Try our new research platform with insights from 80,000+ expert users

Microsoft Defender External Attack Surface Management vs Qualys CyberSecurity Asset Management (CSAM) comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Customer Service

No sentiment score available
Sentiment score
9.0
Qualys CSAM receives high praise for responsive, knowledgeable support, despite occasional delays when queries require redirection to other teams.
The support team was knowledgeable and offered a variety of quick resolution options.
Their SMEs have sufficient knowledge, and if they are not the right contact, they quickly redirect us to someone who can help resolve issues.
I would rate their customer support a ten out of ten.
 

Room For Improvement

No sentiment score available
Sentiment score
5.2
Qualys CyberSecurity Asset Management needs improved CMDB support, interface simplicity, reporting, integration, efficiency, and learning materials for enhanced usability.
Qualys is currently not able to identify assets lacking DNS information.
We would prefer more options, such as 'approved only for pilot' or 'approved for this line of business,' allowing for better granularity in categorizing software.
The reporting feature could offer more customizable templates and easier-to-digest visualizations.
 

Scalability Issues

No sentiment score available
Sentiment score
9.4
Qualys CyberSecurity Asset Management is highly rated for its scalability, effectively managing diverse environments and large asset quantities.
We have about 300,000 assets installed with agents worldwide.
Qualys Cybersecurity Asset Management has proven to be a highly scalable solution for us over the past couple of years.
 

Setup Cost

No sentiment score available
Sentiment score
7.5
Qualys CyberSecurity Asset Management offers transparent pricing perceived as cost-effective by large enterprises but expensive for smaller ones.
A monthly subscription starting at approximately $72 per month, depending on the specific package and features included.
Though the solution is considered expensive, if bundled with other services such as VMDR or cloud agents, its value would significantly increase.
The Qualys Cybersecurity Asset Management pricing is well-aligned with our usage.
 

Stability Issues

No sentiment score available
Sentiment score
7.7
Qualys CyberSecurity Asset Management is mostly stable with minor syncing issues, appreciated for updates, performance, and data management.
They are constantly adding capabilities.
This platform demonstrates excellent stability with consistent 100 percent uptime and no glitches observed.
Everything is smoothly managed by a different team, and our scheduled scans run without interruptions.
 

Valuable Features

No sentiment score available
Sentiment score
8.3
Qualys CyberSecurity Asset Management provides comprehensive features for asset visibility, risk mitigation efficiency, and advanced integration capabilities.
By correlating this with QDS scores, we can accurately assess the risk level of high or low QDS scores associated with each asset and monitor them accordingly.
The most valuable feature is the real-time visibility Qualys CyberSecurity Asset Management provides into all assets across our development and operational environments.
It also performs scans to identify any vulnerabilities, which helps to take proactive measures before those vulnerabilities are identified by any attacker.
 

Categories and Ranking

Microsoft Defender External...
Ranking in Attack Surface Management (ASM)
10th
Average Rating
8.0
Reviews Sentiment
5.7
Number of Reviews
1
Ranking in other categories
Microsoft Security Suite (27th)
Qualys CyberSecurity Asset ...
Ranking in Attack Surface Management (ASM)
5th
Average Rating
9.2
Reviews Sentiment
7.9
Number of Reviews
14
Ranking in other categories
Vulnerability Management (14th), Patch Management (9th), Cyber Asset Attack Surface Management (CAASM) (4th), Software Supply Chain Security (7th)
 

Featured Reviews

SF
Better at protecting from cyberattacks and haven't had any problems with the scalability of this solution
With Microsoft, support is always crazy, it's not easy to get support. That's their weakness. They need to improve their support. Microsoft will always give good support to their big customers or partners, but we're not a big company. If you had a thousand employees and were a big customer, maybe they'd offer better support. But in my 35 years of IT experience, it's always been the same with Microsoft. They transfer us to Europe because we speak French, but when we want to speak in English, they transfer us to people who don't know the product. Most of the time, we find a solution before they call us back.
Brad Mathis - PeerSpot reviewer
Improves visibility, reliability, and scalability
The external attack surface management identified unexpected assets, suggesting some exist outside our known inventory. While these may not be directly managed by us, the process has brought valuable awareness to the fact that our core servers are externally hosted, prompting a review of similar situations. An external attack surface management scan revealed several outsourced name services, along with one unexpected third-party-linked IP. It's unclear if this was due to past consulting work or a registration error, but since it wasn't relevant to our company, it was easily excluded from future scans. The benefits of Qualys CyberSecurity Asset Management are immediate. We already had the cloud agents installed. They were already on all the servers and workstations. Once we upgraded from the VMDR included GAV (Global AssetView) to CSAM, it was no time before I could see the end-of-life, end-of-service software, and hardware. In addition to vulnerabilities, CSAM provides a better view of other risk factors, but VMDR is very powerful. VMDR was already seeing our limitations in hardening our vulnerabilities. CSAM enhanced our view by adding more visibility and insight into what we have. TruRisk scoring goes beyond traditional vulnerability scoring like CVSS to prioritize both vulnerabilities and assets based on real-world exploitability and industry targeting. This provides a clearer picture of our actual risk by considering factors like published exploits and what attackers are currently focusing on, allowing us to quickly identify critical issues and avoid wasting time on vulnerabilities with a high theoretical risk but low real-world threat. Qualys Cloud Agents can now be configured as passive sensors to discover all devices on our network in real-time, eliminating the requirement for separate virtual or physical passive sensor appliances. These cloud agent sensors monitor network broadcasts instead of egress traffic, and they can even designate a secondary sensor to take over if the primary becomes unavailable, ensuring continuous asset discovery and populating our CSAM platform with managed and unmanaged devices.
report
Use our free recommendation engine to learn which Attack Surface Management (ASM) solutions are best for your needs.
816,636 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
18%
Financial Services Firm
14%
Manufacturing Company
7%
Healthcare Company
7%
Computer Software Company
25%
Financial Services Firm
12%
Government
9%
Retailer
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

What is your experience regarding pricing and costs for Microsoft Defender External Attack Surface Management?
I don't see a big difference in pricing compared to its competitors. With "intelligent" or "smart" antivirus, people are willing to pay a little more for something that could make a difference for ...
What needs improvement with Microsoft Defender External Attack Surface Management?
With Microsoft, support is always crazy, it's not easy to get support. That's their weakness. They need to improve their support. Microsoft will always give good support to their big customers or p...
What is your primary use case for Microsoft Defender External Attack Surface Management?
The kind of companies using it typically have one hundred or more users and are in various sectors, like manufacturing and insurance. We use it to protect against cyberattacks.
What is your experience regarding pricing and costs for Qualys CyberSecurity Asset Management (CSAM)?
Qualys is competitively priced for its features. Its pricing is suitable for large organizations with more than 4,000 assets, but for smaller organizations with few assets, such as banks, the costs...
What needs improvement with Qualys CyberSecurity Asset Management (CSAM)?
Initial scans can produce excess data that needs refining. This extra data is not always useful for us in terms of understanding. They should provide the exact information required by the end user....
What is your primary use case for Qualys CyberSecurity Asset Management (CSAM)?
Currently, I use Qualys CSAM for asset management. It allows me to search for assets and manage them by implementing license management, asset inventory discovery, and ensuring that no device goes ...
 

Learn More

Video not available
 

Overview

Find out what your peers are saying about CrowdStrike, Trend Micro, Darktrace and others in Attack Surface Management (ASM). Updated: November 2024.
816,636 professionals have used our research since 2012.