Lead Security Architect at a financial services firm with 501-1,000 employees
Real User
Puts our services in compliance and minimizes our risk for exposure
Pros and Cons
  • "With our vulnerabilities under control, it's putting our services in compliance and minimizing our risk for exposure."
  • "The solution needs to adjust its pricing. They should make it more affordable."

How has it helped my organization?

With our vulnerabilities under control, it puts our services in compliance and minimizes our risk for exposure.

What is most valuable?

The vulnerability scanning and patching features are the most valuable parts of the solution.

What needs improvement?

The solution needs to adjust its pricing. They should make it more affordable.

For how long have I used the solution?

I've been using the solution for over five years.
Buyer's Guide
Qualys Web Application Scanning
April 2024
Learn what your peers think about Qualys Web Application Scanning. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
770,141 professionals have used our research since 2012.

What do I think about the stability of the solution?

The solution is stable.

What do I think about the scalability of the solution?

The cloud service makes the solution very scalable. We have about ten users right now, however we don't intend to increase usage at this time.

How are customer service and support?

Technical support is excellent. I would rate it ten out of ten.

Which solution did I use previously and why did I switch?

We've never used a different solution.

How was the initial setup?

The initial setup was straightforward. Deployment took about two weeks.

What about the implementation team?

Our internal team handled the implementation.

Which other solutions did I evaluate?

We did not evaluate other options before choosing Qualys.

What other advice do I have?

We are using the cloud deployment model.

I would recommend other users to use Qualys Application Scanning for application security. If you're serious about security you need a service or a solution that does continuous scanning of your application and infrastructure. There are always vulnerabilities being introduced.

I would rate the solution eight out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
PeerSpot user
Ex Senior Security Analyst and Onsite consultant at Paladion Networks
Consultant
Its web-based scanner is very useful for performing external penetration and PCI scans from remote locations
Pros and Cons
  • "​QualysGuard web-based scanner is very useful for performing external penetration and PCI scans from remote locations.​"
  • "By using QualysGuard, we are able to finish external scans with assured results in half the time.​"
  • "​This product is designed for easy scalability and can easily scale up ​without major challenges."
  • "​We have experienced quick customer support. They have a complete list of our previous issues along with our history, which makes it faster for them to solve issues.​"
  • "They should try to include business logic vulnerabilities in the scanner testing."
  • "In certain cases, this product does have false positives, which the company should work on."

What is our primary use case?

We use Qualys Internet-based scanners for external penetration testing as well as PCI scans for our clients. The tool being Internet based, it can be accessed from any location, and it does not have issues with updating the patches as well as versions (QualysGuard updates the tool at specific periods in a year with prior information). The report generated by QualysGuard is very detailed and easy to understand.

How has it helped my organization?

In order to finish a project, a penetration test in our company is on average five days, including documentation. Without this tool, the testing would take five days! 

By using QualysGuard, we are able to finish external scans with assured results in half the time.

What is most valuable?

QualysGuard web-based scanner is very useful for performing external penetration and PCI scans from remote locations.

What needs improvement?

In certain cases, this product does have false positives, which the company should work on. They should also try to include business logic vulnerabilities in the scanner testing.

For how long have I used the solution?

Three to five years.

What do I think about the stability of the solution?

The product that we used in our office under different environments is highly stable.

What do I think about the scalability of the solution?

This product is designed for easy scalability and can easily scale up without major challenges.

How is customer service and technical support?

We have experienced quick customer support. They have a complete list of our previous issues along with our history, which makes it faster for them to solve issues.

How was the initial setup?

It is a straightforward implementation. Once you register over the Internet, they assign you a set of static IP addresses which can be used to perform web-based scans. The administrator panel is easy to understand and create.

What's my experience with pricing, setup cost, and licensing?

It is best to be an institutional buyer and directly contact the sales team, as they can provide over-the-top discounts for bulk orders.

Try the free trial of the product to understand the basic working mechanisms.

Which other solutions did I evaluate?

We did try Acutenix, but the quality of results and user interface of Qualys was excellent in comparison.

What other advice do I have?

We are an institutional partner of QualysGuard and buy bulk licenses. 

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner.
PeerSpot user
Buyer's Guide
Qualys Web Application Scanning
April 2024
Learn what your peers think about Qualys Web Application Scanning. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
770,141 professionals have used our research since 2012.
CEO at a tech services company with 51-200 employees
Real User
Has comprehensive SSL security measurements but the price should be lowered
Pros and Cons
  • "The simplicity of exporting reports and the simplicity and clarity of the reports included with the product are good."
  • "The pricing does not seem to be competitive."

What is our primary use case?

For some projects, we will need to use this on-premises. It depends on the confidentiality of our project. For other projects, we will also be deploying on the cloud or maybe a hybrid solution as well.  

We are looking forward to having a relationship as a partner with this company and maybe one or two others. We are not just a customer. We have a bunch of freelancers that we are working with in three different companies in Slovenia, Australia, and other countries. We are looking for solutions to make our testing and security checks more affordable.  

What is most valuable?

I am not the person who is actually directly testing this. One of the other people from our team is doing that. But I was involved in the selection of what we products we should compare based on available features, demos, and how products appear to meet our needs. What I remember from my experience with Qualys is that the simplicity of exporting reports and the simplicity and clarity of the reports included with the product is good. The website was also well-designed and easy to navigate. The SSL security measurements that the product offers seem comprehensive. But I can not say, at this preliminary phase, that I specifically think this or that from Qualys is the most valuable. It is intriguing enough to make our shortlist and POC efforts.  

What needs improvement?

Knowing we are in an early phase of discovery and comparison, it is impossible to know exactly what features may need improvement. Some seem to be interesting, on the other hand. The only thing that is in need of improvement from my perspective at this point is pricing in comparison to other, similar products.   

For how long have I used the solution?

We are in the process of analyzing several products over several months in this category for comparison and proof of concept.  

How are customer service and technical support?

We have not yet had to contact technical support for any reason.  

How was the initial setup?

I don't have information at this moment because we are in the process of discovery and we have not fully deployed. We do have a test deployment running.  

What's my experience with pricing, setup cost, and licensing?

The pricing of Qualys is quite expensive in comparison with the other products in this category that are offering pretty much the same thing. Pricing is one area of the product that can be improved. At this stage of our discovery, we only know the initial cost is high.  

Which other solutions did I evaluate?

We were testing a lot of products. We were looking for a good product for our needs and for the needs of our customers to scan vulnerabilities. Qualys was one of the products we chose to do further testing with. The testing with data is still continuing and is a process. As we are in the process of discovery now, we cannot exactly qualify our experience with the product.  

What other advice do I have?

On a scale from one to ten where one is the worst ten is the best, I would rate Qualys as a seven at this point. It is difficult to rate Qualys — or even products from other companies — as better than this because we are hearing the same thing from all the product manufacturers before we went into testing. But based on the references from other users about Qualys, our current level of experience, the pricing as we know it and the services that are offered for free, Qualys is a seven.  

What we have mostly found at this point is that you can't just install a free trial version of a product and get a complete impression immediately. With some products like Qualys or others in the category, the pricing may not be completely right because there are hidden costs. It could be one solution is not quick to deploy and that seems to make it difficult but in actual use, it is easier than everything else. Some products will be easy to set up and after 10 days of trying to work with it, I might be disappointed because of what I committed to.  

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user335103 - PeerSpot reviewer
Info-Security Consultant at a financial services firm with 1,001-5,000 employees
Vendor
It protects against zero-day vulnerabilities, like Heartbleed.

What is most valuable?

It protects against zero-day vulnerabilities, like Heartbleed.

What needs improvement?

It's missing some zero-day patches.

For how long have I used the solution?

I've used it for a few months.

What was my experience with deployment of the solution?

No issues encountered.

What do I think about the stability of the solution?

No issues encountered.

What do I think about the scalability of the solution?

No issues encountered.

How are customer service and technical support?

Customer Service:

It's high.

Technical Support:

It's high.

Which solution did I use previously and why did I switch?

I used Rapid7 NeXpose in another shop.

How was the initial setup?

The product was already installed when I got there, I just added more scanning jobs and used the reports for remediation, etc.

Which other solutions did I evaluate?

I evaluated and selected Rapid7 NeXpose in a previous job (over QualysGuard) because the compliance department there vetoed using “an external service”. Also, we wanted to get Metasploit later.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user563475 - PeerSpot reviewer
Deputy Manager at a tech services company with 10,001+ employees
Consultant
Network scanner has good reporting and coverage, but it needs manual pen testing

What is our primary use case?

Cloud hosted application, and was also accessible through mobile app.

How has it helped my organization?

Dynamic features for pen testing automation, with manual.

What is most valuable?

Network scanner has good reporting, coverage was also good. In Web scanner, dashboard was good but features were limited.

What needs improvement?

Please add manual penetration testing features. 

Also I didn't like the license terms and the features were limited compared to other tools used for web applications.

For how long have I used the solution?

Trial/evaluations only.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user255879 - PeerSpot reviewer
Security Analyst at a tech services company with 1,001-5,000 employees
Consultant
Automated tools cannot find all the vulnerabilities, but this is one of the best.

What is most valuable?

WAS and being able to integrate Selenium IDE to automate the login process was most helpful.

How has it helped my organization?

Scheduling feature allows to scan on the weekends and holidays in a planned way.

What needs improvement?

Enhancing the capability to find XSS.

For how long have I used the solution?

I've used it for six months.

What was my experience with deployment of the solution?

No issues encountered.

What do I think about the stability of the solution?

No issues encountered.

What do I think about the scalability of the solution?

No issues encountered.

How are customer service and technical support?

Customer Service:

I've never had the chance to interact.

Technical Support:

I've never had the chance to interact.

Which solution did I use previously and why did I switch?

This would depend on the clients' requirements.

How was the initial setup?

It's straightforward. In fact, it's one of the easiest solutions to implement.

What about the implementation team?

We used a vendor team who had good expertise.

What other advice do I have?

I would recommend this tool. Simply, go for it. The video tutorials would give an insight on the simplicity and effectiveness of the product.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Cyber Security Consultant at a tech services company with 10,001+ employees
Consultant
The way results are presented makes remediation easy, but GUI is a little complex
Pros and Cons
  • "Key features include: Cloud-based, so the installation is not so tedious. Easily deployed. Highly scalable. Comprehensive reporting."
  • "You can integrate your Burp Suite results and create an integrated report. Also, the way it shows the results - threats and exploit details - makes remediation very easy."
  • "The GUI could be a little less complicated as it opens a lot of new windows for creating search lists, templates, reports, or for scanning purposes."

What is our primary use case?

We have a lot of applications in our environment that we need to scan frequently. We have a lot of tutorial sites, e-learning sites, and other related websites which we have to build, maintain, and scan continuously for security purposes.

How has it helped my organization?

It definitely helps us with the remediation process as we can create different reports, whatever is required at the time. 

What is most valuable?

  • It's cloud-based so the installation is not so tedious.
  • Easily deployed.
  • Highly scalable.
  • Comprehensive reporting.

Also, you can integrate your Burp Suite results and create an integrated report. 

The way it shows the results - threats and exploit details - makes remediation very easy.

We have seen very few false positives. We found the documentation very useful, particularly the roll-out guide. While the tool is not hard to use, by dividing the documentation into sections, the company provided specific guidance on use cases that are not necessarily limited to the tool itself.

What needs improvement?

The GUI could be a little less complicated as it opens a lot of new windows for creating search lists, templates, reports, or for scanning purposes. 

Also, occasionally it can't even authenticate to basic web forms.

For how long have I used the solution?

One to three years.

How is customer service and technical support?

Qualys offers one excellent support, which includes 24/7 phone and mail support, as well as access to its online user community.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free Qualys Web Application Scanning Report and get advice and tips from experienced pros sharing their opinions.
Updated: April 2024
Buyer's Guide
Download our free Qualys Web Application Scanning Report and get advice and tips from experienced pros sharing their opinions.