Try our new research platform with insights from 80,000+ expert users

Amazon Inspector vs Qualys CyberSecurity Asset Management (CSAM) comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 9, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Customer Service

Sentiment score
8.5
Amazon Inspector offers reliable customer service, with varying response times based on subscription tier, ensuring user satisfaction.
Sentiment score
9.0
Qualys CSAM receives high praise for responsive, knowledgeable support, despite occasional delays when queries require redirection to other teams.
I have not needed to use AWS support for Inspector, which indicates that the service is almost perfect.
The support team was knowledgeable and offered a variety of quick resolution options.
Their SMEs have sufficient knowledge, and if they are not the right contact, they quickly redirect us to someone who can help resolve issues.
I would rate their customer support a ten out of ten.
 

Room For Improvement

Sentiment score
5.6
Amazon Inspector needs better integration, expanded vulnerability coverage, real-time protection, automation, and improved guidance for comprehensive security.
Sentiment score
5.2
Qualys CyberSecurity Asset Management needs improved CMDB support, interface simplicity, reporting, integration, efficiency, and learning materials for enhanced usability.
Automation for scheduling 'turn on' and 'turn off' operations and better integration with CloudWatch for alarms could enhance the service's functionality.
Qualys is currently not able to identify assets lacking DNS information.
We would prefer more options, such as 'approved only for pilot' or 'approved for this line of business,' allowing for better granularity in categorizing software.
The reporting feature could offer more customizable templates and easier-to-digest visualizations.
 

Scalability Issues

Sentiment score
7.6
Amazon Inspector offers scalable vulnerability monitoring with ECR integration, popular among security teams but sometimes limited for developers.
Sentiment score
9.4
Qualys CyberSecurity Asset Management is highly rated for its scalability, effectively managing diverse environments and large asset quantities.
Scalability is not an issue with Amazon Inspector as it is scalable to the maximum, covering any business scale effectively.
We have about 300,000 assets installed with agents worldwide.
Qualys Cybersecurity Asset Management has proven to be a highly scalable solution for us over the past couple of years.
 

Setup Cost

No sentiment score available
Amazon Inspector offers a cost-effective, tiered pricing model with transparent, low-cost scans suitable for diverse organizational needs.
Sentiment score
7.5
Qualys CyberSecurity Asset Management offers transparent pricing perceived as cost-effective by large enterprises but expensive for smaller ones.
The pricing for Amazon Inspector is very fair, and I would rate it as two out of ten, with ten being the most expensive.
A monthly subscription starting at approximately $72 per month, depending on the specific package and features included.
Though the solution is considered expensive, if bundled with other services such as VMDR or cloud agents, its value would significantly increase.
The Qualys Cybersecurity Asset Management pricing is well-aligned with our usage.
 

Stability Issues

Sentiment score
9.5
Amazon Inspector is highly stable and reliable, receiving excellent user support and impacting business security positively.
Sentiment score
7.7
Qualys CyberSecurity Asset Management is mostly stable with minor syncing issues, appreciated for updates, performance, and data management.
Amazon Inspector is highly stable, rated ten out of ten, and this stability impacts business security and administration positively.
They are constantly adding capabilities.
This platform demonstrates excellent stability with consistent 100 percent uptime and no glitches observed.
Everything is smoothly managed by a different team, and our scheduled scans run without interruptions.
 

Valuable Features

Sentiment score
8.2
Amazon Inspector offers automated vulnerability detection, categorization, and Security Hub integration for enhanced AWS security assessment across resources.
Sentiment score
8.3
Qualys CyberSecurity Asset Management provides comprehensive features for asset visibility, risk mitigation efficiency, and advanced integration capabilities.
The most valuable feature of Amazon Inspector is the categorization of findings, which filters vulnerabilities by instance, container image, container repository, and Lambda function.
By correlating this with QDS scores, we can accurately assess the risk level of high or low QDS scores associated with each asset and monitor them accordingly.
The most valuable feature is the real-time visibility Qualys CyberSecurity Asset Management provides into all assets across our development and operational environments.
It also performs scans to identify any vulnerabilities, which helps to take proactive measures before those vulnerabilities are identified by any attacker.
 

Categories and Ranking

Amazon Inspector
Ranking in Vulnerability Management
24th
Average Rating
8.0
Reviews Sentiment
8.0
Number of Reviews
5
Ranking in other categories
IT Vendor Risk Management (9th)
Qualys CyberSecurity Asset ...
Ranking in Vulnerability Management
14th
Average Rating
9.2
Reviews Sentiment
7.9
Number of Reviews
14
Ranking in other categories
Patch Management (9th), Cyber Asset Attack Surface Management (CAASM) (4th), Attack Surface Management (ASM) (5th), Software Supply Chain Security (7th)
 

Featured Reviews

Nikhil Sehgal - PeerSpot reviewer
Primarily focuses on security of EC2 instances, provides point-in-time assessments rather than real time protection but provides automated vulnerability detection
It has a limited scope. So, AWS Inspector primarily focuses on the security of the EC2 instance. So, if your architecture includes other AWS services, then you may need to use additional tools for your comprehensive security assessment. So that is one con. Another is, like, we have a dependency on agents. So other is dependency on agents, like, Inspector relies on agents installed on instances for deeper assessment. So managing these agents can be additional overhead. So these kinds of things. It does not even provide real-time protection. So, Inspector provides point-in-time assessment rather than continuous monitoring. So these are all cons. When it comes to false positives, it is there for most security tools as of now. I would not consider false positives a major concern. So, these are the major concerns that I found: dependency on agents, limited scope, and no real-time protection.
Brad Mathis - PeerSpot reviewer
Improves visibility, reliability, and scalability
The external attack surface management identified unexpected assets, suggesting some exist outside our known inventory. While these may not be directly managed by us, the process has brought valuable awareness to the fact that our core servers are externally hosted, prompting a review of similar situations. An external attack surface management scan revealed several outsourced name services, along with one unexpected third-party-linked IP. It's unclear if this was due to past consulting work or a registration error, but since it wasn't relevant to our company, it was easily excluded from future scans. The benefits of Qualys CyberSecurity Asset Management are immediate. We already had the cloud agents installed. They were already on all the servers and workstations. Once we upgraded from the VMDR included GAV (Global AssetView) to CSAM, it was no time before I could see the end-of-life, end-of-service software, and hardware. In addition to vulnerabilities, CSAM provides a better view of other risk factors, but VMDR is very powerful. VMDR was already seeing our limitations in hardening our vulnerabilities. CSAM enhanced our view by adding more visibility and insight into what we have. TruRisk scoring goes beyond traditional vulnerability scoring like CVSS to prioritize both vulnerabilities and assets based on real-world exploitability and industry targeting. This provides a clearer picture of our actual risk by considering factors like published exploits and what attackers are currently focusing on, allowing us to quickly identify critical issues and avoid wasting time on vulnerabilities with a high theoretical risk but low real-world threat. Qualys Cloud Agents can now be configured as passive sensors to discover all devices on our network in real-time, eliminating the requirement for separate virtual or physical passive sensor appliances. These cloud agent sensors monitor network broadcasts instead of egress traffic, and they can even designate a secondary sensor to take over if the primary becomes unavailable, ensuring continuous asset discovery and populating our CSAM platform with managed and unmanaged devices.
report
Use our free recommendation engine to learn which Vulnerability Management solutions are best for your needs.
816,406 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
13%
Financial Services Firm
12%
Government
7%
Manufacturing Company
6%
Computer Software Company
24%
Financial Services Firm
12%
Government
9%
Retailer
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Amazon Inspector?
The integration of Amazon Inspector with other AWS services has enhanced our security. Security Hub is a major asset because it allows us to centralize data from various AWS services. We can integ...
What is your experience regarding pricing and costs for Amazon Inspector?
The pricing is very transparent and clear, so I don't have any challenges with it. It's good.
What needs improvement with Amazon Inspector?
There is room for improvement in the scanning capabilities. I'd like to see broader coverage in terms of the vulnerabilities detected. Right now, it's not as comprehensive as some of the third-part...
What is your experience regarding pricing and costs for Qualys CyberSecurity Asset Management (CSAM)?
Qualys is competitively priced for its features. Its pricing is suitable for large organizations with more than 4,000 assets, but for smaller organizations with few assets, such as banks, the costs...
What needs improvement with Qualys CyberSecurity Asset Management (CSAM)?
Initial scans can produce excess data that needs refining. This extra data is not always useful for us in terms of understanding. They should provide the exact information required by the end user....
What is your primary use case for Qualys CyberSecurity Asset Management (CSAM)?
Currently, I use Qualys CSAM for asset management. It allows me to search for assets and manage them by implementing license management, asset inventory discovery, and ensuring that no device goes ...
 

Overview

 

Sample Customers

betterment, caplinked, flatiron, university of nutri dame
Information Not Available
Find out what your peers are saying about Amazon Inspector vs. Qualys CyberSecurity Asset Management (CSAM) and other solutions. Updated: October 2024.
816,406 professionals have used our research since 2012.