# Best Risk-Based Vulnerability Management Software

## How Many Risk-Based Vulnerability Management Software Products Does G2 Track?

**Total Products under this Category:** 194

### Category Stats (Jul 2026)

- **Average Rating:** 4.48/5 (↓0.03 vs Jun 2026) The average rating of products in this category, based on all submitted ratings
- **Top Trending Product:** Ivanti Neurons for RBVM (+5.88%) - Among all products in this category, Ivanti Neurons for RBVM recorded the largest rating increase compared to last month

_Last updated: July 31, 2026_

## How Does G2 Rank Risk-Based Vulnerability Management Software Products?

**Why You Can Trust G2's Software Rankings:**

- 30 Analysts and Data Experts
- 4,700+ Authentic Reviews
- 194+ Products
- Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

## G2 Grid® for Risk-Based Vulnerability Management Software
 ![G2 Grid® for Risk-Based Vulnerability Management Software plotting products by satisfaction and market presence](https://www.g2.com/categories/risk-based-vulnerability-management/grids.png?focus%5B%5D=38011&focus%5B%5D=31923&focus%5B%5D=7337&focus%5B%5D=160601&focus%5B%5D=130651&focus%5B%5D=39589&focus%5B%5D=98391&focus%5B%5D=55997)

Highlighted products: Arctic Wolf, Tenable Vulnerability Management, Recorded Future, RiskProfiler - External Threat Exposure Management, YesWeHack, H1 Platform, Pentera, and Check Point Exposure Management.

Underlying data: [Grid® JSON](https://www.g2.com/categories/risk-based-vulnerability-management/grids.json?focus%5B%5D=arctic-wolf&focus%5B%5D=tenable-vulnerability-management&focus%5B%5D=recorded-future&focus%5B%5D=riskprofiler-external-threat-exposure-management&focus%5B%5D=yeswehack&focus%5B%5D=h1-platform&focus%5B%5D=pentera&focus%5B%5D=check-point-exposure-management)

**Sponsored**

### ThreatScope

ThreatScope is an external attack surface management platform built specifically for mid-market companies ($50M–$500M revenue). Unlike enterprise tools that cost six figures and require dedicated analysts, ThreatScope gives lean security teams continuous visibility into their internet-facing attack surface — with AI-powered findings anyone can understand. What it does: Discovers all internet-facing assets (subdomains, IPs, services, certificates) Continuously monitors for vulnerabilities and misconfigurations Cross-references findings with CISA's Known Exploited Vulnerabilities (KEV) catalog Maps threats to MITRE ATT&CK techniques Generates plain-English findings with step-by-step remediation Produces executive, technical, and compliance (NIST CSF) PDF reports What makes it different: Built for mid-market, not enterprise — simple pricing, no complexity AI-powered analysis explains findings in plain English Agentless — no software to install, no network access needed Threat intelligence from 6+ sources (CISA KEV, NVD, MITRE ATT&CK, OTX, Abuse.ch, GitHub Advisories) Includes attack surface discovery (subdomain enumeration, DNS, HTTP probing) Scheduled scans with email alerts for critical findings Pricing: Starting at $500/month (Starter: 5 domains, 10 IPs)

[Visit website](https://www.g2.com/external_clickthroughs/record?secure%5Bad_program%5D=ppc&secure%5Bad_slot%5D=category_product_list_llm&secure%5Bcategory_id%5D=2246&secure%5Bchosen_at%5D=2026-07-31T15%3A59%3A01Z&secure%5Bdisplayable_resource_id%5D=2832&secure%5Bdisplayable_resource_type%5D=Category&secure%5Bmedium%5D=sponsored&secure%5Bplacement_reason%5D=neighbor_category&secure%5Bplacement_resource_ids%5D%5B%5D=2832&secure%5Bprioritized%5D=false&secure%5Bproduct_id%5D=1846755&secure%5Bresource_id%5D=2246&secure%5Bresource_type%5D=Category&secure%5Bsource_type%5D=category_page&secure%5Bsource_url%5D=https%3A%2F%2Fwww.g2.com%2Fcategories%2Frisk-based-vulnerability-management%3Fopen_modal_url%3D%252Fproducts%252Fcycognito%252Fwishlists%253Fhost_path%253D%25252Fcategories%25252Frisk-based-vulnerability-management%2526source%253Dcategory&secure%5Btoken%5D=7a8d9a7fbee79e0bd04a6698cd40527a9c9f8d9813b6a403e2baea3d860fc129&secure%5Burl%5D=https%3A%2F%2Fviso.group%2Fthreatscope&secure%5Burl_type%5D=custom_url)

### [Arctic Wolf](https://www.g2.com/products/arctic-wolf/reviews)

Arctic Wolf® is the market leader in security operations. Using the cloud-native Arctic Wolf® Platform, we help organizations end cyber risk by providing security operations as a concierge service. Arctic Wolf solutions include Arctic Wolf® Managed Detection and Response (MDR), Managed Risk, and Managed Security Awareness —each delivered by the industry’s original Concierge Security® Team. Highly-trained Concierge Security experts work as an extension of internal teams to provide 24x7 monitoring, detection, and response, as well as ongoing risk management to give organizations the protection, resilience and guidance they need to defend against cyber threats. Visit arcticwolf.com to get the latest industry resources and learn more about our solutions.

**Average Rating:** 4.7/5.0

**Total Reviews:** 276

#### How Do G2 Users Rate Arctic Wolf?

- **Has the product been a good partner in doing business?:** 9.5/10 (Category avg: 9.2/10)
- **Reporting:** 9.5/10 (Category avg: 8.8/10)
- **Vulnerability Intelligence:** 9.6/10 (Category avg: 8.7/10)
- **Risk-Prioritization:** 9.6/10 (Category avg: 8.8/10)

#### Who Is the Company Behind Arctic Wolf?

- **Seller:** [Arctic Wolf Networks](https://www.g2.com/sellers/arctic-wolf-networks)
- **Company Website:** www.arcticwolf.com
- **Year Founded:** 2012
- **HQ Location:** Eden Prairie, MN
- **Twitter:** @AWNetworks  
4,520 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=e68870c648dd385580ab25d4ff5749288aa4c362b659f7c696476f37cbac7fc1&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F2760138%2F&secure%5Burl_type%5D=linkedin_company_website)  
3,286 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** IT Manager, IT Director
- **Top Industries:** Hospital & Health Care, Information Technology and Services
- **Company Size:** 71% Medium, 20% Large

#### What Do G2 Reviewers Say About Arctic Wolf?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **responsive and helpful customer support** from Arctic Wolf, ensuring quick resolutions to any inquiries.
- Users value Arctic Wolf for its **proactive threat detection** , ensuring swift response to potential security issues.
- Users appreciate the **hands-on and proactive cybersecurity approach** of Arctic Wolf, feeling supported and secure in their operations.
- Users value the **ease of use** of Arctic Wolf, enjoying its seamless integration and user-friendly interface.
- Users value the **fast notification of events** , enabling quick response and engagement with professionals for effective triage.

##### Cons

- Users find Arctic Wolf to be **quite pricey** , wishing the product was more affordable despite its excellent performance.
- Users experience **false positives** with Arctic Wolf, which can lead to time-consuming investigations despite good alert tuning.
- Users note a **steep learning curve** with Arctic Wolf, requiring time to adapt and some IT knowledge for troubleshooting.
- Users note that the **cybersecurity risks can be overwhelming** , suggesting better consolidation and notification methods for clarity.
- Users note **dashboard issues** with quirks and alert overload, though updates help address these challenges over time.

#### What Are Recent G2 Reviews of Arctic Wolf?

**["Effortless Log Management and Monitoring with Built-In Parsers"](https://www.g2.com/survey_responses/arctic-wolf-review-12190051)**

**Rating:** 4.5/5.0 stars

_— Jenine M._

[Read full review](https://www.g2.com/survey_responses/arctic-wolf-review-12190051)

**["Arctic Wolf: Amazing Team, Constant Innovation, and Peace of Mind 24x7"](https://www.g2.com/survey_responses/arctic-wolf-review-12647394)**

**Rating:** 5.0/5.0 stars

_— Kris I._

[Read full review](https://www.g2.com/survey_responses/arctic-wolf-review-12647394)

#### What Are G2 Users Discussing About Arctic Wolf?

- [What is CylancePROTECT used for?](https://www.g2.com/discussions/what-is-cylanceprotect-used-for) - 1 comment
- [What is CylanceOPTICS used for?](https://www.g2.com/discussions/what-is-cylanceoptics-used-for) - 1 comment
- [How much does arctic wolf cost?](https://www.g2.com/discussions/arctic-wolf-how-much-does-arctic-wolf-cost) - 1 comment
- [How much does arctic wolf cost?](https://www.g2.com/discussions/how-much-does-arctic-wolf-cost)
- [Is Arctic wolf a SIEM?](https://www.g2.com/discussions/is-arctic-wolf-a-siem) - 1 comment

### [Tenable Vulnerability Management](https://www.g2.com/products/tenable-vulnerability-management/reviews)

Tenable Vulnerability Management provides a risk-based approach to identifying, prioritizing, and remediating vulnerabilities across your entire attack surface. Powered by Nessus technology and AI-driven analytics, it goes beyond CVSS scores to assess exploitability, asset criticality, and business impact—so you can focus on what matters most. With continuous visibility, automated scanning, and real-time risk insights, security teams can quickly expose and close critical vulnerabilities before they’re exploited. Advanced asset identification ensures accurate tracking in dynamic environments, while intuitive dashboards, comprehensive reporting, and seamless third-party integrations help streamline workflows. As a cloud-based solution, Tenable Vulnerability Management scales with your organization, empowering security teams to maximize efficiency, reduce risk, and improve resilience against evolving threats.

**Average Rating:** 4.5/5.0

**Total Reviews:** 114

#### How Do G2 Users Rate Tenable Vulnerability Management?

- **Has the product been a good partner in doing business?:** 8.6/10 (Category avg: 9.2/10)
- **Reporting:** 8.1/10 (Category avg: 8.8/10)
- **Vulnerability Intelligence:** 9.2/10 (Category avg: 8.7/10)
- **Risk-Prioritization:** 8.8/10 (Category avg: 8.8/10)

#### Who Is the Company Behind Tenable Vulnerability Management?

- **Seller:** [Tenable](https://www.g2.com/sellers/tenable)
- **Company Website:** www.tenable.com
- **HQ Location:** Columbia, MD
- **Twitter:** @TenableSecurity  
87,752 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=029266d223c06e6b09e6d209209f15aad3bbad59d05069b38d5ec2757e74adef&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F25452%2F&secure%5Burl_type%5D=linkedin_company_website)  
2,350 employees on LinkedIn®
- **Ownership:** NASDAQ: TENB

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Financial Services
- **Company Size:** 55% Large, 33% Medium

#### What Do G2 Reviewers Say About Tenable Vulnerability Management?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **user-friendly interface** of Tenable Vulnerability Management, making prioritization and action on vulnerabilities seamless.
- Users praise the **scanning efficiency** of Tenable Vulnerability Management, highlighting its speed and comprehensive capabilities.
- Users value the **powerful scanning and reporting features** of Tenable Vulnerability Management for enhanced asset management.
- Users appreciate the **fast and efficient automated scanning** of Tenable Vulnerability Management, enhancing resource management and reporting.
- Users value the **effective vulnerability identification** that helps prioritize remediation efforts efficiently within their environments.

##### Cons

- Users find the **cost of Tenable Vulnerability Management** to be prohibitive, especially for organizations with tight budgets.
- Users find the **reporting capabilities inadequate** , often needing external tools for refined and personalized analysis.
- Users find the **reporting capabilities to be limited** , often needing external tools for better data insights.
- Users find the **pricing issues** of Tenable Vulnerability Management to be a barrier, especially for smaller organizations.
- Users find the platform's **complexity** to manage licensing and reporting options challenging, especially under budget constraints.

#### What Are Recent G2 Reviews of Tenable Vulnerability Management?

**["TVM Does What You Need"](https://www.g2.com/survey_responses/tenable-vulnerability-management-review-12937561)**

**Rating:** 4.5/5.0 stars

_— Verified User in Higher Education_

[Read full review](https://www.g2.com/survey_responses/tenable-vulnerability-management-review-12937561)

**["Intuitive, Easy to Deploy, and Packed with Comprehensive Reporting"](https://www.g2.com/survey_responses/tenable-vulnerability-management-review-13067235)**

**Rating:** 4.5/5.0 stars

_— Grace Y._

[Read full review](https://www.g2.com/survey_responses/tenable-vulnerability-management-review-13067235)

#### What Are G2 Users Discussing About Tenable Vulnerability Management?

- [What is your primary use case for Tenable Vulnerability Management, and how has it impacted your security posture?](https://www.g2.com/discussions/what-is-your-primary-use-case-for-tenable-vulnerability-management-and-how-has-it-impacted-your-security-posture) - 1 comment
- [What is Tenable.io used for?](https://www.g2.com/discussions/what-is-tenable-io-used-for) - 1 comment
- [How much is tenable io?](https://www.g2.com/discussions/how-much-is-tenable-io)
- [How do I link Nessus to tenable io?](https://www.g2.com/discussions/how-do-i-link-nessus-to-tenable-io)
- [What is the difference between Nessus and tenable io?](https://www.g2.com/discussions/what-is-the-difference-between-nessus-and-tenable-io)

### [Recorded Future](https://www.g2.com/products/recorded-future/reviews)

Recorded Future is the world’s largest threat intelligence company. Recorded Future’s Intelligence Cloud provides end-to-end intelligence across adversaries, infrastructure, and targets. Indexing the internet across the open web, dark web, and technical sources, Recorded Future provides real-time visibility into an expanding attack surface and threat landscape, empowering clients to act with speed and confidence to reduce risk and securely drive business forward. Headquartered in Boston with offices and employees around the world, Recorded Future works with over 1,900 businesses and government organizations across 80 countries to provide real-time, unbiased and actionable intelligence. Learn more at recordedfuture.com.

**Average Rating:** 4.6/5.0

**Total Reviews:** 225

#### How Do G2 Users Rate Recorded Future?

- **Has the product been a good partner in doing business?:** 9.1/10 (Category avg: 9.2/10)
- **Reporting:** 8.4/10 (Category avg: 8.8/10)
- **Vulnerability Intelligence:** 8.9/10 (Category avg: 8.7/10)
- **Risk-Prioritization:** 8.8/10 (Category avg: 8.8/10)

#### Who Is the Company Behind Recorded Future?

- **Seller:** [Recorded Future](https://www.g2.com/sellers/recorded-future)
- **Company Website:** www.recordedfuture.com
- **Year Founded:** 2009
- **HQ Location:** Somerville, US
- **Twitter:** @RecordedFuture  
107,965 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=5ee71819ceccdda0cfcf9823a42cc2607450baca1c57a72aaa518d8c2171046c&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F678036%2F&secure%5Burl_type%5D=linkedin_company_website)  
1,150 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Threat Intelligence Analyst, Cyber Threat Intelligence Analyst
- **Top Industries:** Financial Services, Information Technology and Services
- **Company Size:** 66% Large, 20% Medium

#### What Do G2 Reviewers Say About Recorded Future?

_AI-generated summary from verified user reviews_

##### Pros

- Users find Recorded Future's **ease of use** exceptional, appreciating its intuitive interface and centralized features for daily tasks.
- Users value the **enhanced customization features** of Recorded Future, allowing for detailed insights and tailored alerts.
- Users value the **comprehensive insights** provided by Recorded Future, enhancing their understanding of data relationships and intel.
- Users highlight the **excellent threat detection** capabilities of Recorded Future, praising its ease of use and robust support.
- Users benefit from the **precise and actionable threat intelligence** provided by Recorded Future, enhancing security management.

##### Cons

- Users find the **complex navigation** of Recorded Future challenging, making it hard to create accurate queries.
- Users find Recorded Future to be **expensive** , making budgeting tricky for smaller teams despite its critical role in security.
- Users find the **learning curve steep** , requiring significant time investment and commitment to fully understand the platform.
- Users find the **difficult learning curve** of Recorded Future challenging, requiring significant time and expertise for effective use.
- Users experience significant **inaccuracy issues** with Recorded Future, affecting the reliability of alerts and predictions.

#### What Are Recent G2 Reviews of Recorded Future?

**["Recorded Future Delivers Actionable Threat Intelligence and Proactive Alerts"](https://www.g2.com/survey_responses/recorded-future-review-12940427)**

**Rating:** 4.5/5.0 stars

_— Luciana S._

[Read full review](https://www.g2.com/survey_responses/recorded-future-review-12940427)

**["Real-Time, Actionable Threat Intelligence with Seamless Security Tool Compatibility"](https://www.g2.com/survey_responses/recorded-future-review-12733983)**

**Rating:** 4.5/5.0 stars

_— Nijat I._

[Read full review](https://www.g2.com/survey_responses/recorded-future-review-12733983)

#### What Are G2 Users Discussing About Recorded Future?

- [Is Recorded Future a good company?](https://www.g2.com/discussions/is-recorded-future-a-good-company)
- [Is Recorded Future a tip?](https://www.g2.com/discussions/is-recorded-future-a-tip) - 1 comment
- [What is Recorded Future tool?](https://www.g2.com/discussions/what-is-recorded-future-tool) - 1 comment
- [What do Recorded Future do?](https://www.g2.com/discussions/what-do-recorded-future-do) - 1 comment

### [RiskProfiler - External Threat Exposure Management](https://www.g2.com/products/riskprofiler-external-threat-exposure-management/reviews)

RiskProfiler is an advanced cybersecurity platform purpose-built for Continuous Threat Exposure Management (CTEM). It unifies external, cloud, vendor, and brand risk intelligence into a single ecosystem—providing organizations with real-time visibility, contextual threat insights, and actionable remediation guidance. Through its integrated suite, External Attack Surface Managemnet, Third\_party Risk Management, Cloud Attack Surface Management, and Brand Risk Protection; the platform continuously discovers, classifies, and evaluates external-facing assets and risks across the internet, multi-cloud environments, and third-party ecosystems. Powered by AI-enabled risk questionnaires, RiskProfiler automates the exchange, validation, and scoring of security assessments, dramatically accelerating third-party due diligence and compliance validation. The platform’s context-enriched graph engine correlates vulnerabilities, exposures, and configurations with real-world threat data, revealing how attackers might exploit an organization’s digital footprint. Its newly enhanced Cyber Threat Intelligence (CTI) module provides live insights into industry-specific attack trends, threat actor profiles, and evolving TTPs, directly embedded within the dashboard. By analyzing CVEs, IOCs, and exploit patterns, it maps these to relevant assets and potential attack paths, enabling focused, prioritized mitigation. From identifying exposed cloud resources across AWS, Azure, and Google Cloud to uncovering brand impersonation, phishing campaigns, or logo abuse, RiskProfiler delivers unified visibility and continuous monitoring that extends beyond the perimeter. It helps organizations anticipate, contextualize, and neutralize threats before they turn into breaches, transforming exposure management into a truly intelligent, predictive defense capability.

**Average Rating:** 4.9/5.0

**Total Reviews:** 118

#### How Do G2 Users Rate RiskProfiler - External Threat Exposure Management?

- **Has the product been a good partner in doing business?:** 9.9/10 (Category avg: 9.2/10)
- **Reporting:** 9.9/10 (Category avg: 8.8/10)
- **Vulnerability Intelligence:** 9.9/10 (Category avg: 8.7/10)
- **Risk-Prioritization:** 9.9/10 (Category avg: 8.8/10)

#### Who Is the Company Behind RiskProfiler - External Threat Exposure Management?

- **Seller:** [Riskprofiler](https://www.g2.com/sellers/riskprofiler)
- **Company Website:** riskprofiler.io
- **Year Founded:** 2019
- **HQ Location:** Rock Hill , US
- **Twitter:** @riskprofilerio  
209 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=b24e229941d4d86cfe1c465f2ca6c72933d43e43c05341e557ac04e379d138f3&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Friskprofiler&secure%5Burl_type%5D=linkedin_company_website)  
32 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Software Engineer, Security Consultant
- **Top Industries:** Information Technology and Services, Design
- **Company Size:** 66% Medium, 33% Small

#### What Do G2 Reviewers Say About RiskProfiler - External Threat Exposure Management?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **effective risk management** capabilities of RiskProfiler, facilitating informed decisions and quick responses to threats.
- Users appreciate the **seamless onboarding and integration** of RiskProfiler, enhancing visibility and monitoring of external threats.
- Users commend the **fast and efficient customer support** of RiskProfiler, enhancing their overall experience and response time.
- Users value the **ease of use** of RiskProfiler, particularly the seamless integration and user-friendly dashboard.
- Users value the **easy setup** of RiskProfiler, appreciating its intuitive dashboard and quick implementation process.

##### Cons

- Users face a **steep learning curve** with RiskProfiler, requiring time for training and customization to navigate effectively.
- Users find the **complexity** of RiskProfiler overwhelming, necessitating significant time for training and adjustment.
- Users find a **difficult learning curve** for RiskProfiler, requiring significant training and time to navigate effectively.
- Users find the **learning difficulty** of RiskProfiler challenging, necessitating extra training and time for effective use.
- Users find the **complex setup** of RiskProfiler challenging, particularly for non-specialist teams trying to integrate it.

#### What Are Recent G2 Reviews of RiskProfiler - External Threat Exposure Management?

**["Contextual Intelligence That Connects Risk Across the Attack Surface"](https://www.g2.com/survey_responses/riskprofiler-external-threat-exposure-management-review-12719957)**

**Rating:** 5.0/5.0 stars

_— Verified User in Information Technology and Services_

[Read full review](https://www.g2.com/survey_responses/riskprofiler-external-threat-exposure-management-review-12719957)

**["Single Pane of Truth for External Exposure Correlation and Fast Risk Prioritization"](https://www.g2.com/survey_responses/riskprofiler-external-threat-exposure-management-review-12394581)**

**Rating:** 5.0/5.0 stars

_— Verified User in Information Technology and Services_

[Read full review](https://www.g2.com/survey_responses/riskprofiler-external-threat-exposure-management-review-12394581)

### [YesWeHack](https://www.g2.com/products/yeswehack/reviews)

YesWeHack is a leading Offensive Security and Exposure Management platform delivering integrated, API-based solutions to secure organisations’ growing attack surfaces. Its human-in-the-loop model combines Bug Bounty (leveraging a global community of 150,000+ skilled ethical hackers), Autonomous Pentesting, Continuous Pentesting and unified vulnerability management to deliver agile, exhaustive security testing at scale. Customers include Louis Vuitton, Ferrero, the European Commission, Tencent and L’Oréal Groupe. ISO 27001-certified, CREST-accredited, and EU-hosted with full GDPR compliance. YesWeHack #1 Bug Bounty Platform in Europe and APAC

**Average Rating:** 4.8/5.0

**Total Reviews:** 33

#### How Do G2 Users Rate YesWeHack?

- **Has the product been a good partner in doing business?:** 9.9/10 (Category avg: 9.2/10)
- **Reporting:** 9.2/10 (Category avg: 8.8/10)
- **Vulnerability Intelligence:** 8.3/10 (Category avg: 8.7/10)
- **Risk-Prioritization:** 9.0/10 (Category avg: 8.8/10)

#### Who Is the Company Behind YesWeHack?

- **Seller:** [YesWeHack](https://www.g2.com/sellers/yeswehack)
- **Company Website:** www.yeswehack.com
- **Year Founded:** 2015
- **HQ Location:** Paris, France
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=679e5aae70401319c15e7eec013d56bc6fb716e49254994453f4e7ef2e693e49&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fyes-we-hack%2F&secure%5Burl_type%5D=linkedin_company_website)  
728 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Computer & Network Security
- **Company Size:** 42% Large, 36% Small

#### What Do G2 Reviewers Say About YesWeHack?

_AI-generated summary from verified user reviews_

##### Pros

- Users find YesWeHack to have an **intuitive platform** , ensuring smooth management and communication for vulnerability management.
- Users value the **exceptional customer support** from YesWeHack, enhancing their bug bounty experience and partnership effectiveness.
- Users admire the **exceptional customer support** and intuitive user experience of YesWeHack's platform, enhancing engagement and efficiency.
- Users admire the **high quality of bug reports** from YesWeHack, appreciating the clarity and thoroughness provided by the triagers.
- Users value the **exceptional quality and support** provided by YesWeHack's team, enhancing their bug bounty experience.

##### Cons

- Users feel that YesWeHack is somewhat **expensive** , particularly for smaller organizations looking for accessible solutions.
- Users find the **poor interface design** of YesWeHack could be improved for a better user experience.
- Users find the **limited scope** of YesWeHack unsuitable for handling a large number of programs efficiently.
- Users note the **missing tracking features** in YesWeHack's interface, impacting its overall effectiveness despite responsive support.
- Users find the **pricing issues** of YesWeHack to be steep, limiting accessibility for smaller organizations.

#### What Are Recent G2 Reviews of YesWeHack?

**["Reliable BugBounty platform!"](https://www.g2.com/survey_responses/yeswehack-review-13153139)**

**Rating:** 5.0/5.0 stars

_— Julien M._

[Read full review](https://www.g2.com/survey_responses/yeswehack-review-13153139)

**["The experience was satisfactory"](https://www.g2.com/survey_responses/yeswehack-review-7640568)**

**Rating:** 4.0/5.0 stars

_— Teboho P._

[Read full review](https://www.g2.com/survey_responses/yeswehack-review-7640568)

### [H1 Platform](https://www.g2.com/products/h1-platform/reviews)

HackerOne is a global leader in Continuous Threat Exposure Management (CTEM) and the only solution provider that pairs the simultaneous trust of the Fortune 500 and the world's largest community of security researchers to secure the AI-native enterprise. The H1 Platform unites agentic AI solutions with security researchers ingenuity to continuously discover, validate, prioritize, and remediate exposures across code, cloud, and AI systems. Through solutions like bug bounty, vulnerability disclosure, agentic pentesting, AI red teaming, and code security, HackerOne delivers measurable, continuous reduction of cyber risk for enterprises. Industry leaders, including Anthropic, Crypto.com, General Motors, Goldman Sachs, Lufthansa, Uber, UK Ministry of Defence, and the U.S. Department of Defense, trust HackerOne to safeguard their digital ecosystems. HackerOne was recognized in Gartner’s Emerging Tech Impact Radar: AI Cybersecurity Ecosystem report for its leadership in AI Security Testing.

**Average Rating:** 4.5/5.0

**Total Reviews:** 73

#### How Do G2 Users Rate H1 Platform?

- **Has the product been a good partner in doing business?:** 8.9/10 (Category avg: 9.2/10)
- **Reporting:** 10.0/10 (Category avg: 8.8/10)
- **Risk-Prioritization:** 10.0/10 (Category avg: 8.8/10)

#### Who Is the Company Behind H1 Platform?

- **Seller:** [HackerOne](https://www.g2.com/sellers/hackerone)
- **Company Website:** hackerone.com
- **Year Founded:** 2012
- **HQ Location:** San Francisco, California
- **Twitter:** @Hacker0x01  
337,493 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=66564701ea46682e07fb494dc3da56457fbf656178a90fc0665fd15f314bdc5d&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fhackerone%2F&secure%5Burl_type%5D=linkedin_company_website)  
6,738 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Computer & Network Security
- **Company Size:** 42% Large, 41% Medium

#### What Do G2 Reviewers Say About H1 Platform?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **ease of use** of HackerOne, enabling quick onboarding and seamless program management.
- Users value the **streamlined interface** of H1 Platform, facilitating efficient bug management and collaboration with ethical hackers.
- Users value the **collaboration with skilled ethical hackers** , enhancing security and improving vulnerability management effectively.
- Users value the **strong security protection** offered by HackerOne, enhancing overall safety through expert vulnerability management.
- Users value the **responsive customer support** of H1 Platform, consistently providing guidance and assistance when needed.

##### Cons

- Users experience **complexity issues** with triage workflows and credentials management, affecting overall efficiency and satisfaction.
- Users note the **expensive pricing** of the H1 Platform, which can strain budgets despite its valuable features.
- Users find **time management challenging** on H1 Platform due to inconsistent triage speeds and complexities in report handling.
- Users report **poor customer support** with slow response times and unresolved tickets affecting their overall experience.
- Users find the **poor interface design** confusing and difficult to navigate, impacting their overall experience.

#### What Are Recent G2 Reviews of H1 Platform?

**["Straightforward, Practical Vulnerability Management with Clear Visibility"](https://www.g2.com/survey_responses/h1-platform-review-12788653)**

**Rating:** 5.0/5.0 stars

_— Verified User in Automotive_

[Read full review](https://www.g2.com/survey_responses/h1-platform-review-12788653)

**["Powerful Bug Bounty Platform with Room for Improvements"](https://www.g2.com/survey_responses/h1-platform-review-12784912)**

**Rating:** 4.5/5.0 stars

_— Mikhail Y._

[Read full review](https://www.g2.com/survey_responses/h1-platform-review-12784912)

#### What Are G2 Users Discussing About H1 Platform?

- [How many hackers are there in HackerOne?](https://www.g2.com/discussions/how-many-hackers-are-there-in-hackerone) - 2 comments, 1 upvote
- [What is managed program in HackerOne?](https://www.g2.com/discussions/what-is-managed-program-in-hackerone)
- [How many programs are managed by HackerOne?](https://www.g2.com/discussions/how-many-programs-are-managed-by-hackerone)
- [What is the use of HackerOne?](https://www.g2.com/discussions/what-is-the-use-of-hackerone)

### [Pentera](https://www.g2.com/products/pentera/reviews)

Pentera is the category leader for Automated Security Validation, allowing every organization to test with ease the integrity of all cybersecurity layers, unfolding true, current security exposures at any moment, at any scale. Thousands of security professionals and service providers around the world use Pentera to guide remediation and close security gaps before they are exploited. Its customers include Casey's General Stores, Emeria, LuLu International Exchange, IP Telecom PT, BrewDog, City National Bank, Schmitz Cargobull, and MBC Group. Pentera is backed by leading investors such as K1 Investment Management, Insight Partners, Blackstone, Evolution Equity Partners, and AWZ. Visit https://pentera.io for more information.

**Average Rating:** 4.5/5.0

**Total Reviews:** 171

#### How Do G2 Users Rate Pentera?

- **Has the product been a good partner in doing business?:** 9.3/10 (Category avg: 9.2/10)
- **Reporting:** 7.8/10 (Category avg: 8.8/10)
- **Vulnerability Intelligence:** 8.3/10 (Category avg: 8.7/10)
- **Risk-Prioritization:** 8.3/10 (Category avg: 8.8/10)

#### Who Is the Company Behind Pentera?

- **Seller:** [Pentera](https://www.g2.com/sellers/pentera)
- **Company Website:** pentera.io
- **Year Founded:** 2015
- **HQ Location:** Boston, MA
- **Twitter:** @penterasec  
3,291 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=9f2c0c558c875a98d2d9fc35b9d10d7247ea125fd4eaf33d374195bfe744ebba&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fpenterasecurity%2F&secure%5Burl_type%5D=linkedin_company_website)  
483 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Banking, Government Administration
- **Company Size:** 52% Large, 36% Medium

#### What Do G2 Reviewers Say About Pentera?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **automation features** of Pentera, enhancing ease of use and enabling efficient continuous operation.
- Users recognize the **powerful automation and detailed remediation suggestions** of Pentera for effective vulnerability detection.
- Users value Pentera's **effective vulnerability scanning and remediation suggestions** , enhancing their overall security posture and testing efficacy.
- Users value the **responsive customer support** of Pentera, enhancing their overall vulnerability scanning experience.
- Users appreciate the **efficiency** of Pentera, notably for its quick implementation and time-saving automation.

##### Cons

- Users find the **reporting inadequate** , particularly for enterprise-level assessments, necessitating significant improvements.
- Users experience a **lack of essential features** , including limited TTP updates and inadequate user permissions management.
- Users find the **reporting in Pentera lacking** , especially for enterprise-level needs and multilingual support.
- Users find Pentera demands a **high amount of system resources** , which can hinder overall performance and efficiency.
- Users report **technical issues** , particularly with module compatibility and unexpected upgrade failures, though support is responsive.

#### What Are Recent G2 Reviews of Pentera?

**["Cutting-Edge Security with a Real Attacker Approach"](https://www.g2.com/survey_responses/pentera-review-12864952)**

**Rating:** 4.5/5.0 stars

_— Yaron C._

[Read full review](https://www.g2.com/survey_responses/pentera-review-12864952)

**["Reliable Tool for Vulnerability Detection but Script Issues"](https://www.g2.com/survey_responses/pentera-review-12864934)**

**Rating:** 4.0/5.0 stars

_— Avitzur Y._

[Read full review](https://www.g2.com/survey_responses/pentera-review-12864934)

### [Check Point Exposure Management](https://www.g2.com/products/check-point-exposure-management/reviews)

Exposure Management is changing how organizations react to cyber risk. Attackers exploit exposed assets, leaked credentials, and misconfigurations within hours, while security teams are left sorting through dashboards, alerts, and disconnected tools. For a limited time only, we are providing an Agentic Exposure Validation Scan at no cost. It delivers proven, evidence-backed findings your team can act on immediately. Request scan here - https://checkpoint.cyberint.com/limited-time-offer-aev-scan Check Point Exposure Management closes that gap by combining billions of external intelligence signals into a Unified Intelligence Fabric. The platform continuously identifies, validates, prioritizes, and safely remediates the exposures attackers are most likely to exploit. With Cyber Asset Attack Surface Management (CAASM), security teams gain a real-time inventory across cloud, SaaS, on-premises infrastructure, endpoints, and identities through 150+ agentless integrations. Unlike traditional vulnerability management, Check Point prioritizes exposures based on real-world exploitability, active threat intelligence, business context, and existing security controls, eliminating duplicate alerts and reducing remediation noise. It does so while maintaining business continuity. Safe-by-design remediation then validates every action before enforcement, enabling capabilities such as virtual patching, IPS activation, configuration hardening, and policy enforcement without disrupting business operations. Organizations using the platform achieve a 93% true positive rate, 12-hour average takedown MTTR, and 504 safe remediations per organization every month. Built around Gartner's Continuous Threat Exposure Management (CTEM) framework, Check Point helps organizations move from visibility to measurable risk reduction. Gartner predicts organizations adopting CTEM with mobilization will experience 50% fewer successful cyberattacks by 2028. Ready to see Exposure Management in action? Get a 15-minute demo: https://l.cyberint.com/exposure-management-demo

**Average Rating:** 4.6/5.0

**Total Reviews:** 169

#### How Do G2 Users Rate Check Point Exposure Management?

- **Has the product been a good partner in doing business?:** 9.4/10 (Category avg: 9.2/10)
- **Reporting:** 9.0/10 (Category avg: 8.8/10)
- **Vulnerability Intelligence:** 9.3/10 (Category avg: 8.7/10)
- **Risk-Prioritization:** 9.0/10 (Category avg: 8.8/10)

#### Who Is the Company Behind Check Point Exposure Management?

- **Seller:** [Check Point Software Technologies](https://www.g2.com/sellers/check-point-software-technologies)
- **Company Website:** www.checkpoint.com
- **Year Founded:** 1993
- **HQ Location:** Redwood City, CA
- **Twitter:** @CheckPointSW  
70,955 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=d885813f6605ba84238ae4a21d169e0c9ade054cf0c99ff53e72483b54a8b521&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fcheck-point-software-technologies%2F&secure%5Burl_type%5D=linkedin_company_website)  
8,554 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Security Threat Analyst, Cyber Security Analyst
- **Top Industries:** Banking, Financial Services
- **Company Size:** 69% Large, 19% Medium

#### What Do G2 Reviewers Say About Check Point Exposure Management?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **ease of use** of Cyberint, enjoying its intuitive interface and seamless integration into workflows.
- Users value the **comprehensive threat intelligence** of Check Point Exposure Management, enhancing proactive threat detection and response capabilities.
- Users find **Cyberint's threat detection** valuable for enhancing situational awareness and proactive threat response in sensitive environments.
- Users commend the **comprehensive threat intelligence** of Check Point Exposure Management, enhancing detection and response to potential cyber threats.
- Users commend the **responsive and proactive support** from Cyberint, enhancing their ability to manage complex threats effectively.

##### Cons

- Users experience **inefficient alerts** due to occasional false positives, requiring extra time for verification and impacting productivity.
- Users experience **false positives** in alerts, necessitating extra analyst time for validation and slowing response efforts.
- Users experience **inefficient alert systems** , finding the volume of alerts overwhelming and slow threat intel response frustrating.
- Users often face **integration issues** , particularly with centralizing alerts and security tool compatibility.
- Users note the **limited features** of Check Point Exposure Management, particularly regarding alert tuning and third-party integrations.

#### What Are Recent G2 Reviews of Check Point Exposure Management?

**["Streamlined Threat Intelligence Acquisition"](https://www.g2.com/survey_responses/check-point-exposure-management-review-9805489)**

**Rating:** 5.0/5.0 stars

_— Asaf A._

[Read full review](https://www.g2.com/survey_responses/check-point-exposure-management-review-9805489)

**["Cuts Vulnerability Noise with Context and Strong External Surface Visibility"](https://www.g2.com/survey_responses/check-point-exposure-management-review-12515925)**

**Rating:** 4.5/5.0 stars

_— Verified User in Utilities_

[Read full review](https://www.g2.com/survey_responses/check-point-exposure-management-review-12515925)

#### What Are G2 Users Discussing About Check Point Exposure Management?

- [What is Argos™ Threat Intelligence Platform used for?](https://www.g2.com/discussions/what-is-argos-threat-intelligence-platform-used-for) - 1 comment

### [Cortex Cloud](https://www.g2.com/products/cortex-cloud/reviews)

Cortex Cloud by Palo Alto Networks, the next version of Prisma Cloud, understands a unified security approach is essential for effectively addressing AppSec, CloudSec, and SecOps. Connecting cloud security and SOC workflows enables teams to achieve holistic visibility, trace risk across the lifecycle, and correlate real-time threat activity with development and runtime contexts. Cortex Cloud is a unified platform built on three core pillars: data integration, AI-driven intelligence, and automation. Now you can safeguard applications, data, and infrastructure across multicloud and hybrid environments with a unified data model that consolidates telemetry from code, runtime, identity, and endpoints, all into a single data source. Empower teams with precise, AI-powered insights and 2200+ machine learning models to identify and stop zero-day threats with real-time advanced threat detection and response. And automate with 1000+ prebuilt playbooks across your cloud stack to reduce manual workloads, accelerate remediations, and cut response times tenfold. Cortex Cloud delivers more than tools—it transforms how organizations secure their cloud environments.

**Average Rating:** 4.1/5.0

**Total Reviews:** 124

#### How Do G2 Users Rate Cortex Cloud?

- **Has the product been a good partner in doing business?:** 8.0/10 (Category avg: 9.2/10)
- **Reporting:** 7.8/10 (Category avg: 8.8/10)
- **Vulnerability Intelligence:** 7.5/10 (Category avg: 8.7/10)
- **Risk-Prioritization:** 8.1/10 (Category avg: 8.8/10)

#### Who Is the Company Behind Cortex Cloud?

- **Seller:** [Palo Alto Networks](https://www.g2.com/sellers/palo-alto-networks)
- **Company Website:** www.paloaltonetworks.com
- **Year Founded:** 2005
- **HQ Location:** Santa Clara, CA
- **Twitter:** @PaloAltoNtwks  
128,951 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=283fa006a7b7db5565e608e4d1bc1dafae45bdf4b312f2cd5bb208ac9271f81d&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F30086%2F&secure%5Burl_type%5D=linkedin_company_website)  
22,313 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Computer & Network Security
- **Company Size:** 38% Large, 31% Medium

#### What Do G2 Reviewers Say About Cortex Cloud?

_AI-generated summary from verified user reviews_

##### Pros

- Users find Cortex Cloud to be **extremely easy to use** , appreciating its intuitive interface and seamless integration.
- Users value **strong cloud security** and appreciate the intuitive interface and effective compliance support of Cortex Cloud.
- Users value the **ease of managing cloud security** with Cortex Cloud, enhancing focus on critical threats efficiently.
- Users value the **clear visibility** provided by Cortex Cloud, enhancing their management of cloud security and team coordination.
- Users value the **ease of integration** with operations, enhancing the management of cloud security efficiently.

##### Cons

- Users find the **high cost** of Cortex Cloud to be a significant drawback, impacting budget for mid-sized organizations.
- Users find the **difficult learning** curve challenging, especially with complex features and insufficient documentation for beginners.
- Users find the **learning curve steep** due to time-intensive onboarding and a cluttered user interface.
- Users express concerns about **pricing issues** with Cortex Cloud, as costs can rise significantly in larger setups.
- Users find the **complex setup** of Cortex Cloud to be time-consuming and challenging to navigate effectively.

#### What Are Recent G2 Reviews of Cortex Cloud?

**["Cortex Cloud earned it's place before every release."](https://www.g2.com/survey_responses/cortex-cloud-review-13089470)**

**Rating:** 5.0/5.0 stars

_— Johanna K._

[Read full review](https://www.g2.com/survey_responses/cortex-cloud-review-13089470)

**["Cortex Cloud Unifies Cloud Security with Real-Time Protection and Smart Prioritization"](https://www.g2.com/survey_responses/cortex-cloud-review-12997786)**

**Rating:** 4.0/5.0 stars

_— Galateya M._

[Read full review](https://www.g2.com/survey_responses/cortex-cloud-review-12997786)

### [ServiceNow Security Operations](https://www.g2.com/products/servicenow-security-operations/reviews)

ServiceNow Security Operations is a sophisticated software solution designed to enhance threat and vulnerability management as well as incident response for organizations. By leveraging artificial intelligence, this platform empowers security teams to operate more efficiently and effectively, allowing for streamlined collaboration across IT, security, and risk management departments. The primary goal of ServiceNow Security Operations is to simplify complex security processes while minimizing risks associated with cybersecurity threats. Targeted at security teams within organizations of various sizes, ServiceNow Security Operations addresses the need for a cohesive approach to managing security incidents and vulnerabilities. It is particularly beneficial for organizations that utilize multiple security tools, as it integrates security and vulnerability data from these existing systems. This integration enables teams to respond to threats more rapidly by automating critical workflows and processes, thus reducing the manual effort traditionally required in incident response. Key features of ServiceNow Security Operations include intelligent workflows that automate routine tasks, allowing security professionals to focus on more strategic initiatives. The platform’s AI-driven capabilities facilitate the automatic correlation of threat intelligence from diverse sources, such as the MITRE ATT&CK framework. This feature enhances situational awareness and enables teams to prioritize threats effectively based on real-time data. Additionally, the ability to take action within other security or IT management tools from a centralized console streamlines operations, ensuring that teams can respond to incidents without unnecessary delays. Moreover, the use of digital security workflows and orchestration significantly accelerates tasks such as analysis, prioritization, and remediation. By automating these processes, organizations can not only improve their response times but also enhance their overall cybersecurity posture. The integration of AI-driven automation within the ServiceNow AI Platform® further strengthens the platform's capabilities, enabling organizations to drive cyber resilience and reduce their exposure to potential threats. In summary, ServiceNow Security Operations is a comprehensive solution that addresses the complexities of modern cybersecurity challenges. By automating and simplifying threat and vulnerability management, it empowers security teams to respond more effectively, thereby enhancing the overall security framework of an organization.

**Average Rating:** 4.4/5.0

**Total Reviews:** 74

#### How Do G2 Users Rate ServiceNow Security Operations?

- **Has the product been a good partner in doing business?:** 8.8/10 (Category avg: 9.2/10)
- **Reporting:** 8.9/10 (Category avg: 8.8/10)
- **Vulnerability Intelligence:** 9.5/10 (Category avg: 8.7/10)
- **Risk-Prioritization:** 9.5/10 (Category avg: 8.8/10)

#### Who Is the Company Behind ServiceNow Security Operations?

- **Seller:** [ServiceNow](https://www.g2.com/sellers/servicenow)
- **Company Website:** www.servicenow.com
- **Year Founded:** 2004
- **HQ Location:** Santa Clara, CA
- **Twitter:** @servicenow  
55,548 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=8f146dd2da6255ae21db2f89043b268912043fe250660dfee40ba3c0574bb1ba&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F29352%2F&secure%5Burl_type%5D=linkedin_company_website)  
35,081 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Computer & Network Security
- **Company Size:** 52% Large, 19% Medium

#### What Do G2 Reviewers Say About ServiceNow Security Operations?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **integration capabilities** of ServiceNow Security Operations, enabling seamless connections with essential third-party tools.
- Users value the **remarkable integration capabilities** of ServiceNow Security Operations, enhancing incident management and data processing efficiency.
- Users appreciate the **ease of use** of ServiceNow Security Operations, enhancing productivity with seamless integration and setup.
- Users value the **robust integration capabilities** of ServiceNow Security Operations, enhancing workflow and incident management efficiency.
- Users appreciate the **end-to-end incident management** capabilities in ServiceNow, making it a comprehensive security solution.

##### Cons

- Users find the **difficult setup** of ServiceNow Security Operations a barrier, impacting overall usability and cost-effectiveness.
- Users face **integration issues** , struggling with field mapping, initial setup, and documentation, affecting overall usability.
- Users find the **restrictive licensing issues** limiting for playbooks, impacting remediation efficiency and security operations.
- Users face **complexity in building playbooks** within ServiceNow Security Operations, finding the process challenging and costly.
- Users find **difficult customization** in ServiceNow Security Operations hinders their ability to effectively build playbooks.

#### What Are Recent G2 Reviews of ServiceNow Security Operations?

**["Centralized Incident Management with Intuitive Dashboard"](https://www.g2.com/survey_responses/servicenow-security-operations-review-13161740)**

**Rating:** 4.0/5.0 stars

_— vignesh m._

[Read full review](https://www.g2.com/survey_responses/servicenow-security-operations-review-13161740)

**["All Security Tools in One Place with Fast, Automated Playbooks"](https://www.g2.com/survey_responses/servicenow-security-operations-review-13168876)**

**Rating:** 4.0/5.0 stars

_— Adam R._

[Read full review](https://www.g2.com/survey_responses/servicenow-security-operations-review-13168876)

#### What Are G2 Users Discussing About ServiceNow Security Operations?

- [What is ServiceNow sir?](https://www.g2.com/discussions/what-is-servicenow-sir)
- [What is service now in cyber security?](https://www.g2.com/discussions/what-is-service-now-in-cyber-security)
- [What are the typical functions of the Security Operations Center SOC analysts?](https://www.g2.com/discussions/what-are-the-typical-functions-of-the-security-operations-center-soc-analysts)
- [What can ServiceNow security operations do?](https://www.g2.com/discussions/what-can-servicenow-security-operations-do)

### [vRx by Vicarius](https://www.g2.com/products/vrx-by-vicarius/reviews)

vRx by Vicarius goes beyond patch management to offer the most advanced vulnerability remediation solution in the market. vRx offers 3 built-in methods to keep you covered at all times: 1) Automated Patching: vRx catalogs all your apps and finds the patches they need, and applies them - automatically and on the schedule or frequency of your choosing. 2) Scripting: For more complex vulnerabilities or configuration based vulnerabilities, vRx includes a fully fledged scripting engine. 3) Patchless Protection: x\_protect or patchless protection is a compensating control that reduces the risk of an affected app even when a patch is not yet developed or cannot be deployed vRx helps 500+ customers across 50 countries find AND immediately remediate vulns that impact their business.

**Average Rating:** 4.9/5.0

**Total Reviews:** 61

#### How Do G2 Users Rate vRx by Vicarius?

- **Has the product been a good partner in doing business?:** 9.6/10 (Category avg: 9.2/10)
- **Reporting:** 8.7/10 (Category avg: 8.8/10)
- **Vulnerability Intelligence:** 9.2/10 (Category avg: 8.7/10)
- **Risk-Prioritization:** 9.6/10 (Category avg: 8.8/10)

#### Who Is the Company Behind vRx by Vicarius?

- **Seller:** [Vicarius](https://www.g2.com/sellers/vicarius)
- **Company Website:** www.vicarius.io
- **Year Founded:** 2016
- **HQ Location:** New York, New York
- **Twitter:** @vicariusltd  
2,018 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=5a640080a4a45db76d4f955678631879797bbb1293db8870164c3d905a568307&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fvicarius%2F&secure%5Burl_type%5D=linkedin_company_website)  
109 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Computer & Network Security, Information Technology and Services
- **Company Size:** 44% Medium, 32% Small

#### What Do G2 Reviewers Say About vRx by Vicarius?

_AI-generated summary from verified user reviews_

##### Pros

- Users highlight the **ease of use** of vRx, appreciating its user-friendly interface and quick setup process.
- Users value the **automation capabilities** of vRx, enhancing efficiency in vulnerability management and patching processes.
- Users value the **intuitive interface** of vRx, which simplifies task management and enhances overall efficiency.
- Users appreciate the **comprehensive vulnerability management** of Vicarius vRx, simplifying processes and enhancing team efficiency immensely.
- Users highlight the **intuitive interface and exceptional support** of vRx, making patch management efficient and user-friendly.

##### Cons

- Users note the **missing features** like automatic asset addition and advanced reporting that limit vRx's capabilities.
- Users note **inadequate reporting** features, expressing a desire for more customization and compliance capabilities in vRx.
- Users find vRx's **complexity in deployment and integration** challenging, especially for those lacking technical expertise.
- Users often face **dashboard issues** , seeking more customization options for better adaptation to different audiences.
- Users face **inaccurate information** regarding reporting and risk scoring, leading to confusion about vulnerabilities management.

#### What Are Recent G2 Reviews of vRx by Vicarius?

**["Unify Vulnerabilities and Remediation in a single console with great granularity"](https://www.g2.com/survey_responses/vrx-by-vicarius-review-12264787)**

**Rating:** 5.0/5.0 stars

_— Fernando V._

[Read full review](https://www.g2.com/survey_responses/vrx-by-vicarius-review-12264787)

**["Efficient Security Management with Real-Time Insights"](https://www.g2.com/survey_responses/vrx-by-vicarius-review-12266234)**

**Rating:** 4.5/5.0 stars

_— Luis Ernesto V._

[Read full review](https://www.g2.com/survey_responses/vrx-by-vicarius-review-12266234)

#### What Are G2 Users Discussing About vRx by Vicarius?

- [What is Vicarius used for?](https://www.g2.com/discussions/what-is-vicarius-used-for) - 1 comment

### [Titania Nipper InfraSight](https://www.g2.com/products/titania-nipper-infrasight/reviews)

Award-winning Risk-Based Vulnerability Management. Nipper InfraSight analyzes network device configurations in the way Advances Persistent Threat (APT) groups do, to identify misconfigurations that could create attack paths. This analysis offers unparalleled, pen-tester accuracy, finding critical vulnerabilities in firewalls, routers, switches that other tools simply cannot see. Our solutions then prioritize the biggest risks to your business and provide device-specific remediation guidance, right down to specific command line prompts.  By analyzing device configurations against key compliance standards and security frameworks (including STIGs/CIS Benchmarks/PCI DSS/CMMC/CORA/NIST SP 800-53), Nipper solutions tell you precisely which devices are at risk of failing, how significant that risk is, and how you can solve it, with auditor-ready reports. Whether your focus is taking pragmatic, risk-based security measures to minimize known vulnerabilities or ensuring compliance with industry security standards, Nipper solutions provide the targeted insights you need. No other security provider looks at the network in the same way. That’s why Nipper can uniquely provide the network configuration coverage that organizations urgently require. 30+ U.S. federal agencies and 800+ organizations globally trust Nipper solutions to deliver vulnerability analysis and compliance automation while supporting air-gapped environments, sovereign cloud requirements, and complex regulated infrastructures.

**Average Rating:** 4.3/5.0

**Total Reviews:** 28

#### How Do G2 Users Rate Titania Nipper InfraSight?

- **Has the product been a good partner in doing business?:** 9.2/10 (Category avg: 9.2/10)
- **Reporting:** 9.1/10 (Category avg: 8.8/10)
- **Vulnerability Intelligence:** 6.0/10 (Category avg: 8.7/10)
- **Risk-Prioritization:** 8.6/10 (Category avg: 8.8/10)

#### Who Is the Company Behind Titania Nipper InfraSight?

- **Seller:** [Titania](https://www.g2.com/sellers/titania)
- **Company Website:** www.titania.com
- **Year Founded:** 2009
- **HQ Location:** London, GB
- **Twitter:** @TitaniaLtd  
2,821 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=092ac01f8e1b12cc1191c9739568f5ffa647760a0f4d324aec6eacb0f0e658fd&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Ftitania-ltd%2F&secure%5Burl_type%5D=linkedin_company_website)  
104 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 43% Large, 25% Medium

#### What Do G2 Reviewers Say About Titania Nipper InfraSight?

_AI-generated summary from verified user reviews_

##### Pros

- Users find the **ease of use** of Titania Nipper InfraSight remarkable, appreciating its straightforward and user-friendly design.
- Users appreciate the **reporting quality** of Titania Nipper InfraSight, as it provides clear assessments and actionable recommendations.
- Users value the **scanning efficiency** of Titania Nipper InfraSight, enabling quick detection of network misconfigurations.
- Users value the **effective vulnerability detection** in Titania Nipper, providing actionable insights and continuous improvement for network security.
- Users value the **clear and user-friendly interface** of Titania Nipper InfraSight, enhancing their assessment experience significantly.

##### Cons

- Users express concerns about the **licensing model** , noting it requires a minimum of 100 devices, complicating usage.
- Users encounter issues with **false positives** , leading to confusion and frustration when checking actual device findings.
- Users find the **lack of cloud support** frustrating, particularly with device-specific recommendations that are often inaccurate.
- Users face **limited compatibility** issues, resulting in the need for maintaining outdated versions and difficulties with integrations.
- Users note the **limited device support** of Titania Nipper InfraSight, which complicates maintenance and functionality.

#### What Are Recent G2 Reviews of Titania Nipper InfraSight?

**["Clean, Easy Reporting Time saving for audits"](https://www.g2.com/survey_responses/titania-nipper-infrasight-review-13136919)**

**Rating:** 5.0/5.0 stars

_— Verified User in Information Technology and Services_

[Read full review](https://www.g2.com/survey_responses/titania-nipper-infrasight-review-13136919)

**["Titania Nipper InfraSight Delivers Fast, Audit-Ready Insights and Clear Remediation"](https://www.g2.com/survey_responses/titania-nipper-infrasight-review-13135720)**

**Rating:** 5.0/5.0 stars

_— Shauna S._

[Read full review](https://www.g2.com/survey_responses/titania-nipper-infrasight-review-13135720)

#### What Are G2 Users Discussing About Titania Nipper InfraSight?

- [What is Nipper Titania?](https://www.g2.com/discussions/what-is-nipper-titania) - 1 comment

### [Qualys VMDR](https://www.g2.com/products/qualys-vmdr/reviews)

Qualys VMDR is an all-in-one risk-based vulnerability management solution that quantifies cyber risk. It gives organizations unprecedented insights into their risk posture and provides actionable steps to reduce risk. It also gives cybersecurity and IT teams a shared platform to collaborate, and the power to quickly align and automate no-code workflows to respond to threats with automated remediation and integrations with ITSM solutions such as ServiceNow.

**Average Rating:** 4.4/5.0

**Total Reviews:** 164

#### How Do G2 Users Rate Qualys VMDR?

- **Has the product been a good partner in doing business?:** 8.6/10 (Category avg: 9.2/10)
- **Reporting:** 8.3/10 (Category avg: 8.8/10)
- **Vulnerability Intelligence:** 8.7/10 (Category avg: 8.7/10)
- **Risk-Prioritization:** 8.5/10 (Category avg: 8.8/10)

#### Who Is the Company Behind Qualys VMDR?

- **Seller:** [Qualys](https://www.g2.com/sellers/qualys)
- **Year Founded:** 1999
- **HQ Location:** Foster City, CA
- **Twitter:** @qualys  
34,248 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=8a475a11170e5fc9a7fb2e49ea7fa51a39a6bed39344b64cb6253a55cb740892&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F8561%2F&secure%5Burl_type%5D=linkedin_company_website)  
3,627 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Security Engineer
- **Top Industries:** Information Technology and Services, Computer & Network Security
- **Company Size:** 51% Large, 28% Medium

#### What Do G2 Reviewers Say About Qualys VMDR?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **efficient vulnerability detection** of Qualys VMDR, which enhances security and ensures swift remediation.
- Users value the **swift vulnerability identification** capabilities of Qualys VMDR, enhancing their overall security posture effectively.
- Users value the **real-time alerting system** of Qualys VMDR, ensuring prompt notifications for critical vulnerabilities and swift responses.
- Users value the **automated vulnerability detection** of Qualys VMDR, appreciating its effortless cloud deployment and easy setup.
- Users value the **cloud integration** of Qualys VMDR, as it simplifies deployment without infrastructure requirements.

##### Cons

- Users find the **interface complex** , making it challenging for newcomers to navigate and use effectively.
- Users find the **complex reporting** of Qualys VMDR challenging, particularly for new users during initial use.
- Users find the **complex setup** challenging, especially for new users grappling with the initial interface.
- Users find the **difficult learning** curve of Qualys VMDR challenging, especially for newcomers to the platform.
- Users find the **interface overly complex** , making it challenging for new users to navigate successfully.

#### What Are Recent G2 Reviews of Qualys VMDR?

**["One Go Tool for small or medium level Organizations"](https://www.g2.com/survey_responses/qualys-vmdr-review-5466550)**

**Rating:** 4.0/5.0 stars

_— Verified User in Security and Investigations_

[Read full review](https://www.g2.com/survey_responses/qualys-vmdr-review-5466550)

**["Real-Time Asset Visibility and TruRisk Prioritization at Scale"](https://www.g2.com/survey_responses/qualys-vmdr-review-12484147)**

**Rating:** 5.0/5.0 stars

_— Verified User in Information Technology and Services_

[Read full review](https://www.g2.com/survey_responses/qualys-vmdr-review-12484147)

#### What Are G2 Users Discussing About Qualys VMDR?

- [What does Qualys Vmdr do?](https://www.g2.com/discussions/what-does-qualys-vmdr-do) - 1 comment
- [What vulnerabilities does Qualys scan for?](https://www.g2.com/discussions/qualys-vmdr-what-vulnerabilities-does-qualys-scan-for)
- [What does Qualys cloud agent do?](https://www.g2.com/discussions/what-does-qualys-cloud-agent-do)
- [How does Qualys patch management work?](https://www.g2.com/discussions/how-does-qualys-patch-management-work)
- [What is Qualys software?](https://www.g2.com/discussions/what-is-qualys-software)

### [Bitsight](https://www.g2.com/products/bitsight/reviews)

Bitsight is the global leader in cyber risk intelligence, leveraging advanced AI to empower organizations with precise insights derived from the industry’s most extensive external cybersecurity dataset. With more than 3,500 customers and over 68,000 organizations active on its platform, Bitsight delivers real-time visibility into cyber risk and threat exposure, enabling teams to rapidly identify vulnerabilities, detect emerging threats, prioritize remediation, and mitigate risks across their extended attack surface. Bitsight proactively uncovers security gaps across infrastructure, cloud environments, digital identities, and third- and fourth-party ecosystems. From security operations and governance teams to executive boardrooms, Bitsight provides the unified intelligence backbone required to confidently manage cyber risk and address exposures before they impact performance.

**Average Rating:** 4.5/5.0

**Total Reviews:** 76

#### How Do G2 Users Rate Bitsight?

- **Has the product been a good partner in doing business?:** 9.3/10 (Category avg: 9.2/10)
- **Reporting:** 7.4/10 (Category avg: 8.8/10)
- **Vulnerability Intelligence:** 7.4/10 (Category avg: 8.7/10)
- **Risk-Prioritization:** 7.9/10 (Category avg: 8.8/10)

#### Who Is the Company Behind Bitsight?

- **Seller:** [Bitsight](https://www.g2.com/sellers/bitsight)
- **Company Website:** www.bitsight.com
- **Year Founded:** 2011
- **HQ Location:** Boston, MA
- **Twitter:** @BitSight  
4,503 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=56e1c298f7c9929e49118678bddc5bbe3f8b17ba55b522d776985c6f3a6c58e8&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fbitsight%2F&secure%5Burl_type%5D=linkedin_company_website)  
741 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Hospital & Health Care
- **Company Size:** 71% Large, 24% Medium

#### What Do G2 Reviewers Say About Bitsight?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **comprehensive security posture** provided by Bitsight, enhancing protection for their organization and suppliers.
- Users value the **comprehensive security posture** provided by Bitsight, enhancing management of cyber risk and third-party suppliers.
- Users find Bitsight's **ease of use** remarkable, enjoying its intuitive interface and seamless integration with various platforms.
- Users appreciate the **detailed insights** and **collaboration features** of Bitsight, enhancing vendor risk management effectively.
- Users praise the **fantastic customer support** of Bitsight, highlighting their knowledge and eagerness to assist effectively.

##### Cons

- Users find **missing features** in Bitsight, such as lack of transparency and inadequate questionnaire management, frustrating overall.
- Users criticize the **lack of clarity** in BitSight's scoring mechanism and experience occasional inaccuracies in domain reporting.
- Users experience **poor customer support** and inadequate documentation, hindering effective use of the Bitsight platform.
- Users experience **poor notifications** with delayed alerts and irrelevant historical breaches, impacting timely critical monitoring.
- Users experience **slow loading** times and timeouts that hinder workflow and overall satisfaction with Bitsight.

#### What Are Recent G2 Reviews of Bitsight?

**["Finds Public-Facing Security Flaws and Clearly Shows How to Fix Them"](https://www.g2.com/survey_responses/bitsight-review-12760320)**

**Rating:** 4.5/5.0 stars

_— Verified User in Computer Software_

[Read full review](https://www.g2.com/survey_responses/bitsight-review-12760320)

**["Effortless Cyber Risk Scoring for Proactive Security"](https://www.g2.com/survey_responses/bitsight-review-12098656)**

**Rating:** 4.0/5.0 stars

_— Matthew P._

[Read full review](https://www.g2.com/survey_responses/bitsight-review-12098656)

#### What Are G2 Users Discussing About Bitsight?

- [What does Bitsight Security Ratings do?](https://www.g2.com/discussions/what-does-bitsight-security-ratings-do)
- [How is BitSight calculated?](https://www.g2.com/discussions/how-is-bitsight-calculated)
- [What is a BitSight security rating?](https://www.g2.com/discussions/what-is-a-bitsight-security-rating)

### [HeroDevs](https://www.g2.com/products/herodevs/reviews)

HeroDevs Never-Ending Support provides secure drop-in replacements and updates for end-of-life open source libraries, protecting businesses from vulnerabilities in deprecated software. Our team delivers proactive security updates—often before CVEs are publicly disclosed—and maintains continuous monitoring of your technology stack to identify potential threats before they impact your systems. Our solution eliminates the need for costly, time-consuming rewrites when open source libraries reach end-of-life by extending support indefinitely. HeroDevs' expert engineers maintain your existing codebase with security patches, bug fixes, and compatibility updates, allowing your development team to focus on innovation rather than remediation. This approach preserves your investment in current applications while ensuring they remain secure and compliant. HeroDevs partners directly with your security and development teams to rapidly assess vulnerabilities, prioritize remediation efforts, and implement fixes with minimal disruption. Our service includes detailed reporting on security posture, comprehensive documentation of all changes, and dedicated technical support from engineers specialized in your specific technologies. By extending the life of critical open source components, we help organizations maintain business continuity while significantly reducing security risks and compliance concerns. Keep your business secure and your applications running without costly rewrites or risky exposure.

**Average Rating:** 4.7/5.0

**Total Reviews:** 18

#### How Do G2 Users Rate HeroDevs?

- **Has the product been a good partner in doing business?:** 9.5/10 (Category avg: 9.2/10)
- **Reporting:** 7.5/10 (Category avg: 8.8/10)
- **Vulnerability Intelligence:** 8.3/10 (Category avg: 8.7/10)
- **Risk-Prioritization:** 8.3/10 (Category avg: 8.8/10)

#### Who Is the Company Behind HeroDevs?

- **Seller:** [HeroDevs](https://www.g2.com/sellers/herodevs)
- **Year Founded:** 2018
- **HQ Location:** Sandy, Utah
- **Twitter:** @herodevs  
2,672 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=06349b56e598966758f5a591da15dd2eba8a53865926232017b79918072d8bcb&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fherodevs&secure%5Burl_type%5D=linkedin_company_website)  
102 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 61% Medium, 39% Small

#### What Do G2 Reviewers Say About HeroDevs?

_AI-generated summary from verified user reviews_

##### Pros

- Users highly value the **responsive and professional customer support** from HeroDevs, ensuring seamless integration and peace of mind.
- Users commend the **seamless integrations** of HeroDevs, enhancing their development workflow with reliable support and peace of mind.
- Users highlight the **ease of use** of HeroDevs, praising its smooth integration and straightforward implementation.
- Users value the **reliable security support** from HeroDevs, ensuring peace of mind without urgent migration demands.
- Users value the **reliable authentication security** of HeroDevs, ensuring peace of mind through extended support and professional guidance.

##### Cons

- Users note the **expensive pricing** , particularly for smaller teams, although they acknowledge the overall value.
- Users find the current **dashboard issues** hindered communication and tracking, impacting overall effectiveness in managing requests.
- Users report **missing features** like a dashboard, subscription management, and support for deprecated package managers.
- Users wish for a **monthly billing option** for better cash flow management, but it is not available.
- Users report a **complex implementation** process due to version incompatibilities and limited support for package managers.

#### What Are Recent G2 Reviews of HeroDevs?

**["Never ending support"](https://www.g2.com/survey_responses/herodevs-review-11530966)**

**Rating:** 5.0/5.0 stars

_— Mark N._

[Read full review](https://www.g2.com/survey_responses/herodevs-review-11530966)

**["HeroDevs: Reliable AngularJS Support with Great Value and Responsive Team"](https://www.g2.com/survey_responses/herodevs-review-11808578)**

**Rating:** 4.5/5.0 stars

_— Kris A._

[Read full review](https://www.g2.com/survey_responses/herodevs-review-11808578)

- &lsaquo; Prev‹ Prev
- 1
- [2](/categories/risk-based-vulnerability-management?open_modal_url=%2Fproducts%2Fcycognito%2Fwishlists%3Fhost_path%3D%252Fcategories%252Frisk-based-vulnerability-management%26source%3Dcategory&order=g2_score&page=2#product-list)
- [3](/categories/risk-based-vulnerability-management?open_modal_url=%2Fproducts%2Fcycognito%2Fwishlists%3Fhost_path%3D%252Fcategories%252Frisk-based-vulnerability-management%26source%3Dcategory&order=g2_score&page=3#product-list)
- [4](/categories/risk-based-vulnerability-management?open_modal_url=%2Fproducts%2Fcycognito%2Fwishlists%3Fhost_path%3D%252Fcategories%252Frisk-based-vulnerability-management%26source%3Dcategory&order=g2_score&page=4#product-list)
- [5](/categories/risk-based-vulnerability-management?open_modal_url=%2Fproducts%2Fcycognito%2Fwishlists%3Fhost_path%3D%252Fcategories%252Frisk-based-vulnerability-management%26source%3Dcategory&order=g2_score&page=5#product-list)
- …
- [12](/categories/risk-based-vulnerability-management?open_modal_url=%2Fproducts%2Fcycognito%2Fwishlists%3Fhost_path%3D%252Fcategories%252Frisk-based-vulnerability-management%26source%3Dcategory&order=g2_score&page=12#product-list)
- [13](/categories/risk-based-vulnerability-management?open_modal_url=%2Fproducts%2Fcycognito%2Fwishlists%3Fhost_path%3D%252Fcategories%252Frisk-based-vulnerability-management%26source%3Dcategory&order=g2_score&page=13#product-list)
- [Next &rsaquo;Next ›](/categories/risk-based-vulnerability-management?open_modal_url=%2Fproducts%2Fcycognito%2Fwishlists%3Fhost_path%3D%252Fcategories%252Frisk-based-vulnerability-management%26source%3Dcategory&order=g2_score&page=2#product-list)

Spotlight Categories

[Marketing Analytics Tools](https://www.g2.com/categories/marketing-analytics)

[Core HR Software](https://www.g2.com/categories/core-hr)

[A/B Testing Tools](https://www.g2.com/categories/a-b-testing-tools)

[Video Conferencing Software](https://www.g2.com/categories/video-conferencing)

[Security Awareness Training Software](https://www.g2.com/categories/security-awareness-training)

Similar Categories

- [Attack Surface Management](/categories/attack-surface-management)
- [Cybersecurity Professional Development](/categories/cybersecurity-professional-development)

- [Exposure Management Platforms](/categories/exposure-management-platforms)
- [Patch Management](/categories/patch-management)

- [Secure Code Training](/categories/secure-code-training)
- [Security Awareness Training](/categories/security-awareness-training)

[Browse Risk-Based Vulnerability Management Themes](/categories/risk-based-vulnerability-management/themes)

 ![Brandon Summers-Miller](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Brandon Summers-Miller")
BS

Researched and written by [Brandon Summers-Miller](https://research.g2.com/insights/author/brandon-summers-miller)

Updated October 3, 2024

Risk-based vulnerability management software is used to identify and prioritize vulnerabilities based on customizable risk factors. These tools are more advanced than traditional vulnerability management solutions, as they assist in the prioritization of issues and execution of remedies based on the results of machine learning algorithms.

Companies use risk-based vulnerability management solutions to analyze entire organizations’ IT systems, cloud services, and/or applications and identify priorities. Instead of manually identifying vulnerabilities and remediating them in order of discovery, an organization can automate that process to remediate vulnerabilities impacting critical business components first. From there, they can address issues as the system has ordered by impact and remediation time. Companies can customize these priorities as they see fit by weighing risk factors differently.

Risk-based vulnerability management solutions are primarily used by IT professionals and security staff. These teams will integrate system and application information, outline priorities, and analyze assets. Automation within these tools saves significant time; furthermore, addressing critical vulnerabilities first can significantly reduce the likelihood of security incidents, failover, and data loss.

There is some overlap between risk-based vulnerability management solutions and [security risk analysis software](https://www.g2.com/categories/security-risk-analysis), but there are a few key differences. Security risk analysis tools provide similar capabilities in identifying vulnerabilities and other security risks. But security risk analysis tools, aside from a few outlier products, will not utilize machine learning and automation to assist in the prioritization and execution of vulnerability remediation.

To qualify for inclusion in the Risk-Based Vulnerability Management category, a product must:

- Integrate threat intelligence and contextual data for analysis
- Analyze applications, networks, and cloud services for vulnerabilities
- Utilize risk factors and machine learning to prioritize vulnerabilities

Top Tools at a Glance

| 

 | 

24/7 SOC coverage for under-resourced security teams

 | 

User Review

"Effortless Log Management and Monitoring with Built-In Parsers"

 |
| 

 | 

Risk-based prioritization with VPR scoring

 | 

User Review

"TVM Does What You Need"

 |
| 

 | 

Vulnerability prioritization with threat exploitation intelligence

 | 

User Review

"Recorded Future Delivers Actionable Threat Intelligence and Proactive Alerts"

 |
| 

 | 

Contextual attack path mapping across external surfaces

 | 

User Review

"Single Pane of Truth for External Exposure Correlation and Fast Risk Prioritization"

 |
| 

 | 

Continuous crowdsourced testing with triaged vulnerability validation

 | 

User Review

"Reliable BugBounty platform!"

 |
| 

 | 

Continuous bug bounty with triage-first workflows

 | 

User Review

"Powerful Bug Bounty Platform with Room for Improvements"

 |
| 

 | 

External threat context for vulnerability prioritization

 | 

User Review

"Cuts Vulnerability Noise with Context and Strong External Surface Visibility"

 |
| 

 | 

Multi-cloud vulnerability detection with compliance enforcement

 | 

User Review

"Cortex Cloud earned it's place before every release."

 |
| 

 | 

Vulnerability remediation workflows anchored in ServiceNow CMDB

 | 

User Review

"Centralized Incident Management with Intuitive Dashboard"

 |

* * *

Show More