No more typing reviews! Try our Samantha, our new voice AI agent.

Aqua Cloud Security Platform vs Orca Security comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 16, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Qualys TotalCloud
Sponsored
Ranking in Container Security
11th
Ranking in Cloud Workload Protection Platforms (CWPP)
8th
Ranking in Cloud-Native Application Protection Platforms (CNAPP)
6th
Average Rating
8.6
Reviews Sentiment
7.3
Number of Reviews
39
Ranking in other categories
Vulnerability Management (11th), Cloud Security Posture Management (CSPM) (8th), SaaS Security Posture Management (SSPM) (1st)
Aqua Cloud Security Platform
Ranking in Container Security
20th
Ranking in Cloud Workload Protection Platforms (CWPP)
19th
Ranking in Cloud-Native Application Protection Platforms (CNAPP)
18th
Average Rating
8.0
Reviews Sentiment
6.8
Number of Reviews
17
Ranking in other categories
Cloud and Data Center Security (14th), Software Supply Chain Security (11th), DevSecOps (13th)
Orca Security
Ranking in Container Security
8th
Ranking in Cloud Workload Protection Platforms (CWPP)
6th
Ranking in Cloud-Native Application Protection Platforms (CNAPP)
5th
Average Rating
8.8
Reviews Sentiment
6.9
Number of Reviews
33
Ranking in other categories
Vulnerability Management (10th), API Security (3rd), Cloud Security Posture Management (CSPM) (6th), Data Security Posture Management (DSPM) (7th), Cloud Detection and Response (CDR) (2nd), AI Security (3rd)
 

Mindshare comparison

As of June 2026, in the Cloud-Native Application Protection Platforms (CNAPP) category, the mindshare of Qualys TotalCloud is 2.0%, up from 1.4% compared to the previous year. The mindshare of Aqua Cloud Security Platform is 3.0%, down from 4.0% compared to the previous year. The mindshare of Orca Security is 5.8%, down from 7.6% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Cloud-Native Application Protection Platforms (CNAPP) Mindshare Distribution
ProductMindshare (%)
Orca Security5.8%
Qualys TotalCloud2.0%
Aqua Cloud Security Platform3.0%
Other89.2%
Cloud-Native Application Protection Platforms (CNAPP)
 

Featured Reviews

RO
IT Security Expert at Alior Bank S.A.
Unified risk scoring has improved our cloud visibility and simplifies remediation priorities
Qualys TotalCloud provides unified vulnerability and threat assessment across both IAS and SaaS. This solution provides a single prioritized view of risk, which helps reduce the work I would have to do. We are no longer based on CVSS; we are based on Qualys risk scoring, which is based on CVSS plus internal findings made by Qualys, and then assigns its own score. The TruRisk insight feature has found a small number of assets with high vulnerability scores, though I am cautious since some information is classified. Qualys TotalCloud has positively impacted our bank's performance, and we have definitely seen benefits after implementing this solution.
SP
Cloud Security Practitioner at a tech vendor with 10,001+ employees
Secures cloud workloads from build to runtime and has needed simpler setup and alert tuning
Regarding how Aqua Cloud Security Platform can be improved, the first area is the complex initial setup. Deployment and configuration can be complex, especially in large environments that require skilled resources. For Kubernetes environments, initial onboarding and policy setup takes time. Compared to Wiz onboarding, it is not very straightforward, as I have also worked with Wiz. The UI is powerful but not very simple for new users, as navigation and dashboard can be overwhelming. Alert noise and tuning are required because Aqua generates a large number of initial alerts that need tuning to reduce false positives. Additionally, pricing can be high depending on workload scale, especially for large Kubernetes and multi-cloud environments. For improvements to Aqua Cloud Security Platform, I think better integration with SOAR and XDR platforms, more AI-driven prioritization, and providing simpler out-of-the-box policies would be beneficial.
reviewer2799597 - PeerSpot reviewer
Soc Analyst at a tech consulting company with 11-50 employees
Agentless cloud security has improved attack path visibility but still needs stronger real-time blocking
Yes, as per my experience, it has been very helpful. In our organization, we did not find any major or priority one kind of alerts or risks because we had a very good infrastructure structure and cybersecurity architecture built in our organization. Orca Security helped us find what vulnerabilities or gaps existed which we could improve within our architecture. It helped us in such a way that we used to close the open ports and only allowed internal IPs for necessity. For staging environments and for prod we had DOS protection. If network traffic showed that anybody was trying to flood our systems, we would only accept all and our client-related IPs or an approved list of vendor lists we would have. We would get to know where the gaps are and where the improvements we could make. Being an analyst class engineer, I could use my brain in those areas and it was very helpful to have Orca Security in my arsenal.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"In my opinion, this is the best tool."
"Qualys TotalCloud is an excellent platform, and the beauty of the platform is that we can get all the vulnerabilities, see all the reports in a single dashboard, view them segregated, and easily learn about critical, high, and medium findings with appropriately provided remediation steps."
"The best feature would be the ability to create policies. It is easy to control and update policies as required."
"I appreciate Qualys TotalCloud's ability to onboard any type of device with ease, including containers."
"The vulnerability management feature is the one I like the most because it provides a clear picture of all vulnerabilities."
"Qualys TotalCloud's most valuable feature is its agent versatility."
"TruRisk Insights is the most important innovation they've released this year."
"The agent and agentless scanning in TotalCloud, particularly the FlexScan method, is incredibly valuable. With traditional scanning approaches, we had to give IP ranges and whitelist IPs. All that is now simplified. FlexScan requires minimal intervention, and after configuration, it automatically collects data and performs necessary scans."
"The DTA, which stands for Dynamic Threat Analysis, allows me to analyze Docker images in a sandbox environment before deployment, helping me anticipate risks."
"The CSPM product is great at securing our cloud accounts and I really like the runtime protection for containers and functions too."
"The most valuable features are that it's easy to use and manage."
"It is a very good product from an environmental perspective."
"Support is very helpful."
"The most valuable feature is the on-demand patching, as there are times when vulnerabilities don't have available fixes, and Aqua Security allows it to pass the vulnerability in real-time while the fix is being developed."
"Aqua Security allowed us to gain visibility into the vulnerabilities that were present in the container images, that were being rolled out, the amount of risk that we were introducing to the platform, and provided us a look into the container environment by introducing access control mechanisms. In addition, when it came to runtime-level policies, we could restrict container access to resources in our environment, such as network-level or other application-level access."
"The image security and image scanning were quite easy compared to Prisma, the solution was very user-friendly, easy to set up, stable, and the documentation was robust."
"Orca Security integration was one of the easiest we have done because it is cloud-native and agentless."
"There are so many valuable features that I could list, but one that I appreciate is the PCI DSS compliance report."
"The visibility Orca provides into my environment is at the highest level... When I dropped them into the environment, from the very get-go I had more insight into the risks in my environment than I had had during the entire two and a half years I had been here."
"The GUI features are very good. Threat intelligence is also very good."
"Once our organization is configured, any cloud account under that organization is automatically detected in Orca Security, along with all the assets associated with it."
"Orca's SideScanning is the biggest feature. It's the 'wow' factor... With Orca's SideScanning, they just need permissions for your account and that makes it so simple."
"Orca Security has helped reduce the time it takes to address cloud security alerts."
"In our opinion, Orca Sensor is the best solution available at the moment, and it significantly affects the visibility and protection of environments."
 

Cons

"Regarding technical support from Qualys, they respond, but the response time can be too long. Sometimes we need to wait weeks for solutions to simple questions."
"TotalCloud could improve the classification of vulnerabilities. Specifically, it could enhance the categorization of what aspects fall under patches resolved by OS or software updates and what pertains to configuration adjustments."
"TotalCloud could improve its scanning of niche devices like Wi-Fi dongles and USB modems because they are often untested. It covers everything else, like laptops, mobile devices, and Bluetooth IoT devices. They can improve on the small IoT devices because hackers and testers use these."
"The patching process with Qualys Patch Management, which is part of TotalCloud, does not cover installing certain prerequisites on the servers or workstations. This shortcoming means we must rely on SCCM when any service stack updates or additional prerequisites are needed."
"With the growing integration of AI, I would like Qualys to enhance its service offerings to better accommodate AI-related risks."
"Overall, we are satisfied with it. However, the response part of the Cloud Detection and Response (CDR) module can be improved. It is not yet in place according to requirements; it is not completely available even though the module has been released."
"There is room for improvement in vulnerability scanning, particularly for PaaS environments. Currently, Qualys does not have full access to these instances, which limits its effectiveness."
"We would like to see Windows-based sensors available in Qualys, as this would make the platform more versatile and support a broader range of environments."
"Aqua Security could provide more open documentation so that their learning resources can be more easily accessed and searched through online. Right now, a lot of the documentation is closed and not available to the public."
"The solution could improve user-friendliness."
"Aqua Security could improve the forwarding of logging into Splunk and into other tools, it should be easier."
"Aqua Security lacks a lot in reporting. It provides all the open issues, but no actionable solution is provided."
"We would like to see an improvement in the overview visibility that this solution offers."
"In the next release, Aqua Security should add the ability to automatically send reports to customers."
"I would like Aqua Security to look into is the development of a web security portal."
"Aqua is a bit expensive so you have to really justify going for it or not."
"I have concerns about OCI support. When I work with Orca Security, the support for OCI is limited, so I cannot effectively work with the OCI environment."
"The presentation of the data in the dashboard is a little bit chaotic."
"I would like to see an option to do security checks on a code level. This is possible because they have access to all of the code running in the cloud provider, and combining their site-scanning solution with that would be a nice add-on."
"Orca Security can be improved as there should be some kind of central pane of glass. Similar to how cloud management works, Orca Security should have something comparable."
"Customer support is very poor, in my opinion, because when I have a few problems, the customer support says your solution is bad or it is easier."
"Another improvement would be that, in addition to focusing on endpoint compliance, they would focus on general compliance."
"A notable limitation with Orca Security is its scanning feature. The automatic scan only runs every 24 hours, and if an alert is remediated within an hour, it still remains until the next scheduled scan."
"I experienced some problems with custom tags in Orca Security where I tried to separate the environment for business units so I could ask the tech lead responsible for that vulnerability to fix them."
 

Pricing and Cost Advice

"I am not sure about the pricing. From what I understand, it is a bit on the higher side, but I do not have the exact numbers."
"Qualys TotalCloud offers good pricing that is affordable and competitive with the market. Our partnership also provides us with additional benefits."
"Qualys TotalCloud offers cost-effective licensing flexibility."
"The cost is high, but it meets our organizational needs."
"The pricing for TotalCloud is attractive and competitive in the market. Given the features, especially the dashboard, I have no concerns regarding pricing."
"Qualys TotalCloud offers competitive pricing given its comprehensive suite of features, including integration, assessment, remediation, and detection capabilities, all within a single platform."
"As a middle management member, I do not have direct pricing knowledge, but based on the knowledge from our meetings, its pricing is competitive."
"The pricing is comparable. It is built into our other product, so I cannot piecemeal it. It is a part of our subscription."
"The pricing of this solution could be improved."
"It comes at a reasonable cost."
"They were reasonable with their pricing. They were pretty down-to-earth about the way they pitched their product and the way they tried to close the deal. They were one of the rare companies that approached the whole valuation in a way that made sense for our company, for our needs, and for their own requirements as well... They will accommodate your needs if they are able to understand them and they're stated clearly."
"Aqua Security is not cheap, and it's not very expensive, such as Splunk, they are in the middle."
"Dealing with licensing costs isn't my responsibility, but I know that the licenses don't depend on the number of users, but instead are priced according to your workload."
"It is the cost of the visibility that you get. When you really sit down and think about what do you need to do to secure an environment with a low impact on the business, and you take a look out into the world, I think this tool is well justified around cost."
"Overall, the pricing is reasonable and the discounts have been acceptable."
"Its license is a bit expensive."
"I think their pricing model is aligned with market demand. Of course, Orca could probably better align their pricing model with the needs of smaller businesses as well as some larger-scale enterprises with millions of assets. But in all fairness, I think the Orca sales team has been accommodating and ensured that we're happy with the pricing."
"Orca Security is cheaper compared to other solutions in the same space."
"The price is a bit expensive for smaller organizations."
"The most expensive solution is Palo Alto. They claim to be very robust. The next most expensive is Wiz, followed by Orca and all the rest."
"The pricing depends on how many assets you have running in your cloud and how many environments you have. If you have a dev environment, test environment, and a production environment then it's really important that you have coverage for all of them."
report
Use our free recommendation engine to learn which Cloud-Native Application Protection Platforms (CNAPP) solutions are best for your needs.
896,803 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
14%
Computer Software Company
9%
Manufacturing Company
8%
Government
7%
Financial Services Firm
21%
Government
9%
Computer Software Company
9%
Manufacturing Company
8%
Financial Services Firm
16%
Computer Software Company
12%
Manufacturing Company
8%
Comms Service Provider
5%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business10
Midsize Enterprise3
Large Enterprise28
By reviewers
Company SizeCount
Small Business6
Midsize Enterprise1
Large Enterprise11
By reviewers
Company SizeCount
Small Business15
Midsize Enterprise8
Large Enterprise10
 

Questions from the Community

What needs improvement with Qualys TotalCloud?
Areas that need improvement in every solution include the remediation part. The remediation steps should be simple en...
What is your primary use case for Qualys TotalCloud?
Our use case involves the assets that we have under cloud, the assets exposed to the internet, and the internal appli...
What do you think of Aqua Security vs Prisma Cloud?
Aqua Security is easy to use and very manageable. Its main focus is on Kubernetes and Docker. Security is a very valu...
What needs improvement with Orca Security?
In two implementation projects that I participated in, the customers reported difficulty with the options for generat...
What is your primary use case for Orca Security?
When discussing the main use case for Orca Security, I am referring to implementations for my clients. I participate ...
What advice do you have for others considering Orca Security?
Orca Security typically delivers three major positive changes, in my opinion: a faster understanding of risks in clou...
 

Also Known As

Qualys TotalCloud with FlexScan
Aqua Security Platform, CloudSploit, Argon
No data available
 

Overview

 

Sample Customers

Information Not Available
HPE Salesforce Telstra Ellie Mae Cathay Pacific HomeAway
BeyondTrust, Postman, Digital Turbine, Solarisbank, Lemonade, C6 Bank, Docebo, Vercel, and Vivino
Find out what your peers are saying about Aqua Cloud Security Platform vs. Orca Security and other solutions. Updated: May 2026.
896,803 professionals have used our research since 2012.