I used this solution for one of my clients and the primary use case was for the compliance mode and scanning. We are customers of Qualys and I am senior vice president information security.
Senior Vice President | Information Security at a financial services firm with 1,001-5,000 employees
Very intuitive, easy going and simple to use
Pros and Cons
- "Intuitive and easy to use."
- "Reports were lacking somewhat on the customization side."
What is our primary use case?
What is most valuable?
I found the solution quite intuitive and easy going. I have worked with other similar tools and found this simple to use.
What needs improvement?
I felt hindered sometimes within reports in that they were lacking somewhat on the customization side in terms of making use of the data. The cloud user interface could be a little more responsive. It was a click and then a wait.
For how long have I used the solution?
I used this solution recently for about five months.
Buyer's Guide
Qualys VMDR
November 2024
Learn what your peers think about Qualys VMDR. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
816,406 professionals have used our research since 2012.
What do I think about the stability of the solution?
There were a couple of small bugs but the solution was stable.
What other advice do I have?
I would recommend this solution and rate it a nine out of 10.
Which deployment model are you using for this solution?
Private Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Junior Information Security Analyst at Visma
Detects new hosts along with vulnerabilities
Pros and Cons
- "Monitors workstations and servers for vulnerabilities and creates reports."
- "Performs automated, regular scans in the network."
- "Detects new hosts along with vulnerabilities."
- "Improve the API speed."
- "Make some minimal dashboard improvements."
- "Improve the user interface."
What is our primary use case?
Our primary use case is to manage vulnerabilities, scan web applications, and report assets throughout the network. Also, we create reports based on this data.
How has it helped my organization?
- Tracks workstations and servers.
- Monitors workstations and servers for vulnerabilities and creates reports.
- Performs automated, regular scans in the network.
- Detects new hosts along with vulnerabilities.
What is most valuable?
The Qualys Agent is most valuable for getting insight into what is happening on what device with all its metadata.
What needs improvement?
- Improve the API speed.
- Make some minimal dashboard improvements.
- Improve the user interface.
For how long have I used the solution?
Less than one year.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Qualys VMDR
November 2024
Learn what your peers think about Qualys VMDR. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
816,406 professionals have used our research since 2012.
Information Risk Analyst at a healthcare company with 1,001-5,000 employees
We've gained insight into vulnerabilities across our environment, but reports should be more customizable.
What is most valuable?
The vulnerability scanning feature is valuable.
How has it helped my organization?
QualysGuard has provided us with a valuable insight into vulnerabilities across our environment. Before the use of this product, we had no way of identifying or tracking vulnerabilities.
What needs improvement?
The reporting capabilities are good but I would like to be able to make more customized reports. In addition, I would like to be able to assign a numerical asset value to critical hosts.
For how long have I used the solution?
I've used it for six years.
What was my experience with deployment of the solution?
No issues encountered, it went very smoothly.
What do I think about the stability of the solution?
No issues encountered.
What do I think about the scalability of the solution?
No, as it's very easy to add additional hosts.
How are customer service and technical support?
Customer Service:
8/10.
Technical Support:8/10.
Which solution did I use previously and why did I switch?
We didn't use a previous solution.
How was the initial setup?
It was straightforward.
What about the implementation team?
It was implemented in-house.
Which other solutions did I evaluate?
We also looked at Nessus.
What other advice do I have?
Make sure you take advantage of authenticated scans and it is also very helpful if you have a complete server inventory.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Consultant at a media company with 51-200 employees
Enables us to check the validity of legacy applications, infrastructure, and simple data operating systems
Pros and Cons
- "The initial setup was good. We didn't have any problems with it."
- "The ability to manage user accounts and give rights to the operator to know about abnormalities of applications is something that needs improvement."
What is our primary use case?
I use Qualys to review the validity of legacy applications, infrastructure, and simple data operating systems.
What needs improvement?
The ability to manage user accounts and give rights to the operator to know about abnormalities of applications is something that needs improvement.
The pricing is also expensive.
For how long have I used the solution?
I have been using Qualys for four years.
What do I think about the stability of the solution?
It's stable.
How are customer service and technical support?
I haven't needed to use technical support.
How was the initial setup?
The initial setup was good. We didn't have any problems with it.
What other advice do I have?
I would rate Qualys VM a ten out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Senior System Engineer at a comms service provider with 1,001-5,000 employees
It's easy to download/install the correct patch, but the reporting could be improved.
What is most valuable?
The feature where the solutions to issues are mentioned in the reports.
How has it helped my organization?
It's easy to reach the current location and download/install the correct patch.
What needs improvement?
The feature where the solutions to issues are mentioned in the reports could be improved.
For how long have I used the solution?
I've been using it for over three years.
What was my experience with deployment of the solution?
No issues encountered.
What do I think about the stability of the solution?
No issues encountered.
What do I think about the scalability of the solution?
No issues encountered.
How are customer service and technical support?
Customer Service:
7/10.
Technical Support:5/10,
Which solution did I use previously and why did I switch?
No previous solution was used.
What about the implementation team?
It was implemented by the vendor.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Customer Technical Leader for Galeries Lafayette at a tech company with 10,001+ employees
The GUI needs work, but the vulnerabilities are kept up to date.
What is most valuable?
The top one for me is that the vulnerabilities are kept up to date.
How has it helped my organization?
It has reduced the cost of ownership for the engineers who can launch scans on the customers’ networks.
What needs improvement?
I’m convinced it could be possible to do a simpler interface.
For how long have I used the solution?
I used it for about four years.
What was my experience with deployment of the solution?
No issues encountered.
What do I think about the stability of the solution?
There is an issue with the web browser, but it's not an issue with the product itself.
What do I think about the scalability of the solution?
No issues encountered.
How are customer service and technical support?
Customer Service:
9/10.
Technical Support:8/10.
Which solution did I use previously and why did I switch?
I switched due to the cost.
How was the initial setup?
It was simple because it's only used for external scans.
What's my experience with pricing, setup cost, and licensing?
You have to find the best solution regarding functions and cost.
Which other solutions did I evaluate?
- Tripwire
- Nessus
- Accunetix
- OIpenvas
What other advice do I have?
- Take your time
- Study all the functionalities of the product
- Try to set it up in a lab first before your production environment.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Senior IT Security Analyst at a tech services company with 501-1,000 employees
The IT infrastructure needs work but WAF has improved our vulnerability identification.
What is most valuable?
WAF integration is valuable.
How has it helped my organization?
We can now perform vulnerability scans with WAF integration. The WAF has improved the vulnerability identification and reports to the SOC and CSO.
What needs improvement?
The IT infrastructure, especially server administration, needs to be improved.
For how long have I used the solution?
I've used it for two years.
What was my experience with deployment of the solution?
There was only one related, and that need work on our technology. As the solution is cloud based, we needed to adapt our internal policies.
What do I think about the stability of the solution?
There were no issues.
What do I think about the scalability of the solution?
This been done without a problem.
How are customer service and technical support?
Customer Service:
It's good.
Technical Support:It's good.
Which solution did I use previously and why did I switch?
There was no previous solution, but I did execute several POCs.
How was the initial setup?
It was a regular setup for the configuration, but the official training was necessary.
What's my experience with pricing, setup cost, and licensing?
We also looked at Nessus and GFI Languard.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Chief Information Officer/Senior Vice President at a tech services company with 51-200 employees
Helps prioritize which security patches need to be deployed on specific equipment
Pros and Cons
- "The prioritization feature is great. I think it has all of the advanced features that we need."
- "It's too early for me to say if there is any room for improvement since we're in the first couple of months of using this solution."
What is our primary use case?
It's used for vulnerability assessments, assessment of IT equipment, PCs, servers. It's supposed to help prioritize which security patches need to be deployed on that equipment.
What is most valuable?
The prioritization feature is great. I think it has all of the advanced features that we need.
What needs improvement?
It's too early for me to say if there is any room for improvement since we're in the first couple of months of using this solution. So far, we've been pretty happy about it. Nothing comes to mind that is negative.
Given that it's really new, we're really trying to use all of the features and get a good comfort level and gain more experience in it. For this reason, I can't speak negatively of it, yet.
For how long have I used the solution?
We've been using Qualys for roughly six to seven years, but we've only been using Qualys VMDR for a few months.
What do I think about the stability of the solution?
Qualys VMDR is very stable.
What do I think about the scalability of the solution?
Qualys VMDR is definitely scalable.
How are customer service and technical support?
They provide a lot of free virtual training to really understand the technology and the solution. That's a plus for them.
Which solution did I use previously and why did I switch?
I used to work with QualysGuard VM — an older version. The earlier version didn't have the detection response that we needed, that's why this time it has the detection response. VMDR is the evolution of the solution.
How was the initial setup?
The initial setup was pretty straightforward. Deployment was quick.
What about the implementation team?
We implemented this solution ourselves.
What other advice do I have?
Overall, on a scale from one to ten, I would give this solution a rating of eight. For us, it's just more of gathering more experience. The more we learn, I think we'll appreciate it, and then maybe from that point, we'll be able to say it's a nine, or a ten. It's more on us versus the solution.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Download our free Qualys VMDR Report and get advice and tips from experienced pros
sharing their opinions.
Updated: November 2024
Product Categories
Vulnerability Management IT Asset Management Configuration Management Databases Container Security Risk-Based Vulnerability ManagementPopular Comparisons
Tenable Nessus
Tenable Security Center
Tanium
Tenable Vulnerability Management
SentinelOne Singularity Cloud Security
Orca Security
Pentera
Acunetix
JFrog Xray
Skybox Security Suite
Lacework
Check Point CloudGuard CNAPP
Trend Vision One - Cloud Security
Microsoft Defender Vulnerability Management
Buyer's Guide
Download our free Qualys VMDR Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Qualys VM vs Tenable Nessus: Comparison
- How does Tenable Nessus compare with Qualys VM?
- How does Pentera compare with Qualys VMDR?
- What are the main differences between Qualys VMDR and Tenable Nessus?
- How inadvisable is it to use a single vulnerability analysis tool?
- What are the benefits of continuous scanning for vulnerability management?
- When evaluating Vulnerability Management, what aspect do you think is the most important to look for?
- What is a more effective approach to cyber defense: risk-based vulnerability management or vulnerability assessment?
- What are the main KPIs that need to be implemented to have better posture in vulnerability projects?
- Which is the best vulnerability scanner tool?