No more typing reviews! Try our Samantha, our new voice AI agent.

Google Cloud Security Command Center vs Sophos Cloud Optix comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Qualys TotalCloud
Sponsored
Ranking in Cloud Security Posture Management (CSPM)
8th
Average Rating
8.6
Reviews Sentiment
7.3
Number of Reviews
39
Ranking in other categories
Vulnerability Management (11th), Container Security (11th), Cloud Workload Protection Platforms (CWPP) (7th), SaaS Security Posture Management (SSPM) (1st), Cloud-Native Application Protection Platforms (CNAPP) (6th)
Google Cloud Security Comma...
Ranking in Cloud Security Posture Management (CSPM)
26th
Average Rating
7.6
Reviews Sentiment
5.0
Number of Reviews
4
Ranking in other categories
Cloud-Native Application Protection Platforms (CNAPP) (20th)
Sophos Cloud Optix
Ranking in Cloud Security Posture Management (CSPM)
21st
Average Rating
8.2
Reviews Sentiment
6.7
Number of Reviews
8
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of July 2026, in the Cloud Security Posture Management (CSPM) category, the mindshare of Qualys TotalCloud is 1.8%, up from 1.2% compared to the previous year. The mindshare of Google Cloud Security Command Center is 1.4%, down from 2.0% compared to the previous year. The mindshare of Sophos Cloud Optix is 0.7%, up from 0.4% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Cloud Security Posture Management (CSPM) Mindshare Distribution
ProductMindshare (%)
Qualys TotalCloud1.8%
Sophos Cloud Optix0.7%
Google Cloud Security Command Center1.4%
Other96.1%
Cloud Security Posture Management (CSPM)
 

Featured Reviews

RO
IT Security Expert at Alior Bank S.A.
Unified risk scoring has improved our cloud visibility and simplifies remediation priorities
Qualys TotalCloud provides unified vulnerability and threat assessment across both IAS and SaaS. This solution provides a single prioritized view of risk, which helps reduce the work I would have to do. We are no longer based on CVSS; we are based on Qualys risk scoring, which is based on CVSS plus internal findings made by Qualys, and then assigns its own score. The TruRisk insight feature has found a small number of assets with high vulnerability scores, though I am cautious since some information is classified. Qualys TotalCloud has positively impacted our bank's performance, and we have definitely seen benefits after implementing this solution.
RaviUpadhyay - PeerSpot reviewer
Security Consultant at HCLSoftware
Security posture has improved with automated insights but reporting and integrations still need work
The best feature of Google Cloud Security Command Center is that it is flexible to integrate with several third-party tools or services, and it is more customized. For example, it is already giving a misconfiguration and the vulnerability, and if somebody wants to do some in-depth analysis for patterns such as metrics, they can export the continuous log on the spot with that tool. From an integration point of view, I would say it is more customized with different tools. The asset discovery feature of Google Cloud Security Command Center enhances my security strategy because, nowadays, data sensitivity and data privacy are very important, and using some DLP utility, I can classify and set up rules to generate reports based on the classification in their asset discovery. This can also include data classification on Google storage buckets, and overall, Google Cloud Security Command Center has that information, which can be used for various analyses or alerts. It is very important for compliance assessment because every business is global and connects with different geographical locations, meaning each country has its own regulatory systems and internal compliance policies. Google Cloud Security Command Center has the feature to set up security postures based on which resources or assets inside Google Cloud can be marked as compliant or non-compliant, giving a risk score for immediate reporting to higher management or CISO, making it very helpful in terms of security, risk, and compliance.
Tanzeel Iqbal - PeerSpot reviewer
DevOps Architect at Testware ApS
Cloud posture has improved and security reports drive ongoing compliance and cost control
I really appreciate most aspects of Sophos Cloud Optix, especially that we can set it up on AWS marketplace without needing to host a new machine. We can use their trial version where we can monitor a small number of resources without any additional cost. Setting up Sophos Cloud Optix on AWS is not difficult at all, also because my team has experience with it, making it very easy and quick to set up a trial version that helps us see the initial posture of our security setup as we grow, and then they charge based on the cloud resources. Sophos Cloud Optix impacts us positively in many ways, particularly in security, which is an important part. It is not just about fixing everything without a clear picture of what we have done to improve security, as there must be a portal explaining our progress, which I really appreciate, and it helps us save time and in optimization for performance and cost. While I have not seen much for cost optimization as we have another great tool for it, Sophos Cloud Optix aids us to set up our infrastructure appropriately, making sure databases are in a private network, and if systems are wrongly set up, it helps us quickly mitigate those issues and provides a report indicating the problem. I am really impressed with the way Sophos Cloud Optix provides its features, so I am not sure about any specific improvements needed. I am really satisfied about the reports Sophos Cloud Optix generates, provided in a PDF format which is very useful for our recording purposes.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"I appreciate TotalCloud's real-time protection and remediation features. The remediation options include automated one-click remedies and custom changes that help manage vulnerabilities efficiently."
"I would definitely recommend it because it is easy to handle any cloud resources."
"I highly recommend Qualys TotalCloud to other users."
"I would definitely recommend Qualys TotalCloud to other users."
"Qualys TotalCloud has significantly improved our organization by automating our reporting processes, reducing the time spent on report creation from two hours to less than fifteen to twenty minutes."
"The vulnerability management feature is the one I like the most because it provides a clear picture of all vulnerabilities."
"The most valuable feature of Qualys TotalCloud is the visibility it provides."
"The agent and agentless scanning in TotalCloud, particularly the FlexScan method, is incredibly valuable. With traditional scanning approaches, we had to give IP ranges and whitelist IPs. All that is now simplified. FlexScan requires minimal intervention, and after configuration, it automatically collects data and performs necessary scans."
"It simplifies compliance efforts."
"I would definitely recommend Google Cloud Security Command Center to others."
"Most people use the threat detection dashboard."
"The compliance reporting feature helped us maintain a baseline of compliance within the information security policies."
"Since adopting Sophos Cloud Optix, audit prep time has dropped from several days to just a few hours thanks to automated compliance checks, while multi-cloud visibility has cut incident investigation time by nearly fifty percent since we no longer have to jump between AWS and Azure consoles, and IAM analytics have reduced over-privileged accounts by about thirty percent, lowering risk."
"The most valuable feature for me would be the solution's endpoint protection."
"Compared to Sophos, Symantec is like not having any protection at all, so once we deployed Sophos in multiple locations, we instantly had a sense of security."
"The most valuable feature of Sophos Cloud Optix is the simple way to manage my devices on the network. Additionally, it is easy to navigate and has a user-friendly interface."
"Sophos Cloud Optix has had a clear positive impact on my organization, improving compliance efficiency by cutting audit prep from weeks to minutes, thanks to automatic checks, and strengthening our cloud security posture with misconfigurations flagged before they become risks, resulting in reduced incidents and downtime."
"Sophos Cloud Optix impacts us positively in many ways, particularly in security, which is an important part, and it helps us save time and in optimization for performance and cost."
"Time saving has been one of the most impactful outcomes for us, as automated compliance checks reduced manual audit preparation by about two weeks per quarter."
"I find Cloud Optix to be a valuable solution since it provides a single, unified dashboard to monitor cloud assets, such as AWS and Azure."
 

Cons

"There is a lack of data segregation according to criticality or inventory."
"I would appreciate additional integration options to connect Qualys TotalCloud with our other vulnerability management tools."
"A feature improvement could be the inclusion of Windows OS support for container security, as it is currently only supported for Linux."
"To improve the user experience, reporting could be simplified for better comprehension by end users and project managers, facilitating issue resolution."
"There should be improvement from a dashboard perspective when collecting and showcasing data to lead management."
"An area for improvement would be to focus on risks related to AI, such as large language models and potential data leakage."
"There is room for improvement in the support."
"Their support could be improved."
"The AI capabilities have been heavily promoted, but I haven't seen a significant impact."
"There is definitely room for improvement in Google Cloud Security Command Center. While the functionality is very native, compared to third-party tools that offer a variety of features for easy integrations and custom KPIs, Google Cloud Security Command Center lacks some of these functionalities, requiring complex workarounds for custom reporting, and given that customers often use hybrid environments, having a broader perspective is necessary for integration."
"Visibility can be improved along with automation."
"There are times when the devices are at maximum capacity, and it takes a while before the device is updated. For example, if the device has a virus, and it's not aligned to connect to the network, even after you've scanned the device, and cleaned out the virus, once the management clears the system to allow it back on the network it takes some time. It can be frustrating when you have your line manager or in management affected trying to access the network."
"The setup was a little bit complex."
"The dashboard and the process for applying policies could be more intuitive. Cloud Optix isn't that difficult once you get the hang of it, but the IT folks managing this want it to be more user-friendly."
"The dashboard and the process for applying policies could be more intuitive."
"Sophos should enhance its AI-driven detection features and anomaly detection."
"I have not connected with Sophos Cloud Optix customer support yet, but I had a bad experience when our AWS cloud got compromised, leading to many resources being provisioned, and while Sophos Cloud Optix identified those resources, the resulting bill from AWS was quite high due to the usage charges, which I tried to investigate with the Sophos team, though I am not sure if they assisted with the refund."
"While I find Sophos Cloud Optix strong, it could improve by reducing alert noise, as I sometimes get too many notifications without enough prioritization, and more customizable compliance reports would help tailor outputs to specific frameworks, and deeper integration with niche cloud services beyond AWS, Azure, and GCP would also add value."
"Automated fixes are helpful, but sometimes we would prefer more control over how they are applied."
 

Pricing and Cost Advice

"The cost is high, but it meets our organizational needs."
"Qualys TotalCloud is cost-efficient and was selected for its value compared to other products."
"Its price seems higher compared to other tools, but it is worth it. If they could adjust the pricing and make it comparable with other tools, that would be great."
"The pricing is comparable. It is built into our other product, so I cannot piecemeal it. It is a part of our subscription."
"Although Qualys TotalCloud is relatively expensive due to its unique automation features, its cost-effectiveness is rated an eight out of ten, with ten being the most costly."
"As a middle management member, I do not have direct pricing knowledge, but based on the knowledge from our meetings, its pricing is competitive."
"Qualys TotalCloud offers competitive pricing given its comprehensive suite of features, including integration, assessment, remediation, and detection capabilities, all within a single platform."
"TotalCloud's price is about right where I would expect it to be."
"Initially, it used to be relatively expensive, starting at around four or five hundred dollars."
"Regarding the pricing for Sophos Cloud Optix, I would say that it was a very good price."
report
Use our free recommendation engine to learn which Cloud Security Posture Management (CSPM) solutions are best for your needs.
902,894 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Manufacturing Company
17%
Financial Services Firm
14%
Construction Company
8%
Comms Service Provider
7%
Financial Services Firm
14%
Computer Software Company
13%
Comms Service Provider
6%
Hospitality Company
6%
Construction Company
11%
University
8%
Financial Services Firm
7%
Security Firm
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise4
Large Enterprise29
No data available
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise1
Large Enterprise1
 

Questions from the Community

What needs improvement with Qualys TotalCloud?
Areas that need improvement in every solution include the remediation part. The remediation steps should be simple en...
What is your primary use case for Qualys TotalCloud?
Our use case involves the assets that we have under cloud, the assets exposed to the internet, and the internal appli...
What is your primary use case for Google Cloud Security Command Center?
I am primarily working with Google Cloud Security Command Center, which is their CSPM, and also with the next-generat...
What advice do you have for others considering Google Cloud Security Command Center?
I rate Google Cloud Security Command Center a seven and a half out of ten. While it is a ten from a security perspect...
What needs improvement with Sophos Cloud Optix?
I believe there can be improvements in the logging mechanism, with more detailed information available about systems ...
What is your primary use case for Sophos Cloud Optix?
I use Sophos Cloud Optix most of the time to harden our AWS infrastructure or Azure infrastructure, and sometimes I u...
What advice do you have for others considering Sophos Cloud Optix?
I have not integrated Sophos Cloud Optix with other tools, but I believe there are many integration options available...
 

Also Known As

Qualys TotalCloud with FlexScan
No data available
No data available
 

Overview

Find out what your peers are saying about Google Cloud Security Command Center vs. Sophos Cloud Optix and other solutions. Updated: June 2026.
902,894 professionals have used our research since 2012.