Try our new research platform with insights from 80,000+ expert users
Reviewer214 - PeerSpot reviewer
Senior Information Security Engineer at a financial services firm with 501-1,000 employees
Real User
It is a stable product. Tech support is quick to respond to any inquiries.
Pros and Cons
  • "There are fewer false positives when using this solution."
  • "Tech support is helpful."
  • "I do not like that all of the data is stored on the cloud."

What is our primary use case?

It mainly scans the model against all of our online websites.

How has it helped my organization?

There are fewer false positives when using this solution. We are also cutting the need for news monitoring with this solution.

What is most valuable?

We find all of the features useful. 

What needs improvement?

One note for room for improvement is that all of the data is stored on the cloud. I think it would be better if they came up with a big box that could store the data and collect data from, it would be a huge improvement.

Buyer's Guide
Qualys VMDR
January 2025
Learn what your peers think about Qualys VMDR. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,265 professionals have used our research since 2012.

For how long have I used the solution?

Three to five years.

What do I think about the stability of the solution?

It is an extremely impressive and stable product. I would give it a 99% out of 100%. It is very close to being perfect.

What do I think about the scalability of the solution?

I have had no issues with scalability. Initially, we had some issues with the dashboard, but eventually, it set and stabilized. There was an issue with the data dashing between the two models initially, but it was resolved.

How are customer service and support?

The tech support is helpful. When we initially open a ticket, we get response within five minutes. Then, they open a case and we receive input from tech support within 24-48 hours with a Q-ID.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer1405830 - PeerSpot reviewer
Technical Architect at a outsourcing company with 1,001-5,000 employees
Real User
Great vulnerability management but doesn't pick up every vulnerability
Pros and Cons
  • "Qualys VM's best feature is vulnerability management."
  • "Qualys VM's scanner doesn't pick up every vulnerability, so we have to use multiple scanners to cover that gap."

What is most valuable?

Qualys VM's best feature is vulnerability management.

What needs improvement?

Qualys VM's scanner doesn't pick up every vulnerability, so we have to use multiple scanners to cover that gap. Their reporting could also be more user-friendly. In the next release, I would like Qualys to include basic policy and compliance checks in the basic licensing. 

For how long have I used the solution?

I've been using Qualys VM for almost two years.

What do I think about the stability of the solution?

Qualys VM is quite stable - we've had no problems with it.

What do I think about the scalability of the solution?

Qualys VM's scalability depends on the license that you use.

Which solution did I use previously and why did I switch?

Previously we used Nessus, but only Qualys does intrusive scanning.

What about the implementation team?

We used an in-house team.

What's my experience with pricing, setup cost, and licensing?

An annual license for a single scanner costs around $3,000.

What other advice do I have?

Qualys VM is a really good tool for vulnerability scanning, and it has different sets of profiles that can be utilized for your own requirements. I would rate Qualys VM as seven out of ten.

Which deployment model are you using for this solution?

Private Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Qualys VMDR
January 2025
Learn what your peers think about Qualys VMDR. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,265 professionals have used our research since 2012.
PeerSpot user
ITSM & AntiFraud Consultant at a tech company with 51-200 employees
Real User
Vulnerability management is the most valuable feature but it would be good if they could provide an internal computing appliance.
Pros and Cons
  • "Vulnerability management is the most valuable one and it’s a must in every organization."
  • "One of the biggest issues from the clients' perspective is that all Qualys computing is on the cloud."

What is most valuable?

From my point of view all the Qualys products are valuable. From the clients' perspective, I believe vulnerability management is the most valuable one and it’s a must in every organization. After the client realize the risks from outside, and that the vulnerabilities are real, a proper compliance policy implementation using Qualys Policy Compliance (I'm using v8.4), the second product needed in any infrastructure, can be done. If the organization has public websites, Web Application Scanning (I'm using v4.1) is the third valuable product needed in an organization.

How has it helped my organization?

After the first scan of the servers at all the POCs QualysGuard discovered many vulnerabilities that are grouped from low to high impact. The ability to use asset management to scan the grouped servers from the vulnerability management feature with the policy compliance engine helps the security officer to perform the daily/monthly tasks faster and make them more organized.

What needs improvement?

One of the biggest issues from the clients' perspective is that all Qualys computing is on the cloud.

As last month ( this is when I found out) Qualys offers a On-Premise instalation for it's customers.

https://www.qualys.com/enterprises/qualysguard/pri...

The issue with the private cloud is that is costs very much for a small firm.


For how long have I used the solution?

I have been using QualysGuard since 2012, and I have followed the certification from Qualys in class. After that, I implemented it for one of our clients, and did some POCs using Qualys. In the last month I had another PoC with Qualys and the client looks interested.

What was my experience with deployment of the solution?

need support from sysadmin to deploy the ovf file.

What do I think about the stability of the solution?

Qualys appliances are based on Linux OS, and they are very stable. I didn’t encounter any stability issues.

What do I think about the scalability of the solution?

The big advantage of using the virtual appliances is that you can increase the allocated hardware if you need more resources.

How are customer service and technical support?

Customer Service:

The customer service level is very high. All the requests made to the reseller were fulfilled in a very short time.

Technical Support:

We didn’t need to use Qualys technical support as the product was very stable, and our knowledge of the product was enough to fulfil all the clients needs.

Which solution did I use previously and why did I switch?

I have used both Nessus and Rapid 7 Nexpose. I am working as a security consultant and I need to know the big players so I could present to my clients the pluses and minuses of the products they might choose.

How was the initial setup?

Qualys initial setup is straightforward and if you follow the manual you don’t have any problems. You receive the credentials, login to the Qualys website, download the virtual appliance, configure the IP, and, after defining the credentials and the assets, you can start scanning your environment. For the hardware appliance you have to connect it to the network and after the configuration you can start the scanning.

What about the implementation team?

I was part of the consultant team that implemented this solution to the client. We didn't have any complaints from him, and he used us to implement the rest of Qualys' components.

What's my experience with pricing, setup cost, and licensing?

Usually every implementation is different and the quote is in function of number of assets.

Which other solutions did I evaluate?

The clients are usually evaluating the top three vendors from Gartner. From my clients side, the vendors used in evaluation were Nexpose, McAfee Vulnerability Manager and Nessus. Also I have tried the open source VM OpenVAS

What other advice do I have?

Follow the vendor provided steps, and you will not have any problems during the initial implementation. If you don’t have experience with server policies, use a consultant that will be able to identify your business needs.

Disclosure: My company has a business relationship with this vendor other than being a customer: We are a QualysGuard partner
PeerSpot user
Alireza Ghahrood - PeerSpot reviewer
Alireza GhahroodConsultant & Instructor -Cyber Security,GovernanceRIskCompliance (CISO as a Services) at Independent
Top 10Real User

Thanks 4 share

See all 2 comments
PeerSpot user
Shared Information Security Officer at a university with 1,001-5,000 employees
Real User
It is a totally vendor-managed appliance. It distributes administration functions based on access roles.

What is most valuable?

  • Totally vendor-managed appliance
  • Highly scalable and deployable portal interface
  • Ability to easily distribute administration functions based on access roles

How has it helped my organization?

It provides fully automated internal and external vulnerability management.

What needs improvement?

Streamline PCI integration and attestation.

For how long have I used the solution?

I have used it for five years.

What do I think about the scalability of the solution?

I have not encountered any scalability issues.

How are customer service and technical support?

Technical staff are excellent.

Which solution did I use previously and why did I switch?

We previously used Rapid 7. The product was not staying current with shifting trends, sales staff were pushy and management were arrogant.

How was the initial setup?

Initial setup was simple.

What's my experience with pricing, setup cost, and licensing?

Negotiate for the pricing model that fits your budget. The vendor is willing to customize pricing.

Which other solutions did I evaluate?

Before choosing this product, we evaluated Rapid 7, Nessus.

What other advice do I have?

Take your time and have each vendor set up an actual proof of concept, rather than just relying on a demo. Get your network and support staff engaged in the process early on because they will be instrumental in deployment and support. Know what you’re trying to accomplish.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user297117 - PeerSpot reviewer
Information Risk Analyst at a healthcare company with 1,001-5,000 employees
Vendor
We've gained insight into vulnerabilities across our environment, but reports should be more customizable.

What is most valuable?

The vulnerability scanning feature is valuable.

How has it helped my organization?

QualysGuard has provided us with a valuable insight into vulnerabilities across our environment. Before the use of this product, we had no way of identifying or tracking vulnerabilities.

What needs improvement?

The reporting capabilities are good but I would like to be able to make more customized reports. In addition, I would like to be able to assign a numerical asset value to critical hosts.

For how long have I used the solution?

I've used it for six years.

What was my experience with deployment of the solution?

No issues encountered, it went very smoothly.

What do I think about the stability of the solution?

No issues encountered.

What do I think about the scalability of the solution?

No, as it's very easy to add additional hosts.

How are customer service and technical support?

Customer Service:

8/10.

Technical Support:

8/10.

Which solution did I use previously and why did I switch?

We didn't use a previous solution.

How was the initial setup?

It was straightforward.

What about the implementation team?

It was implemented in-house.

Which other solutions did I evaluate?

We also looked at Nessus.

What other advice do I have?

Make sure you take advantage of authenticated scans and it is also very helpful if you have a complete server inventory.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user254967 - PeerSpot reviewer
Linux Administrator at a comms service provider with 501-1,000 employees
Vendor
The users on the forums are very knowledgeable, but the reporting in the solution is lacking.

What is most valuable?

The reporting and vulnerability analysis features.

How has it helped my organization?

Vulnerability scans are easily managed and maintained using Qualys. What used to be a manual process is now automatic. When we have an issue, I can easily see what production systems are affected and I can easily pinpoint a solution to mitigate the issue.

What needs improvement?

The reporting is lacking a little, and it would be nice to have reports sent via email. Often times we have to manually generate the reports after a vulnerability is fixed and a scan has to be re-run.

For how long have I used the solution?

I've used it for three years.

What was my experience with deployment of the solution?

We did not.

What do I think about the stability of the solution?

Our Qualys box is hardware and it's very easy to set up and maintain. It's very little maintenance, and the most time consuming part is setting up everything initially, such as what subnets you want to scan, what reports you want to run, etc.

What do I think about the scalability of the solution?

We have over 15,000 devices and had no issues with scaling up our Qualys infrastructure.

How are customer service and technical support?

Customer Service:

I have never had to interact with them. I get most of the information on the forums, and even there the responses are lighting fast. As far as actually talking to someone, I personally have never had to speak to Qualys support.

Technical Support:

It's great. The users on the forums are very knowledgeable and eager to help. If I need a quick answer I will always get one from the support forum.

Which solution did I use previously and why did I switch?

We used Nessus before. It was a manual process and very time consuming. I like Nessus, but it was very tedious to get it to function automatically.

How was the initial setup?

There are always complexities to every setup. I think the biggest issue was the learning curve. Having to learn all the new pieces and how they fit into our environment was probably the single biggest hurdle we had to face.

What about the implementation team?

We did it in-house.

Which other solutions did I evaluate?

We looked at Metasploit Expose but the price was too much for what we needed.

What other advice do I have?

Do your research and see how this product would best fit into your environment.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Director Transformación Digital at oesia
Real User
A feature-rich, complete product, and the multilingual technical support is good
Pros and Cons
  • "I like Qualys because it is a very complete product, more so than Tenable."

    What is our primary use case?

    We use this product for vulnerability management.

    What is most valuable?

    I like Qualys because it is a very complete product, more so than Tenable. It has vast capabilities.

    For how long have I used the solution?

    We have been working with Qualys VM for a very short time, perhaps six months.

    What do I think about the stability of the solution?

    This is a stable solution.

    What do I think about the scalability of the solution?

    Scalability-wise, this is a good product.

    How are customer service and technical support?

    The technical support is very good and they have it both in Spanish and English.

    Which solution did I use previously and why did I switch?

    We are also working with Tenable SC. Qualys is both more complete and for us, better in terms of pricing.

    How was the initial setup?

    For a beginning, the initial setup is complex. You have to have some knowledge for setting it up and using it.

    What's my experience with pricing, setup cost, and licensing?

    The price of Qualys for us is better than Tenable, although that is only because we are partners. The retail price of Qualys is higher than that of tenable. The pricing and licensing for Qualys could be improved.

    What other advice do I have?

    Overall, this is a good product and I recommend it, mainly because of the capabilities and the management using a single console. I can even create a calendar for activities from the main screen.

    I would rate this solution a nine out of ten.

    Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
    PeerSpot user
    it_user268167 - PeerSpot reviewer
    Senior System Engineer at a comms service provider with 1,001-5,000 employees
    Vendor
    It's easy to download/install the correct patch, but the reporting could be improved.

    What is most valuable?

    The feature where the solutions to issues are mentioned in the reports.

    How has it helped my organization?

    It's easy to reach the current location and download/install the correct patch.

    What needs improvement?

    The feature where the solutions to issues are mentioned in the reports could be improved.

    For how long have I used the solution?

    I've been using it for over three years.

    What was my experience with deployment of the solution?

    No issues encountered.

    What do I think about the stability of the solution?

    No issues encountered.

    What do I think about the scalability of the solution?

    No issues encountered.

    How are customer service and technical support?

    Customer Service:

    7/10.

    Technical Support:

    5/10,

    Which solution did I use previously and why did I switch?

    No previous solution was used.

    What about the implementation team?

    It was implemented by the vendor.

    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    Buyer's Guide
    Download our free Qualys VMDR Report and get advice and tips from experienced pros sharing their opinions.
    Updated: January 2025
    Buyer's Guide
    Download our free Qualys VMDR Report and get advice and tips from experienced pros sharing their opinions.