Try our new research platform with insights from 80,000+ expert users
reviewer1636329 - PeerSpot reviewer
Senior Vice President | Information Security at a financial services firm with 1,001-5,000 employees
Real User
Very intuitive, easy going and simple to use
Pros and Cons
  • "Intuitive and easy to use."
  • "Reports were lacking somewhat on the customization side."

What is our primary use case?

I used this solution for one of my clients and the primary use case was for the compliance mode and scanning. We are customers of Qualys and I am senior vice president information security.

What is most valuable?

I found the solution quite intuitive and easy going. I have worked with other similar tools and found this simple to use. 

What needs improvement?

I felt hindered sometimes within reports in that they were lacking somewhat on the customization side in terms of making use of the data. The cloud user interface could be a little more responsive. It was a click and then a wait. 

For how long have I used the solution?

I used this solution recently for about five months. 

Buyer's Guide
Qualys VMDR
February 2025
Learn what your peers think about Qualys VMDR. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
838,713 professionals have used our research since 2012.

What do I think about the stability of the solution?

There were a couple of small bugs but the solution was stable. 

What other advice do I have?

I would recommend this solution and rate it a nine out of 10. 

Which deployment model are you using for this solution?

Private Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user254613 - PeerSpot reviewer
Security Consultant at Cyber Intelligence Sdn Bhd
Consultant
The reporting features needs to be improved, but you don't need to spend a lot of time on the deployment.

What is most valuable?

The fact that it's on the cloud, so there's no configuration whatsoever on my physical machine except for the VM scanner.

How has it helped my organization?

It now takes less time to run a vulnerability assessment for our client. I do not have to bring two laptops anymore to my clients sites.

What needs improvement?

Maybe the reporting features. It is too granular, so that if someone new wants to get familiar with it, they will have a hard time. A few more tutorials or guide on screen would also be appreciated.

For how long have I used the solution?

I've been using the consultant edition for two years.

What was my experience with deployment of the solution?

During the internal scanner deployment, but the issue was mostly not the product, but more the network architecture of our client.

What do I think about the stability of the solution?

No issues encountered.

What do I think about the scalability of the solution?

No issues encountered.

How are customer service and technical support?

Customer Service:

9/10

Technical Support:

9/10

Which solution did I use previously and why did I switch?

Rapid 7 Nexpose. To use the software, it takes a whole laptop just to run it, and the results have too much redundancy. Additionally, the scan rate is very slow compared to Qualys, and furthermore it is too expensive when compared to Qualys.

How was the initial setup?

It's very straightforward. Basically you can scan anything external/internet facing within five minutes. For internal scans you have to deploy the internal scanner which can be done in five minutes if the network architecture is not too complex.

What about the implementation team?

It was done In-house, but the help we get from their Singapore support team is awesome.

Which other solutions did I evaluate?

  • Nessus
  • Nexpose

What other advice do I have?

Use it. It is a great product. Many people are sceptical that their scan results are in the cloud. But if you want something affordable and that works like a charm, go for Qualys. Less headaches and easy to achieve ROI as you don't spend much on the deployment or maintenance.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: We have been doing some road-shows, & conferences in Malaysia to introduce Qualys.
PeerSpot user
Buyer's Guide
Qualys VMDR
February 2025
Learn what your peers think about Qualys VMDR. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
838,713 professionals have used our research since 2012.
it_user147540 - PeerSpot reviewer
Security Compliance Analyst at a healthcare company with 501-1,000 employees
Vendor
Delivers higher frequency of scans & better aggregation of results. Ticket management has room for improvement.

Valuable Features

Integrity of scanners; never do I need to worry….“Is this scanner going to bring down a host?”.

Improvements to My Organization

Higher frequency of scans, better aggregation of scan results, abundance of different reports (can be scheduled and automated), delivering metrics to senior management.

Room for Improvement

Ticket management

Use of Solution

5 + years

Deployment Issues

No

Stability Issues

No

Scalability Issues

No

Customer Service and Technical Support

Customer Service: Good – 4 out of 5Technical Support: Good – 4 out of 5

Initial Setup

Straightforward. Assuming you know your network layout, # of devices and other basic information it is pretty simple to figure out what you need. Qualys ships you the scanners, you rack them, set them up and technically could start scanning. Though, there is other recommended tasks to complete via the QualysGuard Vulnerability Management web portal such as defining asset groups, setting up scan rules, turning ticketing on, generating reports, etc.

Implementation Team

In-house

ROI

I do not have a specific quantitative number to provide but from a qualitative perspective it has been enormous. Once you are set up properly and have proper acceptance from support teams, device owners and senior management you can start to scan your environment much more often which increases your organizations ability to detect vulnerabilities more often reducing your overall vulnerability footprint and corresponding business risk.

Pricing, Setup Cost and Licensing

The original setup cost was about $10,000 and the day-to-day costs is less than $100 per day with one caveat. Our parent company is large and has allowed us to fall under their pricing model. If we were not under their model our costs would be about 40% higher.

Other Solutions Considered

No, we had a 3rd party running the scans for us. We were very happy with Qualys but wanted to bring it “in-house”. We brought it in-house 5 years ago and never looked back.

Other Advice

Take the time to properly identify your network and as importantly get approval and acceptance from the group up – especially senior management. In addition, it is very important to have your scan schedule, profiles, reporting, metrics, expectations, etc. documented so that everyone in the company understands your expectations.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Renato Jager - PeerSpot reviewer
CIO at Oakmount
MSP
A powerful virtual scanner appliance that scans batch files, BIT files, and compact files.
Pros and Cons
  • "This is one of the best products I have worked with so far. I like the power of Qualys, and it's a better solution because you can scan a compact file, a BIT file, or batch files. The product already knows what's happening inside, and you don't need to expand the package. Tenable will do the same thing, but you need to have a package issuance claim. With Qualys, we can immediately understand the file, even a compact file. If there's some kind of discovery or incident, you will know what happened in the environment."
  • "Integration could be better. When you think about scanning, it's not used just with this product alone but with other Qualys products. If you think about the bundle, the product itself is good. But integration with other products and packages has space for improvement. They should also offer a better price for bundles."

What is our primary use case?

We use Qualys Virtual Scanner Appliance for the big scan. 

What is most valuable?

This is one of the best products I have worked with so far. I like the power of Qualys, and it's a better solution because you can scan a compact file, a BIT file, or batch files. The product already knows what's happening inside, and you don't need to expand the package. Tenable will do the same thing, but you need to have a package issuance claim. With Qualys, we can immediately understand the file, even a compact file. If there's some kind of discovery or incident, you will know what happened in the environment. 

What needs improvement?

Integration could be better. When you think about scanning, it's not used just with this product alone but with other Qualys products. If you think about the bundle, the product itself is good. But integration with other products and packages has space for improvement. They should also offer a better price for bundles.

For how long have I used the solution?

I have been using Qualys Virtual Scanner Appliance since I joined my company three years ago.

What do I think about the stability of the solution?

Qualys Virtual Scanner Appliance is very stable.

What do I think about the scalability of the solution?

Qualys Virtual Scanner Appliance is scalable.

How was the initial setup?

The initial setup is straightforward. You only need one technician to deploy and maintain this solution. However, it really depends on the size of the customer's environment. 

What's my experience with pricing, setup cost, and licensing?

Qualys Virtual Scanner Appliance isn't expensive right now. But the price for their product bundles could be better.

What other advice do I have?

I would advise potential users to look into the environment and understand what they want to do before implementing this solution. They must understand how to communicate with the network and what kind of network they want to put together. Just read the manual first. 

On a scale from one to ten, I would give Qualys Virtual Scanner Appliance a nine.

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Technology Security Expert at T-Mobile Polska (Deutsche Telekom)
Real User
Identifies and helps to remedy vulnerabilities, has good certificate management
Pros and Cons
  • "The most valuable feature is the certificate management."
  • "The reporting in this solution can be improved."

What is our primary use case?

Our primary use case is vulnerability assessment.

How has it helped my organization?

This solution has provided information about existing vulnerabilities, and helped with quick remediation in case of global malware attacks.

What is most valuable?

The most valuable feature is the certificate management. The reason is the limited license provided by the mother company.

What needs improvement?

The reporting in this solution can be improved.

For how long have I used the solution?

I have been using this solution for five years.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user1017003 - PeerSpot reviewer
Information Technology Analyst at Tata Consultancy Services
Real User
Patch supersedence has been an invaluable feature

What is our primary use case?

Datacenters which are in different locations.

How has it helped my organization?

  • Asset discovery
  • Asset sanitization
  • Scan scheduling
  • Patch supersedence.

What is most valuable?

Patch supersedence.

What needs improvement?

Representation of the total number of vulnerabilities (with name) vs. the number of patches (with name).

For how long have I used the solution?

One to three years.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Alireza Ghahrood - PeerSpot reviewer
Alireza GhahroodConsultant & Instructor -Cyber Security,GovernanceRIskCompliance (CISO as a Services) at Independent
Top 10Real User

Publish!? Or

it_user1004325 - PeerSpot reviewer
Works at Tata Consultancy Services
Real User
Generated more complete coverage of assets and saved time

What is our primary use case?

The primary use case is using this as the infrastructure scanner for an enterprise vulnerability programme in a customer organization.

How has it helped my organization?

The customer was manually testing asset health by point-in-time audits. Using the policy compliance module allowed this to be automated and saved time as well as generated more complete coverage of assets leading to greater assurance.

What is most valuable?

The prebuilt CIS templates are very useful.

What needs improvement?

Expanding the template library would be very useful.

For how long have I used the solution?

Three to five years.
Disclosure: My company has a business relationship with this vendor other than being a customer: My company is a service provider that installs and operates solutions for customers.
PeerSpot user
reviewer1781004 - PeerSpot reviewer
GM Network Information Security at a tech services company with 1,001-5,000 employees
Real User
Helpful support and scalable
Pros and Cons
  • "Qualys VM had a recent upgrade and the newer version is supporting the cloud."
  • "The reporting and dashboards could improve in Qualys VM. However, they have improved since the previous versions."

What is most valuable?

Qualys VM had a recent upgrade and the newer version is supporting the cloud.

What needs improvement?

The reporting and dashboards could improve in Qualys VM. However, they have improved since the previous versions.

For how long have I used the solution?

I have been using Qualys VM for approximately 10 years.

What do I think about the scalability of the solution?

Qualys VM is highly scalable.

How are customer service and support?

The technical support was very good from Qualys VM.

What was our ROI?

Qualys VM helps to identify the vulnerabilities on a timely basis. It helps the companies to upgrade their networks and apply patches. In the latest version, it has added the patching capability, it's very useful.

What other advice do I have?

My advice to others is this is one of the top solutions in its category. However, they can evaluate many solutions to see for themselves. 

I would recommend this solution to others to implement it in their network.

I rate Qualys VM an eight out of ten

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free Qualys VMDR Report and get advice and tips from experienced pros sharing their opinions.
Updated: February 2025
Buyer's Guide
Download our free Qualys VMDR Report and get advice and tips from experienced pros sharing their opinions.