution that quantifies cyber risk. It gives organizations unprecedented insights into their risk posture and provides actionable steps to reduce risk. It also gives cybersecurity and IT teams a shared platform to collaborate, and the power to quickly align and automate no-code workflows to respond to threats with automated remediation and integrations with ITSM solutions such as ServiceNow.

Average Rating: 4.4/5.0

Total Reviews: 165

How Do G2 Users Rate Qualys VMDR?

  • Has the product been a good partner in doing business?: 8.5/10 (Category avg: 9.2/10)
  • Reporting: 8.3/10 (Category avg: 8.8/10)
  • Vulnerability Intelligence: 8.7/10 (Category avg: 8.7/10)
  • Risk-Prioritization: 8.5/10 (Category avg: 8.8/10)

Who Is the Company Behind Qualys VMDR?

  • Seller: Qualys
  • Year Founded: 1999
  • HQ Location: Foster City, CA
  • Twitter: @qualys
    34,248 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    3,637 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Security Engineer
  • Top Industries: Information Technology and Services, Computer & Network Security
  • Company Size: 51% Large, 28% Medium

What Do G2 Reviewers Say About Qualys VMDR?

AI-generated summary from verified user reviews

Pros
  • Users value the swift and comprehensive vulnerability detection of Qualys VMDR, enhancing overall security and response times.
  • Users value the swift vulnerability identification of Qualys VMDR, allowing for quick corrections and enhanced security posture.
  • Users value the real-time alerting system of Qualys VMDR, which ensures quick responses to critical vulnerabilities.
  • Users value the automation capabilities of Qualys VMDR, simplifying vulnerability detection and remediation processes effectively.
  • Users value the cloud integration for its ease of deployment and comprehensive vulnerability management solutions.
Cons
  • Users find the interface complexity challenging, especially for new users during the initial setup.
  • Users find the complex reporting challenging, especially for new users, making initial use difficult.
  • Users find the complex setup challenging, especially for new users unfamiliar with the interface.
  • Users find the difficult learning curve of Qualys VMDR challenging, especially for newcomers to the platform.
  • Users find the feature complexity of Qualys VMDR challenging, especially during the initial stage for new users.

What Are Recent G2 Reviews of Qualys VMDR?

What Are G2 Users Discussing About Qualys VMDR?

Brandon Summers-Miller
BS
Researched and written by Brandon Summers-Miller
Updated October 3, 2024