No more typing reviews! Try our Samantha, our new voice AI agent.

BMC Helix Cloud Security vs VMware Aria Operations comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Qualys TotalCloud
Sponsored
Average Rating
8.6
Reviews Sentiment
7.3
Number of Reviews
39
Ranking in other categories
Vulnerability Management (11th), Container Security (11th), Cloud Workload Protection Platforms (CWPP) (8th), Cloud Security Posture Management (CSPM) (8th), SaaS Security Posture Management (SSPM) (1st), Cloud-Native Application Protection Platforms (CNAPP) (6th)
BMC Helix Cloud Security
Average Rating
8.0
Reviews Sentiment
7.5
Number of Reviews
5
Ranking in other categories
Cloud Workload Protection Platforms (CWPP) (25th), Cloud Security Posture Management (CSPM) (38th)
VMware Aria Operations
Average Rating
8.2
Reviews Sentiment
6.9
Number of Reviews
376
Ranking in other categories
Cloud Management (1st), Virtualization Management Tools (1st)
 

Mindshare comparison

Cloud Workload Protection Platforms (CWPP) Mindshare Distribution
ProductMindshare (%)
BMC Helix Cloud Security1.2%
Microsoft Defender for Cloud13.2%
AWS GuardDuty10.4%
Other75.2%
Cloud Workload Protection Platforms (CWPP)
Virtualization Management Tools Mindshare Distribution
ProductMindshare (%)
VMware Aria Operations23.7%
IBM Turbonomic17.0%
SolarWinds Virtualization Manager9.7%
Other49.599999999999994%
Virtualization Management Tools
 

Featured Reviews

RO
IT Security Expert at Alior Bank S.A.
Unified risk scoring has improved our cloud visibility and simplifies remediation priorities
Qualys TotalCloud provides unified vulnerability and threat assessment across both IAS and SaaS. This solution provides a single prioritized view of risk, which helps reduce the work I would have to do. We are no longer based on CVSS; we are based on Qualys risk scoring, which is based on CVSS plus internal findings made by Qualys, and then assigns its own score. The TruRisk insight feature has found a small number of assets with high vulnerability scores, though I am cautious since some information is classified. Qualys TotalCloud has positively impacted our bank's performance, and we have definitely seen benefits after implementing this solution.
DG
Portfolio Manager/ Helix Administrator at Frontier Communications
A highly scalable and straightforward solution with a knowledgeable support team
We work on a third-party shared environment. It wouldn’t have been feasible for a smaller company. My company was actually the first one to do it. Just like any cloud security, it pays to do your research and have complimentary security involved. The product can’t be the be-all and end-all tool for your security. Overall, I rate the solution a nine out of ten.
AldoDomini - PeerSpot reviewer
Senior System Network Analyst at Net spa
Have faced limitations due to high costs but have maintained reliability over time
The primary issue is the pricing, which is very expensive for my company's budget. We cannot afford to pay such a large fee. We are not Microsoft or BMW; we are a small company. As a small company, I have no power to negotiate directly with VMware. Perhaps larger companies have more opportunity to contract directly with VMware, but I do not have that leverage. The only path I can follow is to change solutions. Net.spA is a company working in the field of waste management. We are not a technological company, so we do not have a large margin to justify purchasing and maintaining the VMware infrastructure at current costs.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"By integrating TotalCloud, we have significantly reduced vulnerabilities in our deployment pipeline."
"It is a cloud-native app that integrates with both IaaS and SaaS. It seamlessly integrates with other platforms."
"One of Qualys' best features is its categorization, which allows us to see the types of assets, their security postures, and the AI-powered version of the tool."
"Generally, Qualys is very good at detections, whether on cloud or on-prem, and the agent allows deployment on both infrastructures, providing continuous monitoring of your assets, which is a key selling point for us."
"I found the initial setup user-friendly."
"TruRisk Insights is the most important innovation they've released this year."
"Vulnerability and threat detection and assessment of the criticality of the vulnerabilities exposed are most valuable."
"The most valuable feature is the consolidated information that it provides from various platforms."
"The best feature is time to value. With very minimal effort, you are able to have a cohesive view into your security posture on one or multiple cloud accounts, particularly if you are dealing with multicloud. If you have Azure and AWS deployments, you might have multiple subscriptions in Azure and usually multiple accounts in AWS. You may even be doing some GCP work (around Google Cloud Platform). It's very difficult to manage a common set of policies, even less reporting, across multiple subscriptions, accounts, and cloud environments. What BMC Helix Cloud Security does is provide a unified view or single pane of glass as to your baseline. Then, it also facilitates the ability for Level 1 or 2 operations support to take action and report on security vulnerabilities."
"It's also multi-cloud. You can look at several cloud providers: AWS, Azure, or GCP."
"With very minimal effort, you are able to have a cohesive view into your security posture on one or multiple cloud accounts, particularly if you are dealing with multicloud."
"The cool feature of Helix Cloud Security is that you can do all that — understand and remediate issues — in one dashboard, based on the different policies that are available for security, out-of-the-box."
"The features that I've found most valuable are its container security aspect. I also like its vulnerability management tools."
"Role-based security is a valuable feature."
"It is a good tool to make sure that your containers are safe and sound."
"Using this solution is an eye-opener; having that holistic view is the biggest eye-opener because you understand, from any of your connected cloud accounts, what your vulnerabilities are with it."
"Its technical support team responds quickly."
"It has helped our organization a great deal in terms of being able to identify and troubleshoot problems."
"Their technical support is good. We haven't had too much use for them."
"This solution has helped to improve my organization because we use it for reporting when management wants to know what we have in the data center in our virtualization environment, it can alert us as to what resources we need to buy for the next financial year, prevent downtime by warning of upcoming failures, and help us efficiently reuse resources so we save a lot with it."
"We are not constantly having to babysit or troubleshoot it. It does what it is designed to do, and it does a very good job of it."
"It gives us a single pane of glass to be able to look into our environment and find what the problems are."
"The most valuable feature is the single pane of glass so we can see all our vCenters, all our machines, all our storage arrays. We can see if there are alerts in any of these systems, and follow up on that alert and see if it's impacting just that area or if there is a bigger problem behind it."
"The capacity management has saved us more than 30% on storage."
 

Cons

"Some major banks and insurance companies require an on-premises solution for comprehensive vulnerability management, which TotalCloud does not offer."
"Enhancing clarity regarding its compliance capabilities would be beneficial, as the current scope is limited in geographic coverage."
"TotalCloud could improve its scanning of niche devices like Wi-Fi dongles and USB modems because they are often untested. It covers everything else, like laptops, mobile devices, and Bluetooth IoT devices. They can improve on the small IoT devices because hackers and testers use these."
"The onboarding process is a bit difficult. In the initial phase, it is very difficult to understand the features, what the dashboard contains, and what criteria they are using."
"Their support could be improved."
"TotalCloud could improve the classification of vulnerabilities. Specifically, it could enhance the categorization of what aspects fall under patches resolved by OS or software updates and what pertains to configuration adjustments."
"I would appreciate additional integration options to connect Qualys TotalCloud with our other vulnerability management tools."
"Qualys's ticketing system can be confusing when assigning tasks to individuals, and support could be improved by offering instant call solutions with engineers in addition to ticket replies."
"The UI could be more user-friendly."
"BMC Helix Cloud Security has room for improvement in terms of integrating its various features."
"Every organization out there doesn't rely on just one control body. They use FISMA control. They may use HIPAA, CIS, PCI, or SOX, then blend them. One of the things that is now in big demand for BMC Helix Cloud Security is content. That's the next journey in its lifespan, making it easier for the community to share and collaborate on content for security controls that can be measured and remediated."
"I think its TOA interfaces are still not that comfortable. The UI could be more user-friendly, easier to use."
"I want the role-based security feature to be improved."
"We've had some with issues connectors. The connectors have seemed to have caused a little bit of trouble, perhaps with the APIs trying to scan the environment. The only time I've had to reach out to tech support was for that. It seems it may not have been scanning correctly or I wasn't seeing data within a specific time. But we've set up a couple of connectors in the past couple of weeks and they actually scanned the AWS environment and we had data within about 10 minutes. It's working a lot faster and I think they're making improvements as they go."
"We've had some issues with connectors; the connectors have seemed to cause a little bit of trouble, perhaps with the APIs trying to scan the environment."
"The biggest challenge now, which is a good problem to have, with BMC Helix is content."
"I would like to see them do something about the complexity of the reporting mechanisms."
"We had an issue a couple weeks ago, opened the case and the person never responded. I escalated twice and we finally got a call back the day I provided this review."
"The VMware Aria Operations solution is a very technical product and is not for everyone. As a top-of-the-chain VMware tool, it is only normal that it has a learning curve. While the UI has been improved, it may still be difficult for some users. The solution has a lot of functionality and can monitor all areas of infrastructure, such as storage and network."
"Also, it is very CPU intensive."
"There is scope to improve the computing aspect."
"compare-to-competition; We had a lot of homegrown solutions and different products. We have Splunk, we're using Tableau, different reporting services that were based on gathering our own data, power CLI scripts, going out and individually running things against vCenters, pulling them back in, and then dumping them into something centrally that we could view for capacity. But it really was point-in-time, it wasn't real-time, it wasn't something that could even be predictive for us. We would look at it and say, "Well, that looked different last month so let me go look and see why," and then it was a lot more time-consuming to go about that method. It was more of a manual method. vROps is a tool that gathers that data every five minutes, or whatever the time duration is that you have set for collections. We're more up to the minute, more quick to respond. I think it's a smarter product than homegrown stuff. That's why we moved away from the homegrown stuff."
"One of the shortfalls with the algorithms of vRealize Operations is that if you want to add additional capacity and you're moving from one, just as an example, Intel generation to another generation, generally speaking, vROps only does it by megahertz, and not the new spec end values, as other tools can."
"Probably, there needs to be some sort of improvement in terms of the costing."
 

Pricing and Cost Advice

"Its price seems higher compared to other tools, but it is worth it. If they could adjust the pricing and make it comparable with other tools, that would be great."
"Qualys TotalCloud offers cost-effective licensing flexibility."
"TotalCloud's price is about right where I would expect it to be."
"The pricing for TotalCloud is attractive and competitive in the market. Given the features, especially the dashboard, I have no concerns regarding pricing."
"The pricing is comparable. It is built into our other product, so I cannot piecemeal it. It is a part of our subscription."
"Qualys TotalCloud is expensive, but it offers a premier solution with no headaches."
"While Qualys TotalCloud's pricing is currently acceptable, it is becoming increasingly expensive and may soon be considered overpriced."
"Qualys TotalCloud is expensive."
"It is a subscription model with term licensing that is usually yearly. This includes, not only the product, but support and maintenance. It is based on cloud assets. Therefore, if you have 100 cloud assets, those cloud assets are measured based on evaluation or transactions. For example, if I'm evaluating that cloud asset for CIS compliance, PCI compliance, and AWS best practices, that asset gets evaluated three times, as those are three transactions. However, the license model is based on peak asset usage. So, over a year, if you deploy 100, 1000, 500, and then 2000 assets, you will be charged for the 2000 peak of assets managed by Helix Cloud Security."
"The pricing is based on an annual subscription, upfront, and it's based on cloud assets. Whether your assets are in Azure and AWS combined, the tool tells you how many assets are being scanned and that's the number used for pricing."
"I would like to see a free offering. Cost is always a factor in any sort of line. Obviously, the value added is there and it's worth it."
"The licensing is quite expensive for our company."
"The value that we get from vROps is okay. It could be cheaper."
"The solution is slightly expensive."
"The price of the solution is expensive."
"We would like to build custom dashboards in the standard license. Right now, this is available in the enterprise license, not the standard license."
"It is an affordable solution that doesn't require any additional costs."
"The solution requires an annual license which is very expensive."
report
Use our free recommendation engine to learn which Cloud Workload Protection Platforms (CWPP) solutions are best for your needs.
896,803 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
14%
Computer Software Company
9%
Manufacturing Company
9%
Comms Service Provider
7%
Construction Company
16%
Comms Service Provider
12%
Performing Arts
9%
Manufacturing Company
8%
Financial Services Firm
10%
Manufacturing Company
9%
Marketing Services Firm
7%
Construction Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business10
Midsize Enterprise3
Large Enterprise28
No data available
By reviewers
Company SizeCount
Small Business66
Midsize Enterprise61
Large Enterprise281
 

Questions from the Community

What needs improvement with Qualys TotalCloud?
Areas that need improvement in every solution include the remediation part. The remediation steps should be simple en...
What is your primary use case for Qualys TotalCloud?
Our use case involves the assets that we have under cloud, the assets exposed to the internet, and the internal appli...
Ask a question
Earn 20 points
What's the difference between VMware vRA (automation) and vROps (operations)?
vROP is a virtualization management solution from VMWare. It is efficient and easy to manage. You can find anything y...
Is VMware Aria Operations a user friendly solution?
In terms of user-friendliness, VMware Aria Operations is one of the best solutions out there. It is not overly compl...
What is the most useful new feature of VMware Aria Operations?
For me, the alerts features are the most unique part of this product, no matter the current name it uses. When they i...
 

Also Known As

Qualys TotalCloud with FlexScan
TrueSight Cloud Security, SecOps Policy Service
VMware vRealize Operations (vROps), vCenter Operations Manager (VCOPS)
 

Overview

 

Sample Customers

Information Not Available
NHS, Vodafone, Kansas City Life, SKY Italia, Cybera
Science Applications International Corporation, Tribune Media, Heartland Payment Systems, Telkom Indonesia, Columbia Sportswear, iGATE, CSS Corp, Angel Broking, Adira Finance, Hipskind, Beiersdorf Shared Services, Innovate Mas Indonesia, Adobe, Cleveland Clinic Abu Dhabi , Join Experience S.A, Borusan Holdings, Department of Transport - Abu Dhabi
Find out what your peers are saying about Microsoft, Wiz, Amazon Web Services (AWS) and others in Cloud Workload Protection Platforms (CWPP). Updated: May 2026.
896,803 professionals have used our research since 2012.