Try our new research platform with insights from 80,000+ expert users
IRM Technical Consultant at Shell
Real User
Vulnerability scanner with good dashboard presentation and clear reporting
Pros and Cons
  • "What I like about Qualys VM is the dashboard presentation. It's very good."
  • "The customer support is very bad."

What is our primary use case?

The primary use cases of this solution are as a scanner. We use it with Azure and AWS. For on-premises, we use physical scanners all over the globe. We have deployed our external scanners in approximately 70 regions.

What is most valuable?

What I like about Qualys VM is the dashboard presentation. It's very good.

The reporting capability and executive reporting are very good.

What needs improvement?

Customer support needs to be improved because it was not to our SLA standards.

Suddenly, the scan engine will go down. We don't know what the reason is, or how it goes down. Because of that, the business is impacted.

I had a look at the PCI reports  (policy compliance reports) and I have heard that most memberships have been taken by Azure, although I was not aware of that. I would like to see more documentation or awareness.

For how long have I used the solution?

I have worked with Qualys VM for the last two years.

Buyer's Guide
Qualys VMDR
November 2024
Learn what your peers think about Qualys VMDR. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
816,406 professionals have used our research since 2012.

What do I think about the stability of the solution?

This solution is stable.

What do I think about the scalability of the solution?

The scalability is good.

How are customer service and support?

The customer support is very bad. When we submit a ticket, we do not get a response immediately.

Which solution did I use previously and why did I switch?

Previously, I have used Rapid 7 Nexpose. They are similar solutions although what Qualys is providing, it provides well but requires less. Qualys reporting is better.

Nexpose has upgraded too, and now their reporting is also very good.

How was the initial setup?

The initial setup was straightforward and we didn't have any issues with it.

What other advice do I have?

If you are comparing Nexpose and Qualys, I would prefer Qualys. The UI is good and whatever reports you are getting, are very clear. If you present it to management, the reports are good. They require an executive report that highlights the vulnerability and how many servers are affected. You can customize it also.

Nexpose is coming out with new features, but Qualys has already implemented them.

I would rate this solution an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Senior Vulnerability Analyst at a comms service provider with 10,001+ employees
Real User
It has a quicker response time to incidents. And it has a stable performance record.
Pros and Cons
  • "I find the most valuable features are the continuous monitoring. Even on premises, there is constant monitoring."
  • "They have integrated with other third parties, but it is still not viable."
  • "When tested on Zero day, there were errors."

What is our primary use case?

It improves the continuous monitoring of the systems on-premises.

How has it helped my organization?

If any anomalies are there, we can easily detect with our agent based solutions, and we can isolate them quickly, and response time or any incident is much quicker than previous. Before we were taking eight hours, now we're taking around 30 minutes to respond to any incident, security and such.

What is most valuable?

I find the most valuable features are the continuous monitoring.  Even on premises, there is constant monitoring.

What needs improvement?

When tested on Zero day, there were errors.

In addition, they have integrated with other third parties, but it is still not viable. They are using their own Q id's. This sometimes leads to a false positive. And, even the updating of signatures into Qualys is not that much quicker. Maybe for Windows and Linux, it is a little quicker or networks and other devices. The signature updating is not quicker.

What do I think about the stability of the solution?

I have not experienced issues with stability of the solution. There were a few bugs, but we reported it.

What do I think about the scalability of the solution?

I did not have any issues of scalability.

How are customer service and technical support?

The tech support acted quickly and responded quickly to our tickets. There was a good response time.

Which solution did I use previously and why did I switch?

I also have previous experience with Tennable Nessus, and I find Qualys is better than Nessus, which is slow in the security center and lags a bit.

What's my experience with pricing, setup cost, and licensing?

It's good. Yes, it's competitive. We got the best price.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Qualys VMDR
November 2024
Learn what your peers think about Qualys VMDR. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
816,406 professionals have used our research since 2012.
Former Employee of Orange Business Services as Head of Security Engineering at a comms service provider with 5,001-10,000 employees
Real User
Top 5Leaderboard
Comprehensive and stable solution, but its technical support service needs improvement
Pros and Cons
  • "The solution is easy to use."
  • "They should make it accessible for more operating systems."

What is our primary use case?

We use the solution for vulnerability management. It helps us identify potentially vulnerable assets. Thus, we can prioritize patching based on a risk score.

What is most valuable?

The solution is easy to use and has many essential features. I found the concept of tags the most valuable feature. It allows us to build assets from different views. We can categorize systems with tags, either automatically or manually.

What needs improvement?

The solution's cloud agent is available only for limited operating systems such as Windows and Linux. They should make it accessible for more systems like FreeBSD. Also, it would be helpful if they made it available for Cisco or Juniper routers. Additionally, its price and support could be better as well.

For how long have I used the solution?

We have been using the solution for six years.

What do I think about the stability of the solution?

The solution is stable. However, it takes time to generate reports.

What do I think about the scalability of the solution?

We have ten solution users in our organization.

How are customer service and support?

The solution's technical support team replies with generic answers. The quality of the response could be better.

How would you rate customer service and support?

Neutral

How was the initial setup?

The solution's initial setup process was straightforward. We just followed the documentation.

What's my experience with pricing, setup cost, and licensing?

The solution is costly.

What other advice do I have?

I recommend the solution to others and rate it as a eight.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer1145985 - PeerSpot reviewer
Manager, Info Security Planning & Architecture at a comms service provider with 10,001+ employees
Real User
A great help to improve and maintain security
Pros and Cons
  • "The most valuable features are vulnerability scanning, policy compliance scanning, and tablet for web application scanning."
  • "Sometimes the scanning can get overwhelmed and start to drag when a lot of users are trying to scan at once."

What is our primary use case?

I mainly use Qualys VM for vulnerability management to carry out vulnerability scans on IT assets to find out which are vulnerable and what is needed to patch them. We also use it for policy compliance scans and in tablet for web application scans.

How has it helped my organization?

Qualys VM has greatly helped us to improve and maintain our posture of security.

What is most valuable?

The most valuable features are vulnerability scanning, policy compliance scanning, and tablet for web application scanning.

What needs improvement?

Sometimes the scanning can get overwhelmed and start to drag when a lot of users are trying to scan at once. I think cloud-based solutions like Qualys VM should be prepared to throw more resources in to ensure they don't get overwhelmed like this.

For how long have I used the solution?

I've been using Qualys VM for about six years.

What do I think about the stability of the solution?

The stability and performance have been fine.

What do I think about the scalability of the solution?

Qualys VM is very easy to scale - that's one of the benefits of cloud-based solutions.

How are customer service and support?

Qualys' technical support is very responsive.

How was the initial setup?

Qualys VM is straightforward to set up.

What about the implementation team?

The deployment was done in-house.

What other advice do I have?

I would advise anybody looking into using Qualys to go online to also check on Gartner and Forrester. From a planning perspective, you need to look at your estate to determine what kind of tool you need. I would rate Qualys VM eight out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer1248798 - PeerSpot reviewer
Sr. Manager, Vulnerability Management at a transportation company with 10,001+ employees
Real User
User-friendly, supports multiple platforms, and the VM DR capabilities are helpful
Pros and Cons
  • "The features that are most valuable are the identification, scan features, and the identification of vulnerabilities."
  • "I would like to see more accuracy in detections, better reporting capabilities, and better dashboard download capabilities."

What is our primary use case?

We are using Qualys VM, as our scanner tool. We also use it for Application Security and Policy Compliance.

We use it for the identification of vulnerabilities for all of our devices on the network. This includes Windows workstations, servers, and Linux machines. We also use it for cloud, and external use as well.

What is most valuable?

The features that are most valuable are the identification, scan features, and the identification of vulnerabilities. Recently, the VMDR additions and the threat protection has been useful.

It's pretty user-friendly.

What needs improvement?

The Patch Identifications, which are supersedence identifications, need improvement.

I would like to see more accuracy in detections, better reporting capabilities, and better dashboard download capabilities. These are things that are definitely needed.

For how long have I used the solution?

I have been using Qualys VM for more than 15 years.

We are using the latest version.

VMDR was added in July with newer enhancements.

What do I think about the stability of the solution?

It's a stable solution.

What do I think about the scalability of the solution?

It's very scalable for large networks. We have also used the agents and they work very well.

I have a team of five in our organization and external to it, there are approximately twenty-five.

How are customer service and technical support?

We engage with technical support often. There could be some improvements made.

How was the initial setup?

The initial setup is straightforward.

What's my experience with pricing, setup cost, and licensing?

It is different for every company, but for us, it's every three years. I will know more about the pricing in September because we are going to be looking at our pricing again.

We get a large volume discount, which is good.

What other advice do I have?

I would recommend this product to others who are interested in using it.

I would rate this solution an eight out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer2004561 - PeerSpot reviewer
Security Specialist at a financial services firm with 1,001-5,000 employees
Real User
Top 20
Robust, good agent support, and simple to setup
Pros and Cons
  • "It's really beneficial for scanning and interacting with the agent."
  • "The disadvantage of working with Qualys is that the graphical interface is quite outdated."

What is our primary use case?

Qualys VM is used for vulnerability scanning.

What is most valuable?

It's really beneficial for scanning and interacting with the agent. 

What needs improvement?

The disadvantage of working with Qualys is that the graphical interface is quite outdated.

If you want to choose a scan result, or maybe configure an IP range or something similar, it opens up a lot of processes, or steps, which is somewhat bothersome. Because it opens several phases, it is not a single-window program. 

For how long have I used the solution?

We are testing it, as well as Rapid 7 InsightVM.

We have been testing Qualys VM for approximately five weeks.

What do I think about the stability of the solution?

Qualys VM is a stable solution.

What do I think about the scalability of the solution?

Qualys VM is a scalable product.

It works with ten assets. It works with 100 assets. It has worked with 3,000 assets. It's quite scalable.

In our organization, we have two dedicated people, and five others are only dedicated to gaining insights. 

It actually depends on how you remediate all of the vulnerabilities in Qualys since you can also set up it such that product owners, that is, the owners of the apps that are deployed on all systems, can access reports and everything. But that's not how we do things.

The security and infrastructure departments are using this solution in our organization.

How are customer service and support?

We have a dedicated Qualys team of two persons assisting us with the implementation.

Which solution did I use previously and why did I switch?

We are currently doing a proof of concept with both Qualys VM and Rapid 7 InsightVM.

How was the initial setup?

Qualys is a fully SaaS solution.

It is dependent on the configuration. When you work with the agent, you are primarily concerned with deploying the agents to all assets. However, if you want to scan based on IP, you'll run into some problems.

If you wish to scan on an IP basis, for example, you should deploy a virtual appliance. You may set up several appliances for different domains. Otherwise, you must have your network rules properly configured so that the appliance can reach every asset.

It's relatively simple to set up the basics, but if you want to scan, it really depends on how many networks and domains you have.

In a couple of weeks, you can set it up.

What's my experience with pricing, setup cost, and licensing?

It's very expensive, especially if you want to use multiple modules of Qualys.

What other advice do I have?

I think mainly decide how you want to scan: based on IP or based on an agent.

Then work with the interface and then explore how it works.

I would rate Qualys VM an eight out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Gabriel Clement - PeerSpot reviewer
Lead IT Security and Remediation at ARM Holdings Company
Real User
Top 5Leaderboard
Cloud-based vulnerability management solution that provides protection of our systems but could offer improved performance
Pros and Cons
  • "This solution gives us insight into our environment and improves our security. It helps us to maintain a good patching system whereby we know that XYZ is vulnerable within the system."
  • "Qualys could be improved in its overall performance compared to other vulnerability management or scanning tools."

What is our primary use case?

We use this solution to scan the servers on the network. It is used predominantly by our information security team.

How has it helped my organization?

This solution gives us insight into our environment and improves our security. It helps us to maintain a good patching system whereby we know that XYZ is vulnerable within the system. 

What is most valuable?

Qualys makes us proactive in terms of handling patching and effective when it comes to scanning out network.

What needs improvement?

Qualys could be improved in its overall performance compared to other vulnerability management or scanning tools. 

For how long have I used the solution?

I have been using this solution for five years. 

Which solution did I use previously and why did I switch?

I have previously used Nessus. Overall, Nessus is a better tool because it provides greater insight into all vulnerabilities, some of which are skipped by Qualys. 

How was the initial setup?

This solution is very easy to set up. 

What about the implementation team?

We worked with a third party to complete deployment. 

What's my experience with pricing, setup cost, and licensing?

In Nigerian Naira, we spend about roughly four to five million to use this solution and this is expensive compared to solutions like Nessus.

What other advice do I have?

I would advise others to run a proof of concept and to exhaust all functionality if considering Qualys. This may take between 15 and 60 days to complete. 

I would rate this solution a six out of ten. 

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user259977 - PeerSpot reviewer
Analista de Seguridad TI at a manufacturing company with 1,001-5,000 employees
Real User
It's worth the investment, but score calculation needs to be improved. I had to manually re-calculate scoring at times.

What is most valuable?

The interface is pretty good, as all the instructions are clear enough. The way you can create groups or scheduling scans and reports is a very good feature, and the CSV reports have very good information.

How has it helped my organization?

In this case, my last employer was a Qualys partner and the consultancy was extra. But, the reports and the way the information is, helped a lot. Also, with this information concise presentations were sent to the CIO every month.

What needs improvement?

I think the only area to improve it is the way the scores are calculated. That was the only problem I had and because of that, all scores had to be rectified manually.

For how long have I used the solution?

I was using both Multimedios Redes (Enterprise version) and Lamosa for three years. I also used PC, PCI, and WAS.

What was my experience with deployment of the solution?

No issues were encountered.

What do I think about the stability of the solution?

Maybe one or two times, but they were caused by scheduled windows, but these problems were fixed very quickly.

What do I think about the scalability of the solution?

No issues were encountered.

How are customer service and technical support?

Customer Service:

Very good! I think I would give them 10/10 because in Latin America the service was excellent.

Technical Support:

Again, I would give them 10/10, as the documentation is so good and all is clear, but if you have a doubt, technical support was always concise and had a quick answer. Also the community helps a lot.

Which solution did I use previously and why did I switch?

I did not personally, but the technical contacts that worked for my customers tried another solutions, and they chose Qualys for the easy way it manages the processes.

How was the initial setup?

The initial setup was very easy, with no complications found when the instructions were followed. Also, this activity was done with a physical and virtual appliance, and both ways were very easy to follow.

What was our ROI?

I was the vendor team, but I can give you the answer from the actual companies I worked for. The administrators, before Qualys, did not care so much about security, patching, etc.; but, after Qualys they changed their minds. Security took a very important role and of course they reduced, a lot, the chances of being hacked or attacked. It also helped, at this point, to be verified by auditors.

What's my experience with pricing, setup cost, and licensing?

It's worth it, really, when you see the complete picture and see all the factors. It is a very good investment. Qualys is a very good tool and very easy to use and it is also better to have an annual subscription rather than paying for a scan.

Which other solutions did I evaluate?

My customers evaluated Foundstone and Rapid7, and possibly others.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free Qualys VMDR Report and get advice and tips from experienced pros sharing their opinions.
Updated: November 2024
Buyer's Guide
Download our free Qualys VMDR Report and get advice and tips from experienced pros sharing their opinions.