Best Risk-Based Vulnerability Management Software - Page 8

How Many Risk-Based Vulnerability Management Software Products Does G2 Track?

Total Products under this Category: 215

Category Stats (Sep 2026)

  • Average Rating: 4.5/5 (↓0.01 vs Aug 2026) The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: Ethiack (+0.86%) - Among all products in this category, Ethiack recorded the largest rating increase compared to last month

Last updated: September 15, 2026

How Does G2 Rank Risk-Based Vulnerability Management Software Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 5,400+ Authentic Reviews
  • 215+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Risk-Based Vulnerability Management Software

G2 Grid® for Risk-Based Vulnerability Management Software plotting products by satisfaction and market presence

Highlighted products: Ivanti Autonomous Endpoint Management, Arctic Wolf, Tenable Vulnerability Management, RiskProfiler - External Threat Exposure Management, YesWeHack, Check Point Exposure Management, H1 Platform, and Pentera.

Underlying data: [Grid® JSON](https://www.g2.com/categories/risk-based-vulnerability-management/grids.json?focus%5B%5D=ivanti-autonomous-endpoint-management&focus%5B%5D=arctic-wolf&focus%5B%5D=tenable-vulnerability-management&focus%5B%5D=riskprofiler-external-threat-exposure-management&focus%5B%5D=yeswehack&focus%5B%5D=check-point-exposure-management&focus%5B%5D=h1-platform&focus%5B%5D=pentera)

NopSec Unified VRM

NopSec Unified Vulnerability Risk Management (VRM) correlates vulnerability data with your IT environment and attack patterns in the wild to help you avoid false positives and find the threats that matter. Unified VRM prioritizes security vulnerabilities based on business risk and context with proprietary threat prediction models and cyber intelligence – including malware, exploit, patching and social media feeds to predict the true probability of attacks. It replaces manual remediation tasks with automated workflow, integrated communication capabilities and incident management – guided by rich visualization dashboards for easy reporting on current status.

Average Rating: 5.0/5.0

Total Reviews: 1

How Do G2 Users Rate NopSec Unified VRM?

  • Reporting: 10.0/10 (Category avg: 8.8/10)
  • Vulnerability Intelligence: 8.3/10 (Category avg: 8.7/10)
  • Risk-Prioritization: 8.3/10 (Category avg: 8.8/10)

Who Is the Company Behind NopSec Unified VRM?

  • Seller: NopSec
  • Year Founded: 2013
  • HQ Location: New York, US
  • Twitter: @nopsec
    2,200 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    29 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 100% Medium

What Are Recent G2 Reviews of NopSec Unified VRM?

What Are G2 Users Discussing About NopSec Unified VRM?

Ostrich Birdseye

Ostrich Cyber-Risk helps organizations reduce the complexity of identifying, quantifying and communicating cyber and operational risks related to their cybersecurity posture with its Birdseye™ SaaS solution. Benchmarked against NIST CSF with references to best standards, like NIST 800-53, ISO 27001, CIS 18, etc. Birdseye is a unified qualitative and quantitative cyber risk management application that offers an intuitive assessment workflow to track your organization’s risk over time, all in one place. The Birdseye™ proprietary features include continuous progress tracking, real world data insights from Advisen for peer comparison, CRQ Simulator that simulates unlimited risk scenarios to enable risk-reduction ROI calculations, and shareable reports. Learn more at https://www.ostrichcyber-risk.com/.

Average Rating: 4.0/5.0

Total Reviews: 1

How Do G2 Users Rate Ostrich Birdseye?

  • Reporting: 10.0/10 (Category avg: 8.8/10)
  • Risk-Prioritization: 10.0/10 (Category avg: 8.8/10)

Who Is the Company Behind Ostrich Birdseye?

Who Uses This Product?

  • Company Size: 100% Small

What Are Recent G2 Reviews of Ostrich Birdseye?

Phoenix Security

Phoenix Security is a Contextual ASPM focused on product security. It combines risk-based Vulnerability Management, Application Security Posture Management, and Cloud into a risk and remediation-first platform. Phoenix was founded by the team running Application security and Cloud security posture for HSBC. What sets Phoenix apart is the risk-based quantitative view, the level of customization, and the scanning code to cloud vulnerabilities. Phoenix security utilizes threat intelligence, dependency analysis, and cloud analysis to detect which category of vulnerabilities needs to be addressed and minimize the false positives.

Average Rating: 5.0/5.0

Total Reviews: 1

Who Is the Company Behind Phoenix Security?

  • Seller: Phoenix Security
  • Year Founded: 2021
  • HQ Location: London, GB
  • Twitter: @sec_phoenix
    268 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    27 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 100% Small

What Are Recent G2 Reviews of Phoenix Security?

Predictive

PREDICTIVE - UNIFIED SECURITY AND OBSERVABILITY PLATFORM FOR ADVANCED THREAT DETECTION AND FASTER INCIDENT RESPONSE. Experience the power of Predictive, embed with ML and Artificial intelligence, its a cutting-edge SaaS application designed to fortify organizations against cyber threats, empowering them with informed insights for decisive action. Key features of Predictive' s offering include: - Security Audit: Leverage automated vulnerability scanning to ensure a comprehensive assessment of your digital defenses. - Security Alerts: Benefit from advanced Events and Anomaly Monitoring, utilizing Predictive Analytics to stay one step ahead of potential threats. - Cyber Awareness: Elevate your organization's security posture through staff cybersecurity training and proactive awareness-building initiatives. - Cyber Hygiene: Assess, Benchmark with CIS (Centre of Internet Security) and provide insights that help companies to improve enterprise's security readiness levels. Predictive is your ally in the ever-evolving landscape of cybersecurity, providing a holistic solution for proactive defense and strategic decision-making.

Average Rating: 5.0/5.0

Total Reviews: 1

How Do G2 Users Rate Predictive?

  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 9.2/10)
  • Reporting: 10.0/10 (Category avg: 8.8/10)
  • Vulnerability Intelligence: 10.0/10 (Category avg: 8.7/10)
  • Risk-Prioritization: 10.0/10 (Category avg: 8.8/10)

Who Is the Company Behind Predictive?

  • Seller: Tisalabs Limited
  • Year Founded: 2017
  • HQ Location: Cork, IE
  • Twitter: @tisalabs
    44 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    12 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 100% Small

What Are Recent G2 Reviews of Predictive?

Prelude Security

Prelude helps security and IT teams continuously validate that their security controls are fully deployed, optimally configured, and working as intended. Through read-only, API integrations to your existing tools like EDR, IAM, email security, MDM, vulnerability management, and others, Prelude drives visibility across controls and identifiese critical gaps and misconfigurations in your environment. With automated control assessments mapped to leading frameworks like MITRE ATT&CK and NIST, Prelude turns otherwise siloed and fragmented security data into clear visibility, actionable insights, and a measurable assurance of your security posture.

Average Rating: 5.0/5.0

Total Reviews: 1

How Do G2 Users Rate Prelude Security?

  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 9.2/10)
  • Reporting: 10.0/10 (Category avg: 8.8/10)
  • Vulnerability Intelligence: 10.0/10 (Category avg: 8.7/10)
  • Risk-Prioritization: 10.0/10 (Category avg: 8.8/10)

Who Is the Company Behind Prelude Security?

  • Seller: Prelude Security
  • Year Founded: 2020
  • HQ Location: N/A
  • Twitter: @preludeorg
    1,550 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    29 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 100% Medium

What Are Recent G2 Reviews of Prelude Security?

RankedRight

RankedRight is the triage tool that automatically ranks vulnerabilities - new and existing - based on the rules set by its user, factoring in what is critical to the business, and delegating it to the most appropriate person to resolve. This means teams spend less time on the admin and diagnosis of vulnerabilities and more time on keeping their companies safe.

Average Rating: 5.0/5.0

Total Reviews: 1

How Do G2 Users Rate RankedRight?

  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 9.2/10)

Who Is the Company Behind RankedRight?

Who Uses This Product?

  • Company Size: 100% Large

What Are Recent G2 Reviews of RankedRight?

What Are G2 Users Discussing About RankedRight?

RedSeal

RedSeal, the pioneer in network exposure analytics, delivers actionable insights to close defensive gaps across your entire network, in the cloud and on premises. Defenders gain the upper hand by knowing their cyber terrain better than their adversaries. RedSeal’s patented analytics explain what is left open, and what it takes to block it, so defensive teams can react faster, spend less effort on compliance, and stay ahead. Hundreds of Fortune 1000 companies and more than 75 US federal agencies, including five branches of the US military, depend on RedSeal for exceptionally secure environments.

Average Rating: 3.0/5.0

Total Reviews: 1

Who Is the Company Behind RedSeal?

  • Seller: RedSeal
  • Year Founded: 2004
  • HQ Location: Menlo Park, California, United States
  • Twitter: @RedSeal_co
    2,215 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    155 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 100% Large

Rescana

Rescana is a cybersecurity company focused on Third-Party Risk Management (TPRM) and External Attack Surface Management (EASM). It was founded in 2016 and has evolved into a platform that uses AI-powered automation to streamline how organizations assess and manage the security risks posed by their vendors and external digital assets. What Rescana Does: Rescana automates the traditionally manual and time-consuming processes of TPRM by: 1. Vendor Discovery & Classification Automatically identifies and classifies vendors, even those without a web presence, using AI and OSINT (open-source intelligence). 2. Risk Assessment Runs autonomous, on-demand security assessments and generates detailed risk profiles for vendors, integrating questionnaires, external scans, and organizational policies. 3. Remediation Guidance Offers actionable remediation steps and guidance based on the specific risks found. 4. Interactive Chat-Based Interface Enables users to interact with the system like a chatbot (powered by LLMs), asking questions about vendors, risks, policies, and controls. 5. Support for ESG and Multiple Questionnaire Formats Handles diverse compliance needs, including environmental, social, and governance (ESG) questionnaires, and supports multiple formats per vendor. Key Differentiators: • Agentic AI: Not just automation — Rescana employs autonomous agents that reason through questionnaire filling, evidence matching, and more. • No ticketing system needed: Unlike competitors, it doesn’t require manual back-and-forth with vendors. • Live risk dashboards: With real-time scanning and risk scoring. • Low false positives: Thanks to contextual analysis and risk validation. • Vendor Simulator: For demos and internal testing of workflows using simulated vendor responses.

Average Rating: 5.0/5.0

Total Reviews: 1

Who Is the Company Behind Rescana?

  • Seller: Rescana
  • Year Founded: 2017
  • HQ Location: New York, US
  • LinkedIn® Page: www.linkedin.com
    19 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 100% Large

What Are Recent G2 Reviews of Rescana?

What Are G2 Users Discussing About Rescana?

Resilience

Resilience is a cyber risk management platform that helps organizations identify vulnerabilities across their applications, networks, and cloud services, quantify the financial impact of those vulnerabilities, and prioritize remediation based on expected dollar loss. The platform integrates real-time threat intelligence, security posture data, and insurance claims data to produce risk models that use machine learning to rank vulnerabilities by their likelihood of causing financial harm. The platform is built on the Threatonomics Risk Graph, a proprietary AI-powered engine that ingests security control data from an organization's existing tools (EDR, SIEM, vulnerability scanners, cloud security), enriches it with live threat intelligence and aggregated loss data from Resilience's insurance portfolio, and outputs financially quantified risk assessments. These assessments express cyber risk in dollar terms rather than abstract severity scores. Resilience is available in two packages: Resilience Edge is designed for individual enterprises. It includes continuous security posture assessment, a financially prioritized Cyber Action Plan with projected ROI for each remediation, breach and attack simulation powered by AttackIQ, vendor risk reports, and board-ready reporting with peer benchmarks. The Risk Operations Center provides ongoing monitoring of threat activity, delivering expert-validated alerts on industry-specific threats, active ransomware campaigns, and vulnerabilities under active exploitation. Resilience Arc is designed for multi-entity organizations such as holding companies, private equity portfolios, and multinationals. It includes everything in Edge plus automated risk assessments across every subsidiary and business unit, a portfolio-level dashboard that stack-ranks entities by financial risk exposure, and centralized monitoring across all entities from a single interface. Resilience also provides integrated cyber insurance, connecting risk quantification directly to coverage decisions. The platform's risk models are trained and continuously validated against actual insurance claims outcomes from Resilience's underwriting portfolio, creating a feedback loop between security controls and real-world loss data. Primary users include CISOs and security leaders (for vulnerability prioritization and security investment planning), CFOs and boards (for financial visibility into cyber exposure), and risk managers (for balancing security investment against insurance coverage). The platform serves mid-market and enterprise organizations across manufacturing, financial services, healthcare, technology, construction, energy, transportation, and the public sector. Resilience serves 800+ enterprise clients, including more than 10% of US-based companies with revenue over $1 billion. The platform is recognized in Gartner's Hype Cycle for Cyber Risk Management. The company is headquartered in San Francisco and backed by over $200M in venture funding.

Average Rating: 4.5/5.0

Total Reviews: 1

Who Is the Company Behind Resilience?

  • Seller: Resilience
  • Year Founded: 2016
  • HQ Location: New York, New York, United States
  • Twitter: @ResilienceSays
    352 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    294 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 100% Large

What Do G2 Reviewers Say About Resilience?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the automation features of Resilience, simplifying cyber risk management and insurance integration.
  • Users value the integration of cyber risk insurance and management in Resilience, enhancing overall usability and efficiency.
  • Users value the integration of cyber risk insurance and risk management in Resilience, enhancing their experience and convenience.
Cons
  • Users often face complex setup issues with Resilience, making the initial integration challenging and frustrating.
  • Users often face integration issues and a complex initial setup that detracts from the overall experience.
  • Users often face integration challenges and complex initial setup, leading to frustration during the onboarding process.

What Are Recent G2 Reviews of Resilience?

Secureworks Taegis VDR

Secureworks Taegis VDR delivers a fully integrated, comprehensive vulnerability management solution via an automated and configuration-free approach with machine learning and self-learning, and built-in contextual prioritization. VDR automates manual tasks, uses machine learning to improve over time, and provides focus on vulnerabilities that are most meaningful.

Average Rating: 2.5/5.0

Total Reviews: 1

Who Is the Company Behind Secureworks Taegis VDR?

  • Seller: Sophos
  • Year Founded: 1985
  • HQ Location: Oxfordshire
  • Twitter: @Sophos
    36,759 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    5,550 employees on LinkedIn®
  • Ownership: LSE:SOPH

Who Uses This Product?

  • Company Size: 100% Large

What Are G2 Users Discussing About Secureworks Taegis VDR?

UNGUESS

The crowdsourcing platform for effective tests and real insights in UX, Accessibility, Quality and Safety. Whether you are developing a website, a mobile app or a software solution, we support the improvement of user experience, accessibility, quality and security with unparalleled speed and scalability. Engage a real crowd of skilled humans. Get powerful insights and answers at any time needed. With UNGUESS you have much more than a crowdtesting platform: it’s everything your digital solutions deserve, in one place. Learn more: https://unguess.io/

Average Rating: 4.8/5.0

Total Reviews: 27

How Do G2 Users Rate UNGUESS?

  • Has the product been a good partner in doing business?: 9.6/10 (Category avg: 9.2/10)

Who Is the Company Behind UNGUESS?

  • Seller: UNGUESS
  • Year Founded: 2015
  • HQ Location: Milan, IT
  • LinkedIn® Page: www.linkedin.com
    374 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 41% Large, 33% Small

What Are Recent G2 Reviews of UNGUESS?

Vijilan Threat Respond

Vijilan will deploy and implement its fully managed service in record time, and as part of the service, Vijilan will monitor and respond to any threat or suspicious behavior on the network through its technologically advanced SOC and Incident Response Team (IRT) who operate around the clock.

Average Rating: 5.0/5.0

Total Reviews: 2

How Do G2 Users Rate Vijilan Threat Respond?

  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 9.2/10)

Who Is the Company Behind Vijilan Threat Respond?

  • Seller: Vijilan
  • Year Founded: 2014
  • HQ Location: Hallandale Beach, US
  • Twitter: @vijilansoc
    408 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    79 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 67% Small

What Are Recent G2 Reviews of Vijilan Threat Respond?

What Are G2 Users Discussing About Vijilan Threat Respond?

WithSecure Elements Exposure Management

WithSecure™ Elements Exposure Management (XM) is a continuous and proactive solution that predicts and prevents breaches against your company’s assets and business operations. Elements XM provides visibility into your attack surface and enables the efficient remediation of its highest-impact exposures through a unified view, thanks to our exposure scoring and AI-enabled recommendations. Get one solution for 360° digital exposure management and visibility across your external attack surface and internal security posture, to proactively prevent cyber-attacks. Elements XM is a bit like pen testing or red teaming, but more continuous and comprehensive of your entire digital environment. WithSecure™ Elements XM uses patent-pending AI-based attack path simulation technologies for heuristic exposure hunting and adversarial exposure validation. The solution is more powerful than traditional vulnerability scanners or vulnerability management software, as it prioritizes your exposures by using AI-powered attack path mapping. In other words, you can remediate exposures through the attacker’s lens. Elements XM discovers exposures for your: - Devices - Digital identities (Entra ID) - Cloud infrastructure (misconfigurations in AWS and Azure cloud) - Networks - External Attack Surface (EASM - External Attack Surface Mapping)

Average Rating: 4.0/5.0

Total Reviews: 1

Who Is the Company Behind WithSecure Elements Exposure Management?

  • Seller: WithSecure
  • Year Founded: 1988
  • HQ Location: Helsinki, Finland
  • Twitter: @WithSecure
    66,501 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    1,780 employees on LinkedIn®
  • Ownership: FSOYF

Who Uses This Product?

  • Company Size: 100% Large

What Are Recent G2 Reviews of WithSecure Elements Exposure Management?

What Are G2 Users Discussing About WithSecure Elements Exposure Management?

Zscaler Unified Vulnerability Management

Zscaler Unified Vulnerability Management (UVM) empowers organizations to comprehensively understand and address cybersecurity risks through a single, integrated platform. Built on the Data Fabric for Security, Zscaler UVM seamlessly aggregates, deduplicates, and contextualizes data from across your security stack, correlating related findings to deliver true risk-based prioritization. UVM enables remediation strategies that reflect your unique business context and mitigating controls, while automated, customizable workflows deliver measurable improvements to your security posture. By breaking down silos and allowing fully tailored risk scoring and reporting, UVM enables security teams to focus on what matters most and respond faster than ever. Key Features and Benefits: • Unify exposure findings from every source: Aggregate and enrich exposure data with threat intelligence and business context using 200+ pre-built connectors. • Prioritize and act on the most critical risks: Identify which vulnerabilities and security gaps to address first, with contextual risk scoring based on custom factors and complete data input. • Gain real-time insight into KPIs and SLAs: Access dynamic, pre-built, and custom reports to measure security posture and team performance from any perspective. • Accelerate resolution with intelligent, flexible workflows: Speed incident response by clustering related findings, tracking ticket status and exceptions, and empowering remediation teams with AI-guided recommendations and interactive smart prompts.

Average Rating: 5.0/5.0

Total Reviews: 1

How Do G2 Users Rate Zscaler Unified Vulnerability Management?

  • Reporting: 10.0/10 (Category avg: 8.8/10)
  • Risk-Prioritization: 10.0/10 (Category avg: 8.8/10)

Who Is the Company Behind Zscaler Unified Vulnerability Management?

  • Seller: Zscaler
  • Year Founded: 2008
  • HQ Location: San Jose, California
  • Twitter: @zscaler
    17,676 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    9,150 employees on LinkedIn®
  • Ownership: NASDAQ:ZS

Who Uses This Product?

  • Company Size: 100% Large

What Are Recent G2 Reviews of Zscaler Unified Vulnerability Management?

Actifile

Holistic. Automated. Real-time. Actifile automates data risk assessments, ongoing sensitive data monitoring and data protection.

Who Is the Company Behind Actifile?

Brandon Summers-Miller
BS
Researched and written by Brandon Summers-Miller
Updated October 3, 2024