Try our new research platform with insights from 80,000+ expert users

Qualys TotalCloud vs Rapid7 InsightCloudSec comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 9, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

SentinelOne Singularity Clo...
Sponsored
Ranking in Cloud Security Posture Management (CSPM)
4th
Ranking in Cloud-Native Application Protection Platforms (CNAPP)
3rd
Average Rating
8.6
Reviews Sentiment
7.8
Number of Reviews
103
Ranking in other categories
Vulnerability Management (6th), Cloud and Data Center Security (5th), Container Security (3rd), Cloud Workload Protection Platforms (CWPP) (4th), Compliance Management (3rd)
Qualys TotalCloud
Ranking in Cloud Security Posture Management (CSPM)
10th
Ranking in Cloud-Native Application Protection Platforms (CNAPP)
9th
Average Rating
8.8
Reviews Sentiment
7.8
Number of Reviews
26
Ranking in other categories
Vulnerability Management (13th), Container Security (11th), Cloud Workload Protection Platforms (CWPP) (10th), SaaS Security Posture Management (SSPM) (2nd)
Rapid7 InsightCloudSec
Ranking in Cloud Security Posture Management (CSPM)
21st
Ranking in Cloud-Native Application Protection Platforms (CNAPP)
18th
Average Rating
7.2
Reviews Sentiment
6.9
Number of Reviews
5
Ranking in other categories
Cloud Management (24th)
 

Featured Reviews

Andrew W - PeerSpot reviewer
Tells us about vulnerabilities as well as their impact and helps to focus on real issues
Looking at all the different pieces, it has got everything we need. Some of the pieces we do not even use. For example, we do not have Kubernetes Security. We are not running any K8 clusters, so it is good for us. Overall, we find the solution to be fantastic. There can be additional education components. This may not be truly fair to them because of what the product is going for, but it would be great to see additional education for compliance. It is not a criticism of the tool per se, but anything to help non-development resources understand some of the complexities of the cloud is always appreciated. Any additional educational resources are always helpful for security teams, especially those without a development background.
Vikasha Sharma - PeerSpot reviewer
Enables us to mitigate and prioritize risks, ultimately reducing our attack surface for critical assets
TotalCloud provides written explanations that guide remediation and eliminate risk. We have used Qualys for over ten years, and TotalCloud and TruRisk for the last two to three years, successfully leveraging their benefits. Our technical account manager is responsive to our requests for additional features or suggestions, ensuring our needs are met. I would rate the helpfulness of written explanations compared to visualizations of attack paths a nine out of ten. The explanations effectively detail how the scores are derived, making them verifiable and useful for regulatory audits. This allows us to clearly justify the chosen approach and the tool's output. Qualys TotalCloud has significantly benefited our organization by reducing our vulnerability count and overall team size. The platform's user-friendly interface has streamlined management, eliminating the need for additional staff and enabling us to efficiently handle our workload. With the support of our technical account manager and their team, we saw initial benefits within a month, achieving full utilization within six months due to the minimal learning curve. TotalCloud provides a single, prioritized view of risk. We are also evaluating Qualys' new Enterprise Threat Management module, part of their enterprise risk platform, recently launched at the Qualys Security Conference. While we are still assessing this module, the dashboards are well-designed, configurable, and useful. The single, prioritized view of risk has significantly streamlined our workload by consolidating multiple sources, resulting in an estimated 60 percent reduction in effort due to the tool's prioritization capabilities. Our use of TruRisk allows us to effectively justify our risk management processes to regulators and auditors. The system provides clear and verifiable risk assessments, which facilitates a smooth audit process and ensures compliance with regulatory requirements. The comprehensiveness of range of risk found by TruRisk Insights is an eight out of ten. The TruRisk Insights feature has helped us identify assets with high vulnerability scores, significantly impacting our business by enabling us to mitigate and prioritize risks, ultimately reducing our attack surface for critical assets. Previously, we applied the same logic to all assets, but TruRisk now allows us to pinpoint the areas of maximum risk and prioritize our efforts accordingly. We've improved our security posture by 30 to 40 percent and reduced our attack surface, consistently maintaining good security scores, such as our Bitsight Security Rating, since implementing Qualys TruRisk over two years ago.
Chenna Vemula - PeerSpot reviewer
Enhances security posture with cost efficiency and powerful APIs
We have been using it for almost four years. We are one of the top first customers who implemented it. It's a cloud security solution With this tool, we have a neat security posture at least in terms of securing our environment. It helps us handle all the misconfigurations, and we do day-to-day…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"PingSafe's integration is smooth. They are highly customer-oriented, and the integration went well for us."
"SentinelOne Singularity Cloud Security has saved up to 50 percent in engineering time."
"It is fairly simple. Anybody can use it."
"SentinelOne Singularity Cloud Security offers valuable features like runtime notifications. These alerts come to my account, ensuring that if any port or component within my infrastructure is opened or compromised, I am informed immediately. It highlights issues within minutes or even seconds."
"The key strength of Singularity Cloud Security lies in its ability to pinpoint vulnerabilities in our cloud accounts and identify suspicious activity that warrants further investigation."
"PingSafe offers security solutions for both Kubernetes and CI/CD pipelines."
"SentinelOne Singularity Cloud Security offers several valuable features, most notably the rapid vulnerability notifications that provide timely alerts regarding our infrastructure."
"The visibility PingSafe provides into the Cloud environment is a valuable feature."
"The agent and agentless scanning in TotalCloud, particularly the FlexScan method, is incredibly valuable. With traditional scanning approaches, we had to give IP ranges and whitelist IPs. All that is now simplified. FlexScan requires minimal intervention, and after configuration, it automatically collects data and performs necessary scans."
"Qualys TotalCloud's most valuable features are its security capabilities that help identify and mitigate risk factors."
"Qualys TotalCloud's most valuable feature is its ability to link clusters of assets, providing a clear model of deployments, vulnerabilities, and statuses."
"Qualys TotalCloud has significantly reduced our workload in terms of managing risks, helping us to be more efficient and save substantial resources."
"The scalability is good as well. I would rate it ten out of ten."
"While automatic inventory detection upon connection is a helpful feature, a truly valuable capability would be assessing an environment's security posture against Azure and CIS best practices."
"Qualys TotalCloud's most valuable features are its security capabilities that help identify and mitigate risk factors."
"The platform's unified view of the organization proves particularly valuable for leadership team meetings."
"The tool provides centralized visibility through dashboards and alerts, allowing customers to receive reports on cloud vulnerabilities and security posture. Rapid7 InsightCloudSec provides customers with a robust understanding of cloud security."
"It runs every hour and has been reliable since I started."
"ICSE is cheaper compared to other tools and has a pleasant user experience with good support."
"Agentless scanning is a possible use with Rapid7 InsightCloudSec."
"ICSE is cheaper compared to other tools and has a pleasant user experience with good support."
"The tool's most valuable feature is workload protection for Kubernetes and container security. It has agents that identify bugs or lack of security on runtime containers."
"I find the security frameworks and security tools valuable. I think they're good in the infrastructure of the code security. They are also good at threat protection."
 

Cons

"The Kubernetes scanning on the Oracle Cloud needs to be improved. It's on the roadmap. AWS has this capability, but it's unavailable for Oracle Cloud."
"When we request any changes, they must be reflected in the next update."
"SentinelOne Singularity Cloud Security could be improved with easier integrations to the Singularity Data Lake, particularly for various vendors."
"We are experiencing problems with Cloud Native Security reporting."
"I would like PingSafe to add real-time detection of vulnerabilities and cloud misconfigurations."
"Sometimes the Storyline ID is a bit wacky."
"I believe the UI/UX updates for SentinelOne Singularity Cloud Security have room for improvement."
"To enhance the notification system's efficiency, resolved issues should be promptly removed from the portal."
"Qualys's ticketing system can be confusing when assigning tasks to individuals, and support could be improved by offering instant call solutions with engineers in addition to ticket replies."
"TotalCloud could improve its scanning of niche devices like Wi-Fi dongles and USB modems because they are often untested. It covers everything else, like laptops, mobile devices, and Bluetooth IoT devices. They can improve on the small IoT devices because hackers and testers use these."
"An area for improvement would be to focus on risks related to AI, such as large language models and potential data leakage."
"Qualys TotalCloud needs to improve its accuracy for non-Windows operating systems."
"Although TotalCloud is a helpful tool, some of its advanced features are still under development."
"Although TotalCloud is a helpful tool, some of its advanced features are still under development."
"Some major banks and insurance companies require an on-premises solution for comprehensive vulnerability management, which TotalCloud does not offer."
"Two areas for improvement in Qualys TotalCloud are the speed of the public cloud platform and vulnerability detection."
"There are a lot of other solutions in the market, not only providing the features of a CSPM, but also CNAPP."
"Technical support could be better. It could also be easier, more user-friendly, and intuitive. The API keys aren't easy to understand, and the cloud layouts aren't intuitive and user-friendly. We should be able to integrate IM governance and APIs into non-compliant workloads like legacy solutions."
"A couple of modules are missing when compared to other providers, specifically related to some IAM, and the login piece needs improvement."
"The tool needs to improve its documentation."
"The login piece needs improvement."
"Rapid7 InsightCloudSec could be better at showing dashboards for virtual firewalls and appliances. Compared to other solutions like Palo Alto, this area is not as good. So, they should work on improving this for virtual devices."
"They didn't have any documentation on how to patch it."
 

Pricing and Cost Advice

"It's not expensive. The product is in its initial growth stages and appears more competitive compared to others. It comes in different variants, and I believe the enterprise version costs around $55 per user per year. I would rate it a five, somewhere fairly moderate."
"It is not that expensive. There are some tools that are double the cost of PingSafe. It is good on the pricing side."
"We found it to be fine for us. Its price was competitive. It was something we were happy with. We are not a Fortune 500 company, so I do not know how pricing scales at the top end, but for our cloud environment, it works very well."
"While I'm slightly out of touch with pricing, I know SentinelOne is much cheaper than other products."
"Its pricing is okay. It is in line with what other providers were providing. It is not cheap. It is not expensive."
"PingSafe is affordable."
"Pricing is based on modules, which was ideal for us."
"PingSafe is cost-effective for the amount of infrastructure we have. It's reasonable for what they offer compared to our previous solution. It's at least 25 percent to 30 percent less."
"Qualys TotalCloud is expensive, but it offers a premier solution with no headaches."
"The pricing for TotalCloud is attractive and competitive in the market. Given the features, especially the dashboard, I have no concerns regarding pricing."
"Qualys TotalCloud is cost-efficient and was selected for its value compared to other products."
"The pricing is comparable. It is built into our other product, so I cannot piecemeal it. It is a part of our subscription."
"I am not sure about the pricing. From what I understand, it is a bit on the higher side, but I do not have the exact numbers."
"The cost is high, but it meets our organizational needs."
"Qualys TotalCloud offers competitive pricing given its comprehensive suite of features, including integration, assessment, remediation, and detection capabilities, all within a single platform."
"Although Qualys TotalCloud is relatively expensive due to its unique automation features, its cost-effectiveness is rated an eight out of ten, with ten being the most costly."
"Companies generally buy this tool because the pricing is not that high."
"We're doing an annual subscription. There are additional expenses, but not within the confines of this platform."
report
Use our free recommendation engine to learn which Cloud Security Posture Management (CSPM) solutions are best for your needs.
831,265 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
19%
Financial Services Firm
15%
Manufacturing Company
9%
Government
5%
Computer Software Company
20%
Financial Services Firm
14%
Government
12%
Manufacturing Company
9%
Computer Software Company
13%
Manufacturing Company
10%
Insurance Company
9%
Retailer
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

What do you like most about PingSafe?
The dashboard gives me an overview of all the things happening in the product, making it one of the tool's best featu...
What is your experience regarding pricing and costs for PingSafe?
SentinelOne is relatively cheap. If ten is the most expensive, I would rate it a seven.
What needs improvement with PingSafe?
The areas with room for improvement include the cost, which is higher compared to other security platforms. The dashb...
What is your experience regarding pricing and costs for Qualys TotalCloud?
Qualys TotalCloud is cost-efficient and was selected for its value compared to other products.
What needs improvement with Qualys TotalCloud?
In TotalCloud, I would suggest improvements in policy checks to cater to various inventory types like VPCs, subnets, ...
What is your primary use case for Qualys TotalCloud?
We use TotalCloud for CSPM or Cloud Security Posture Management. We have integrated our cloud accounts with TotalClou...
What do you like most about Rapid7 InsightCloudSec?
The tool provides centralized visibility through dashboards and alerts, allowing customers to receive reports on clou...
What is your experience regarding pricing and costs for Rapid7 InsightCloudSec?
The pricing is good when compared to other leaders. It is cheaper.
What needs improvement with Rapid7 InsightCloudSec?
A couple of modules are missing when compared to other providers, specifically related to some IAM, and the login pie...
 

Also Known As

PingSafe
Qualys TotalCloud with FlexScan
DivvyCloud
 

Overview

 

Sample Customers

Information Not Available
Information Not Available
Fannie Mae, 3M, PizzaHut, Spotify, Autodesk, Discovery
Find out what your peers are saying about Qualys TotalCloud vs. Rapid7 InsightCloudSec and other solutions. Updated: December 2024.
831,265 professionals have used our research since 2012.