Try our new research platform with insights from 80,000+ expert users
Cyber security specialist at a financial services firm with 10,001+ employees
Real User
Top 20
Reliable tool for managing web application security with effective technical support services
Pros and Cons
  • "Automated scanning has significantly improved our web application security management by reducing manual work."
  • "One area for improvement is the user interface. The new UI, which was recently upgraded, feels more complex and less user-friendly than the old version."

What is our primary use case?

We use the platform for vulnerability management and website testing. It helps us identify and remediate web-based vulnerabilities in our applications, ensuring their security from potential attackers.

What is most valuable?

The solution offers several valuable features. It crawls through all pages quickly and provides fewer false positives than other tools. Additionally, the support team is highly responsive and supportive, addressing any issues promptly.

What needs improvement?

One area for improvement is the user interface. The new UI, which was recently upgraded, feels more complex and less user-friendly than the old version. However, as we continue to use it, we anticipate becoming more accustomed to it. 

Additionally, improved scan scheduling options are needed, which Qualys is working on implementing.

For how long have I used the solution?

We have been using Qualys Web Application Scanning for five years.

Buyer's Guide
Qualys Web Application Scanning
December 2024
Learn what your peers think about Qualys Web Application Scanning. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
824,053 professionals have used our research since 2012.

What do I think about the stability of the solution?

Although we have encountered a few bugs over the past two years, they have been addressed effectively.

I rate the stability an eight. 

What do I think about the scalability of the solution?

The product is scalable. 

How are customer service and support?

The support team is very effective and responsive.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We previously used HCL AppScan. We switched to Qualys primarily because of its superior customer support and responsiveness.

How was the initial setup?

The initial deployment was straightforward. Switching from HCL AppScan to the Qualys solution took approximately six to eight months, including the planning and actual migration.

It does not require significant maintenance. We typically raise two to three cases monthly with the support team, who promptly address them. Otherwise, there are no regular maintenance tasks.

What was our ROI?

While I cannot provide an exact number of hours saved, the automation has reduced the time required for scanning and scheduling tasks by about 70% compared to our previous process.

Over the past five years, we have observed a significant reduction in the failure rate of web applications, from 20% to 2%.

What's my experience with pricing, setup cost, and licensing?

The product pricing is fair and reasonably priced.

What other advice do I have?

We implemented the platform to identify web-based vulnerabilities in our applications, allowing us to address these issues proactively. It helps protect our web applications from potential attackers and secure them against loopholes.

Automated scanning has significantly improved our web application security management by reducing manual work. It has also streamlined the process, saving us considerable time. Previously, scheduling scans for many applications would take about a week, but automation makes this process much quicker and more efficient.

Regarding incident reduction, we have seen about a 20 % decrease. Cost-wise, there has been no significant difference compared to our previous tool. However, the speed of response and reduced false positives have been valuable.

I would recommend it to others for its excellent customer support, scanning efficiency, and scalability. It is a reliable tool for managing web application security.

Overall, I rate it an eight. 

Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
PeerSpot user
reviewer2561502 - PeerSpot reviewer
Senior Application Security Engineer at a real estate/law firm with 501-1,000 employees
Real User
Top 20
Automated scanning enhanced by detailed reporting and integration
Pros and Cons
  • "The most valuable features are the scheduled scanning, detailed reports, asset management, the knowledge database, and the overall product framework."
  • "The authenticated scanning feature could be improved by adding support for real-time scanning tokens and authorization tokens."

What is our primary use case?

We have been using Qualys Web Application Scanning for automated web architecture scanning in an enterprise environment.

How has it helped my organization?

The solution integrates well with our database and asset management, providing a detailed framework that connects products and shares knowledge across them.

What is most valuable?

The most valuable features are the scheduled scanning, detailed reports, asset management, the knowledge database, and the overall product framework. The integration with other tools is also a significant advantage.

What needs improvement?

The authenticated scanning feature could be improved by adding support for real-time scanning tokens and authorization tokens. For example, after sessions, having tokens valid for applications allowing automated authenticated scanning, similar to what Burp offers with proxy support, would be beneficial.

What do I think about the scalability of the solution?

The enterprise-level deployment was scalable and supported our business growth well.

Which solution did I use previously and why did I switch?

We were looking at alternatives like Burp and Acunetix, particularly from the security research side, for better results and accuracy.

What's my experience with pricing, setup cost, and licensing?

Pricing is a significant consideration. Although the product is good for certain details and automated processes, it may not be as cost-effective for some tasks.

Which other solutions did I evaluate?

We evaluated other solutions like Burp and Acunetix.

What other advice do I have?

For specific web applications, Burp may provide better results, however, for integration of tools, Qualys Web Application Scanning is a good choice.

I'd rate the solution eight out of ten.

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
PeerSpot user
Buyer's Guide
Qualys Web Application Scanning
December 2024
Learn what your peers think about Qualys Web Application Scanning. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
824,053 professionals have used our research since 2012.
reviewer1387992 - PeerSpot reviewer
Senior Software Developer at a tech vendor with 1,001-5,000 employees
Real User
Has a good progressive scan feature but the data server needs improvement
Pros and Cons
  • "The feature that I have found most valuable is the progressive scan. It is good. It's done in 24 hours."
  • "The UI is not user-friendly and you don't have a yearly reporting facility where you can slice and dice in different jobs."

What is our primary use case?

I think we have the fastest version, and they always upgrade it. I think it's the $2 or $3-a-month version. They have multiple engines inside it, but it's a site-based service. It is not on-demand, so Qualys will host it. It's the pay as you go service that is on the software-as-a-service. 

We use the DAST, dynamic application scan test.

What is most valuable?

The feature that I have found most valuable is the progressive scan. It is good. It's done in 24 hours.

What needs improvement?

One area that could be improved is the a data server. That's probably what I most noticed in comparison with the Rapid7. Also, the UI is not user-friendly and you don't have a yearly reporting facility where you can slice and dice in different jobs. This is not good. 

Additionally, you don't have a recording feature, where you can record your screen navigation. Like a macro, you want to create the full screen, and they don't provide a tool which can record your navigation and then do a replay.

In terms of what should be included in the next release, like I mentioned, just the UI, the user interface screen. Also, it would be good If they could improve and enrich the reports. These are the fundamental differences with Rapid7.

For how long have I used the solution?

I have been using Qualys Web Application Scanning for five years.

What do I think about the stability of the solution?

Qualys Web Application Scanning is very stable and reliable. But the reporting does not look that great.

What do I think about the scalability of the solution?

In terms of scalability, it is very easy to expand. It's very fast and visible.

We don't have many people working on the solution. But our applications are big applications. We are using six components in different applications.

How are customer service and technical support?

Support is very good.

How was the initial setup?

Because of tasking, the initial setup is very straightforward. We didn't have to purchase any hardware for the installation. It is task-based. The cloud provision is there. It is good. I think nowadays everyone is going with the cloud provisioning. That way you can subscribe for any number of years to use the software. 

I think the initial setup took a couple of hours because there were no plugins and nothing to be installed.

What about the implementation team?

We implemented it ourselves and there was no installation expert here.

Which other solutions did I evaluate?

Yes, we are still comparing it with Rapid7. We want to first make assessments of what advantages we can get with Rapid7.

What other advice do I have?

My advice for anyone considering this solution is, "Go for it." 

On a scale of one to ten, I would give Qualys Web Application Scanning a seven.

Which deployment model are you using for this solution?

Private Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Akhat Tukenov - PeerSpot reviewer
Cyber Security Engineer at Alexis Company
Reseller
Top 10
Provides the best web application vulnerability audit with a lot of integrations but doesn’t allow users to upload their payloads
Pros and Cons
  • "Licensing is the most valuable. Qualys provides the best licensing for companies. It is the best product for the development purposes of web applications. The product has a lot of integrations."
  • "The product should allow users to upload their payloads."

What is our primary use case?

Our customers use the solution to audit their web-application before releasing them to the Internet.

What is most valuable?

Licensing is the most valuable. Qualys provides the best licensing for companies. It is the best product for the development purposes of web applications. The product has a lot of integrations.

What needs improvement?

The product should allow users to upload their payloads.

For how long have I used the solution?

I have been using the solution for three years.

What do I think about the stability of the solution?

I rate the product’s stability an eight out of ten.

What do I think about the scalability of the solution?

I rate the product’s scalability a nine out of ten. 

How was the initial setup?

We did not face any issues while deploying the solution. The product provides good documentation for deployment.

What's my experience with pricing, setup cost, and licensing?

The product has a very good licensing model.

What other advice do I have?

I am using the latest version of the solution.

Tenable makes us wait 90 days to delete the test web application, and Rapid7 does not allow us to delete it as well as  Acunetix (once a year).
I will recommend the solution to others. Overall, I rate the solution an eight out of ten.

Which deployment model are you using for this solution?

Private Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
PeerSpot user
SandeepKumar1 - PeerSpot reviewer
Design Engineer at Uop Ipl, Honeywell
Real User
Good security options but slow response time and needs more integration
Pros and Cons
  • "Qualys WAS' most valuable features are the navigation flow of the UI and the option for a different layer of security (identification and operation through email and mobile)."
  • "Sometimes the response time is low because the handshake fails, and then you have to re-login and start again."

What is our primary use case?

My main use of Qualys WAS is for multifactor authentication for web and mobile applications.

What is most valuable?

Qualys WAS' most valuable features are the navigation flow of the UI and the option for a different layer of security (identification and operation through email and mobile).

What needs improvement?

Sometimes the response time is low because the handshake fails, and then you have to re-login and start again. In the next release, Qualys should include more integration with different applications and single-sign-on protocol.

For how long have I used the solution?

I've been using Qualys Web Application Scanning for a year and a half.

What do I think about the stability of the solution?

Qualys WAS is stable unless we have a breach.

What do I think about the scalability of the solution?

Qualys WAS is scalable.

How are customer service and support?

Qualys' technical support is good but could improve its resolution speed.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Previously, I used CA Identity Solutions by Broadcom, which had easier integration, more options for MFA, and biometric options.

How was the initial setup?

The initial setup was complex and took about three months to deploy. I would rate the setup experience as four out of five.

What about the implementation team?

We used a vendor team.

What's my experience with pricing, setup cost, and licensing?

Qualys WAS' pricing is competitive.

What other advice do I have?

I would recommend getting the POC done before implementing WAS, especially if there will be a lot of APIs involved in developing the product. Look at how the endpoint security works when the APIs run with a different channel, like web and mobile applications. I would give Qualys WAS a rating of six out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
YongjinLee - PeerSpot reviewer
Commercial Pre-Sales at Megazone
Reseller
Top 5
Highly stable and scalable solution which is suitable for enterprise businesses
Pros and Cons
  • "The Qualys Web Application Scanning solution offers a single comprehensive console and consolidated reporting, covering all aspects from on-prem to cloud and compliance, etcetera."
  • "There should be better visibility into the application."

What is our primary use case?

The primary use case includes scanning the web applications that are public facing.

What is most valuable?

The Qualys Web Application Scanning solution offers a single comprehensive console and consolidated reporting, covering all aspects from on-prem to cloud and compliance, etcetera.

What needs improvement?

There should be better visibility into the application. 

For how long have I used the solution?

Our customers have been using this solution for more than three years now.

What do I think about the stability of the solution?

It is a stable solution.

What do I think about the scalability of the solution?

It is a cloud-based solution, so it is easy to scale. 

We work with enterprise-level clients with over 2500 endpoints. 

How are customer service and support?

The customer service and support are good.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I would say Qualys is on the better side. It's more about the performance and the quality of the product because it's been around for a long time.

How was the initial setup?

The initial setup is easy. 

What about the implementation team?

The time taken for implementation depends on the customer's environment. It could take around a month, depending on the module. 

We have a team of two to three people to implement at the enterprise level. Moreover, it is easy to maintain. 

What's my experience with pricing, setup cost, and licensing?

We normally purchase an annual license. There are additional costs. From Qualys, it's for the license and maintenance, which includes patches and stuff like that. Additionally, we have our own service delivery costs.

Which other solutions did I evaluate?

I'm familiar with all of the Qualys-based products because we partner with Qualys, so I have a local contact in New Zealand who helps me with all the technical information.

Moreover, I'm a pre-sales specialist, so I recommend the solution to our potential customers and then we implement through another team for customers.

What other advice do I have?

Qualys is a stable and reliable solution. It has been around for a long time.

Overall, I would rate the solution an eight out of ten. There is scope for improvement. It is still an early technology. 

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
PeerSpot user
S S RAMA KRISHNA MURTHY  SURI - PeerSpot reviewer
Senior Manager at valuelabs LLP
MSP
Helpful support, many great integrations, and lots of reference material
Pros and Cons
  • "It works with many different products."
  • "There could be better management and faster scanning."

What is our primary use case?

We use the solution alongside others for static scanning. It's used for endpoint scanning. 

What is most valuable?

The monitor's ability to read the reports, or to do very detailed reports is great. It's good at looking at the different vulnerabilities. Rarely are there security loopholes. It can also suggest ways to mitigate risks and vulnerabilities. 

There's a lot of great reference material. 

The integration is great. It works with many different products. 

What needs improvement?

There could be better management and faster scanning. An application may have a lot of URLs and complexity. If there are a couple of applications, that complexity multiplies. It can take three or four days to scan. That's too long. It should be maybe three or four hours. 

For how long have I used the solution?

We've been using the solution for two years. 

What do I think about the stability of the solution?

It's a stable product. There are no bugs or glitches and it doesn't crash or freeze. The solution is reliable. 

What do I think about the scalability of the solution?

It leverages the cloud. One of the upsides of that is the scalability that is possible. 

We have about 500 to 600 people on the solution currently.

How are customer service and support?

Technical support is very good whenever we send them a message. They will schedule a call and then they will check in with us until the issue's resolved or until we understand the entire problem and they clarify issues. They're very quick as well.

How was the initial setup?

The initial setup, due to the fact that it is the cloud, is very easy. It's a SaaS solution. We don't have to install anything in order to get going. You are on it right away. There is no deployment time to get through. 

Since it's so quick and immediate, you don't need a big team to get it of the ground. 

What about the implementation team?

We were able to handle the implementation ourselves. It's not hard. You don't need consultants or integrators.

What was our ROI?

We have seen an ROI and my understanding is that it is pretty good. 

What's my experience with pricing, setup cost, and licensing?

I don't directly deal with the licensing aspect of the product. 

What other advice do I have?

I'd recommend the solution to others. We haven't had any issues after two years of working with it. 

I'd rate the solution eight out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer1138395 - PeerSpot reviewer
Sr Cybersecurity Leader at a non-tech company with 1,001-5,000 employees
Real User
We like its process of updating signatures, and it's way ahead of its industry peers.
Pros and Cons
  • "Qualys' process of updating signatures is something we really appreciate, and it's way ahead of its industry peers."
  • "We procured around 110 licenses for Web Application Scanning, but we have issues running concurrent scans. I don't currently have the option to trigger scans for all 100-plus websites. The default limit is around 10 conference scans. It's not very scalable, to be honest, because of the limitation that they put on concurrent scans."

What is our primary use case?

There are two parts. We use Web Application Scanning licenses to constantly assess our websites. When there are any changes on our websites, Qualys checks to see if there is a vulnerability. We use a SecOps/DevOps methodology, so Qualys is integrated into the development cycle. Qualys runs every time we update the site.

What is most valuable?

Qualys' process of updating signatures is something we really appreciate, and it's way ahead of its industry peers. 

For how long have I used the solution?

We have been using Web Application Scanning since 2018. 

What do I think about the stability of the solution?

Web Application Scanning is a stable solution.

What do I think about the scalability of the solution?

We procured around 110 licenses for Web Application Scanning, but we have issues running concurrent scans. I don't currently have the option to trigger scans for all 100-plus websites. The default limit is around 10 conference scans. It's not very scalable, to be honest, because of the limitation that they put on concurrent scans.

How are customer service and support?

I've had some issues with Qualys support. It's transactional. There is no face to the support model. I don't see anyone from Qualys engaging with us on a quarterly business or annual business review to help us understand if we are fully utilizing Qualys' capabilities. 

This isn't a technical problem. It's more of an issue with customer relations. I think they can improve by touching base with us more often to let us know if our rollout is following industry best practices or not. 

How was the initial setup?

We used Verizon to help us with the rollout, and there were no trouble tickets or any technical issues with the rollout, so I would say the implementation was pretty smooth. The design-build phase took a couple of weeks.

What's my experience with pricing, setup cost, and licensing?

We pay for a yearly license, but we also pay a separate cost for an engineer from Verizon.

Which other solutions did I evaluate?

When evaluating Qualys, we looked at industry best practices and state of-art-tools. Qualys was the default leader in its segment, so we went ahead with Qualys. I've used other solutions in the past, but Qualys the segment. That's why we went with them.

What other advice do I have?

I rate Qualys Web Application Scanning nine out of 10. I think Web Application Scanning should integrate VMDR, a more enhanced capability that Qualys offers for enterprise vulnerability assessments. However, Qualys is way ahead of the competition on the web application front. 

If you're an industrial company, you should evaluate the OT scanning capability that Qualys is about to launch. It will cover all your enterprise web applications and secure your factories as well. Qualys should be a one-stop shop meeting all your end-to-end vulnerability assessment requirements, so you don't need to buy solutions from different vendors,

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free Qualys Web Application Scanning Report and get advice and tips from experienced pros sharing their opinions.
Updated: December 2024
Buyer's Guide
Download our free Qualys Web Application Scanning Report and get advice and tips from experienced pros sharing their opinions.