Ruan Kotze - PeerSpot reviewer
Head: Cloud Platform Security at BCX Namibia
Reseller
Top 5
Helped us quickly remediate vulnerabilities thanks to its automation and ease of use
Pros and Cons
  • "The biggest benefit is from a security operations perspective, where we are able to drive our security posture upwards by remediating any discovered vulnerabilities."
  • "If anything, I would like to see the user interface modernized a bit more."

What is our primary use case?

Our use cases are primarily on-premises vulnerability management and remediation, external attack surface management and vulnerability scanning.

How has it helped my organization?

The benefits I've seen are twofold. The biggest benefit is from a security operations perspective, where we are able to drive our security posture upwards by remediating any discovered vulnerabilities. We can also automate the remediation process. The other big benefit is executive reporting because it's very easy to produce trends over time to report on risk.

What is most valuable?

The most valuable features are vulnerability detection, patching capabilities, and remediation. Cloud security posture management is also very valuable. I find these features valuable because getting a unified view of your cloud security posture across different environments is not always easy. For example, you might have most of your resources sitting in Azure, but you might have a couple of workloads in AWS. Naturally, there are different tools that report on that, so it's invaluable to have those pulled into a single dashboard so you can drive your remediation from a single platform.

What needs improvement?

If anything, I would like to see the user interface modernized a bit more. Also, there are a lot of various modules, and if they could be consolidated into fewer options, it would make the buying experience easier.

Buyer's Guide
Qualys VMDR
April 2024
Learn what your peers think about Qualys VMDR. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
768,886 professionals have used our research since 2012.

For how long have I used the solution?

I've been working with Qualys VMDR for the last three years or so.

What do I think about the stability of the solution?

We haven’t faced any issues, the solution is very stable.

What do I think about the scalability of the solution?

Because the management sits in the cloud, you don't have to worry about management appliances or anything like that on-premise, so the solution is very scalable. You can split your assets into asset groups and delegate management to different teams. Around 1,000 users are using Qualys in my organization across 60 locations.

How are customer service and support?

We've had very few technical issues, and the customer support team has quickly resolved issues we've had.

How would you rate customer service and support?

Positive

How was the initial setup?

In the first step, Qualys provisions your cloud-based management instance. From there, you get a small, lightweight agent deployed by deployment technology like Microsoft Intune, in our case, SCCM, or any deployment technology.

We worked with BCX Namibia and the Qualys team in South Africa while deploying the solution. It took two weeks to deploy the solution. The solution is not difficult to maintain because the management component is cloud-based and is taken care of by Qualys. Any agent upgrades that might be necessary are very seamless.

What was our ROI?

We have seen an ROI using Qualys. Most breaches nowadays are because of a vulnerability that is exploited. By virtue of being able to identify and remediate these vulnerabilities, I believe we are significantly driving our cybersecurity risk downwards.

What's my experience with pricing, setup cost, and licensing?

The pricing is very competitive, especially because Qualys is integrated and does vulnerability management and remediation patching in one solution, so there's no need for a separate patching solution. You can also get very granular with the amount of IP addresses you can cover. You can go from as few as 16 IP addresses to many more. And the Qualys team is also willing to work with organizations to make the solution make commercial sense. The prices are fixed. We have a yearly subscription model based on the number of IP addresses we’re scanning.

Which other solutions did I evaluate?

We evaluated vulnerability management in Microsoft Defender, but we found the reporting and functionality lacking compared to Qualys. And then the Microsoft licensing costs were also a bit of a dealbreaker.

What other advice do I have?

If you're considering implementing Qualys in your organization, work with a strong pre-sales partner. Evaluate the product, make sure it does what you need, make sure you buy the features that you need, and make sure to use the training and onboarding material that Qualys has made available on its website so you can leverage the solution's full capability from the start. I rate Qualys VMDR a nine out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Microsoft Azure
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
PeerSpot user
Security Expert at a insurance company with 10,001+ employees
Real User
Top 20
The solution is efficient, with easy implementation, and simple to use
Pros and Cons
  • "The most valuable feature of the solution is the external channel."
  • "I would like to have CSPM, a continuous scan-like cloud added to the solution."

What is our primary use case?

Qualys VM is used for vulnerability scans for the internet and applications using application exchange. There are many applications. We also use the solution for asset management per team, and the network scan to discover the devices on our network.

How has it helped my organization?

We have an excellent relationship with the vendor, so we use the solution in our company and in two other companies. We have a communication program. Japanese people can't speak English, but most of the tools have only English support, Qualys VM offers support in other languages which are essential for our company.

What is most valuable?

The most valuable feature of the solution is the external channel. The cloud-based channel within the AWS, which we implement accordingly.

The vulnerability cycle feature of the solution is valuable.

What needs improvement?

I would like to have CSPM, a continuous scan-like cloud added to the solution.

For how long have I used the solution?

I have been using the solution for one year.

What do I think about the stability of the solution?

The solution is stable.

What do I think about the scalability of the solution?

The solution is scalable.

We have 25,000 storage devices that are currently using the solution.

Which solution did I use previously and why did I switch?

We previously used an AWS scanner but switched to Qualys VM because of the Japanese support and the cost. 

How was the initial setup?

The initial setup is straightforward.

Qualys environment is implemented very easily, within one or two months. However, setting up the standard devices, such as opening a firewall, and preparing the network can take up to four or five months. The entire deployment takes about six months.

What about the implementation team?

The implementation was completed in-house.

What other advice do I have?

I give the solution an eight out of ten.

The maintenance is not difficult and we don't have any problems or concerns.

Implementation of the solution is very easy, using the solution is very easy, and it is very efficient.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Qualys VMDR
April 2024
Learn what your peers think about Qualys VMDR. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
768,886 professionals have used our research since 2012.
JoaoManso - PeerSpot reviewer
CIO / IT Consultant at RedShift
Reseller
Top 5
Cloud based service that offers insight into security and the vulnerability management of assets
Pros and Cons
  • "The most valuable feature is the ability to run different capabilities with the same agent. With only one agent, we can have EDR, vulnerability management, compliance and some basic SaaS security capabilities."
  • "This solution could be improved by extending the agent capabilities to different operating systems including Mac and Linux. We would also like the capability to easily check for vulnerability in assets in the IOTs."

What is our primary use case?

We use this solution to manage compliance and to verify the gap between the policy defined by the company and the ones that are implemented in the system. We also use Qualys for vulnerability management of assets in the cloud or on-prem. 

What is most valuable?

The most valuable feature is the ability to run different capabilities with the same agent. With only one agent, we can have EDR, vulnerability management, compliance and some basic SaaS security capabilities.

What needs improvement?

This solution could be improved by extending the agent capabilities to different operating systems including Mac and Linux. We would also like the capability to easily check for vulnerability in assets in the IOTs. 

They have been adding additional features such as attack surface monitoring and intelligence to help managers detect additional risks. Adding intelligence is one of the most important features that we need.

For how long have I used the solution?

We have been using this solution for two years. 

What do I think about the stability of the solution?

This is a stable solution. 

What do I think about the scalability of the solution?

For a company with over 100,000 assets, there are challenges with scalability. 

How are customer service and support?

We haven't often needed support from Qualys but when we have needed it, they have been quick to respond and resolve our issues. 

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

If we compare Qualys VM to other vulnerability management solutions like Tenable, Qualys is only for agents. Their on-prem capabilities are pretty limited so it is very easy to manage assets that are cloud connected, but if they are not cloud connected, it is challenging. Tenable is better at managing non-cloud connected agents.

How was the initial setup?

The initial setup is straightforward. After the cloud tenant is available and the agents are installed, the first scans can be done in one to two days.

There is maintenance required for the agents but it is completely controlled by the cloud and is done automatically. There is a necessity for human intervention when there is a new agent or new feature that must be tested before it is implemented.

What about the implementation team?

We implemented the solution in-house. 

What was our ROI?

Return of investment is difficult to assess because it's a tool that helps to reduce risks but doesn't have a direct feature on ROI.

What's my experience with pricing, setup cost, and licensing?

It is a high cost product. Compared to the other solutions, it is around 15 to 20% higher in cost. Qualys VMDR has multiple features in addition to vulnerability management and there is an additional cost for these features. 

What other advice do I have?

The initial setup is not straightforward and it's important to have the agent connectivity linked to the cloud and available all the time.

If you have assets that are not connected to the cloud, you will need help from a service provider or integrator because the introduction of passive scanning is not straightforward.

I would rate this solution a seven out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Integrator
PeerSpot user
Edward Manuel - PeerSpot reviewer
Risk & Security Admin at Goodyear Tire & Rubber Company
Real User
Top 10
It is scalable and has efficient features for scanning and detecting vulnerabilities
Pros and Cons
  • "It is a stable solution."
  • "We face issues while scanning multiple assets."

What is our primary use case?

We use the solution for vulnerability management.

What is most valuable?

The solution's best features are scanning and vulnerability management. By using them, we can obtain all critical reports.

What needs improvement?

They should improve the solution's pricing. Also, they should enhance the authentication feature. Presently, we face issues while scanning multiple assets. In cases of heavy workloads, it must scan assets properly.

For how long have I used the solution?

We have been using the solution for more than six years.

What do I think about the stability of the solution?

It is a stable solution.

What do I think about the scalability of the solution?

It is a scalable solution. We have more than 50,000 solution users in our organization globally.

How are customer service and support?

The solution's technical support is excellent and responsive.

How was the initial setup?

The solution's initial setup is straightforward.

What about the implementation team?

We have over 30 administrators managing the solution in our organization. In addition to installing the solution internally, we receive assistance from other vendors.

What's my experience with pricing, setup cost, and licensing?

The solution is expensive.

What other advice do I have?

I recommend the solution to others. It is excellent. We can detect and mitigate all the vulnerabilities using it.

I rate the solution as an eight.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Swami Govindan - PeerSpot reviewer
Security Architect at a tech vendor with 5,001-10,000 employees
MSP
Top 10
Good analysis, helpful reports, and a straightforward setup
Pros and Cons
  • "The solution shows us classic categories, including high, medium, and low risks. It also shows critical items, and that gives us the advantage of prioritizing things."
  • "It would be nice to have an all-in-one solution that was automated and could handle the scanning and reports as well as the patching and updating."

What is our primary use case?

This is a virtual scanner appliance. We have both physical and virtual options. 

I'm still in training and getting the hang of the solution. I do not know what features the company uses the most. They generally use it to scan all the AWS workloads and Azure workloads.

What is most valuable?

We generally analyze everything at the OS level and application level, including the open ports, the OS, and older versions, including the packaged versions. We generate the scan, and then we generate the report, and then we will issue it to the application teams to clear off those. 

We have Java remediation happening, and if Java has, for example, multiple versions and when I run the scan, it is going to identify all Java versions that are really vulnerable so you can fix them. Therefore, it helps keep things secure and up-to-date. 

The reporting is good. We give reports to the application teams and we will ask them to either fix or remove applications. Once that is done, then we will read the scan, and if it comes back that we don't have any critical, we are assured of good safety. 

The solution shows us classic categories, including high, medium, and low risks. It also shows critical items, and that gives us the advantage of prioritizing things. 

It's very clear on what components need to be fixed. 

The initial setup is straightforward. 

It's stable.

Technical support is helpful. 

What needs improvement?

I can't speak to disadvantages since I am in training and still learning and have yet to run a scan. 

It would be nice to have an all-in-one solution that was automated and could handle the scanning and reports as well as the patching and updating. 

For how long have I used the solution?

I am pretty new to this organization. However, the organization has been dealing with the solution for almost four or five years now.

What do I think about the stability of the solution?

The stability has been good. The company has been using it for a while and hasn't had issues. I use dit in a previous company as well and never hear of any problems. 

What do I think about the scalability of the solution?

It's easy to scale. 

How are customer service and support?

Technical support is good. We always get a quick response. 

How was the initial setup?

The setup process is simple. It's not overly complex. 

What's my experience with pricing, setup cost, and licensing?

I don't have any details about the licensing process. 

What other advice do I have?

We're implementors. 

When it comes to security, my only advice is based on my experience. They always say to use multiple products due to the fact that, even if the vulnerability is missed in one product, it'll be identified in the other product so that you are safe. 

However, when it comes to implementation, if you have multiple products, pipelining is a big problem. For example, if I use the Qualys scanner, and then it gives me all the vulnerabilities: how do I fix it? Either I have to fix it manually, or I have to fix it automatically. 

I'd like to use one product, and, for example, use a vulnerability scanner from Qualys and have patch management as well. While the solution is still maturing, I like the tight integration and I like that the scanner can identify items and patch management can fix them. It simplifies things, instead of having to deal with multiple products and then maybe having to manually fix items on top of that. 

I'd rate the solution nine out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer: Implementer
PeerSpot user
Former Employee of Orange Business Services as Head of Security Engineering at a comms service provider with 5,001-10,000 employees
Real User
Top 5Leaderboard
Comprehensive and stable solution, but its technical support service needs improvement
Pros and Cons
  • "The solution is easy to use."
  • "They should make it accessible for more operating systems."

What is our primary use case?

We use the solution for vulnerability management. It helps us identify potentially vulnerable assets. Thus, we can prioritize patching based on a risk score.

What is most valuable?

The solution is easy to use and has many essential features. I found the concept of tags the most valuable feature. It allows us to build assets from different views. We can categorize systems with tags, either automatically or manually.

What needs improvement?

The solution's cloud agent is available only for limited operating systems such as Windows and Linux. They should make it accessible for more systems like FreeBSD. Also, it would be helpful if they made it available for Cisco or Juniper routers. Additionally, its price and support could be better as well.

For how long have I used the solution?

We have been using the solution for six years.

What do I think about the stability of the solution?

The solution is stable. However, it takes time to generate reports.

What do I think about the scalability of the solution?

We have ten solution users in our organization.

How are customer service and support?

The solution's technical support team replies with generic answers. The quality of the response could be better.

How would you rate customer service and support?

Neutral

How was the initial setup?

The solution's initial setup process was straightforward. We just followed the documentation.

What's my experience with pricing, setup cost, and licensing?

The solution is costly.

What other advice do I have?

I recommend the solution to others and rate it as a eight.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Assistant Manager Solutions at Mutex Systems Pvt. Ltd.
Real User
Top 20
A robust and user-friendly cloud-based service that gives you immediate, global visibility into potential vulnerabilities and threats
Pros and Cons
  • "I find Qualys VM very robust, and it's very useful for vulnerability management and patch management. The value that it brings to my environment is economies of scale. There is no limitation on adding any endpoints. You go by the rule, and it's added once another endpoint is added to our environment. It's automatically installed, and it's less work from our end. It frees up my license automatically if I don't need an endpoint or if my machine is decommissioned. I like the dashboard displays because I don't see any duplication. The most important part is vulnerability management and prioritization. Unlike Symantec, it shows the kind of vulnerability I would want to patch first. It provides a holistic view of the kind of vulnerabilities and the ones I should remediate first. I don't have to do a scan; it just brings up those critical kinds of vulnerabilities like zero-day vulnerabilities and tells me to prioritize them. You have to prioritize these vulnerabilities first and go on with the rest. The dashboard shows me the ones that have been fixed, so I don't have to complete an aging report. The user experience and the graphical interface are good. As it's user-friendly and understandable on an executive level, it brings real value. We also use this solution because it's robust and flexibile."
  • "The price could be better. Asset view is still a legacy feature. I'm not able to extract the information about the asset with complete details. It would be better if they fixed that in the next release. I know Qualys is already working on it, so I'm hopeful it will be available in the next five or six months. That would be something that's changed where I seek improvement."

What is our primary use case?

We're using the entire suite except for Patch Management. I use Qualys VM for my production environment on Amazon AWS. I also use it for my endpoints and some BDI solutions that require on-premise solutions, and I use it for both.

What is most valuable?

I find Qualys VM very robust, and it's very useful for vulnerability management and patch management. The value that it brings to my environment is economies of scale. There is no limitation on adding any endpoints. You go by the rule, and it's added once another endpoint is added to our environment. It's automatically installed, and it's less work from our end. It frees up my license automatically if I don't need an endpoint or if my machine is decommissioned.

I like the dashboard displays because I don't see any duplication. The most important part is vulnerability management and prioritization. Unlike Symantec, it shows the kind of vulnerability I would want to patch first. It provides a holistic view of the kind of vulnerabilities and the ones I should remediate first.

I don't have to do a scan; it just brings up those critical kinds of vulnerabilities like zero-day vulnerabilities and tells me to prioritize them. You have to prioritize these vulnerabilities first and go on with the rest. The dashboard shows me the ones that have been fixed, so I don't have to complete an aging report.

The user experience and the graphical interface are good. As it's user-friendly and understandable on an executive level, it brings real value. We also use this solution because it's robust and flexibile. 

What needs improvement?

The price could be better. Asset view is still a legacy feature. I'm not able to extract the information about the asset with complete details. It would be better if they fixed that in the next release.

I know Qualys is already working on it, so I'm hopeful it will be available in the next five or six months. That would be something that's changed where I seek improvement.

For how long have I used the solution?

I have been working with Qualys VM for the past six months.

What do I think about the stability of the solution?

Qualys VM is a stable solution.

What do I think about the scalability of the solution?

Qualys VM is a scalable solution. We currently have about 4500 users in our organization.

How are customer service and support?

Support could be a little bit faster. I haven't been granted access to their support portal, but I have a technical support engineer who's always available, and there is only one person I can talk to. But the problem is if he's absent, I'm left waiting for access to his portal. 

Which solution did I use previously and why did I switch?

I used Symantec before but switched to Qualys VM as there's no limitation to adding endpoints. The other reason everyone moved to Qualys VM was its robustness and flexibility. I think that's something that's there, and there was no hassle in deploying the agent. All I had to do was get these machines that were enrolled in our MDM solutions.

How was the initial setup?

As it's a cloud agent, there wasn't any specific setup. It's also managed centrally by Qualys, and when they always release a new update, all we have to do is push it. So, the maintenance requirement is minimum at best.

What about the implementation team?

We deployed this solution by ourselves.

What's my experience with pricing, setup cost, and licensing?

Qualys VM is quite expensive. It's a subscription-based license, and it's yearly. Right now, it's open for me, and I don't have any limitations or caps on the licenses. They are seeing if the product is viable for 4500 users. I can add as much as I want, and at the end of the subscription, they'll let me know how many licenses were actually used and bill me accordingly.

On a scale from one to five, I would give their pricing a three. It's still expensive.

What other advice do I have?

If you're going for an on-premises solution, you should dive into the POC. Because I wasn't procuring an on-premises solution, it was pretty easy for me, and the support was quite helpful. But if you're going to deploy it on-premises, you should go through a proper procedure of going through the POC and getting to know the product. I would rate it at the top because it's better than Nexpose, it's better than Tenable, and it's better than Symantec.

On a scale from one to ten, I would give Qualys VM an eight. 

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Manager, Info Security Planning & Architecture at a comms service provider with 10,001+ employees
Real User
Top 20
A great help to improve and maintain security
Pros and Cons
  • "The most valuable features are vulnerability scanning, policy compliance scanning, and tablet for web application scanning."
  • "Sometimes the scanning can get overwhelmed and start to drag when a lot of users are trying to scan at once."

What is our primary use case?

I mainly use Qualys VM for vulnerability management to carry out vulnerability scans on IT assets to find out which are vulnerable and what is needed to patch them. We also use it for policy compliance scans and in tablet for web application scans.

How has it helped my organization?

Qualys VM has greatly helped us to improve and maintain our posture of security.

What is most valuable?

The most valuable features are vulnerability scanning, policy compliance scanning, and tablet for web application scanning.

What needs improvement?

Sometimes the scanning can get overwhelmed and start to drag when a lot of users are trying to scan at once. I think cloud-based solutions like Qualys VM should be prepared to throw more resources in to ensure they don't get overwhelmed like this.

For how long have I used the solution?

I've been using Qualys VM for about six years.

What do I think about the stability of the solution?

The stability and performance have been fine.

What do I think about the scalability of the solution?

Qualys VM is very easy to scale - that's one of the benefits of cloud-based solutions.

How are customer service and support?

Qualys' technical support is very responsive.

How was the initial setup?

Qualys VM is straightforward to set up.

What about the implementation team?

The deployment was done in-house.

What other advice do I have?

I would advise anybody looking into using Qualys to go online to also check on Gartner and Forrester. From a planning perspective, you need to look at your estate to determine what kind of tool you need. I would rate Qualys VM eight out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free Qualys VMDR Report and get advice and tips from experienced pros sharing their opinions.
Updated: April 2024
Buyer's Guide
Download our free Qualys VMDR Report and get advice and tips from experienced pros sharing their opinions.