Try our new research platform with insights from 80,000+ expert users
it_user259977 - PeerSpot reviewer
Analista de Seguridad TI at a manufacturing company with 1,001-5,000 employees
Real User
It's worth the investment, but score calculation needs to be improved. I had to manually re-calculate scoring at times.

What is most valuable?

The interface is pretty good, as all the instructions are clear enough. The way you can create groups or scheduling scans and reports is a very good feature, and the CSV reports have very good information.

How has it helped my organization?

In this case, my last employer was a Qualys partner and the consultancy was extra. But, the reports and the way the information is, helped a lot. Also, with this information concise presentations were sent to the CIO every month.

What needs improvement?

I think the only area to improve it is the way the scores are calculated. That was the only problem I had and because of that, all scores had to be rectified manually.

For how long have I used the solution?

I was using both Multimedios Redes (Enterprise version) and Lamosa for three years. I also used PC, PCI, and WAS.

Buyer's Guide
Qualys VMDR
January 2025
Learn what your peers think about Qualys VMDR. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,265 professionals have used our research since 2012.

What was my experience with deployment of the solution?

No issues were encountered.

What do I think about the stability of the solution?

Maybe one or two times, but they were caused by scheduled windows, but these problems were fixed very quickly.

What do I think about the scalability of the solution?

No issues were encountered.

How are customer service and support?

Customer Service:

Very good! I think I would give them 10/10 because in Latin America the service was excellent.

Technical Support:

Again, I would give them 10/10, as the documentation is so good and all is clear, but if you have a doubt, technical support was always concise and had a quick answer. Also the community helps a lot.

Which solution did I use previously and why did I switch?

I did not personally, but the technical contacts that worked for my customers tried another solutions, and they chose Qualys for the easy way it manages the processes.

How was the initial setup?

The initial setup was very easy, with no complications found when the instructions were followed. Also, this activity was done with a physical and virtual appliance, and both ways were very easy to follow.

What was our ROI?

I was the vendor team, but I can give you the answer from the actual companies I worked for. The administrators, before Qualys, did not care so much about security, patching, etc.; but, after Qualys they changed their minds. Security took a very important role and of course they reduced, a lot, the chances of being hacked or attacked. It also helped, at this point, to be verified by auditors.

What's my experience with pricing, setup cost, and licensing?

It's worth it, really, when you see the complete picture and see all the factors. It is a very good investment. Qualys is a very good tool and very easy to use and it is also better to have an annual subscription rather than paying for a scan.

Which other solutions did I evaluate?

My customers evaluated Foundstone and Rapid7, and possibly others.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Swami Govindan - PeerSpot reviewer
Security Architect at a tech vendor with 5,001-10,000 employees
MSP
Good analysis, helpful reports, and a straightforward setup
Pros and Cons
  • "The solution shows us classic categories, including high, medium, and low risks. It also shows critical items, and that gives us the advantage of prioritizing things."
  • "It would be nice to have an all-in-one solution that was automated and could handle the scanning and reports as well as the patching and updating."

What is our primary use case?

This is a virtual scanner appliance. We have both physical and virtual options. 

I'm still in training and getting the hang of the solution. I do not know what features the company uses the most. They generally use it to scan all the AWS workloads and Azure workloads.

What is most valuable?

We generally analyze everything at the OS level and application level, including the open ports, the OS, and older versions, including the packaged versions. We generate the scan, and then we generate the report, and then we will issue it to the application teams to clear off those. 

We have Java remediation happening, and if Java has, for example, multiple versions and when I run the scan, it is going to identify all Java versions that are really vulnerable so you can fix them. Therefore, it helps keep things secure and up-to-date. 

The reporting is good. We give reports to the application teams and we will ask them to either fix or remove applications. Once that is done, then we will read the scan, and if it comes back that we don't have any critical, we are assured of good safety. 

The solution shows us classic categories, including high, medium, and low risks. It also shows critical items, and that gives us the advantage of prioritizing things. 

It's very clear on what components need to be fixed. 

The initial setup is straightforward. 

It's stable.

Technical support is helpful. 

What needs improvement?

I can't speak to disadvantages since I am in training and still learning and have yet to run a scan. 

It would be nice to have an all-in-one solution that was automated and could handle the scanning and reports as well as the patching and updating. 

For how long have I used the solution?

I am pretty new to this organization. However, the organization has been dealing with the solution for almost four or five years now.

What do I think about the stability of the solution?

The stability has been good. The company has been using it for a while and hasn't had issues. I use dit in a previous company as well and never hear of any problems. 

What do I think about the scalability of the solution?

It's easy to scale. 

How are customer service and support?

Technical support is good. We always get a quick response. 

How was the initial setup?

The setup process is simple. It's not overly complex. 

What's my experience with pricing, setup cost, and licensing?

I don't have any details about the licensing process. 

What other advice do I have?

We're implementors. 

When it comes to security, my only advice is based on my experience. They always say to use multiple products due to the fact that, even if the vulnerability is missed in one product, it'll be identified in the other product so that you are safe. 

However, when it comes to implementation, if you have multiple products, pipelining is a big problem. For example, if I use the Qualys scanner, and then it gives me all the vulnerabilities: how do I fix it? Either I have to fix it manually, or I have to fix it automatically. 

I'd like to use one product, and, for example, use a vulnerability scanner from Qualys and have patch management as well. While the solution is still maturing, I like the tight integration and I like that the scanner can identify items and patch management can fix them. It simplifies things, instead of having to deal with multiple products and then maybe having to manually fix items on top of that. 

I'd rate the solution nine out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer: Implementer
PeerSpot user
Buyer's Guide
Qualys VMDR
January 2025
Learn what your peers think about Qualys VMDR. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,265 professionals have used our research since 2012.
Sr Security Engineer at Jardine Matheson Limited
Real User
Reliable solution with good vulnerability management
Pros and Cons
  • "Qualys VM's best features are vulnerability management and customizable scoring."
  • "Qualys VM's vulnerability scan could be improved, especially the number of CVE numbers it can manage at a time."

What is our primary use case?

I use Qualys VM for vulnerability scanning, enterprise management, web application scanning, and patch deployment.

What is most valuable?

Qualys VM's best features are vulnerability management and customizable scoring.

What needs improvement?

Qualys VM's vulnerability scan could be improved, especially the number of CVE numbers it can manage at a time. It could also be more user-friendly. In the next release, Qualys VM should include threat intelligence and external test service management.

For how long have I used the solution?

I've been using Qualys VM for around six months.

What do I think about the stability of the solution?

Qualys VM is stable and reliable.

What do I think about the scalability of the solution?

Qualys VM is quite easy to scale.

How are customer service and support?

Qualys' customer service could be better.

How would you rate customer service and support?

Neutral

How was the initial setup?

The initial setup was not user-friendly.

Which other solutions did I evaluate?

I evaluated Tenable but chose Qualys VM because of its management features.

What other advice do I have?

I would rate Qualys VM eight out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Lead Cyber Security engineer at a manufacturing company with 10,001+ employees
Real User
Provides an overview of the inventory assessment process and can be accessed across the company
Pros and Cons
  • "It gives a very good overview of the inventory assessment process, and it can be accessed across our company because it's a global tool."
  • "It's not very user-friendly at times and requires in-depth understanding. So, a layman or someone new to Qualys won't be able to easily understand it. You need education to use the solution."

What is our primary use case?

We use Qualys Asset Inventory for doing infrastructure level scans or server inventory, or saving the server database or asset database.

How has it helped my organization?

Good Posture of Servers database. Gives easy access of all hardware details. 

What is most valuable?

I think it's a good tracking mechanism, and it gives a good infrastructure level scan, which helps us to maintain the assets and the asset inventory or gives us a good understanding of both. 

It gives a very good overview of the inventory assessment process.

IT Manages assets in your account that you want to scan for security and
compliance, define asset tags and AWS connectors.

Modules supported
VM, PC, SCA, CERTVIEW, CLOUDVIEW

It can be accessed across our company because it's a global tool.

What needs improvement?

One thing that can be improved is the flexibility and the fact that Qualys Asset Inventory provides too much detail, which makes it not very easy to understand. It's not very user-friendly at times and requires in-depth understanding. So, a layman or someone new to Qualys won't be able to easily understand it. You need education to use the solution.

As for additional features, the first thing would be providing call support whenever we require any kind of help with issues that have been identified. The second would be a simple reporting structure.

For how long have I used the solution?

I've been using Qualys Asset Inventory within the last 12 months.

What do I think about the stability of the solution?

Stability-wise, Qualys Asset Inventory is always stable, and for this particular asset inventory, it is a good tool. We have not had any kind of issues, and as of now, it's a stable environment.

What do I think about the scalability of the solution?

We currently have 50 plus users and have no plans to increase usage at present. 

How are customer service and technical support?

Most of the time technical support has been through emails; calling is a back feature. It's not as easy compared to that of Veracode.

How was the initial setup?

The initial setup was quite complex and took two to three months, including customization and testing.

What's my experience with pricing, setup cost, and licensing?

The license is on a yearly basis.

What other advice do I have?

If you are familiar with or have hands on experience with Qualys Asset Inventory, this is a better tool. It will give you in-depth details of all the assets, and the managing inventory will be better. It will also give you advanced features compared to those of other inventory tools.

I would rate Qualys Asset Inventory at eight on a scale from one to ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer1228836 - PeerSpot reviewer
Solutions Architect at a tech services company with 10,001+ employees
Real User
A lightweight solution with good reporting, but multi-cloud support should be improved
Pros and Cons
  • "The most valuable feature is that this solution is very lightweight."
  • "I would like to see this solution simplified to work more easily in a multi-cloud environment."

What is our primary use case?

We are a solution provider and this is one of the products that we implement for our clients. We do a lot of work with containers. With respect to containerization, security is important for us and we regularly check the market to see what solutions are available in these areas.

This solution is primarily used for container security and compliance. Moving into any environment, in particular, one that is cloud-based, our clients want to make sure that things are okay from a compliance perspective. We generate reports and they can see whether there are any violations. If they see violations or security breaches during the audit then they have to be addressed.

What is most valuable?

The most valuable feature is that this solution is very lightweight.

What needs improvement?

I would like to see this solution simplified to work more easily in a multi-cloud environment. One of our customers has more than 3,000 servers across multiple regions, and they were asking about security and vulnerability checking in an automated fashion. This could be done with a cloud-based service that monitors all of the deployments, pulls the data from the containers, and checks for compliance.

For how long have I used the solution?

We have been dealing with Qualys for at least three years, which is when our container journey began. At that point, our proposals did not deal with security for containers because our customers did not ask for it, but now it is something that we recommend.

How are customer service and technical support?

The technical support for this solution is good. We are required to solve any kind of security issue whin two hours, so these are critical tickets. The entire instance usually has to come down until the fix is delivered.

Which other solutions did I evaluate?

We often demonstrate these types of tools to the enterprise architecture team, who will ultimately decide which solutions they are going to implement based on their environment and requirements.

We are completely agnostic with respect to which tools our customers decide to implement. As an engineering team, we implement what the customer wants. In the case of Qualys and other solutions, we download the information and pass it along to our customers. We also facilitate or set up communication between vendors and customers to best help our clients.

We do try to learn about who the providers are and what differentiates their solutions from others. Sometimes our customers do not know very much about the products, so we try to provide as much insight as possible to facilitate their decision making. 

What other advice do I have?

A lot of our customers have a workload that is scattered across a multi-cloud environment. This means that some of the RFPs we answer are based on very large landscapes with distributed workloads.

I would rate this solution a seven out of ten.

Which deployment model are you using for this solution?

Private Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Gabriel Clement - PeerSpot reviewer
Lead IT Security and Remediation at ARM Holdings Company
Real User
Top 5Leaderboard
Cloud-based vulnerability management solution that provides protection of our systems but could offer improved performance
Pros and Cons
  • "This solution gives us insight into our environment and improves our security. It helps us to maintain a good patching system whereby we know that XYZ is vulnerable within the system."
  • "Qualys could be improved in its overall performance compared to other vulnerability management or scanning tools."

What is our primary use case?

We use this solution to scan the servers on the network. It is used predominantly by our information security team.

How has it helped my organization?

This solution gives us insight into our environment and improves our security. It helps us to maintain a good patching system whereby we know that XYZ is vulnerable within the system. 

What is most valuable?

Qualys makes us proactive in terms of handling patching and effective when it comes to scanning out network.

What needs improvement?

Qualys could be improved in its overall performance compared to other vulnerability management or scanning tools. 

For how long have I used the solution?

I have been using this solution for five years. 

Which solution did I use previously and why did I switch?

I have previously used Nessus. Overall, Nessus is a better tool because it provides greater insight into all vulnerabilities, some of which are skipped by Qualys. 

How was the initial setup?

This solution is very easy to set up. 

What about the implementation team?

We worked with a third party to complete deployment. 

What's my experience with pricing, setup cost, and licensing?

In Nigerian Naira, we spend about roughly four to five million to use this solution and this is expensive compared to solutions like Nessus.

What other advice do I have?

I would advise others to run a proof of concept and to exhaust all functionality if considering Qualys. This may take between 15 and 60 days to complete. 

I would rate this solution a six out of ten. 

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Dharmendra Kr. Chauhan - PeerSpot reviewer
Manager|Cloud Security & Solution Architect| CloudOps|AppSec | DevSecOps | DevOps | CapOps | FinOps at Wipro
Real User
A solution with flexible licensing, easy setup and great integration
Pros and Cons
  • "We also like the flexibility in their licensing."
  • "The IoT scan is not great."

What is our primary use case?

We use this solution mainly for vulnerability management.

What is most valuable?

Qualys is a well-known name in the market and we use it for different scenarios. We also like the flexibility in their licensing.

What needs improvement?

The IoT scan is not great and we would like to see some improvements to it.

For how long have I used the solution?

We have been using this solution for over three years.

What do I think about the stability of the solution?

It is a stable solution.

What do I think about the scalability of the solution?

It is a scalable solution. We use the test version.

How are customer service and support?

I rate the technical support an eight out of ten. They have really good support.

How would you rate customer service and support?

Positive

How was the initial setup?

I rate the initial setup a nine out of ten. It was very good and easy. 

What's my experience with pricing, setup cost, and licensing?

It has a competitive price. I rate the pricing an eight out of ten.

What other advice do I have?

I rate this solution a ten out of ten. Compared to other solutions, brand awareness and Azure integration are the strong points of Qualys VM. We would like to have some predefined parameters for the setup in regards to security and vulnerability, and how to maximize it. For example, we want scans and management with some predefined parameters that we need to have in the environment prior to deployment and initial setup.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Tim Cranny - PeerSpot reviewer
Principal at Cranny Group
Real User
Good return on investment, ease of deployment, and metrics
Pros and Cons
  • "The Vulnerability Management and Patch Management features are the most valuable features of this solution."
  • "Endpoint stability and fault resolution could be improved."

What is our primary use case?

It is a SaaS solution with agents distributed at endpoints.

How has it helped my organization?

Qualys VM has improved the way the organization functions.

What is most valuable?

The Vulnerability Management and Patch Management features are the most valuable features of this solution.

The most valuable qualities of Qualys VM are its ease of deployment and metrics.

What needs improvement?

Endpoint stability and fault resolution could be improved.

I would like to see the solution's footprint expanded to include iOS and iPads in the next release.

One example of how it could be better would be better handling of end-of-life systems and better feedback on job failures.

For how long have I used the solution?

We have been working with Qualys VM for just over two years.

It is a cloud platform. I'm not sure if a version is associated with that. 

What do I think about the stability of the solution?

The stability of Qualys VM is quite good, but not fantastic. I would rate it an eight out of ten.

What do I think about the scalability of the solution?

The scalability of Qualys VM is very good.

This solution is used by five security or system administrators in our organization.

We have no plans to expand our usage; it is already widely deployed.

How are customer service and support?

The technical support is mediocre at best.

I would rate them a two out of five.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

We were previously using Lansweeper, which was not scalable.

How was the initial setup?

I would rate the initial setup a three out of five.

It took several weeks to deploy.

What about the implementation team?

We completed the deployment in-house.

What was our ROI?

We have seen a return on investment.

What's my experience with pricing, setup cost, and licensing?

There are no additional fees in addition to the standard licensing fees.

What other advice do I have?

I would recommend identifying the right metrics to drive the program.

I would rate Qualys VM an eight out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free Qualys VMDR Report and get advice and tips from experienced pros sharing their opinions.
Updated: January 2025
Buyer's Guide
Download our free Qualys VMDR Report and get advice and tips from experienced pros sharing their opinions.