Try our new research platform with insights from 80,000+ expert users
Eshan Kshirsagar - PeerSpot reviewer
retired at a consultancy with 10,001+ employees
Real User
Has immensely helped us reduce active vulnerabilities
Pros and Cons
  • "It is a cloud-native app that integrates with both IaaS and SaaS. It seamlessly integrates with other platforms."
  • "I would definitely recommend Qualys TotalCloud to other customers."
  • "The patching process with Qualys Patch Management, which is part of TotalCloud, does not cover installing certain prerequisites on the servers or workstations. This shortcoming means we must rely on SCCM when any service stack updates or additional prerequisites are needed."
  • "The patching process with Qualys Patch Management, which is part of TotalCloud, does not cover installing certain prerequisites on the servers or workstations."

What is our primary use case?

Our primary use case is to create an automated workflow that involves tagging assets, creating remediation policies, and automated patching. This process is intended to cover everything from asset discovery to remediation.

How has it helped my organization?

Qualys TotalCloud helps us with patching. There are certain limitations with SCCM when it comes to patching. A request needs to be created, and then it takes a lot of time, whereas Qualys TotalCloud, specifically in terms of remediation, is pretty much touchless, so zero-touch patching is what we have been trying to achieve. It helps us greatly in patching certain vulnerabilities that, for example, are Chrome-related. We do not have to depend on any other tool for patching.

Discovery is automated here. We have scheduled scans that discover. We have built an automation for that.

Qualys TotalCloud provides unified vulnerability and threat assessment across both IaaS and SaaS. We are using it more for SaaS environments. We are using it in Azure as well so that we can get a good security posture for it. We have a different team for IaaS.

Qualys TotalCloud has immensely helped us reduce active vulnerabilities. It has greatly affected our ability to build dashboards because we use it through the API. We have generated a lot of content and dashboards based on API integration, which provides us with up-to-date metrics. We have deployed cloud agents across Linux and Windows workstations. We get pretty much up-to-date data from Qualys scans. We also have vault integration. We have integrated it with CyberArk Vault. A lot of features have been helpful.

We are able to see the risks associated. It helps us prioritize based on the risk score. It helps us identify ground rules and remediate risks on them.

It has saved a lot of time and effort, but I do not have any metrics.

The TruRisk Insights feature gives us a good risk posture, but it is not yet embedded in our automation. We have built the GUI dashboards to view the risks and prioritize them.

The risk analysis is good. We are ingesting a lot of resources or products to see how we can improve the accuracy. The risk score helps us with accurate prioritization. There can be a scenario where something with a high vulnerability score might contribute to lower risk.

It has helped us in prioritizing the remediation and preparing better dashboards for our CISO's review.

What is most valuable?

It is a cloud-native app that integrates with both IaaS and SaaS. It seamlessly integrates with other platforms.

The features we use the most include zero-touch assessment for quick patch creation and deployment. Every time any vulnerabilities are identified, we can create quick patches and deploy them. Those are the ones that we basically use.

We are also trying to implement a risk-based program, although it is currently limited.

What needs improvement?

The patching process with Qualys Patch Management, which is part of TotalCloud, does not cover installing certain prerequisites on the servers or workstations. This shortcoming means we must rely on SCCM when any service stack updates or additional prerequisites are needed.

Buyer's Guide
Qualys TotalCloud
February 2025
Learn what your peers think about Qualys TotalCloud. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
838,713 professionals have used our research since 2012.

For how long have I used the solution?

I was a part of Qualys previously. I have used the whole Qualys VMDR suite for almost five years there and three years here. It has been a year or so with TotalCloud.

What do I think about the stability of the solution?

The stability of the solution is strong. I would rate it a nine out of ten for stability.

What do I think about the scalability of the solution?

It is absolutely scalable, and I would rate its scalability as nine out of ten.

We have multiple locations. The assets are spread across the globe, so we have deployments at multiple locations.

We have a team of five people working on this project, but we have many other projects and about 200 to 300 people working on TotalCloud.

How are customer service and support?

Support is good overall. While they do take some time to assess issues, we are generally satisfied with the support received. 

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We have used Qualys for this project since its inception, and we did not use a different solution beforehand.

How was the initial setup?

The deployment was easy. On the infrastructure side, we have added agents to the base image itself. Automated scanning using discovery features helps ensure seamless operation.

We use Azure and OCI Cloud. The documentation provided was clear for our cloud setup. It was easy to install our scanners. The networking was set up by our cloud team, so it was easy to set it up.

We follow the whole change management request process here. The change request needs to be raised two weeks prior to installing the agents. There are a lot of processes involved where a sign-off is made for the agent to be deployed. It takes about two weeks for cloud agents to be deployed. For scanning through existing scanners, since the environment is already built up, we can scan within hours. That is not an issue. Scanner-based scanning is easy. We can scan seamlessly from the cloud and on-prem. Once an agent is a part of the base image, it is provisioned within hours. If we have to upgrade the agent, it goes through a whole change management process, which takes around two weeks.

It does require maintenance because we have to update our agents regularly. That is done as a part of our change management process. Its maintenance includes cleanups. There could be certain stale entries. We have to remove those stale entries in Qualys because there is no mechanism built in right now to clean them.

What other advice do I have?

I would definitely recommend Qualys TotalCloud to other customers. The accuracy of vulnerability detection signatures and the over-the-air updates for both scanners and agents ensure that everything is kept up-to-date.

I would rate Qualys TotalCloud a ten out of ten.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Flag as inappropriate
PeerSpot user
Cyber Security Consultant at Systal Technology Solutions
Consultant
Complete insights and risk score help with efficient threat management
Pros and Cons
  • "Vulnerability and threat detection and assessment of the criticality of the vulnerabilities exposed are most valuable."
  • "I found the initial setup user-friendly."
  • "In a future release, I suggest that zero-day vulnerabilities should be predicted in advance using AI technologies. The system is not 100% secure yet, so proactive threat hunting could be enhanced to be more proactive than the current system."
  • "The system is not 100% secure yet, so proactive threat hunting could be enhanced to be more proactive than the current system."

What is our primary use case?

I use it for scanning the complete environment at an enterprise level. I need to check all the systems to ensure they are secure, and if there are any known vulnerabilities, whether the vulnerabilities are being addressed or any on-demand scan needs to be performed through Qualys.

How has it helped my organization?

FlexScan helps with complete insights, and some AI-driven features are also available in TotalCloud. We use it for SaaS applications such as Microsoft 365.

TotalCloud provides unified vulnerability and threat assessment across both IaaS and SaaS. We have information about any unpatched versions or out-of-support versions. It is cloud-integrated, so all the CVEs and known signatures are integrated, and it can automatically address the issues.

The TruRisk Insights feature has basic vulnerability detection and AI integration. It is like a risk management tool. It provides all security threats with a risk score to the team. That helps to prioritize the threats and remediate them.

The time efficiency depends on the scale of the environment. For example, in large enterprises where hosts are cloud-hosted, one can see some time reductions compared to other scanners.

What is most valuable?

Vulnerability and threat detection and assessment of the criticality of the vulnerabilities exposed are most valuable.

What needs improvement?

In a future release, I suggest that zero-day vulnerabilities should be predicted in advance using AI technologies. The system is not 100% secure yet, so proactive threat hunting could be enhanced to be more proactive than the current system.

For how long have I used the solution?

I have been using Qualys TotalCloud for the past five to six years.

What do I think about the stability of the solution?

The stability is good. It is a reliable tool. It does not crash, and in my experience, this tool has never gone down. The downtime is minimal, and when it occurs, it is usually because of known maintenance.

What do I think about the scalability of the solution?

The scalability level is good compared to other tools. It is scalable and extendable.

How are customer service and support?

I have not contacted them, but I have heard that their technical support is as good as other vendor solutions such as Splunk or QRadar. However, it is not as top-notch as Microsoft. Microsoft provides better vendor support and deals with issues on a high priority.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

I have used Nessus as a previous solution. Qualys TotalCloud is more user-friendly than Nessus, so I prefer Qualys TotalCloud.

How was the initial setup?

I found the initial setup user-friendly. We had the user manual handy. It was like a new learning experience, but it was user-friendly to integrate and implement. It is not difficult. Within a few days, we became accustomed to the console.

In terms of maintenance, though the vendor support is there, we do need the scaling whenever there is a new release or version. We have a maintenance mode window out of business hours to go ahead with the upgrade of the product.

What about the implementation team?

The size of the implementation team depends on the scale of the environment and how many assets we are going to integrate. It depends on whether it is a large-scale or small-scale environment. Generally, a team of three to five members is enough for enterprise scale.

What other advice do I have?

New users should know about the architecture of Qualys TotalCloud and its components and backend infrastructure. Understanding vulnerability detection, AI, threat intelligence, attack vectors, exposure, and risk management is key. They should also read the full user manual and insights from IT professionals. They should learn how to use this solution for threat management.

I would rate Qualys TotalCloud an eight out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
PeerSpot user
Buyer's Guide
Qualys TotalCloud
February 2025
Learn what your peers think about Qualys TotalCloud. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
838,713 professionals have used our research since 2012.
Information Technology Security Analyst at a financial services firm with 10,001+ employees
Real User
Top 20
Provides extensibility, custom controls, and good overview
Pros and Cons
  • "The most valuable feature is extensibility."
  • "I would like the ability to disable certain default built-in policies as they can be misleading when creating dashboards. That is the top one."

What is our primary use case?

We use Qualys TotalCloud for compliance monitoring and compliance checking.

How has it helped my organization?

TotalCloud provides written explanations to help guide remediation paths and eliminate cyber risk. It is very satisfactory.

I could see its benefits immediately after the deployment. I was using another product, and I was trying to switch over to this product.

TruRisk Insights provides a good view of the situation from different perspectives, such as the policy compliance side, the vulnerability side, and a few others. It gives us a better view of what is going on versus just piecemeal from one UI to another and then trying to make sense and sorting things or combining data together.

TruRisk Insights feature found a small number of assets with high vulnerability scores. I reported them to the owner, and then they are going to work on it.

TruRisk Insights are a good indicator, but long term, the managers still want to use the ServiceNow integration. We have this in our back pocket to verify.

What is most valuable?

The most valuable feature is the extensibility. I can create custom controls and rely on Qualys TotalCloud to provide me with updated controls as they come from CS benchmarks.

What needs improvement?

I have already put in a few feature requests. There are features that I would like to have. I would like the ability to disable certain default built-in policies as they can be misleading when creating dashboards. That is the top one. 

Additionally, I would like the ability to generate reports on a schedule and send them via email to the scheduler. 

It is a bit cumbersome to apply some of the features built into policy compliance.

TotalCloud provides a single, prioritized view of risk, but it can be better. I was hoping that they would integrate TruRisk into it, but that is forthcoming. I have already put in the request a while back to add TruRisk, and they are working on it.

For how long have I used the solution?

I have been using the solution for around two years.

What do I think about the stability of the solution?

I have not seen any events like lagging, crashing, or downtime.

What do I think about the scalability of the solution?

It is very scalable, and I would rate it a ten out of ten for scalability.

How are customer service and support?

I usually do not have to contact support. I last contacted them a month or two months ago. They usually respond within 48 hours. I can always escalate as needed. It is not an issue. Overall, their support is top-notch.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I used Dome9 which is under Check Point. I switched to TotalCloud because of better extensibility.

How was the initial setup?

We had some challenges with permissions, but other than that, it was fine. Its implementation took about 60 days.

It requires maintenance on our end. We need to maintain the permissions and the connections to whatever AWS accounts we need to have scanned.

What about the implementation team?

We had an in-house team involved along with Qualys support. Three people were required for the deployment.

What's my experience with pricing, setup cost, and licensing?

The pricing is comparable. It is built into our other product, so I cannot piecemeal it. It is a part of our subscription.

What other advice do I have?

New users should have a deeper understanding of how to use the cloud API because the extensibility is based on that. If they do not understand how to use the API, it would not be effective for them.

TotalCloud provides unified vulnerability and threat assessment across both IaaS and SaaS, but we do not use that. We do not have a use case for that.

I would rate TotalCloud an eight out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Flag as inappropriate
PeerSpot user
reviewer2540010 - PeerSpot reviewer
IT Engineer at a consultancy with 501-1,000 employees
Real User
Top 20
Helps identify vulnerabilities, provides a single view, and reduces costs
Pros and Cons
  • "Its excellent graphical interface makes the scanning process simple."
  • "Qualys TotalCloud needs to enhance its scanning capabilities in the IP domain, as it currently lacks the functionality to resolve IPs to their corresponding domain names."

What is our primary use case?

We utilize Qualys TotalCloud to conduct DNS, IP, and WOS scans and identify system vulnerabilities.

How has it helped my organization?

Qualys TotalCloud helps identify vulnerabilities by providing written explanations to help guide remediation paths and eliminate cyber risk.

The explanations are great compared to the visualizations of attack paths.

The benefits of Qualys TotalCloud are significant. It lists all vulnerabilities, allowing us to patch them effectively. This safeguards the entire company and its environment, offering comprehensive protection.

Qualys TotalCloud provides a single prioritized view of risk.

Qualys TotalCloud has saved us 30 to 40 percent of time and costs.

The TrueRisk Insights feature helps us keep our environment safe and to mitigate vulnerabilities.

TrueRisk Insights found a smaller number of assets with high vulnerability scores.

Using information from TrueRisk Insights, we informed our clients about vulnerabilities and immediately resolved them.

What is most valuable?

Qualys TotalCloud is convenient, and we can perform scans with it. Its excellent graphical interface makes the scanning process simple.

What needs improvement?

Qualys TotalCloud needs to enhance its scanning capabilities in the IP domain, as it currently lacks the functionality to resolve IPs to their corresponding domain names.

For how long have I used the solution?

I have been using Qualys TotalCloud for one year.

What do I think about the stability of the solution?

I would rate the stability of Qualys TotalCloud eight out of ten.

What do I think about the scalability of the solution?

I would rate the scalability of Qualys TotalCloud eight out of ten.

How are customer service and support?

We spent a couple of hours explaining an issue to the technical support and did not receive a proper resolution.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

We previously used Qualys PCI DSS.

What was our ROI?

Qualys TotalCloud has significantly saved us time and resources. It is doing the work of three people.

What's my experience with pricing, setup cost, and licensing?

Qualys TotalCloud is expensive.

What other advice do I have?

I would rate Qualys TotalCloud eight out of ten.

Qualys TotalCloud is deployed in one location, and we have two users.

No maintenance is required.

I recommend Qualys TotalCloud to others. It helps identify vulnerabilities present in the system and simplifies our work.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
PeerSpot user
Arshad Nr - PeerSpot reviewer
Senior Security Consultant at CyberNxt Solutions LLP
Real User
Top 5
Makes cloud and asset management easy
Pros and Cons
  • "With TotalCloud, we can scan through the API. If we are not able to deploy cloud agents on the machine, we can use the API."
  • "I would definitely recommend it because it is easy to handle any cloud resources."
  • "It is already perfect, but they can bring some newer dashboards and customization options for the dashboard. It would be great to be able to include on-prem assets on the dashboard."

What is our primary use case?

Qualys TotalCloud is very helpful for me for auditing purposes.

How has it helped my organization?

Qualys TotalCloud has helped us with centralized cloud management. We have Azure and AWS machines on the cloud. Previously, we were facing a lot of issues with vulnerability remediation. With Qualys TotalCloud, we can see vulnerabilities and misconfigurations and provide them to the remediation team with a timeline for fixing. Previously, we were unable to do that. It has helped us identify and plan the timeframe for the updates.

Qualys TotalCloud helped us show the attack vectors and their criticality to the client. The client could take immediate action. Previously, the client could not understand how critical an issue was. This automation is beneficial for us compared to the manual process.

Qualys TotalCloud has made asset management easy. We have many cloud resources. Previously, the cloud team was not aware of all of the resources. It is pretty easy now because we have visibility into the assets hosted on the cloud.

Qualys TotalCloud provides a single, prioritized view of risk. It reduces the work needed to combine multiple sources to prioritize risk. We can see them categorized based on the criticality which saves time. Previously, it would take us a week to manage, investigate the issues, and configure three or four cloud resources. We can now do that in two days. Once we have the report, we need to analyze it and showcase it to the client. They can then start the remediation.

Over three months, we have seen 20% to 25% improvement in the security posture. It identified about 70% misconfigurations which have now been reduced to 20%.

What is most valuable?

With TotalCloud, we can scan through the API. If we are not able to deploy cloud agents on the machine, we can use the API. This feature is quite nice. 

What needs improvement?

It is already perfect, but they can bring some newer dashboards and customization options for the dashboard. It would be great to be able to include on-prem assets on the dashboard. For example, when I am hosting my own server to the public, I should be able to segregate the dashboard to monitor that particular server.

For how long have I used the solution?

I have been using Qualys TotalCloud for about three months.

What do I think about the stability of the solution?

Initially, we faced some performance issues. After implementing it, I noticed it took a lot of time to load. However, it was not an issue from the Qualys side, so we waited on our end. After logging out and in again, the issue was resolved, and it became perfectly smooth. The initial gathering of data seems to have contributed to the delay.

What do I think about the scalability of the solution?

We have not scaled it yet.

How are customer service and support?

We did not need any support so far because TotalCloud has been working well. However, in the future, I might require support, and I expect good assistance from the company. It should not take much time.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

This is the first time I am working on a cloud security platform like this. 

How was the initial setup?

We did not encounter complexity because TotalCloud supports AWS. We do not need much customization or configuration either. The options for configuration are user-friendly. It took around two weeks to complete, with some management approval delays contributing to the timeframe.

Its maintenance is easy. We do not need more utilization or resources. We currently have 7 applications, and we will be onboarding 17 applications soon.

What about the implementation team?

There are five members in our team. Three of us were deploying and configuring the cloud setup, while others managed tasks, analyzed errors, and showcased the progress to the client.

What's my experience with pricing, setup cost, and licensing?

Its price seems higher compared to other tools, but it is worth it. If they could adjust the pricing and make it comparable with other tools, that would be great.

Which other solutions did I evaluate?

We evaluated WIZ cloud security. It has a limited number of dashboards, and customization is not possible. We have to rely on the data showcased on the dashboards, whereas Qualys TotalCloud shows us a lot of parameters and data which makes it easier to show information to the management. 

What other advice do I have?

I would definitely recommend it because it is easy to handle any cloud resources. Asset management is possible, and we can effectively do an audit of cloud resources. 

I would rate Qualys TotalCloud a ten out of ten.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: MSP
Flag as inappropriate
PeerSpot user
Buyer's Guide
Download our free Qualys TotalCloud Report and get advice and tips from experienced pros sharing their opinions.
Updated: February 2025
Buyer's Guide
Download our free Qualys TotalCloud Report and get advice and tips from experienced pros sharing their opinions.