Try our new research platform with insights from 80,000+ expert users

Check Point CloudGuard CNAPP vs Qualys VMDR comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 29, 2024
 

Categories and Ranking

SentinelOne Singularity Clo...
Sponsored
Ranking in Vulnerability Management
6th
Ranking in Container Security
3rd
Average Rating
8.6
Reviews Sentiment
8.1
Number of Reviews
93
Ranking in other categories
Cloud and Data Center Security (5th), Cloud Workload Protection Platforms (CWPP) (4th), Cloud Security Posture Management (CSPM) (4th), Cloud-Native Application Protection Platforms (CNAPP) (3rd), Compliance Management (3rd)
Check Point CloudGuard CNAPP
Ranking in Vulnerability Management
8th
Ranking in Container Security
6th
Average Rating
8.6
Number of Reviews
69
Ranking in other categories
Cloud and Data Center Security (9th), Cloud Workload Protection Platforms (CWPP) (6th), Cloud Security Posture Management (CSPM) (5th), Cloud-Native Application Protection Platforms (CNAPP) (5th), Data Security Posture Management (DSPM) (4th), Compliance Management (5th)
Qualys VMDR
Ranking in Vulnerability Management
2nd
Ranking in Container Security
10th
Average Rating
8.2
Reviews Sentiment
7.1
Number of Reviews
90
Ranking in other categories
IT Asset Management (4th), Configuration Management Databases (3rd), Risk-Based Vulnerability Management (3rd)
 

Featured Reviews

Andrew W - PeerSpot reviewer
Aug 29, 2024
Tells us about vulnerabilities as well as their impact and helps to focus on real issues
Looking at all the different pieces, it has got everything we need. Some of the pieces we do not even use. For example, we do not have Kubernetes Security. We are not running any K8 clusters, so it is good for us. Overall, we find the solution to be fantastic. There can be additional education components. This may not be truly fair to them because of what the product is going for, but it would be great to see additional education for compliance. It is not a criticism of the tool per se, but anything to help non-development resources understand some of the complexities of the cloud is always appreciated. Any additional educational resources are always helpful for security teams, especially those without a development background.
Yokesh Mani - PeerSpot reviewer
Jan 23, 2024
Easy to write custom rules and policies in the UI with limited coding knowledge
The user interface could be improved. Sometimes, the visibility is not immediately available for the environment. We have the native servers that come with the solutions, but we cannot see them in the Check Point log. Another issue is with the integrated file monitoring. It would make sense to have stuff like file integrity monitoring and malware scanning available within this module because we don't want to integrate another product. For example, let's say it's showing a process violation. It should be able to do some additional malware scanning in that particular bucket to get some additional information. I don't want to integrate with another third-party tool or go to the native server to check something. It would be helpful to have integrated monitoring and malware scanning for the file types. There are a few flaws with the security management portal where I have limited visibility into the workload protection features. There is no error visibility where I can see the communication and workflow between services. Some of the dashboards need to be fine-tuned if they are not customized. For example, I cannot customize anything on the effective risk management dashboard. Some of the information is not correct for my tenant. With respect to passwords and user management, there are no policies I can measure at the user level. If the user was created more than six months ago, you don't need to worry about that password or do anything like two-factor authentication associated with that user. They can still log in after six months or one year. It's also a challenge to use CloudGuard's agentless workload posture with AWS. An Azure storage is summed up with a CNAPP encryption by default. We tried onboarding this data, but the problem is the attachment is not done. After a few days, we identified that it was impossible to do the encryption detection. But CloudGuard's default rules say that this has to be encrypted. The AWS module says that we cannot access this volume with this encryption, so we cannot use an agentless workload posture with AWS because of this. It is a best practice to ensure that all the volumes are being encrypted. Without the encryption, how can I do this? It is a big challenge for CloudGuard.
Harold Jensen - PeerSpot reviewer
Jul 13, 2023
Good visibility but expensive and needs better support
Support: It's often overseas and often following a script, basically asking us to redo what we opened the case with. Multiple APIs: There seems to be a lack of easy onboarding into Qualys. We had to use manual inputs and some API calls to get items in place. Dashboard: It is very rudimentary with very little customization. The Qualys Scripting Language (QSL) works differently in different Qualys modules, so when you get it working in one area you have to modify the syntax in others. User account management: We often have to give users more rights than needed just to give them what they need. Integration with the various Qualys Modules: You can tell the UI is different based on of the different teams that created them. QSL syntax same in all modules Responsiveness of some of the components: They time out, you get a blank screen, etc. Backend updates between the various modules: You update connectors and information takes a few minutes to show in VMDR or Global Asset View Connectors: Connectors have a throttling issue with AWS which causes them to frequently fail unless you manually run them again.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"PingSafe offers security solutions for both Kubernetes and CI/CD pipelines."
"The most valuable features of PingSafe are cloud misconfiguration, Kubernetes, and IaC scanning."
"As a frequently audited company, we value PingSafe's compliance monitoring features. They give us a report with a compliance score for how well we meet certain regulatory standards, like HIPAA. We can show our compliance as a percentage. It's also a way to show that we are serious about security."
"Cloud Native Security offers a valuable tool called an offensive search engine."
"Our organization is growing steadily, so our infrastructure is expanding, and we're managing more technical resources. Singularity Cloud Security helps us track our resources so that we don't get lost in the overwhelming volume of things and ensures we follow best practices. The solution gives us better visibility into our resources and enables faster resolution."
"It integrates very well. We sell different products from different vendors. We know that the SentinelOne Singularity platform can be integrated with several different solutions from different vendors."
"With PingSafe, it's easy to onboard new accounts."
"We really appreciate the Slack integration. When we have an incident, we get an instant notification. We also use Joe Sandbox, which Singularity can integrate with, so we can verify if a threat is legitimate."
"Check Point CloudGuard CNAPP's initial configuration is very easy. It is plug-and-play. It also gives regular updates."
"The most valuable feature is the ability to work with the APIs to integrate into our own backend systems."
"This solution has saved the company from unnecessary data loss that occurs due to cyber attacks."
"The most valuable feature is the single dashboard that enables us to manage the entire cloud environment from one place."
"Dome9 continues to be a major piece of our cloud security architecture and has given our senior leadership team a high degree of confidence in our ability to protect our cloud environment."
"The Compliance engine has helped put our auditors and senior executives at ease, as we can quickly and accurately measure ourselves against hundreds of compliance checks to include CIS benchmarks, PCI, and other best practices."
"Cloud security posture management is the feature we've been using the longest."
"The most valuable feature is the ability to apply common tools across all accounts."
"Technical support is great and we've never really had a problem."
"Qualys VM's best feature is vulnerability management."
"Monitors workstations and servers for vulnerabilities and creates reports."
"The solution shows us classic categories, including high, medium, and low risks. It also shows critical items, and that gives us the advantage of prioritizing things."
"The prioritization feature is great. I think it has all of the advanced features that we need."
"The most valuable features are vulnerability scanning, policy compliance scanning, and tablet for web application scanning."
"It's very configurable to adjust impact to systems."
"I value the scheduling of scans and reports as per the desired timeframes."
 

Cons

"Their search feature could be better."
"It does not bring much threat intel from the outside world. All it does is scan. If it can also correlate things, it will be better."
"The Automation tab is an add-on that doesn’t work properly. They provide a list of scripts that don’t work and I have asked support to assist but they won’t help. When running on various endpoints the script doesn’t work and if it does, it’s only a couple. There are a lot of useful scripts that would be beneficial to run forensics, event logs, and process lists running on the endpoint."
"It took us a while to configure the software to work well in this type of environment, as the support documents were not always clear."
"They can work on policies based on different compliance standards."
"With Cloud Native Security, we can't selectively enable or disable alerts based on our specific use case."
"In terms of ease of use, initially, it is a bit confusing to navigate around, but once you get used to it, it becomes easier."
"I would like additional integrations."
"Reporting should have more options."
"Currently, I would like this solution extended to cellular devices or tablets."
"The rules are not well-tuned, and many of them generate false positives or nonsensical results."
"The main issue that we found with Dome9 is that we have a default rule set with better recommendations that we want to use. So, you do a clone of that rule set, then you do some tweaks and customizations, but there is a problem. When they activate the default rule set with the recommendations and new security measures, it doesn't apply the new security measures to your clones profile. Therefore, you need to clone the profile again. We are already writing a report to Check Point."
"We want to be able to customize the solution more in order to meet the needs of our company."
"Reporting should have more options."
"CloudGuard could be improved by including integration with vendors other than AWS, especially Azure, especially in permissions."
"The integration process could be enhanced by enabling integration at the organizational level rather than requiring the manual setup of individual accounts."
"The reporting in this solution can be improved."
"Qualys should improve their customer experience. They need to improve the tech support experience and the turnaround time."
"When you want to cover yourself for scalability, you will be charged for the number you place on the scan itself."
"The only improvement I can think of is on the implementation side. At times it is a bit slow."
"The reporting and dashboards could improve in Qualys VM. However, they have improved since the previous versions."
"While Qualys VMDR is comprehensive, improvements in asset management functionality would be beneficial."
"In terms of improvement for the web application console, in the older version, things were more segregated and presented in a brief format."
"From the application security perspective, Qualys has a way to go."
 

Pricing and Cost Advice

"As a partner, we receive a discount on the licenses."
"PingSafe falls somewhere in the middle price range, neither particularly cheap nor expensive."
"The features included in PingSafe justify its price point."
"Its pricing was a little less than other providers."
"PingSafe is affordable."
"We found it to be fine for us. Its price was competitive. It was something we were happy with. We are not a Fortune 500 company, so I do not know how pricing scales at the top end, but for our cloud environment, it works very well."
"PingSafe is fairly priced."
"PingSafe is not very expensive compared to Prisma Cloud, but it's also not that cheap. However, because of its features, it makes sense to us as a company. It's fairly priced."
"The pricing of Check Point is very reasonable. Cisco is a very big brand, so the pricing is quite high. We want a solution that fits into our pocket and has all the features. They can improve the licensing model for small and mid-sized organizations. It suits large companies but not small and mid-sized organizations."
"​They support either annual licensing or hourly. At the time of our last negotiation, it was either one or the other, you could not mix or match. I would have liked to mix/match. ​"
"We have the enterprise-level license and we renew it annually because it is worth the cost."
"Right now, we have licenses on 500 machines, and they are not cheap."
"The tool's pricing is moderate. Its licensing costs are yearly."
"Its pricing is competitive."
"In the beginning, the price of Dome9 was cheap, whereas now it is not."
"I suggest that you pay attention to the product pricing because while there are no tricks, and the licensing model is transparent, the final numbers may surprise you."
"Qualys VM is better suited for medium to large companies because the price can be too much for smaller customers."
"Qualys VM is reasonably priced."
"It is more expensive than other products on the market."
"The price is very reasonable."
"There is a license for the use of this solution. We pay annually instead of monthly to receive a better discount on the price."
"There are no additional fees in addition to the standard licensing fees."
"In Nigerian Naira, we spend about roughly four to five million to use this solution and this is expensive compared to solutions like Nessus."
"When you want to cover yourself for scalability, you will be charged for the number you place on the scan itself."
report
Use our free recommendation engine to learn which Vulnerability Management solutions are best for your needs.
815,854 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
19%
Financial Services Firm
16%
Manufacturing Company
10%
Insurance Company
5%
Financial Services Firm
15%
Computer Software Company
14%
Manufacturing Company
9%
Security Firm
6%
Educational Organization
35%
Computer Software Company
11%
Financial Services Firm
11%
Manufacturing Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about PingSafe?
The dashboard gives me an overview of all the things happening in the product, making it one of the tool's best featu...
What is your experience regarding pricing and costs for PingSafe?
SentinelOne provided competitive pricing compared to other vendors, and we are satisfied with the deal.
What needs improvement with PingSafe?
Sometimes, I am not able to see the flow when there is an issue. When anyone complains and I have to troubleshoot it,...
What is your primary use case for Qualys VM?
Qualys VM is used for vulnerability scans for the internet and applications using application exchange. There are man...
What do you like most about Qualys VMDR?
I like that we have many scanners and channels that don't overload. It helps us scan and track easily. Also, the tagg...
What is your experience regarding pricing and costs for Qualys VMDR?
I am not aware of the actual cost or pricing as it is managed by the client.
 

Also Known As

PingSafe
Check Point CloudGuard Posture Management, Dome9, Check Point CloudGuard Workload Protection, Check Point CloudGuard Intelligence
Qualys VM, QualysGuard VM, Qualys Asset Inventory, Qualys Container Security, Qualys Virtual Scanner Appliance
 

Overview

 

Sample Customers

Information Not Available
Symantec, Citrix, Car and Driver, Virgin, Cloud Technology Partners
Agrokor Group, American Specialty Health, American State Bank, Arval, Life:), Axway, Bank of the West, Blueport Commerce, BSkyB, Brinks, CaixaBank, Cartagena, Catholic Health System, CEC Bank, Cegedim, CIGNA, Clickability, Colby-Sawyer College, Commercial Bank of Dubai, University of Utah, eBay Inc., ING Singapore, National Theatre, OTP Bank, Sodexo, WebEx
Find out what your peers are saying about Check Point CloudGuard CNAPP vs. Qualys VMDR and other solutions. Updated: November 2024.
815,854 professionals have used our research since 2012.