We just raised a $30M Series A: Read our story
Omar ORta
Director Transformación Digital at oesia
Real User
Top 20
A feature-rich, complete product, and the multilingual technical support is good

Pros and Cons

  • "I like Qualys because it is a very complete product, more so than Tenable."

    What is our primary use case?

    We use this product for vulnerability management.

    What is most valuable?

    I like Qualys because it is a very complete product, more so than Tenable. It has vast capabilities.

    For how long have I used the solution?

    We have been working with Qualys VM for a very short time, perhaps six months.

    What do I think about the stability of the solution?

    This is a stable solution.

    What do I think about the scalability of the solution?

    Scalability-wise, this is a good product.

    How are customer service and technical support?

    The technical support is very good and they have it both in Spanish and English.

    Which solution did I use previously and why did I switch?

    We are also working with Tenable SC. Qualys is both more complete and for us, better in terms of pricing.

    How was the initial setup?

    For a beginning, the initial setup is complex. You have to have some knowledge for setting it up and using it.

    What's my experience with pricing, setup cost, and licensing?

    The price of Qualys for us is better than Tenable, although that is only because we are partners. The retail price of Qualys is higher than that of tenable. The pricing and licensing for Qualys could be improved.

    What other advice do I have?

    Overall, this is a good product and I recommend it, mainly because of the capabilities and the management using a single console. I can even create a calendar for activities from the main screen.

    I would rate this solution a nine out of ten.

    Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
    PL
    IT Consultant Supervisor at a financial services firm with 5,001-10,000 employees
    Consultant
    Top 20
    Scans our security posture and has very good scalability

    What is our primary use case?

    We use Qualys to check the status of our security posture.

    How has it helped my organization?

    Qualys help identifies the weakness in our critical infrastructure and provides guidelines how to address them.

    What is most valuable?

    maybe compliance monitoring.

    What needs improvement?

    Reporting can be improved more. It should generate much more stuff like field reports. Though the reports generally meet our need we hope we can customize it better.

    For how long have I used the solution?

    2 years

    What do I think about the stability of the solution?

    very satisfactory

    What do I think about the scalability of the solution?

    Its scalability is a four or five out of five. 

    How are customer service and technical support?

    We haven't had problems…

    What is our primary use case?

    We use Qualys to check the status of our security posture.

    How has it helped my organization?

    Qualys help identifies the weakness in our critical infrastructure and provides guidelines how to address them.

    What is most valuable?

    maybe compliance monitoring.

    What needs improvement?

    Reporting can be improved more. It should generate much more stuff like field reports. Though the reports generally meet our need we hope we can customize it better.

    For how long have I used the solution?

    2 years

    What do I think about the stability of the solution?

    very satisfactory

    What do I think about the scalability of the solution?

    Its scalability is a four or five out of five. 

    How are customer service and technical support?

    We haven't had problems up until this point that required technical support. The solution can run by itself and generate reports. We didn't have any issues that would need us to call technical support.

    Which solution did I use previously and why did I switch?

    None

    How was the initial setup?

    Simple and straightforward

    What about the implementation team?

    in-house.

    What was our ROI?

    acceptable.

    What's my experience with pricing, setup cost, and licensing?

    I would give the pricing three out of five.

    Which other solutions did I evaluate?

    No.

    What other advice do I have?

    I would like for Qualys to have the ability to scan OT operation technology assets as well. 

    If it can I would rate it 8 out of 10. 

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    Find out what your peers are saying about Qualys, Rapid7, Tenable Network Security and others in Vulnerability Management. Updated: November 2021.
    555,139 professionals have used our research since 2012.
    ME
    Senior Cyber Security Specialist at a tech services company with 1,001-5,000 employees
    Real User
    Top 5Leaderboard
    The reporting and GUI need improvement but it's reliable

    Pros and Cons

    • "Qualys VM is very stable."
    • "The reporting and the GUI need improvements."

    What is our primary use case?

    It was responsible for vulnerability scanning. It enforces vulnerability management websites.

    What needs improvement?

    The reporting and the GUI need improvements. Tenable dominated in these two areas: reporting and graphical user interface.

    For how long have I used the solution?

    Qualys VM was used once for one of our customers.

    We were using the latest version.

    What do I think about the stability of the solution?

    Qualys VM is very stable.

    What do I think about the scalability of the solution?

    I didn't have all of the necessary information regarding the scalability or how to scale this solution, but all vulnerability management solutions have the same idea. 

    I believe that it is easy to scale.

    How are customer service and support?

    I did not contact technical support.

    Which solution did I use previously and why did I switch?

    I have also used Rapid7, which is very similar to Qualys VM.

    Scaling is more difficult with Rapid7. When it comes to scaling, Rapid7 is not my first choice.

    How was the initial setup?

    I did not implement this solution, I performed one scan for our client.

    What other advice do I have?

    We have regulations in place in Saudi Arabia and Egypt that require all vulnerability management solutions to be implemented on-premise.

    I would recommend this solution to others but Tenable is my preferred option.

    I would rate Qualys VM a five out of ten.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    Flag as inappropriate
    VM
    Consultant at a tech services company with 11-50 employees
    Reseller
    Provides excellent security for scanning, flexible with good integration

    What is our primary use case?

    We are consultants and resellers of Qualys VM. 

    What is most valuable?

    I like the solution's web application security for scanning, the solution is flexible with good integration. 

    What needs improvement?

    I'd like to see additional security for the app. The product lacks integrations for third party solutions or automation integration for other tools.

    For how long have I used the solution?

    I've been using this solution for six months. 

    What do I think about the stability of the solution?

    The product is 100% stable. There are five users in the company who deal with operations and security analysis. There are four people in the company who deploy and provide support.

    How are customer service and technical support?

    I've never used the…

    What is our primary use case?

    We are consultants and resellers of Qualys VM. 

    What is most valuable?

    I like the solution's web application security for scanning, the solution is flexible with good integration. 

    What needs improvement?

    I'd like to see additional security for the app. The product lacks integrations for third party solutions or automation integration for other tools.

    For how long have I used the solution?

    I've been using this solution for six months. 

    What do I think about the stability of the solution?

    The product is 100% stable. There are five users in the company who deal with operations and security analysis. There are four people in the company who deploy and provide support.

    How are customer service and technical support?

    I've never used the technical support. Documentation is simple and complete. 

    Which solution did I use previously and why did I switch?

    I've previously worked with Tenable IO and Rapid 7. We switched because of Qualys's web application feature.

    How was the initial setup?

    The initial setup is straightforward. Initial deployment takes between two and four hours. We did it ourselves. 

    What other advice do I have?

    I would recommend this solution. 

    I would rate this solution a 10 out of 10. 

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Microsoft Azure
    Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
    HS
    Senior Vice President | Information Security at a financial services firm with 1,001-5,000 employees
    Real User
    Very intuitive, easy going and simple to use

    What is our primary use case?

    I used this solution for one of my clients and the primary use case was for the compliance mode and scanning. We are customers of Qualys and I am senior vice president information security.

    What is most valuable?

    I found the solution quite intuitive and easy going. I have worked with other similar tools and found this simple to use. 

    What needs improvement?

    I felt hindered sometimes within reports in that they were lacking somewhat on the customization side in terms of making use of the data. The cloud user interface could be a little more responsive. It was a click and then a wait. 

    For how long have I used the solution?

    I used this solution recently for about five months. 

    What do I think about the stability of the solution?

    There were a…

    What is our primary use case?

    I used this solution for one of my clients and the primary use case was for the compliance mode and scanning. We are customers of Qualys and I am senior vice president information security.

    What is most valuable?

    I found the solution quite intuitive and easy going. I have worked with other similar tools and found this simple to use. 

    What needs improvement?

    I felt hindered sometimes within reports in that they were lacking somewhat on the customization side in terms of making use of the data. The cloud user interface could be a little more responsive. It was a click and then a wait. 

    For how long have I used the solution?

    I used this solution recently for about five months. 

    What do I think about the stability of the solution?

    There were a couple of small bugs but the solution was stable. 

    What other advice do I have?

    I would recommend this solution and rate it a nine out of 10. 

    Which deployment model are you using for this solution?

    Private Cloud
    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    Flag as inappropriate
    RB
    Consultant at a media company with 51-200 employees
    Consultant
    Enables us to check the validity of legacy applications, infrastructure, and simple data operating systems

    What is our primary use case?

    I use Qualys to review the validity of legacy applications, infrastructure, and simple data operating systems.

    What needs improvement?

    The ability to manage user accounts and give rights to the operator to know about abnormalities of applications is something that needs improvement.  The pricing is also expensive.

    For how long have I used the solution?

    I have been using Qualys for four years. 

    What do I think about the stability of the solution?

    It's stable.

    How are customer service and technical support?

    I haven't needed to use technical support. 

    How was the initial setup?

    The initial setup was good. We didn't have any problems with it. 

    What other advice do I have?

    I would rate Qualys VM a ten out of ten. 

    What is our primary use case?

    I use Qualys to review the validity of legacy applications, infrastructure, and simple data operating systems.

    What needs improvement?

    The ability to manage user accounts and give rights to the operator to know about abnormalities of applications is something that needs improvement. 

    The pricing is also expensive.

    For how long have I used the solution?

    I have been using Qualys for four years. 

    What do I think about the stability of the solution?

    It's stable.

    How are customer service and technical support?

    I haven't needed to use technical support. 

    How was the initial setup?

    The initial setup was good. We didn't have any problems with it. 

    What other advice do I have?

    I would rate Qualys VM a ten out of ten. 

    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    BM
    Sr. Manager, Vulnerability Management at a transportation company with 10,001+ employees
    Real User
    Top 5
    Assists us with vulnerability management and policy compliance across our network

    What is our primary use case?

    Our primary uses for this solution are security vulnerability detection and policy compliance.

    How has it helped my organization?

    It's been the chosen solution year after year for vulnerability management and our vulnerability management program is centered around this tool.

    What is most valuable?

    The most valuable features are vulnerability detection and the scanning capability to enable identification of vulnerabilities across our network.

    What needs improvement?

    I would like to see this solution more developed and competitive in the Cloud space.

    For how long have I used the solution?

    We have been using Qualys VM for fifteen years.

    What is our primary use case?

    Our primary uses for this solution are security vulnerability detection and policy compliance.

    How has it helped my organization?

    It's been the chosen solution year after year for vulnerability management and our vulnerability management program is centered around this tool.

    What is most valuable?

    The most valuable features are vulnerability detection and the scanning capability to enable identification of vulnerabilities across our network.

    What needs improvement?

    I would like to see this solution more developed and competitive in the Cloud space.

    For how long have I used the solution?

    We have been using Qualys VM for fifteen years.

    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    Product Categories
    Vulnerability Management
    Buyer's Guide
    Download our free Vulnerability Management Report and find out what your peers are saying about Qualys, Rapid7, Tenable Network Security, and more!