Try our new research platform with insights from 80,000+ expert users
reviewer1781004 - PeerSpot reviewer
GM Network Information Security at a tech services company with 1,001-5,000 employees
Real User
Helpful support and scalable
Pros and Cons
  • "Qualys VM had a recent upgrade and the newer version is supporting the cloud."
  • "The reporting and dashboards could improve in Qualys VM. However, they have improved since the previous versions."

What is most valuable?

Qualys VM had a recent upgrade and the newer version is supporting the cloud.

What needs improvement?

The reporting and dashboards could improve in Qualys VM. However, they have improved since the previous versions.

For how long have I used the solution?

I have been using Qualys VM for approximately 10 years.

What do I think about the scalability of the solution?

Qualys VM is highly scalable.

Buyer's Guide
Qualys VMDR
December 2024
Learn what your peers think about Qualys VMDR. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
824,067 professionals have used our research since 2012.

How are customer service and support?

The technical support was very good from Qualys VM.

What was our ROI?

Qualys VM helps to identify the vulnerabilities on a timely basis. It helps the companies to upgrade their networks and apply patches. In the latest version, it has added the patching capability, it's very useful.

What other advice do I have?

My advice to others is this is one of the top solutions in its category. However, they can evaluate many solutions to see for themselves. 

I would recommend this solution to others to implement it in their network.

I rate Qualys VM an eight out of ten

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user254613 - PeerSpot reviewer
Security Consultant at Cyber Intelligence Sdn Bhd
Consultant
The reporting features needs to be improved, but you don't need to spend a lot of time on the deployment.

What is most valuable?

The fact that it's on the cloud, so there's no configuration whatsoever on my physical machine except for the VM scanner.

How has it helped my organization?

It now takes less time to run a vulnerability assessment for our client. I do not have to bring two laptops anymore to my clients sites.

What needs improvement?

Maybe the reporting features. It is too granular, so that if someone new wants to get familiar with it, they will have a hard time. A few more tutorials or guide on screen would also be appreciated.

For how long have I used the solution?

I've been using the consultant edition for two years.

What was my experience with deployment of the solution?

During the internal scanner deployment, but the issue was mostly not the product, but more the network architecture of our client.

What do I think about the stability of the solution?

No issues encountered.

What do I think about the scalability of the solution?

No issues encountered.

How are customer service and technical support?

Customer Service:

9/10

Technical Support:

9/10

Which solution did I use previously and why did I switch?

Rapid 7 Nexpose. To use the software, it takes a whole laptop just to run it, and the results have too much redundancy. Additionally, the scan rate is very slow compared to Qualys, and furthermore it is too expensive when compared to Qualys.

How was the initial setup?

It's very straightforward. Basically you can scan anything external/internet facing within five minutes. For internal scans you have to deploy the internal scanner which can be done in five minutes if the network architecture is not too complex.

What about the implementation team?

It was done In-house, but the help we get from their Singapore support team is awesome.

Which other solutions did I evaluate?

  • Nessus
  • Nexpose

What other advice do I have?

Use it. It is a great product. Many people are sceptical that their scan results are in the cloud. But if you want something affordable and that works like a charm, go for Qualys. Less headaches and easy to achieve ROI as you don't spend much on the deployment or maintenance.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: We have been doing some road-shows, & conferences in Malaysia to introduce Qualys.
PeerSpot user
Buyer's Guide
Qualys VMDR
December 2024
Learn what your peers think about Qualys VMDR. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
824,067 professionals have used our research since 2012.
reviewer1258674 - PeerSpot reviewer
Director for global support at a tech vendor with 1,001-5,000 employees
Real User
A comprehensive, scalable, and easy-to-deploy platform with a nice UI
Pros and Cons
  • "The vulnerability management feature is what I used the most. It is a good SaaS product. It is easy to use. It has a nice UI where you can see all the assets and vulnerabilities."
  • "Certain integration factors between different options could be improved."

What is our primary use case?

It is for vulnerability management. I used it in my previous company, and I also used it for my home network.

It is a SaaS platform. So, there is always the latest version.

What is most valuable?

The vulnerability management feature is what I used the most. It is a good SaaS product. It is easy to use. It has a nice UI where you can see all the assets and vulnerabilities.

What needs improvement?

Certain integration factors between different options could be improved.

For how long have I used the solution?

I worked with this solution for two years. 

What do I think about the stability of the solution?

Its stability and performance are good.

What do I think about the scalability of the solution?

People use it for hundreds and thousands of assets, so it is definitely scalable.

How are customer service and support?

I used to run technical support there. So, I didn't need to go for support.

How was the initial setup?

It is easy and straightforward to set it up. It takes 5 to 10 minutes to set up a new asset.

What's my experience with pricing, setup cost, and licensing?

I used to work there, so I never paid for the product. As an employee, we get a lifetime license for personal use, and that's what I'm using.

It is a comprehensive platform, so there is a lot more to it. There could be other solutions that are probably a little bit cheaper, but it depends on what people need. Different people have different needs. It offers many things on the same platform. If you add all the things up, it should be cheaper, but I have not done any analysis specifically.

What other advice do I have?

It is a good product. I would recommend it to others. It had whatever I needed for my personal use case. There are a lot of features that I have not explored. Some of the features are applicable for corporate networks, and they can't be used for personal use cases.

I would rate it a nine out of 10.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Absar Shaik - PeerSpot reviewer
DevOps Engineer at a financial services firm with 501-1,000 employees
Real User
Detailed reports and the remediation, but interface needs improvements
Pros and Cons
  • "The most valuable feature of Qualys Container Security is the detailed information in the reports and the remediation. This is done to make sure there are no vulnerabilities."
  • "Qualys Container Security can improve the interface. It could be easier to navigate and be enriched."

What is our primary use case?

Qualys Container Security scans similar to a runtime container and it scans the entire cluster.

What is most valuable?

The most valuable feature of Qualys Container Security is the detailed information in the reports and the remediation. This is done to make sure there are no vulnerabilities.

What needs improvement?

Qualys Container Security can improve the interface. It could be easier to navigate and be enriched.

In a future release, it would be beneficial if the network and port policies we provided with some kind of automation AML script files. Having configuration files related to Kubernetes environments would be helpful.

For how long have I used the solution?

I have been using one year.

What do I think about the stability of the solution?

Qualys Container Security is stable.

What do I think about the scalability of the solution?

The scalability of Qualys Container Security is good.

How are customer service and support?

I have used the support from Qualys Container Security and they could improve their knowledge.

I rate the support from Qualys Container Security a two out of five.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

I have not used another similar solution prior to Qualys Container Security.

How was the initial setup?

The initial setup of Qualys Container Security is complex. The documentation could improve.

I rate the initial setup of Qualys Container Security a three out of five.

What other advice do I have?

I rate Qualys Container Security a six out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user254967 - PeerSpot reviewer
Linux Administrator at a comms service provider with 501-1,000 employees
Vendor
The users on the forums are very knowledgeable, but the reporting in the solution is lacking.

What is most valuable?

The reporting and vulnerability analysis features.

How has it helped my organization?

Vulnerability scans are easily managed and maintained using Qualys. What used to be a manual process is now automatic. When we have an issue, I can easily see what production systems are affected and I can easily pinpoint a solution to mitigate the issue.

What needs improvement?

The reporting is lacking a little, and it would be nice to have reports sent via email. Often times we have to manually generate the reports after a vulnerability is fixed and a scan has to be re-run.

For how long have I used the solution?

I've used it for three years.

What was my experience with deployment of the solution?

We did not.

What do I think about the stability of the solution?

Our Qualys box is hardware and it's very easy to set up and maintain. It's very little maintenance, and the most time consuming part is setting up everything initially, such as what subnets you want to scan, what reports you want to run, etc.

What do I think about the scalability of the solution?

We have over 15,000 devices and had no issues with scaling up our Qualys infrastructure.

How are customer service and technical support?

Customer Service:

I have never had to interact with them. I get most of the information on the forums, and even there the responses are lighting fast. As far as actually talking to someone, I personally have never had to speak to Qualys support.

Technical Support:

It's great. The users on the forums are very knowledgeable and eager to help. If I need a quick answer I will always get one from the support forum.

Which solution did I use previously and why did I switch?

We used Nessus before. It was a manual process and very time consuming. I like Nessus, but it was very tedious to get it to function automatically.

How was the initial setup?

There are always complexities to every setup. I think the biggest issue was the learning curve. Having to learn all the new pieces and how they fit into our environment was probably the single biggest hurdle we had to face.

What about the implementation team?

We did it in-house.

Which other solutions did I evaluate?

We looked at Metasploit Expose but the price was too much for what we needed.

What other advice do I have?

Do your research and see how this product would best fit into your environment.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer1405830 - PeerSpot reviewer
Technical Architect at a outsourcing company with 1,001-5,000 employees
Real User
Great vulnerability management but doesn't pick up every vulnerability
Pros and Cons
  • "Qualys VM's best feature is vulnerability management."
  • "Qualys VM's scanner doesn't pick up every vulnerability, so we have to use multiple scanners to cover that gap."

What is most valuable?

Qualys VM's best feature is vulnerability management.

What needs improvement?

Qualys VM's scanner doesn't pick up every vulnerability, so we have to use multiple scanners to cover that gap. Their reporting could also be more user-friendly. In the next release, I would like Qualys to include basic policy and compliance checks in the basic licensing. 

For how long have I used the solution?

I've been using Qualys VM for almost two years.

What do I think about the stability of the solution?

Qualys VM is quite stable - we've had no problems with it.

What do I think about the scalability of the solution?

Qualys VM's scalability depends on the license that you use.

Which solution did I use previously and why did I switch?

Previously we used Nessus, but only Qualys does intrusive scanning.

What about the implementation team?

We used an in-house team.

What's my experience with pricing, setup cost, and licensing?

An annual license for a single scanner costs around $3,000.

What other advice do I have?

Qualys VM is a really good tool for vulnerability scanning, and it has different sets of profiles that can be utilized for your own requirements. I would rate Qualys VM as seven out of ten.

Which deployment model are you using for this solution?

Private Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
PeerSpot user
Shared Information Security Officer at a university with 1,001-5,000 employees
Real User
It is a totally vendor-managed appliance. It distributes administration functions based on access roles.

What is most valuable?

  • Totally vendor-managed appliance
  • Highly scalable and deployable portal interface
  • Ability to easily distribute administration functions based on access roles

How has it helped my organization?

It provides fully automated internal and external vulnerability management.

What needs improvement?

Streamline PCI integration and attestation.

For how long have I used the solution?

I have used it for five years.

What do I think about the scalability of the solution?

I have not encountered any scalability issues.

How are customer service and technical support?

Technical staff are excellent.

Which solution did I use previously and why did I switch?

We previously used Rapid 7. The product was not staying current with shifting trends, sales staff were pushy and management were arrogant.

How was the initial setup?

Initial setup was simple.

What's my experience with pricing, setup cost, and licensing?

Negotiate for the pricing model that fits your budget. The vendor is willing to customize pricing.

Which other solutions did I evaluate?

Before choosing this product, we evaluated Rapid 7, Nessus.

What other advice do I have?

Take your time and have each vendor set up an actual proof of concept, rather than just relying on a demo. Get your network and support staff engaged in the process early on because they will be instrumental in deployment and support. Know what you’re trying to accomplish.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Director Transformación Digital at oesia
Real User
A feature-rich, complete product, and the multilingual technical support is good
Pros and Cons
  • "I like Qualys because it is a very complete product, more so than Tenable."

    What is our primary use case?

    We use this product for vulnerability management.

    What is most valuable?

    I like Qualys because it is a very complete product, more so than Tenable. It has vast capabilities.

    For how long have I used the solution?

    We have been working with Qualys VM for a very short time, perhaps six months.

    What do I think about the stability of the solution?

    This is a stable solution.

    What do I think about the scalability of the solution?

    Scalability-wise, this is a good product.

    How are customer service and technical support?

    The technical support is very good and they have it both in Spanish and English.

    Which solution did I use previously and why did I switch?

    We are also working with Tenable SC. Qualys is both more complete and for us, better in terms of pricing.

    How was the initial setup?

    For a beginning, the initial setup is complex. You have to have some knowledge for setting it up and using it.

    What's my experience with pricing, setup cost, and licensing?

    The price of Qualys for us is better than Tenable, although that is only because we are partners. The retail price of Qualys is higher than that of tenable. The pricing and licensing for Qualys could be improved.

    What other advice do I have?

    Overall, this is a good product and I recommend it, mainly because of the capabilities and the management using a single console. I can even create a calendar for activities from the main screen.

    I would rate this solution a nine out of ten.

    Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
    PeerSpot user
    Buyer's Guide
    Download our free Qualys VMDR Report and get advice and tips from experienced pros sharing their opinions.
    Updated: December 2024
    Buyer's Guide
    Download our free Qualys VMDR Report and get advice and tips from experienced pros sharing their opinions.