Try our new research platform with insights from 80,000+ expert users
Real User
Top 5Leaderboard
Has tagging system and scanners, that doesn't overload
Pros and Cons
  • "I like that we have many scanners and channels that don't overload. It helps us scan and track easily. Also, the tagging system is good for tagging. We can still use QualysAgent task ID tools even if tags aren't made."
  • "There's a need to upgrade or fix the potential vulnerability rate. Around 20,000 potential vulnerabilities were showing in Qualys VMDR, but none of the other tools showed them. When we checked, it wasn't the case. Support explained that even small issues were being counted as vulnerabilities, causing issues in our audit. So, the security features could be improved to identify vulnerabilities accurately."

What is our primary use case?

In our DLP operations, we use the tool to address stability issues and implement fixes suggested by it. This helps manage risk levels and decide whether to fix issues or implement workarounds.

What is most valuable?

I like that we have many scanners and channels that don't overload. It helps us scan and track easily. Also, the tagging system is good for tagging. We can still use QualysAgent task ID tools even if tags aren't made.

The asset inventory management feature has improved our security posture, which is good. It was introduced recently, and we've just started using it. In terms of management, I believe it's better than what we were using before.

Qualys VMDR is good at handling vulnerability management trends, especially with its policy module. Qualys VMDR offers customizable labels that fit the organization's needs, unlike other tools. This is important for enhancing security and meeting compliance requirements.

What needs improvement?

There's a need to upgrade or fix the potential vulnerability rate. Around 20,000 potential vulnerabilities were showing in Qualys VMDR, but none of the other tools showed them. When we checked, it wasn't the case. Support explained that even small issues were being counted as vulnerabilities, causing issues in our audit. So, the security features could be improved to identify vulnerabilities accurately.

For how long have I used the solution?

I have been working with the product for two years. 

Buyer's Guide
Qualys VMDR
February 2025
Learn what your peers think about Qualys VMDR. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
838,713 professionals have used our research since 2012.

What do I think about the stability of the solution?

The stability is generally good, but we did face issues during the pandemic due to connectivity problems with Qualys VMDR servers. There were syncing issues, and agents weren't getting updated. However, we later realized it was our issue because our software needed updating. We had to manually update the proxy settings, which Qualys VMDR should have done. We managed to tackle the challenge with the help of another team.

How are customer service and support?

Support should be faster and more customer-friendly. We often have to review a lot of documentation for issues we're already aware of and follow basic steps repeatedly. Additionally, we must wait for Qualys VMDR personnel to move scans into debug mode, which can be time-consuming. Getting notifications or updates on these processes more quickly would be helpful.

How was the initial setup?

Setting up the tool doesn't take long and doesn't require many people.

What's my experience with pricing, setup cost, and licensing?

We have an annual contract for Qualys VMDR. I believe it's for either two years or five years.

What other advice do I have?

I haven't personally done any integration, so I can't comment on it. However, I believe some integration was happening between Qualys VMDR and ServiceNow. Our asset management tool was also trying to integrate with Qualys VMDR, but I'm unsure about the details or how it works. I rate the overall product an eight out of ten. 

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Nabhanyu Halgeri - PeerSpot reviewer
Cyber Security Specialist at a tech services company with 51-200 employees
Real User
Effortless asset management, fast support, and an easy setup
Pros and Cons
  • "I value the scheduling of scans and reports as per the desired timeframes."
  • "The reporting section needs improvement as running reports can take several hours."

What is our primary use case?

The use cases would be for scanning purposes, for identifying assets, identifying and viewing assets, and setting up scan schedules. I use it primarily as a vulnerability management and scanning tool.

How has it helped my organization?

When you have everything in one place, the job is very easy. Qualys VMDR having a Russian nesting doll sort of environment does take a steep learning curve, but having everything in one place is quite neat.

What is most valuable?

The most valuable feature is the asset view where I can find individual assets and take a deeper dive into their information gathering section, potential vulnerabilities, and confirmed vulnerabilities. I also value the scheduling of scans and reports as per the desired timeframes.

What needs improvement?

The reporting section needs improvement as running reports can take several hours. A more intuitive way to configure reports settings to reduce run time would be helpful. Improvements are needed for sorting QIDs and findings during the reporting section without downloading the entire report. 

Additionally, there is a need to address the issue of retaining report sections when they exceed one or two GBs. For asset management, adding a notification for unscanned assets or those missing CVE ratings would help.

For how long have I used the solution?

I have been using it for close to three and a half to four years now.

What do I think about the stability of the solution?

There are rarely any stability issues. Discrepancies are usually anticipated due to the downtime and maintenance window provided in advance. It's a technological tool, and random anomalies may happen, but they are manageable.

What do I think about the scalability of the solution?

Qualys offers one of the best scalability capabilities for large-scale deployments. Its tools and solutions work effectively with large corporations. VMDR helps club multiple vulnerabilities into one QID, which assists with remediation cycles.

How are customer service and support?

Customer support is fast, although there can be a lot of back and forth. However, the overall service is satisfactory and of great quality.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I have used Nessus and Burp Suite, however, Burp Suite isn't in close proximity with Qualys for scanning purposes. Microsoft Defender offers some advantages with real-time, agent-based scanning that consumes fewer resources.

How was the initial setup?

The initial setup was quite simple and straightforward. Setting up Qualys was fairly easy with clear documentation and guidance.

What's my experience with pricing, setup cost, and licensing?

I am not familiar with the pricing side as I am not a part of that aspect. However, it is on the higher side, but it provides large-scale scalability for vulnerability management.

Which other solutions did I evaluate?

I have evaluated Nessus and Microsoft Defender for vulnerability management.

What other advice do I have?

Users should go through the training offered by Qualys for all VMDR modules and take an introductory call on how to use and schedule tasks. Setting up one thing at a time and testing the desired results before moving on is advised.

I'd rate the solution eight out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
PeerSpot user
Buyer's Guide
Qualys VMDR
February 2025
Learn what your peers think about Qualys VMDR. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
838,713 professionals have used our research since 2012.
reviewer2564316 - PeerSpot reviewer
System Engineer at a financial services firm with 1-10 employees
Real User
Top 20
Enhanced vulnerability detection and scanning with valuable asset management options
Pros and Cons
  • "Authenticated scans provide different options, including those using or not using the FactSet and adding option profiles."
  • "It would be helpful to have features for better tracking, including options for adding relevant owners or supporting groups for each asset."

What is our primary use case?

We use Qualys VMDR for vulnerability management and operations, such as scanning assets to identify vulnerabilities and updating the reports for different teams.

How has it helped my organization?

We identified and resolved many vulnerabilities by using Qualys VMDR. It has been helpful in detecting externally facing asset vulnerabilities and coordinating patching or remediation with different teams.

What is most valuable?

I find the scans portion of VMDR to be valuable. Authenticated scans provide different options, including those using or not using the FactSet and adding option profiles. Another good feature is the Knowledge Base, which provides detailed information on vulnerabilities, period scores, solutions, issues, and mitigation.

What needs improvement?

I'd suggest improvements in asset management. It would be helpful to have features for better tracking, including options for adding relevant owners or supporting groups for each asset.

For how long have I used the solution?

I have been using Qualys VMDR for about three years.

What do I think about the stability of the solution?

The solution is stable. I would rate it eight out of ten.

What do I think about the scalability of the solution?

Scalability is rated at 7.5 out of ten.

How are customer service and support?

When you raise a report, it will be generated in VMDR and shared with the respective team. Depending on client requests, reports can be in PDF or Excel format.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I did not use any previous vulnerability solutions; I started directly with Qualys.

How was the initial setup?

The setup for Qualys VMDR is easy since it's a cloud tool. Access is provided through different inboxes, and deployment is straightforward.

What's my experience with pricing, setup cost, and licensing?

I am not aware of the actual cost or pricing as it is managed by the client.

Which other solutions did I evaluate?

Compared to other solutions like Nexus, Qualys provides more options and is a better tool.

What other advice do I have?

I recommend using Qualys as it offers many valuable features and options. It is better compared to solutions like Nexus.

I'd rate the solution nine out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
PeerSpot user
reviewer1675638 - PeerSpot reviewer
Cyber Security Director at a manufacturing company with 5,001-10,000 employees
Real User
Top 5
Reliable with good technical support and good stability
Pros and Cons
  • "The initial setup is straightforward."
  • "The solution is a bit expensive if you do not have access to discounts."

What is our primary use case?

We primarily use the solution for full enterprise visibility from both an asset detection perspective and vulnerability detection perspective. Basically, we are tracking all the devices over agents, including PCs and servers, et cetera. 

We are able to understand what our current situation is on the devices. At the second stage, we are able to catch the devices which do not have agents or which are not in the inventory, with on-premise scanners. 

We are running security configuration hardening assessments or compliance with CIA security benchmarks. 

In addition to that, we are also utilizing the cloud assessment solution of the Qualys, to ensure compliance with CIA security standards. For example, the Amazon cloud platform is configured compliantly with the CIA security benchmark. These are the four pillars utilized.

What is most valuable?

The prioritization mechanism is the most valuable aspect of the solution.

The initial setup is straightforward. 

Technical support is great.

The stability and reliability are good.

What needs improvement?

The user experience, the UI, needs to be improved. The technology is there and it is obvious it is able to do many things, however, from a user experience perspective, the UI design is a bit complicated. If the platform could have a bit more of a user-friendly environment, it could be easier for the admins and analysts to use it.

The solution is a bit expensive if you do not have access to discounts. 

From a general perspective, SLA tracking capabilities could be improved with a building method. There was a tracking method to be able to see if this vulnerability for a while or maybe it was patched. However, an internal SLA mechanism could help with batch prioritization and issue detection. 

I'd rate the solution at a nine out of ten.

For how long have I used the solution?

I've been using the solution for six months. I've used it for less than a year now. 

What do I think about the stability of the solution?

The solution is stable. The passive scanning capabilities are advanced. I'm able to see all the missing paths and many vulnerabilities or many configuration mistakes at the same time. Due to its passive scanning, we don't see any stress or research consumption from agents.

Network scans are a bit more intense and they of course require research and can create some noise, however, for the most part, it is okay. There is no reliability issue from our perspective.

What do I think about the scalability of the solution?

I haven't really tried to scale the solution and therefore cannot really speak to it. We do have some activities happening on there, however, I'm not ready to provide feedback for the results. It's my understanding, however, that the API extensibility is great. I've just not seen anything yet that I can really comment on.

How are customer service and technical support?

Technical support is pretty good. It is very easy to get support from the global team, at least for us. We don't depend on local partners, which is great due to the fact that, whenever you are acting in 10 or 11 countries, local partners can be an issue. The language barriers, et cetera, can be an issue. That's why it is great to have responsible global support.

How was the initial setup?

The initial setup was very straightforward. We just deployed the agents and everything went very smoothly. There were no big issues.

What's my experience with pricing, setup cost, and licensing?

We pay a yearly fee for a license. 

They have very good discounts. That's why the price is okay for us. Generally, if we talk about the price without discounts, I do see a big peak in vulnerability management solutions licenses. It is not only Qualys. All the vendors peaked at some point. 

We do see over $100,000 in terms of price, for mid-size programs. You likely will pay more than $100,000 without any discount. It is a bit pricey. There's room to improve, however, I believe they're managing things with discount offerings. I'm saying this not only for Qualys. All the vulnerability management solutions do the same thing price-wise.

Which other solutions did I evaluate?

We did evaluate other solutions. We looked at most other vulnerability management solutions.

What other advice do I have?

We are just a customer and end-user.

We are using the latest version of the solution. I cannot speak to the exact version we are using, however. 

We are using both the on-premises and cloud deployment models. We have on-premise sensors and we have a scan-over cloud service from Qualys. Qualys cloud has a scanning capability for pairing sensors, for scanning an external perimeter. Therefore, we are utilizing that and agents as well.

I'd recommend the solution.

If anybody looks forward to first perimeter security, if any conceptual work is done around perimeter security, they have to solve that agent issue first for their program. Companies need to select a solution that can work wherever the PC is. 

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer1421982 - PeerSpot reviewer
AVP - Information Security at a financial services firm with 10,001+ employees
Real User
Easy to use and scalable but needs to be priced more competitively
Pros and Cons
  • "It is very easy to use and there are lots of options. We can usually easily go through it and all of the things we want to configure, and we can configure everything to our specifications very easily."
  • "Sometimes we face a problem with accessing the tool and not getting an expected result. From a technology point of view, they need to look into this."

What is our primary use case?

We're primarily using the solution for vulnerability assessment of internal server as well as the external server.

What is most valuable?

The solution, overall, is very useful for our organization.

It is very easy to use and there are lots of options. We can usually easily go through it and all of the things we want to configure, and we can configure everything to our specifications very easily.

What needs improvement?

Sometimes we face a problem with accessing the tool and not getting an expected result. From a technology point of view, they need to look into this. 

They need to consider how they can improve tool usability and different scanning options. 

Sometimes we are facing issues while performing a scan and things are not correctly shown on the GUI. Even as we are doing a task, it may show up as completed, and then something is not visible. Sometimes we face other technical problems. For example, sometimes we can't go to the next page. It's limiting any positive results.

The solution needs to be easier to understand and configure.

The pricing is a bit on the higher side compared to other products in the industry.

For how long have I used the solution?

I've been dealing with the solution for the last five or six years now. It's been a while.

What do I think about the stability of the solution?

I haven't had any issues with stability. It's been okay.

What do I think about the scalability of the solution?

I don't see any issues with scalability. When we do multiple IP scans, when we require an increase in the number of IPs, we won't have any problem doing so.

How are customer service and technical support?

The technical support has been fine. We're getting the required support we need when we need it. I'd say we're pretty satisfied in that regard.

What's my experience with pricing, setup cost, and licensing?

I find the pricing to be a bit high, especially compared to the competition.

Which other solutions did I evaluate?

While we didn't evaluate other options previously, currently, we are looking at all sorts of vulnerability management solutions and that's including Kenna and RiskSense. 

Although Qualys has come up with the model, I've not really looked that far into their other offerings. There is the possibility of upgrading the model on the part of vulnerability management. We'll see if we change solutions or decide to upgrade instead.

We've also looked at Tenable, which is easier to understand and configure.

What other advice do I have?

We are a Qualys customer. We aren't a reseller or partner.

Overall I'd rate the solution seven out of ten.

We are currently looking at other options, to see if there's a better solution out there. This one has pretty good technical support and is easy to use, however, there are other issues associated with it.

Which deployment model are you using for this solution?

Private Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Assistant Manager Solutions at Mutex Systems Pvt. Ltd.
Real User
A robust and user-friendly cloud-based service that gives you immediate, global visibility into potential vulnerabilities and threats
Pros and Cons
  • "I find Qualys VM very robust, and it's very useful for vulnerability management and patch management. The value that it brings to my environment is economies of scale. There is no limitation on adding any endpoints. You go by the rule, and it's added once another endpoint is added to our environment. It's automatically installed, and it's less work from our end. It frees up my license automatically if I don't need an endpoint or if my machine is decommissioned. I like the dashboard displays because I don't see any duplication. The most important part is vulnerability management and prioritization. Unlike Symantec, it shows the kind of vulnerability I would want to patch first. It provides a holistic view of the kind of vulnerabilities and the ones I should remediate first. I don't have to do a scan; it just brings up those critical kinds of vulnerabilities like zero-day vulnerabilities and tells me to prioritize them. You have to prioritize these vulnerabilities first and go on with the rest. The dashboard shows me the ones that have been fixed, so I don't have to complete an aging report. The user experience and the graphical interface are good. As it's user-friendly and understandable on an executive level, it brings real value. We also use this solution because it's robust and flexibile."
  • "The price could be better. Asset view is still a legacy feature. I'm not able to extract the information about the asset with complete details. It would be better if they fixed that in the next release. I know Qualys is already working on it, so I'm hopeful it will be available in the next five or six months. That would be something that's changed where I seek improvement."

What is our primary use case?

We're using the entire suite except for Patch Management. I use Qualys VM for my production environment on Amazon AWS. I also use it for my endpoints and some BDI solutions that require on-premise solutions, and I use it for both.

What is most valuable?

I find Qualys VM very robust, and it's very useful for vulnerability management and patch management. The value that it brings to my environment is economies of scale. There is no limitation on adding any endpoints. You go by the rule, and it's added once another endpoint is added to our environment. It's automatically installed, and it's less work from our end. It frees up my license automatically if I don't need an endpoint or if my machine is decommissioned.

I like the dashboard displays because I don't see any duplication. The most important part is vulnerability management and prioritization. Unlike Symantec, it shows the kind of vulnerability I would want to patch first. It provides a holistic view of the kind of vulnerabilities and the ones I should remediate first.

I don't have to do a scan; it just brings up those critical kinds of vulnerabilities like zero-day vulnerabilities and tells me to prioritize them. You have to prioritize these vulnerabilities first and go on with the rest. The dashboard shows me the ones that have been fixed, so I don't have to complete an aging report.

The user experience and the graphical interface are good. As it's user-friendly and understandable on an executive level, it brings real value. We also use this solution because it's robust and flexibile. 

What needs improvement?

The price could be better. Asset view is still a legacy feature. I'm not able to extract the information about the asset with complete details. It would be better if they fixed that in the next release.

I know Qualys is already working on it, so I'm hopeful it will be available in the next five or six months. That would be something that's changed where I seek improvement.

For how long have I used the solution?

I have been working with Qualys VM for the past six months.

What do I think about the stability of the solution?

Qualys VM is a stable solution.

What do I think about the scalability of the solution?

Qualys VM is a scalable solution. We currently have about 4500 users in our organization.

How are customer service and support?

Support could be a little bit faster. I haven't been granted access to their support portal, but I have a technical support engineer who's always available, and there is only one person I can talk to. But the problem is if he's absent, I'm left waiting for access to his portal. 

Which solution did I use previously and why did I switch?

I used Symantec before but switched to Qualys VM as there's no limitation to adding endpoints. The other reason everyone moved to Qualys VM was its robustness and flexibility. I think that's something that's there, and there was no hassle in deploying the agent. All I had to do was get these machines that were enrolled in our MDM solutions.

How was the initial setup?

As it's a cloud agent, there wasn't any specific setup. It's also managed centrally by Qualys, and when they always release a new update, all we have to do is push it. So, the maintenance requirement is minimum at best.

What about the implementation team?

We deployed this solution by ourselves.

What's my experience with pricing, setup cost, and licensing?

Qualys VM is quite expensive. It's a subscription-based license, and it's yearly. Right now, it's open for me, and I don't have any limitations or caps on the licenses. They are seeing if the product is viable for 4500 users. I can add as much as I want, and at the end of the subscription, they'll let me know how many licenses were actually used and bill me accordingly.

On a scale from one to five, I would give their pricing a three. It's still expensive.

What other advice do I have?

If you're going for an on-premises solution, you should dive into the POC. Because I wasn't procuring an on-premises solution, it was pretty easy for me, and the support was quite helpful. But if you're going to deploy it on-premises, you should go through a proper procedure of going through the POC and getting to know the product. I would rate it at the top because it's better than Nexpose, it's better than Tenable, and it's better than Symantec.

On a scale from one to ten, I would give Qualys VM an eight. 

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Senior Vulnerability Analyst at a comms service provider with 10,001+ employees
Real User
It has a quicker response time to incidents. And it has a stable performance record.
Pros and Cons
  • "I find the most valuable features are the continuous monitoring. Even on premises, there is constant monitoring."
  • "They have integrated with other third parties, but it is still not viable."
  • "When tested on Zero day, there were errors."

What is our primary use case?

It improves the continuous monitoring of the systems on-premises.

How has it helped my organization?

If any anomalies are there, we can easily detect with our agent based solutions, and we can isolate them quickly, and response time or any incident is much quicker than previous. Before we were taking eight hours, now we're taking around 30 minutes to respond to any incident, security and such.

What is most valuable?

I find the most valuable features are the continuous monitoring.  Even on premises, there is constant monitoring.

What needs improvement?

When tested on Zero day, there were errors.

In addition, they have integrated with other third parties, but it is still not viable. They are using their own Q id's. This sometimes leads to a false positive. And, even the updating of signatures into Qualys is not that much quicker. Maybe for Windows and Linux, it is a little quicker or networks and other devices. The signature updating is not quicker.

What do I think about the stability of the solution?

I have not experienced issues with stability of the solution. There were a few bugs, but we reported it.

What do I think about the scalability of the solution?

I did not have any issues of scalability.

How are customer service and technical support?

The tech support acted quickly and responded quickly to our tickets. There was a good response time.

Which solution did I use previously and why did I switch?

I also have previous experience with Tennable Nessus, and I find Qualys is better than Nessus, which is slow in the security center and lags a bit.

What's my experience with pricing, setup cost, and licensing?

It's good. Yes, it's competitive. We got the best price.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer2201862 - PeerSpot reviewer
Information Security Engineer at a university with 1,001-5,000 employees
Real User
Top 5Leaderboard
Efficient automation feature and provides us with a comprehensive security solution
Pros and Cons
  • "The most valuable feature is automation."
  • "Qualys VMDR is basically susceptible to false positives, and false negatives."

What is our primary use case?

Qualys VMDR is a vulnerability management and detection response tool. It belongs to the first generation of vulnerability assessment tools. It enables us to manually identify vulnerable keys and fix them. It is built as a cutting-edge continuous platform where we can detect and protect. With this product, we can respond to specific vulnerabilities, going beyond just using artificial intelligence features. We have implemented VMDR across our cloud, physical interfaces, endpoints, and log servers. It's a good digital product for our organization.

How has it helped my organization?

It has improved our organization in many ways. We needed to have a security solution that focuses on different types of things. We discussed budgeting for the cloud and the need for an alternative to taking care of malware. Additionally, we have to consider various attacks. Therefore, Qualys VMDR is a great tool that helps us improve.

What is most valuable?

The most valuable feature is automation.

What needs improvement?

Qualys VMDR is basically susceptible to false positives, and false negatives. We receive a lot of false positives in there. VMDR can be considered a complex solution, especially for enterprises with limited resources or organizations. It requires extensive knowledge as an engineer. So, when using this tool, you need to utilize other tools to remediate the false security issues.

So maybe it should also have the ability to automatically identify and address false positives. In additional features, an automated process for remediating false positives. We might be looking for new types of signatures that can help us identify and address specific issues.

For how long have I used the solution?

I have been using Qualys VMDR for one last year. 

What do I think about the stability of the solution?

I would rate the stability an eight out of ten.

What do I think about the scalability of the solution?

I would rate the scalability an eight out of ten.

How was the initial setup?

It took us one month to set up.

What was our ROI?

I have seen an ROI.

What's my experience with pricing, setup cost, and licensing?

The price is very reasonable, so you can definitely go with all the endpoints it offers.  

What other advice do I have?

Just consider the licenses we have within VMware. They could replicate some of these features, which are used for premium customers. So, it might be useful to include those features in the subscription plans.

Overall, I would rate the solution a nine out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free Qualys VMDR Report and get advice and tips from experienced pros sharing their opinions.
Updated: February 2025
Buyer's Guide
Download our free Qualys VMDR Report and get advice and tips from experienced pros sharing their opinions.