Try our new research platform with insights from 80,000+ expert users

Pentera vs Qualys TotalCloud comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 9, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
5.2
Pentera automates security tests, proving valuable for retests, but rising licensing costs pose ROI challenges for some users.
Sentiment score
8.2
Qualys TotalCloud enhances efficiency, cutting workloads by up to 90%, reducing costs by 20%, and boosting ROI significantly.
Some customers consider the ROI favorable, but facing difficulties now due to changes in the licensing model, which has made it more expensive compared to last year.
It has saved about 90% of our time.
TotalCloud has generated overall savings of 30 to 40 percent across various departments.
CallStream helps us integrate and automate tasks.
 

Customer Service

Sentiment score
6.0
Pentera's support team is reliable and responsive, but documentation needs updating; users rate support highly despite some inconsistency.
Sentiment score
7.4
Qualys TotalCloud's customer service is praised for responsiveness and expertise but sometimes varies in wait times and support quality.
They are helpful, respond to my queries, and can answer any question.
Qualys's tech support is highly responsive, providing multiple ways to interact with them.
Qualys' customer service provides quality answers, but the response time is long, even though it is within the SLA.
 

Scalability Issues

Sentiment score
7.0
Pentera is highly scalable with adaptable equipment requirements, earning strong satisfaction ratings across various enterprise environments.
Sentiment score
8.5
Qualys TotalCloud excels in scalability, supporting varied organizations and seamlessly managing expansive environments and user growth globally.
We started our organization about nine months back. We started with about 30 users, and we now have more than 100 users.
Our organization currently uses it to manage over 1200 web applications.
It is absolutely scalable, and I would rate its scalability as nine out of ten.
 

Stability Issues

Sentiment score
7.3
Pentera is praised for high stability, with most users rating it highly despite minor initial setup concerns.
Sentiment score
8.5
Users praise Qualys TotalCloud for its reliability, minimal downtime, and effective communication about maintenance, ensuring consistent performance.
Overall, the support provided has been excellent.
It is a stable solution, which is why we chose it.
Continuous monitoring is crucial to ensure system stability and avoid vulnerabilities or threats.
 

Room For Improvement

Pentera struggles with cost, licensing flexibility and needs better virtualization, dashboards, hardware support, and detailed credential information.
Qualys TotalCloud needs improvements in licensing, compliance, scanning, integration, UI, vulnerability detection, and Windows container security support.
When the IP is imported into a system, we cannot withdraw or revoke the license.
Ideally, the scanner should automatically detect and scan all subdomains, even if not explicitly defined, ensuring comprehensive vulnerability assessment.
Ideally, updates should be more immediate, enabling quicker implementation of solutions.
Our goal is to integrate all these functions into Qualys, creating a single dashboard for comprehensive security monitoring and management.
 

Setup Cost

Pentera's pricing receives mixed reviews, though many appreciate its value in effectively assessing ransomware protection.
Qualys TotalCloud's pricing is seen as justified by its features and flexibility, though views on affordability vary.
Qualys TotalCloud's pricing is currently acceptable, it is becoming increasingly expensive.
Pricing is managed by our finance team; however, Qualys TotalCloud offers cost-effective licensing flexibility.
Qualys TotalCloud is expensive, but it offers a premier solution with no headaches.
 

Valuable Features

Pentera offers automated vulnerability assessments with valued features like attack surface mapping, AI reporting, and quick, effective processes.
Qualys TotalCloud excels with inventory detection, security assessment, and vulnerability management, enhancing security through real-time protection and comprehensive insights.
We can automate the Pentera processes by automatically creating scenarios to validate the system.
This view of risk helps reduce the work we would have to do to combine multiple sources to prioritize risk.
It will help cybersecurity professionals monitor the cloud and find vulnerabilities.
We are enjoying the new feature, FlexScan, which is valuable for Internet-facing VMs.
 

Categories and Ranking

Pentera
Average Rating
8.0
Reviews Sentiment
6.7
Number of Reviews
9
Ranking in other categories
Penetration Testing Services (2nd), Breach and Attack Simulation (BAS) (2nd)
Qualys TotalCloud
Average Rating
8.8
Reviews Sentiment
7.7
Number of Reviews
30
Ranking in other categories
Vulnerability Management (10th), Container Security (11th), Cloud Workload Protection Platforms (CWPP) (8th), Cloud Security Posture Management (CSPM) (6th), SaaS Security Posture Management (SSPM) (1st), Cloud-Native Application Protection Platforms (CNAPP) (8th)
 

Mindshare comparison

Pentera and Qualys TotalCloud aren’t in the same category and serve different purposes. Pentera is designed for Breach and Attack Simulation (BAS) and holds a mindshare of 28.5%, down 29.0% compared to last year.
Qualys TotalCloud, on the other hand, focuses on Cloud-Native Application Protection Platforms (CNAPP), holds 1.6% mindshare, up 0.6% since last year.
Breach and Attack Simulation (BAS) Market Share Distribution
ProductMarket Share (%)
Pentera28.5%
Cymulate20.5%
Picus Security17.5%
Other33.5%
Breach and Attack Simulation (BAS)
Cloud-Native Application Protection Platforms (CNAPP) Market Share Distribution
ProductMarket Share (%)
Qualys TotalCloud1.6%
Wiz23.8%
Prisma Cloud by Palo Alto Networks14.5%
Other60.099999999999994%
Cloud-Native Application Protection Platforms (CNAPP)
 

Featured Reviews

Sabbir Ahmed - PeerSpot reviewer
Comprehensive attack surface coverage and real-world threat emulation strengthen security while licensing models need improvement
Comprehensive Attack Surface includes several features. Omni Attack Surface discovers, assesses, and exploits vulnerabilities across both internal networks and external assets, including cloud environments from a single platform. External Attack Surface Management (EASM) and Internal Network Validation test internal security controls and identify weaknesses within the internal network. Automated Penetration Testing features are provided through the Pentera Surface module. Surface provides automated validation and penetration testing features with a proactive, continuous, and highly realistic approach to cybersecurity validation, helping organizations understand and reduce their true cyber exposure. They have AI-based reporting that leverages AI to identify patterns of exploitability over time, aggregate results across sites, and highlight recurring weaknesses. They offer two types of reports: an elaborate technical report for CTOs and an Executive Summary for management. When customers see the reports after completing the POC, they are impressed by how detailed the technical report is, while management can understand what actions need to be taken to protect their network and infrastructure. Recent Gartner reports indicate that traditional VAPT companies perform vulnerability testing at specific times, which creates security gaps. Pentera provides continuous validation, running 24/7 in the infrastructure. This means when any vulnerability appears due to firmware upgrades, OS updates, or software changes, it can be automatically identified in real-time.
Sushant Samantara - PeerSpot reviewer
Helps us minimize attack surfaces by identifying root accounts and encryption issues
TotalCloud provides written explanations to guide remediation and eliminate cyber risks. While all cloud platforms offer security features, it's challenging to consolidate them into a single dashboard. Qualys TotalCloud effectively addresses this by consolidating multiple cloud platforms and subscriptions onto one dashboard. This allows users to quickly identify and mitigate misconfigurations and risks, simplifying security management. Before implementing TotalCloud, our compliance rate was approximately 50 to 60 percent. However, after adopting the platform, it has increased to 80 to 90 percent. TotalCloud also helps us minimize attack surfaces by identifying root accounts and encryption issues, thereby enhancing our overall security by 40 percent. TotalCloud offers a unified platform for assessing vulnerabilities and threats across both IaaS and PaaS environments. This unified view has improved our cloud security posture management. We gain a single, prioritized view of risks through TotalCloud's TruRisk Insights feature. This feature considers not only the QDA score but also factors in cost and other relevant elements to provide a comprehensive risk assessment. From a potentially overwhelming list of findings, TruRisk Insights prioritizes the most critical risks, allowing us to focus our efforts and resources on addressing these high-priority tasks efficiently. A single, prioritized view of risk streamlines the risk assessment process by eliminating the need to consolidate multiple sources. This comprehensive view is instrumental in communicating with other business customers who may be unaware of potential risks or misconfigurations within their resources. By identifying and informing them of these issues, we can guide them towards compliance and ensure a more secure environment. TruRisk Insights provides valuable findings by identifying vulnerabilities and misconfigurations, displaying them on a dashboard, and offering deeper insights into the attack surface. It analyzes not only internet-facing devices but also those indirectly connected, providing a comprehensive understanding of potential risks. This is crucial because even devices not directly connected to the internet can be vulnerable if they have an attack surface. TruRisk Insights also offers mitigation strategies, making it a highly useful tool for managing security risks. With the VMDR feature enabled and the Qualys Agent installed on various assets, we can identify existing vulnerabilities. TruRisk Insights then calculates risk scores, prioritizes tasks, and presents the number of findings. This allows us to focus on mitigating high-priority vulnerabilities while deferring those with lower priority, ultimately reducing overall risk. TruRisk Insights provides device details, allowing for containerization of misconfigured devices. This process involves isolating problematic devices and rectifying misconfigurations, ultimately enhancing our security posture.
report
Use our free recommendation engine to learn which Breach and Attack Simulation (BAS) solutions are best for your needs.
866,755 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
13%
Computer Software Company
13%
Manufacturing Company
11%
Educational Organization
6%
Financial Services Firm
16%
Computer Software Company
14%
Government
10%
Manufacturing Company
9%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business5
Midsize Enterprise1
Large Enterprise4
By reviewers
Company SizeCount
Small Business7
Midsize Enterprise2
Large Enterprise22
 

Questions from the Community

What do you like most about Pentera?
What I like the most about Pentera is its solution-oriented approach.
What needs improvement with Pentera?
The licensing model has changed from earlier versions. Previously, there was a 500 IP cap, and customers needed to buy a minimum of 500 IP and consider 500 domains. In Bangladesh, many large organi...
What is your primary use case for Pentera?
Common use cases include several features. The POC is completed before any customer goes for procurement. Once the POC is done, customers appreciate features such as comprehensive attack surface co...
What is your experience regarding pricing and costs for Qualys TotalCloud?
It isn't cheap, but it's reasonable. It helps us to manage things with very few resources.
What needs improvement with Qualys TotalCloud?
The onboarding process is a bit difficult. In the initial phase, it is very difficult to understand the features, what the dashboard contains, and what criteria they are using. This information is ...
What is your primary use case for Qualys TotalCloud?
We are managing AWS, Azure, as well as Google Cloud services in the cloud. We have different applications using those. We were previously checking the configurations manually. Qualys is helping us ...
 

Also Known As

No data available
Qualys TotalCloud with FlexScan
 

Overview

 

Sample Customers

Blackstone Group Caterpillar Apria Healthcare Taylor Vinters Sandler Capital Management Drawbridge BNP Paribas British Red Cross
Information Not Available
Find out what your peers are saying about Pentera vs. Qualys TotalCloud and other solutions. Updated: January 2025.
866,755 professionals have used our research since 2012.