No more typing reviews! Try our Samantha, our new voice AI agent.

BMC Helix Cloud Security vs OpenNebula comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Qualys TotalCloud
Sponsored
Average Rating
8.6
Reviews Sentiment
7.3
Number of Reviews
39
Ranking in other categories
Vulnerability Management (11th), Container Security (11th), Cloud Workload Protection Platforms (CWPP) (8th), Cloud Security Posture Management (CSPM) (8th), SaaS Security Posture Management (SSPM) (1st), Cloud-Native Application Protection Platforms (CNAPP) (6th)
BMC Helix Cloud Security
Average Rating
8.0
Reviews Sentiment
7.5
Number of Reviews
5
Ranking in other categories
Cloud Workload Protection Platforms (CWPP) (25th), Cloud Security Posture Management (CSPM) (38th)
OpenNebula
Average Rating
8.2
Reviews Sentiment
7.0
Number of Reviews
15
Ranking in other categories
Cloud Management (17th)
 

Mindshare comparison

Cloud Workload Protection Platforms (CWPP) Mindshare Distribution
ProductMindshare (%)
BMC Helix Cloud Security1.2%
Microsoft Defender for Cloud13.2%
AWS GuardDuty10.4%
Other75.2%
Cloud Workload Protection Platforms (CWPP)
Cloud Management Mindshare Distribution
ProductMindshare (%)
OpenNebula1.7%
VMware Aria Automation5.5%
IBM Turbonomic4.7%
Other88.1%
Cloud Management
 

Featured Reviews

RO
IT Security Expert at Alior Bank S.A.
Unified risk scoring has improved our cloud visibility and simplifies remediation priorities
Qualys TotalCloud provides unified vulnerability and threat assessment across both IAS and SaaS. This solution provides a single prioritized view of risk, which helps reduce the work I would have to do. We are no longer based on CVSS; we are based on Qualys risk scoring, which is based on CVSS plus internal findings made by Qualys, and then assigns its own score. The TruRisk insight feature has found a small number of assets with high vulnerability scores, though I am cautious since some information is classified. Qualys TotalCloud has positively impacted our bank's performance, and we have definitely seen benefits after implementing this solution.
DG
Portfolio Manager/ Helix Administrator at Frontier Communications
A highly scalable and straightforward solution with a knowledgeable support team
We work on a third-party shared environment. It wouldn’t have been feasible for a smaller company. My company was actually the first one to do it. Just like any cloud security, it pays to do your research and have complimentary security involved. The product can’t be the be-all and end-all tool for your security. Overall, I rate the solution a nine out of ten.
FOURES Jean-Philippe - PeerSpot reviewer
Products Manager at a tech services company with 501-1,000 employees
Reliable, simple to manage, and offers great technical support
The support of VXLAN fits with our network management. Thanks to this we can propose mixed solutions using virtual resources on OpenNebula and bare metal servers hosted in our facilities linked to each other on the sale network. This use case is very useful when some applications need bare metal power (Kubernetes workers, huge databases, AI models computations, et cetera). The cluster management is very useful for splitting our different clusters (mutual vs dedicated). We can manage deployments and capacity planning without pain. The API is also really simple and it helped us to develop the Terraform provider to manage OpenNebula like any other cloud infrastructure.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"I would rate Qualys TotalCloud ten out of ten."
"While automatic inventory detection upon connection is a helpful feature, a truly valuable capability would be assessing an environment's security posture against Azure and CIS best practices."
"The platform's unified view of the organization proves particularly valuable for leadership team meetings."
"Its excellent graphical interface makes the scanning process simple."
"Qualys TotalCloud's most valuable features are its cloud security posture management, Kubernetes, and container security capabilities."
"I would definitely recommend Qualys TotalCloud to other customers."
"If someone were to ask me to review Qualys TotalCloud, I would summarize it as an end-to-end solution for cloud security with visibility and governance-grade controls without needing to manage multiple disconnected tools."
"The best features in Qualys TotalCloud include the total asset management of the cloud environment. It is very easy to export the report and see the vulnerabilities related to the cloud specifically."
"It's also multi-cloud. You can look at several cloud providers: AWS, Azure, or GCP."
"It is a good tool to make sure that your containers are safe and sound."
"The most valuable aspects of BMC Helix Cloud Security are its security features and regulatory compliance capabilities."
"Using this solution is an eye-opener; having that holistic view is the biggest eye-opener because you understand, from any of your connected cloud accounts, what your vulnerabilities are with it."
"With very minimal effort, you are able to have a cohesive view into your security posture on one or multiple cloud accounts, particularly if you are dealing with multicloud."
"The best feature is time to value. With very minimal effort, you are able to have a cohesive view into your security posture on one or multiple cloud accounts, particularly if you are dealing with multicloud. If you have Azure and AWS deployments, you might have multiple subscriptions in Azure and usually multiple accounts in AWS. You may even be doing some GCP work (around Google Cloud Platform). It's very difficult to manage a common set of policies, even less reporting, across multiple subscriptions, accounts, and cloud environments. What BMC Helix Cloud Security does is provide a unified view or single pane of glass as to your baseline. Then, it also facilitates the ability for Level 1 or 2 operations support to take action and report on security vulnerabilities."
"The cool feature of Helix Cloud Security is that you can do all that — understand and remediate issues — in one dashboard, based on the different policies that are available for security, out-of-the-box."
"Role-based security is a valuable feature."
"I'll definitely recommend OpenNebula because it's an open-source solution that's effortless to set up, and the total cost of ownership is low."
"It has enabled us to decrease the optics by around 55 to 60%."
"The solution provides templates for configurations that can easily be exchanged to VMs."
"With a single click, we could set things up and initiate them."
"For our use case, we found the solution to be the best fit when dealing with infrastructure services."
"It is quite easy to deploy."
"It's easy to integrate OpenNebula with our IT systems."
"I also like the ability to build custom functions. I can define a function where I have two types of views and configure the dependencies. The virtual data centers concept allows me to define users. If a user wants to join certain kinds of machines, the host and the other user won't see them. It gives me the flexibility to define multiple views and data centers in one place."
 

Cons

"Qualys TotalCloud needs to enhance its scanning capabilities in the IP domain, as it currently lacks the functionality to resolve IPs to their corresponding domain names."
"In my opinion, what can be improved in Qualys TotalCloud includes pricing and container scanning."
"A feature improvement could be the inclusion of Windows OS support for container security, as it is currently only supported for Linux."
"The support is not up to the mark and seems to be overburdened."
"Qualys' customer service provides quality answers, but the response time is long, even though it is within the SLA."
"There should be improvement from a dashboard perspective when collecting and showcasing data to lead management."
"In a future release, I suggest that zero-day vulnerabilities should be predicted in advance using AI technologies. The system is not 100% secure yet, so proactive threat hunting could be enhanced to be more proactive than the current system."
"TotalCloud could improve the classification of vulnerabilities. Specifically, it could enhance the categorization of what aspects fall under patches resolved by OS or software updates and what pertains to configuration adjustments."
"The UI could be more user-friendly."
"Every organization out there doesn't rely on just one control body. They use FISMA control. They may use HIPAA, CIS, PCI, or SOX, then blend them. One of the things that is now in big demand for BMC Helix Cloud Security is content. That's the next journey in its lifespan, making it easier for the community to share and collaborate on content for security controls that can be measured and remediated."
"I think its TOA interfaces are still not that comfortable. The UI could be more user-friendly, easier to use."
"I want the role-based security feature to be improved."
"BMC Helix Cloud Security has room for improvement in terms of integrating its various features."
"We've had some issues with connectors; the connectors have seemed to cause a little bit of trouble, perhaps with the APIs trying to scan the environment."
"The biggest challenge now, which is a good problem to have, with BMC Helix is content."
"We've had some with issues connectors. The connectors have seemed to have caused a little bit of trouble, perhaps with the APIs trying to scan the environment. The only time I've had to reach out to tech support was for that. It seems it may not have been scanning correctly or I wasn't seeing data within a specific time. But we've set up a couple of connectors in the past couple of weeks and they actually scanned the AWS environment and we had data within about 10 minutes. It's working a lot faster and I think they're making improvements as they go."
"The protocol for clusterization is rough and doesn't work well."
"They have been saying for the past two and a half years that they would develop a feature to hot-add RAM and CPU, but it does not work."
"Most of the competitors are offering some sort of billing software to transform their installation to work as a small-sized public cloud, but those offerings from OpenNebula are still missing."
"It should have a simple REST API like most other tools. It's the industry standard format. An XML-RPC API gives you an XML document that you have to convert and then do something with that. REST API endpoint provides outputs in a JSON document. I would also like to see support for user data or heat templates, which OpenStack offers, but OpenNebula doesn't have this yet."
"The UI, monitoring, and alerting could benefit from further improvements."
"Hosting platforms are limited so the deployment process needs improvement."
"As with all enterprise software licensing, the pricing is not intuitive and must be negotiated; grandfathered contracts are better than anything offered today."
"There are no payment gateways in OpenNebula."
 

Pricing and Cost Advice

"Qualys TotalCloud offers competitive pricing given its comprehensive suite of features, including integration, assessment, remediation, and detection capabilities, all within a single platform."
"I am not sure about the pricing. From what I understand, it is a bit on the higher side, but I do not have the exact numbers."
"It isn't cheap, but it's reasonable. It helps us to manage things with very few resources."
"The pricing is comparable. It is built into our other product, so I cannot piecemeal it. It is a part of our subscription."
"Qualys TotalCloud offers cost-effective licensing flexibility."
"The pricing for TotalCloud is attractive and competitive in the market. Given the features, especially the dashboard, I have no concerns regarding pricing."
"Its price seems higher compared to other tools, but it is worth it. If they could adjust the pricing and make it comparable with other tools, that would be great."
"Qualys TotalCloud is expensive."
"It is a subscription model with term licensing that is usually yearly. This includes, not only the product, but support and maintenance. It is based on cloud assets. Therefore, if you have 100 cloud assets, those cloud assets are measured based on evaluation or transactions. For example, if I'm evaluating that cloud asset for CIS compliance, PCI compliance, and AWS best practices, that asset gets evaluated three times, as those are three transactions. However, the license model is based on peak asset usage. So, over a year, if you deploy 100, 1000, 500, and then 2000 assets, you will be charged for the 2000 peak of assets managed by Helix Cloud Security."
"The pricing is based on an annual subscription, upfront, and it's based on cloud assets. Whether your assets are in Azure and AWS combined, the tool tells you how many assets are being scanned and that's the number used for pricing."
"VRA is very expensive but OpenNebula is free."
"The solution is open source so is free."
"The licensing for OpenNebula used to be free, but now it's no longer free. A customer contacted me asking to move to another provider because of the changes in the licensing terms for OpenNebula. I have no information on how much the OpenNebula license is because the customer pays for it, and I only do the integration."
"We use the Community Edition, rather than the Enterprise Edition."
"OpenNebula gives good value for money."
"OpenNebuoa has recently come up with a new subscription model that is economical and a lot of new customers are choosing this as it is an easy subscription model."
report
Use our free recommendation engine to learn which Cloud Workload Protection Platforms (CWPP) solutions are best for your needs.
900,196 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Manufacturing Company
18%
Financial Services Firm
13%
Construction Company
7%
Comms Service Provider
6%
Construction Company
16%
Comms Service Provider
12%
Performing Arts
9%
Manufacturing Company
9%
Financial Services Firm
12%
Comms Service Provider
10%
Computer Software Company
9%
University
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business10
Midsize Enterprise3
Large Enterprise29
No data available
By reviewers
Company SizeCount
Small Business7
Midsize Enterprise6
Large Enterprise3
 

Questions from the Community

What needs improvement with Qualys TotalCloud?
Areas that need improvement in every solution include the remediation part. The remediation steps should be simple en...
What is your primary use case for Qualys TotalCloud?
Our use case involves the assets that we have under cloud, the assets exposed to the internet, and the internal appli...
Ask a question
Earn 20 points
What needs improvement with OpenNebula?
The web interface could be better. It's not very difficult to use, but there's room for enhancement. Another area for...
What is your primary use case for OpenNebula?
Previously, we were using VMware, but recently, we've started using OpenNebula for cloud management. As a big cloud p...
What advice do you have for others considering OpenNebula?
I recommend it, especially if you need a management interface for a small to medium private cloud. I would rate OpenN...
 

Also Known As

Qualys TotalCloud with FlexScan
TrueSight Cloud Security, SecOps Policy Service
No data available
 

Overview

 

Sample Customers

Information Not Available
NHS, Vodafone, Kansas City Life, SKY Italia, Cybera
Akamai, BBC, Fermilab, Terradue, Surf Sara, Produban, Netways, ESA, China Mobile, BlackBerry, Deloitte, Fuze, Telefonica, Trivago, Nokia, Encore Tech, Beeks.
Find out what your peers are saying about Microsoft, Wiz, Amazon Web Services (AWS) and others in Cloud Workload Protection Platforms (CWPP). Updated: June 2026.
900,196 professionals have used our research since 2012.