Try our new research platform with insights from 80,000+ expert users
reviewer1228836 - PeerSpot reviewer
Solutions Architect at a tech services company with 10,001+ employees
Real User
A lightweight solution with good reporting, but multi-cloud support should be improved
Pros and Cons
  • "The most valuable feature is that this solution is very lightweight."
  • "I would like to see this solution simplified to work more easily in a multi-cloud environment."

What is our primary use case?

We are a solution provider and this is one of the products that we implement for our clients. We do a lot of work with containers. With respect to containerization, security is important for us and we regularly check the market to see what solutions are available in these areas.

This solution is primarily used for container security and compliance. Moving into any environment, in particular, one that is cloud-based, our clients want to make sure that things are okay from a compliance perspective. We generate reports and they can see whether there are any violations. If they see violations or security breaches during the audit then they have to be addressed.

What is most valuable?

The most valuable feature is that this solution is very lightweight.

What needs improvement?

I would like to see this solution simplified to work more easily in a multi-cloud environment. One of our customers has more than 3,000 servers across multiple regions, and they were asking about security and vulnerability checking in an automated fashion. This could be done with a cloud-based service that monitors all of the deployments, pulls the data from the containers, and checks for compliance.

For how long have I used the solution?

We have been dealing with Qualys for at least three years, which is when our container journey began. At that point, our proposals did not deal with security for containers because our customers did not ask for it, but now it is something that we recommend.

Buyer's Guide
Qualys VMDR
November 2024
Learn what your peers think about Qualys VMDR. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
816,406 professionals have used our research since 2012.

How are customer service and support?

The technical support for this solution is good. We are required to solve any kind of security issue whin two hours, so these are critical tickets. The entire instance usually has to come down until the fix is delivered.

Which other solutions did I evaluate?

We often demonstrate these types of tools to the enterprise architecture team, who will ultimately decide which solutions they are going to implement based on their environment and requirements.

We are completely agnostic with respect to which tools our customers decide to implement. As an engineering team, we implement what the customer wants. In the case of Qualys and other solutions, we download the information and pass it along to our customers. We also facilitate or set up communication between vendors and customers to best help our clients.

We do try to learn about who the providers are and what differentiates their solutions from others. Sometimes our customers do not know very much about the products, so we try to provide as much insight as possible to facilitate their decision making. 

What other advice do I have?

A lot of our customers have a workload that is scattered across a multi-cloud environment. This means that some of the RFPs we answer are based on very large landscapes with distributed workloads.

I would rate this solution a seven out of ten.

Which deployment model are you using for this solution?

Private Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer1248798 - PeerSpot reviewer
Sr. Manager, Vulnerability Management at a transportation company with 10,001+ employees
Real User
Assists us with vulnerability management and policy compliance across our network
Pros and Cons
  • "The most valuable features are vulnerability detection and the scanning capability to enable identification of vulnerabilities across our network."
  • "I would like to see this solution more developed and competitive in the Cloud space."

What is our primary use case?

Our primary uses for this solution are security vulnerability detection and policy compliance.

How has it helped my organization?

It's been the chosen solution year after year for vulnerability management and our vulnerability management program is centered around this tool.

What is most valuable?

The most valuable features are vulnerability detection and the scanning capability to enable identification of vulnerabilities across our network.

What needs improvement?

I would like to see this solution more developed and competitive in the Cloud space.

For how long have I used the solution?

We have been using Qualys VM for fifteen years.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Qualys VMDR
November 2024
Learn what your peers think about Qualys VMDR. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
816,406 professionals have used our research since 2012.
Senior Manager Network Design at MEEZA, Managed IT Services Provider
Real User
Top 5Leaderboard
Versatile features, highly scalable, and beneficial reports
Pros and Cons
  • "The most valuable features of Qualys VM are its ability to do proper vulnerability assessment. It has a lot of updates for all the vulnerability databases from all over the globe. It's an amazing solution when it comes to the versatility of the features it has. Additionally, the reports are very good. It generates very detailed reports about the vulnerabilities inside the environment"
  • "Qualys VM could improve by having more skilled support personnel."

What is our primary use case?

We use bother on-premise and cloud deployments of Qualys VM. For my clients in the cloud, we use a cloud solution, which is a bring your own license model. Additionally, We have our own deployment of Qualys VM.

We are using Qualys VM to provide a VM service.

What is most valuable?

The most valuable features of Qualys VM are its ability to do proper vulnerability assessment. It has a lot of updates for all the vulnerability databases from all over the globe.  It's an amazing solution when it comes to the versatility of the features it has. Additionally, the reports are very good. It generates very detailed reports about the vulnerabilities inside the environment

For how long have I used the solution?

I have been using Qualys VM for approximately five years.

What do I think about the stability of the solution?

Qualys VM is a highly stable solution.

How are customer service and support?

Qualys VM could improve by having more skilled support personnel.

How was the initial setup?

The initial setup of Qualys VM is straightforward. The full implementation took us approximately one day.

What about the implementation team?

We have approximately 100 people who are part of our technical team. We did the implementation of this solution.

What's my experience with pricing, setup cost, and licensing?

There is a license for the use of this solution. We pay annually instead of monthly to receive a better discount on the price.

What other advice do I have?

I would recommend this solution to others.

I rate Qualys VM a nine out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Khizar Butt - PeerSpot reviewer
Country Sales Lead at securic systems
Reseller
Top 5Leaderboard
Vulnerability management tool that integrates well with other products
Pros and Cons
  • "The integrations for this solution are very good. I use a different product for virtual patching of vulnerabilities and Qualys integrates well with that product."
  • "Qualys does have an on-prem solution, but it is very expensive."

What is most valuable?

The integrations for this solution are very good. I use a different product for virtual patching of vulnerabilities and Qualys integrates well with that product.

What needs improvement?

Qualys does have an on-prem solution, but it is very expensive. 

For how long have I used the solution?

I have used this solution for six months. 

What other advice do I have?

I would rate this solution a nine out of ten. 

Disclosure: My company has a business relationship with this vendor other than being a customer:
PeerSpot user
it_user1017003 - PeerSpot reviewer
Information Technology Analyst at Tata Consultancy Services
Real User
Patch supersedence has been an invaluable feature

What is our primary use case?

Datacenters which are in different locations.

How has it helped my organization?

  • Asset discovery
  • Asset sanitization
  • Scan scheduling
  • Patch supersedence.

What is most valuable?

Patch supersedence.

What needs improvement?

Representation of the total number of vulnerabilities (with name) vs. the number of patches (with name).

For how long have I used the solution?

One to three years.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Alireza Ghahrood - PeerSpot reviewer
Alireza GhahroodConsultant & Instructor -Cyber Security,GovernanceRIskCompliance (CISO as a Services) at Independent
Top 10Real User

Publish!? Or

it_user1004325 - PeerSpot reviewer
Works at Tata Consultancy Services
Real User
Generated more complete coverage of assets and saved time

What is our primary use case?

The primary use case is using this as the infrastructure scanner for an enterprise vulnerability programme in a customer organization.

How has it helped my organization?

The customer was manually testing asset health by point-in-time audits. Using the policy compliance module allowed this to be automated and saved time as well as generated more complete coverage of assets leading to greater assurance.

What is most valuable?

The prebuilt CIS templates are very useful.

What needs improvement?

Expanding the template library would be very useful.

For how long have I used the solution?

Three to five years.
Disclosure: My company has a business relationship with this vendor other than being a customer: My company is a service provider that installs and operates solutions for customers.
PeerSpot user
it_user259962 - PeerSpot reviewer
Manager System Security at a comms service provider with 1,001-5,000 employees
Vendor
The installation of the local hardware scanner appliance is easy, but the asset tagging needs lots of improvements.

What is most valuable?

  • Vulnerability management
  • Policy compliance
  • Scalability

How has it helped my organization?

As a leading IT services organization, it is very important for us to have a proactive identification/assessment of vulnerabilities. We also need to be able to remedy them in a timely manner before they exploit our security configuration compliance, and then harden our security for both system/network devices and applications. We need to do this both before and after placing them in production environment.

With QualsyGuard we have been able to achieve this by utilizing its modules, such as vulnerability management, policy compliance, web scanning, malware detection, and asset tagging.

What needs improvement?

As users of Qualys for the last three years, we have identified and shared many areas where Qualys needed to have improvements, including --

  • Vulnerability database having some false positives, although this is rare;
  • Web scan module requires authentication to access basic web forms;
  • Asset tagging needs lots of improvements as it's currently a complex technique; and
  • For policy compliance, they need to add more leading IT standards with regards to all the leading IT service provides like Juniper, Cisco, Microsoft, etc.

For how long have I used the solution?

I've been using this product for the last three years.

What do I think about the stability of the solution?

This is a very stable product and we haven't faced any issues since its deployment apart from announced downtimes for upgrades and improvements.

What do I think about the scalability of the solution?

No issues encountered.

How are customer service and technical support?

Customer Service:

Support is available 24/7 via phone and e-mail. Remote session support is also available.

Technical Support:

They have excellent expertise.

Which solution did I use previously and why did I switch?

No previous solution was used.

How was the initial setup?

It's easy as it is a SaaS, cloud-based service. The installation of the local hardware scanner appliance is also easy.

What about the implementation team?

We used a vendor team who was excellent.

What was our ROI?

I cannot give you the exact ROI on this, but as a large information and communication technology service provider, a 24/7 service availability that leads to customer satisfaction is our key goal. Regular VM and compliance assessment results in the complete hardening of our critical assets defending us against any exploits that leads to unavailability of our services.

Which other solutions did I evaluate?

No, because it was already in use at our parent company and it was providing good results for a low price as well.

What other advice do I have?

  • Collect complete asset inventory details (asset type, service/application details, administrator details etc.).
  • Provide awareness session to the support team about Qualys, its usage, and functionality.
  • Prepare OLAs and SOPs for better co-ordination between the teams.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user216711 - PeerSpot reviewer
it_user216711Product Manager with 1,001-5,000 employees
Real User

Yes, this review is helpful.

it_user147540 - PeerSpot reviewer
Security Compliance Analyst at a healthcare company with 501-1,000 employees
Vendor
Delivers higher frequency of scans & better aggregation of results. Ticket management has room for improvement.

Valuable Features

Integrity of scanners; never do I need to worry….“Is this scanner going to bring down a host?”.

Improvements to My Organization

Higher frequency of scans, better aggregation of scan results, abundance of different reports (can be scheduled and automated), delivering metrics to senior management.

Room for Improvement

Ticket management

Use of Solution

5 + years

Deployment Issues

No

Stability Issues

No

Scalability Issues

No

Customer Service and Technical Support

Customer Service: Good – 4 out of 5Technical Support: Good – 4 out of 5

Initial Setup

Straightforward. Assuming you know your network layout, # of devices and other basic information it is pretty simple to figure out what you need. Qualys ships you the scanners, you rack them, set them up and technically could start scanning. Though, there is other recommended tasks to complete via the QualysGuard Vulnerability Management web portal such as defining asset groups, setting up scan rules, turning ticketing on, generating reports, etc.

Implementation Team

In-house

ROI

I do not have a specific quantitative number to provide but from a qualitative perspective it has been enormous. Once you are set up properly and have proper acceptance from support teams, device owners and senior management you can start to scan your environment much more often which increases your organizations ability to detect vulnerabilities more often reducing your overall vulnerability footprint and corresponding business risk.

Pricing, Setup Cost and Licensing

The original setup cost was about $10,000 and the day-to-day costs is less than $100 per day with one caveat. Our parent company is large and has allowed us to fall under their pricing model. If we were not under their model our costs would be about 40% higher.

Other Solutions Considered

No, we had a 3rd party running the scans for us. We were very happy with Qualys but wanted to bring it “in-house”. We brought it in-house 5 years ago and never looked back.

Other Advice

Take the time to properly identify your network and as importantly get approval and acceptance from the group up – especially senior management. In addition, it is very important to have your scan schedule, profiles, reporting, metrics, expectations, etc. documented so that everyone in the company understands your expectations.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free Qualys VMDR Report and get advice and tips from experienced pros sharing their opinions.
Updated: November 2024
Buyer's Guide
Download our free Qualys VMDR Report and get advice and tips from experienced pros sharing their opinions.