Try our new research platform with insights from 80,000+ expert users
reviewer1228836 - PeerSpot reviewer
Solutions Architect at a tech services company with 10,001+ employees
Real User
A lightweight solution with good reporting, but multi-cloud support should be improved
Pros and Cons
  • "The most valuable feature is that this solution is very lightweight."
  • "I would like to see this solution simplified to work more easily in a multi-cloud environment."

What is our primary use case?

We are a solution provider and this is one of the products that we implement for our clients. We do a lot of work with containers. With respect to containerization, security is important for us and we regularly check the market to see what solutions are available in these areas.

This solution is primarily used for container security and compliance. Moving into any environment, in particular, one that is cloud-based, our clients want to make sure that things are okay from a compliance perspective. We generate reports and they can see whether there are any violations. If they see violations or security breaches during the audit then they have to be addressed.

What is most valuable?

The most valuable feature is that this solution is very lightweight.

What needs improvement?

I would like to see this solution simplified to work more easily in a multi-cloud environment. One of our customers has more than 3,000 servers across multiple regions, and they were asking about security and vulnerability checking in an automated fashion. This could be done with a cloud-based service that monitors all of the deployments, pulls the data from the containers, and checks for compliance.

For how long have I used the solution?

We have been dealing with Qualys for at least three years, which is when our container journey began. At that point, our proposals did not deal with security for containers because our customers did not ask for it, but now it is something that we recommend.

Buyer's Guide
Qualys VMDR
December 2024
Learn what your peers think about Qualys VMDR. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
824,067 professionals have used our research since 2012.

How are customer service and support?

The technical support for this solution is good. We are required to solve any kind of security issue whin two hours, so these are critical tickets. The entire instance usually has to come down until the fix is delivered.

Which other solutions did I evaluate?

We often demonstrate these types of tools to the enterprise architecture team, who will ultimately decide which solutions they are going to implement based on their environment and requirements.

We are completely agnostic with respect to which tools our customers decide to implement. As an engineering team, we implement what the customer wants. In the case of Qualys and other solutions, we download the information and pass it along to our customers. We also facilitate or set up communication between vendors and customers to best help our clients.

We do try to learn about who the providers are and what differentiates their solutions from others. Sometimes our customers do not know very much about the products, so we try to provide as much insight as possible to facilitate their decision making. 

What other advice do I have?

A lot of our customers have a workload that is scattered across a multi-cloud environment. This means that some of the RFPs we answer are based on very large landscapes with distributed workloads.

I would rate this solution a seven out of ten.

Which deployment model are you using for this solution?

Private Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer1248798 - PeerSpot reviewer
Sr. Manager, Vulnerability Management at a transportation company with 10,001+ employees
Real User
Assists us with vulnerability management and policy compliance across our network
Pros and Cons
  • "The most valuable features are vulnerability detection and the scanning capability to enable identification of vulnerabilities across our network."
  • "I would like to see this solution more developed and competitive in the Cloud space."

What is our primary use case?

Our primary uses for this solution are security vulnerability detection and policy compliance.

How has it helped my organization?

It's been the chosen solution year after year for vulnerability management and our vulnerability management program is centered around this tool.

What is most valuable?

The most valuable features are vulnerability detection and the scanning capability to enable identification of vulnerabilities across our network.

What needs improvement?

I would like to see this solution more developed and competitive in the Cloud space.

For how long have I used the solution?

We have been using Qualys VM for fifteen years.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Qualys VMDR
December 2024
Learn what your peers think about Qualys VMDR. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
824,067 professionals have used our research since 2012.
reviewer2004561 - PeerSpot reviewer
Security Specialist at a financial services firm with 1,001-5,000 employees
Real User
Robust, good agent support, and simple to setup
Pros and Cons
  • "It's really beneficial for scanning and interacting with the agent."
  • "The disadvantage of working with Qualys is that the graphical interface is quite outdated."

What is our primary use case?

Qualys VM is used for vulnerability scanning.

What is most valuable?

It's really beneficial for scanning and interacting with the agent. 

What needs improvement?

The disadvantage of working with Qualys is that the graphical interface is quite outdated.

If you want to choose a scan result, or maybe configure an IP range or something similar, it opens up a lot of processes, or steps, which is somewhat bothersome. Because it opens several phases, it is not a single-window program. 

For how long have I used the solution?

We are testing it, as well as Rapid 7 InsightVM.

We have been testing Qualys VM for approximately five weeks.

What do I think about the stability of the solution?

Qualys VM is a stable solution.

What do I think about the scalability of the solution?

Qualys VM is a scalable product.

It works with ten assets. It works with 100 assets. It has worked with 3,000 assets. It's quite scalable.

In our organization, we have two dedicated people, and five others are only dedicated to gaining insights. 

It actually depends on how you remediate all of the vulnerabilities in Qualys since you can also set up it such that product owners, that is, the owners of the apps that are deployed on all systems, can access reports and everything. But that's not how we do things.

The security and infrastructure departments are using this solution in our organization.

How are customer service and support?

We have a dedicated Qualys team of two persons assisting us with the implementation.

Which solution did I use previously and why did I switch?

We are currently doing a proof of concept with both Qualys VM and Rapid 7 InsightVM.

How was the initial setup?

Qualys is a fully SaaS solution.

It is dependent on the configuration. When you work with the agent, you are primarily concerned with deploying the agents to all assets. However, if you want to scan based on IP, you'll run into some problems.

If you wish to scan on an IP basis, for example, you should deploy a virtual appliance. You may set up several appliances for different domains. Otherwise, you must have your network rules properly configured so that the appliance can reach every asset.

It's relatively simple to set up the basics, but if you want to scan, it really depends on how many networks and domains you have.

In a couple of weeks, you can set it up.

What's my experience with pricing, setup cost, and licensing?

It's very expensive, especially if you want to use multiple modules of Qualys.

What other advice do I have?

I think mainly decide how you want to scan: based on IP or based on an agent.

Then work with the interface and then explore how it works.

I would rate Qualys VM an eight out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Senior Manager Network Design at MEEZA, Managed IT Services Provider
Real User
Top 5Leaderboard
Versatile features, highly scalable, and beneficial reports
Pros and Cons
  • "The most valuable features of Qualys VM are its ability to do proper vulnerability assessment. It has a lot of updates for all the vulnerability databases from all over the globe. It's an amazing solution when it comes to the versatility of the features it has. Additionally, the reports are very good. It generates very detailed reports about the vulnerabilities inside the environment"
  • "Qualys VM could improve by having more skilled support personnel."

What is our primary use case?

We use bother on-premise and cloud deployments of Qualys VM. For my clients in the cloud, we use a cloud solution, which is a bring your own license model. Additionally, We have our own deployment of Qualys VM.

We are using Qualys VM to provide a VM service.

What is most valuable?

The most valuable features of Qualys VM are its ability to do proper vulnerability assessment. It has a lot of updates for all the vulnerability databases from all over the globe.  It's an amazing solution when it comes to the versatility of the features it has. Additionally, the reports are very good. It generates very detailed reports about the vulnerabilities inside the environment

For how long have I used the solution?

I have been using Qualys VM for approximately five years.

What do I think about the stability of the solution?

Qualys VM is a highly stable solution.

How are customer service and support?

Qualys VM could improve by having more skilled support personnel.

How was the initial setup?

The initial setup of Qualys VM is straightforward. The full implementation took us approximately one day.

What about the implementation team?

We have approximately 100 people who are part of our technical team. We did the implementation of this solution.

What's my experience with pricing, setup cost, and licensing?

There is a license for the use of this solution. We pay annually instead of monthly to receive a better discount on the price.

What other advice do I have?

I would recommend this solution to others.

I rate Qualys VM a nine out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Gabriel Clement - PeerSpot reviewer
Lead IT Security and Remediation at ARM Holdings Company
Real User
Top 5Leaderboard
Cloud-based vulnerability management solution that provides protection of our systems but could offer improved performance
Pros and Cons
  • "This solution gives us insight into our environment and improves our security. It helps us to maintain a good patching system whereby we know that XYZ is vulnerable within the system."
  • "Qualys could be improved in its overall performance compared to other vulnerability management or scanning tools."

What is our primary use case?

We use this solution to scan the servers on the network. It is used predominantly by our information security team.

How has it helped my organization?

This solution gives us insight into our environment and improves our security. It helps us to maintain a good patching system whereby we know that XYZ is vulnerable within the system. 

What is most valuable?

Qualys makes us proactive in terms of handling patching and effective when it comes to scanning out network.

What needs improvement?

Qualys could be improved in its overall performance compared to other vulnerability management or scanning tools. 

For how long have I used the solution?

I have been using this solution for five years. 

Which solution did I use previously and why did I switch?

I have previously used Nessus. Overall, Nessus is a better tool because it provides greater insight into all vulnerabilities, some of which are skipped by Qualys. 

How was the initial setup?

This solution is very easy to set up. 

What about the implementation team?

We worked with a third party to complete deployment. 

What's my experience with pricing, setup cost, and licensing?

In Nigerian Naira, we spend about roughly four to five million to use this solution and this is expensive compared to solutions like Nessus.

What other advice do I have?

I would advise others to run a proof of concept and to exhaust all functionality if considering Qualys. This may take between 15 and 60 days to complete. 

I would rate this solution a six out of ten. 

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Khizar Butt - PeerSpot reviewer
Country Sales Lead at securic systems
Reseller
Top 5Leaderboard
Vulnerability management tool that integrates well with other products
Pros and Cons
  • "The integrations for this solution are very good. I use a different product for virtual patching of vulnerabilities and Qualys integrates well with that product."
  • "Qualys does have an on-prem solution, but it is very expensive."

What is most valuable?

The integrations for this solution are very good. I use a different product for virtual patching of vulnerabilities and Qualys integrates well with that product.

What needs improvement?

Qualys does have an on-prem solution, but it is very expensive. 

For how long have I used the solution?

I have used this solution for six months. 

What other advice do I have?

I would rate this solution a nine out of ten. 

Disclosure: My company has a business relationship with this vendor other than being a customer:
PeerSpot user
it_user1017003 - PeerSpot reviewer
Information Technology Analyst at Tata Consultancy Services
Real User
Patch supersedence has been an invaluable feature

What is our primary use case?

Datacenters which are in different locations.

How has it helped my organization?

  • Asset discovery
  • Asset sanitization
  • Scan scheduling
  • Patch supersedence.

What is most valuable?

Patch supersedence.

What needs improvement?

Representation of the total number of vulnerabilities (with name) vs. the number of patches (with name).

For how long have I used the solution?

One to three years.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Alireza Ghahrood - PeerSpot reviewer
Alireza GhahroodConsultant & Instructor -Cyber Security,GovernanceRIskCompliance (CISO as a Services) at Independent
Top 10Real User

Publish!? Or

it_user1004325 - PeerSpot reviewer
Works at Tata Consultancy Services
Real User
Generated more complete coverage of assets and saved time

What is our primary use case?

The primary use case is using this as the infrastructure scanner for an enterprise vulnerability programme in a customer organization.

How has it helped my organization?

The customer was manually testing asset health by point-in-time audits. Using the policy compliance module allowed this to be automated and saved time as well as generated more complete coverage of assets leading to greater assurance.

What is most valuable?

The prebuilt CIS templates are very useful.

What needs improvement?

Expanding the template library would be very useful.

For how long have I used the solution?

Three to five years.
Disclosure: My company has a business relationship with this vendor other than being a customer: My company is a service provider that installs and operates solutions for customers.
PeerSpot user
Buyer's Guide
Download our free Qualys VMDR Report and get advice and tips from experienced pros sharing their opinions.
Updated: December 2024
Buyer's Guide
Download our free Qualys VMDR Report and get advice and tips from experienced pros sharing their opinions.