- Vulnerability assessment
- Asset management
- WAS
Technical Services Manager at a tech company with 10,001+ employees
It is very simple and yet an effective way to do vulnerability assessment.
What is most valuable?
How has it helped my organization?
Since this is a SaaS based solution, the vulnerability scan with the external scanners as well as the reporting has improved a lot. The reporting is very granular and you can please higher management with your reports.
What needs improvement?
None, as the product is great.
For how long have I used the solution?
I've used it for four years.
Buyer's Guide
Qualys VMDR
December 2024
Learn what your peers think about Qualys VMDR. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
824,067 professionals have used our research since 2012.
What do I think about the stability of the solution?
Stability of the product is very high, I have never seen it unavailable.
How are customer service and support?
Customer Service:
The support needs to improve a lot, their response is absolutely slow. I have had terrible experience with support over the years.
Technical Support:I would rate it great because of its improvement since I have had terrible experiences in the past.
Which solution did I use previously and why did I switch?
We used McAfee Vulnerability Manager/Foundstone and had to switch because this is a SaaS based solution and has more features/capabilities.
How was the initial setup?
The initial setup is very simple in terms of configuring the appliance.
What about the implementation team?
We installed it ourselves,
What other advice do I have?
I would definitely recommmend using this product, as this is very simple and yet an effective way to do vulnerability assessment.
.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Senior Vice President | Information Security at a financial services firm with 1,001-5,000 employees
Very intuitive, easy going and simple to use
Pros and Cons
- "Intuitive and easy to use."
- "Reports were lacking somewhat on the customization side."
What is our primary use case?
I used this solution for one of my clients and the primary use case was for the compliance mode and scanning. We are customers of Qualys and I am senior vice president information security.
What is most valuable?
I found the solution quite intuitive and easy going. I have worked with other similar tools and found this simple to use.
What needs improvement?
I felt hindered sometimes within reports in that they were lacking somewhat on the customization side in terms of making use of the data. The cloud user interface could be a little more responsive. It was a click and then a wait.
For how long have I used the solution?
I used this solution recently for about five months.
What do I think about the stability of the solution?
There were a couple of small bugs but the solution was stable.
What other advice do I have?
I would recommend this solution and rate it a nine out of 10.
Which deployment model are you using for this solution?
Private Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Qualys VMDR
December 2024
Learn what your peers think about Qualys VMDR. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
824,067 professionals have used our research since 2012.
Junior Information Security Analyst at Visma
Detects new hosts along with vulnerabilities
Pros and Cons
- "Monitors workstations and servers for vulnerabilities and creates reports."
- "Performs automated, regular scans in the network."
- "Detects new hosts along with vulnerabilities."
- "Improve the API speed."
- "Make some minimal dashboard improvements."
- "Improve the user interface."
What is our primary use case?
Our primary use case is to manage vulnerabilities, scan web applications, and report assets throughout the network. Also, we create reports based on this data.
How has it helped my organization?
- Tracks workstations and servers.
- Monitors workstations and servers for vulnerabilities and creates reports.
- Performs automated, regular scans in the network.
- Detects new hosts along with vulnerabilities.
What is most valuable?
The Qualys Agent is most valuable for getting insight into what is happening on what device with all its metadata.
What needs improvement?
- Improve the API speed.
- Make some minimal dashboard improvements.
- Improve the user interface.
For how long have I used the solution?
Less than one year.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Information Risk Analyst at a healthcare company with 1,001-5,000 employees
We've gained insight into vulnerabilities across our environment, but reports should be more customizable.
What is most valuable?
The vulnerability scanning feature is valuable.
How has it helped my organization?
QualysGuard has provided us with a valuable insight into vulnerabilities across our environment. Before the use of this product, we had no way of identifying or tracking vulnerabilities.
What needs improvement?
The reporting capabilities are good but I would like to be able to make more customized reports. In addition, I would like to be able to assign a numerical asset value to critical hosts.
For how long have I used the solution?
I've used it for six years.
What was my experience with deployment of the solution?
No issues encountered, it went very smoothly.
What do I think about the stability of the solution?
No issues encountered.
What do I think about the scalability of the solution?
No, as it's very easy to add additional hosts.
How are customer service and technical support?
Customer Service:
8/10.
Technical Support:8/10.
Which solution did I use previously and why did I switch?
We didn't use a previous solution.
How was the initial setup?
It was straightforward.
What about the implementation team?
It was implemented in-house.
Which other solutions did I evaluate?
We also looked at Nessus.
What other advice do I have?
Make sure you take advantage of authenticated scans and it is also very helpful if you have a complete server inventory.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Consultant at a media company with 51-200 employees
Enables us to check the validity of legacy applications, infrastructure, and simple data operating systems
Pros and Cons
- "The initial setup was good. We didn't have any problems with it."
- "The ability to manage user accounts and give rights to the operator to know about abnormalities of applications is something that needs improvement."
What is our primary use case?
I use Qualys to review the validity of legacy applications, infrastructure, and simple data operating systems.
What needs improvement?
The ability to manage user accounts and give rights to the operator to know about abnormalities of applications is something that needs improvement.
The pricing is also expensive.
For how long have I used the solution?
I have been using Qualys for four years.
What do I think about the stability of the solution?
It's stable.
How are customer service and technical support?
I haven't needed to use technical support.
How was the initial setup?
The initial setup was good. We didn't have any problems with it.
What other advice do I have?
I would rate Qualys VM a ten out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Senior System Engineer at a comms service provider with 1,001-5,000 employees
It's easy to download/install the correct patch, but the reporting could be improved.
What is most valuable?
The feature where the solutions to issues are mentioned in the reports.
How has it helped my organization?
It's easy to reach the current location and download/install the correct patch.
What needs improvement?
The feature where the solutions to issues are mentioned in the reports could be improved.
For how long have I used the solution?
I've been using it for over three years.
What was my experience with deployment of the solution?
No issues encountered.
What do I think about the stability of the solution?
No issues encountered.
What do I think about the scalability of the solution?
No issues encountered.
How are customer service and technical support?
Customer Service:
7/10.
Technical Support:5/10,
Which solution did I use previously and why did I switch?
No previous solution was used.
What about the implementation team?
It was implemented by the vendor.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Customer Technical Leader for Galeries Lafayette at a tech company with 10,001+ employees
The GUI needs work, but the vulnerabilities are kept up to date.
What is most valuable?
The top one for me is that the vulnerabilities are kept up to date.
How has it helped my organization?
It has reduced the cost of ownership for the engineers who can launch scans on the customers’ networks.
What needs improvement?
I’m convinced it could be possible to do a simpler interface.
For how long have I used the solution?
I used it for about four years.
What was my experience with deployment of the solution?
No issues encountered.
What do I think about the stability of the solution?
There is an issue with the web browser, but it's not an issue with the product itself.
What do I think about the scalability of the solution?
No issues encountered.
How are customer service and technical support?
Customer Service:
9/10.
Technical Support:8/10.
Which solution did I use previously and why did I switch?
I switched due to the cost.
How was the initial setup?
It was simple because it's only used for external scans.
What's my experience with pricing, setup cost, and licensing?
You have to find the best solution regarding functions and cost.
Which other solutions did I evaluate?
- Tripwire
- Nessus
- Accunetix
- OIpenvas
What other advice do I have?
- Take your time
- Study all the functionalities of the product
- Try to set it up in a lab first before your production environment.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Senior IT Security Analyst at a tech services company with 501-1,000 employees
The IT infrastructure needs work but WAF has improved our vulnerability identification.
What is most valuable?
WAF integration is valuable.
How has it helped my organization?
We can now perform vulnerability scans with WAF integration. The WAF has improved the vulnerability identification and reports to the SOC and CSO.
What needs improvement?
The IT infrastructure, especially server administration, needs to be improved.
For how long have I used the solution?
I've used it for two years.
What was my experience with deployment of the solution?
There was only one related, and that need work on our technology. As the solution is cloud based, we needed to adapt our internal policies.
What do I think about the stability of the solution?
There were no issues.
What do I think about the scalability of the solution?
This been done without a problem.
How are customer service and technical support?
Customer Service:
It's good.
Technical Support:It's good.
Which solution did I use previously and why did I switch?
There was no previous solution, but I did execute several POCs.
How was the initial setup?
It was a regular setup for the configuration, but the official training was necessary.
What's my experience with pricing, setup cost, and licensing?
We also looked at Nessus and GFI Languard.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Download our free Qualys VMDR Report and get advice and tips from experienced pros
sharing their opinions.
Updated: December 2024
Product Categories
Vulnerability Management IT Asset Management Configuration Management Databases Container Security Risk-Based Vulnerability ManagementPopular Comparisons
Tenable Nessus
Tenable Security Center
Tanium
Tenable Vulnerability Management
SentinelOne Singularity Cloud Security
Orca Security
Pentera
Acunetix
JFrog Xray
Lacework FortiCNAPP
Skybox Security Suite
Check Point CloudGuard CNAPP
Trend Vision One - Cloud Security
Microsoft Defender Vulnerability Management
Buyer's Guide
Download our free Qualys VMDR Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Qualys VM vs Tenable Nessus: Comparison
- How does Tenable Nessus compare with Qualys VM?
- How does Pentera compare with Qualys VMDR?
- What are the main differences between Qualys VMDR and Tenable Nessus?
- How inadvisable is it to use a single vulnerability analysis tool?
- What are the benefits of continuous scanning for vulnerability management?
- When evaluating Vulnerability Management, what aspect do you think is the most important to look for?
- What is a more effective approach to cyber defense: risk-based vulnerability management or vulnerability assessment?
- What are the main KPIs that need to be implemented to have better posture in vulnerability projects?
- Which is the best vulnerability scanner tool?