No more typing reviews! Try our Samantha, our new voice AI agent.

Share your experience using IBM Tivoli CMDB [EOL]

The easiest route - we'll conduct a 15 minute phone interview and write up the review for you.

Use our online form to submit your review. It's quick and you can post anonymously.

Your review helps others learn about this solution
The PeerSpot community is built upon trust and sharing with peers.
It's good for your career
In today's digital world, your review shows you have valuable expertise.
You can influence the market
Vendors read their reviews and make improvements based on your feedback.
Examples of the 114,000+ reviews on PeerSpot:

Ajay Paul - PeerSpot reviewer
System Engineer at a outsourcing company with 10,001+ employees
Real User
Top 5
Aug 7, 2026
Vulnerability management has prioritized high‑risk patching and simplified bulk system reporting
Pros and Cons
  • "For vulnerability management, Qualys Enterprise TruRisk Management is very good for our organization."
  • "The main issue is the reporting delay, and sometimes the Qualys Enterprise TruRisk Management agent will not scan the system, which means we do not receive accurate reports in a timely manner."

What is our primary use case?

I use Qualys Enterprise TruRisk Management for vulnerability management. We receive reports daily from Qualys Enterprise TruRisk Management that show which systems have vulnerabilities and prioritize them based on risk factors. This allows us to identify which systems have more vulnerabilities or higher risk levels and take appropriate action. We primarily use this tool for patch management and vulnerability patch management.

What is most valuable?

The most valuable feature is the ability to get vulnerability lists for bulk systems. My company has more than 300,000 employees, so we can generate a report of all systems and filter the results by location. This is the most interesting aspect of the tool. Additionally, Qualys Enterprise TruRisk Management provides many scoring metrics for critical and non-critical vulnerabilities, as well as high-risk ratings. This allows us to prioritize which vulnerabilities are more critical and focus on those first. Qualys Enterprise TruRisk Management also provides resolutions for vulnerabilities. For example, if a Windows update is missing, we can patch those systems directly from Qualys Enterprise TruRisk Management. It will connect directly to the Microsoft site and download the patch, so there is no need to search for patches separately. The patch will install directly from Qualys Enterprise TruRisk Management itself. For vulnerability management, Qualys Enterprise TruRisk Management is very good for our organization.

What needs improvement?

The primary issue is with the reporting functionality. Even though we fix vulnerabilities, the reports do not reflect the changes immediately. Sometimes we need to manually run a script to scan the systems before Qualys Enterprise TruRisk Management will update the scan results. The main issue is the reporting delay, and sometimes the Qualys Enterprise TruRisk Management agent will not scan the system, which means we do not receive accurate reports in a timely manner. Additionally, there are many metrics for calculating vulnerabilities, such as the Qualys ID, severity scores, CVSS scores, and other metrics. The abundance of information can be confusing. These two aspects are the most significant negatives I have experienced with this tool.

For how long have I used the solution?

I have been using this tool for the last one year.

What do I think about the stability of the solution?

I experienced a stability issue last week. For approximately 12 hours, we did not have access to Qualys Enterprise TruRisk Management. Even when we regained access, instead of displaying all 300 plus systems, it only showed fewer than 50 systems. This issue persisted for 12 hours and was only resolved after one day. I am uncertain whether the issue was caused by Qualys Enterprise TruRisk Management or our internal team. In one year of use, I have experienced this issue only once, when we lost access for one day.

What do I think about the scalability of the solution?

Qualys Enterprise TruRisk Management is highly scalable. As my company has many employees, the tool performs very well for handling this large number of users. I believe the tool is very scalable for enterprise environments.

How are customer service and support?

I cannot contact Qualys Enterprise TruRisk Management directly. Only our Qualys team can contact them. I do not have the ability to contact them directly.

Which solution did I use previously and why did I switch?

I have not used other solutions in this company. However, in my previous company, I used a tool called ManageEngine. Compared with ManageEngine, Qualys Enterprise TruRisk Management is by far better.

What about the implementation team?

In my company, we have nearly 300,000 employees and approximately five or six team members dedicated to Qualys Enterprise TruRisk Management. They handle the deployment, access management, and patching for the entire organization. The size of the implementation team depends on the company size. If the company has very few users, such as 10 to 100 users, one fully dedicated team member is sufficient for managing the deployment.

What's my experience with pricing, setup cost, and licensing?

I am not familiar with the pricing structure. I know that Qualys Enterprise TruRisk Management charges per user, but I do not have detailed knowledge of the pricing. The pricing decisions are handled by the marketing team and senior management, so I do not have information about those details.

What other advice do I have?

Qualys Enterprise TruRisk Management is very easy to use. If we have access to the system, there is no need for high technical knowledge, and an average person can navigate and use this tool easily. The tool is also available as a web application, making it very easy to access. If we have internet connectivity and a password, we can access it from any laptop or location. The entire process depends on the type of vulnerability being addressed. For example, for Windows patch updates, the process takes between half an hour and one hour to fully complete, depending on internet speed. I consider this a normal timeframe and it does not take excessively long. I would rate this review an 8.5 out of 10.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Aug 7, 2026
Flag as inappropriate
SharmaAbhijeet - PeerSpot reviewer
Senior Project Engineer at CDACINDIA
Real User
Top 10
Jul 13, 2026
Centralized risk-based visibility has improved vulnerability remediation and automates patching
Pros and Cons
  • "Risk-based prioritization is a new feature with Qualys Enterprise TruRisk Management, and overall, the vulnerability posture of our organization has improved significantly."
  • "Qualys Enterprise TruRisk Management is a big platform, and the initial deployment is tedious."

What is our primary use case?

We are using Qualys Enterprise TruRisk Management for vulnerability management. It identifies, prioritizes, and remediates vulnerabilities while focusing on the business risk itself. The latest TruRisk platform provides this functionality, and we are not just getting vulnerability counts, but we are actually working on the business risk of the vulnerabilities.

We automate the vulnerability patching with Qualys Enterprise TruRisk Management and use patch management as well. In this overall scenario, we are automating the risk factor using Qualys for risk.

What is most valuable?

Qualys Enterprise TruRisk Management is a centralized vulnerability platform that provides us with wide centralized visibility. It has risk-based prioritization, useful reporting capabilities, and integration with different assets is quite easy. It is scalable in our environment.

With Qualys Enterprise TruRisk Management, we are able to perform risk-based prioritization. It is scalable for our environment, which gives us a good advantage. Reporting is very useful, so we get valuable reports.

Risk-based prioritization is a new feature with Qualys Enterprise TruRisk Management, and overall, the vulnerability posture of our organization has improved significantly. Qualys has quite improved the overall vulnerability management.

With Qualys Enterprise TruRisk Management, we are able to automate processes and prioritize risks. The resources who were previously working on the administrative part of vulnerability management are now free to work on different areas and are able to automate the administrative part. They are working on the automation and are able to address different vulnerabilities and patch them in time. This helps us considerably, and resources are easily managed.

With Qualys Enterprise TruRisk Management, all three metrics have improved. Resource allocation has decreased, time has improved, and we are getting positive results.

What needs improvement?

Qualys Enterprise TruRisk Management is a big platform, and the initial deployment is tedious.

Licensing and features are somewhat complex for new customers, and that area could be improved.

For how long have I used the solution?

I have been working on Qualys Enterprise TruRisk Management for around three years.

What do I think about the stability of the solution?

Qualys Enterprise TruRisk Management has been stable, and no downtime has been experienced.

What do I think about the scalability of the solution?

Qualys Enterprise TruRisk Management is scalable, and that is why we opted for it. It is one of the best products available for scalability.

How are customer service and support?

We reach out to customer support for Qualys Enterprise TruRisk Management occasionally, and it is quite easy to reach them. False positives are the main issue that we encounter and need to be handled by the support team.

Which solution did I use previously and why did I switch?

We were using a ManageEngine solution previously with Qualys Enterprise TruRisk Management, and we were conducting a proof of concept. As our environment was quite large, we migrated to Qualys, which proved to be more useful and more powerful for this environment.

How was the initial setup?

My experience with pricing, setup cost, and licensing for Qualys Enterprise TruRisk Management was somewhat tedious, and it consumed a lot of time.

Which other solutions did I evaluate?

Before choosing Qualys Enterprise TruRisk Management, we conducted a requirement analysis and selected a few vendors. We performed our own proofs of concept and finalized Qualys.

What other advice do I have?

We reach out to customer support for Qualys Enterprise TruRisk Management occasionally, and it is quite easy to reach them. False positives are the main issue that we encounter and need to be handled by the support team.

If you are looking for a good vulnerability management platform with Qualys Enterprise TruRisk Management and are open to a cloud-based or hybrid-based environment with good scalability for a large environment, you should choose Qualys. I would rate this solution a 9 out of 10.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Jul 13, 2026
Flag as inappropriate