


Vulcan Cyber and Qualys CyberSecurity Asset Management are key contenders in cybersecurity management. Qualys seems to have the upper hand with its expansive features and comprehensive asset inventory capabilities, providing a holistic view of vulnerabilities and risks.
Features: Vulcan Cyber offers robust automation, centralizing signals for effective prioritization and categorization of vulnerabilities. It integrates diverse vulnerability data to help stakeholders assess threats. Qualys CyberSecurity Asset Management delivers an extensive asset inventory, incorporating dynamic tagging and software lifecycle insights. Its asset discovery and TruRisk scoring offer a comprehensive view of hardware and software vulnerabilities with detailed tagging and customizable options.
Room for Improvement: Vulcan Cyber should enhance connector maintenance, UI and dashboard performance, and tackle bulk data management for better organization and documentation. Qualys needs a refreshed user interface, more flexible scan configurations, and improved integration with non-standard tools. Enhancing dynamic tagging and customizing reports would elevate user experience.
Ease of Deployment and Customer Service: Vulcan Cyber provides flexible deployment with on-premises and public cloud options, although it requires more timely support resolutions. Qualys supports various cloud setups, including public, hybrid, and private clouds. While generally responsive, its complex integrations sometimes lead to service delays.
Pricing and ROI: Vulcan Cyber offers competitive pricing that enhances efficiency for security personnel, despite some missing features. Conversely, Qualys, although costly for smaller entities, delivers excellent value with detailed features. Its transparent pricing and flexibility yield significant value despite higher costs, aiding asset management processes effectively.
It has saved about 90% of our time.
TotalCloud has generated overall savings of 30 to 40 percent across various departments.
CallStream helps us integrate and automate tasks.
Improvements to our security infrastructure contributed to overall business growth of approximately 150 percent over the past year.
By automating tasks, it significantly reduces the human resources required, leading to increased efficiency and productivity.
It has reduced the number of development and scripting hours along with maintenance hours.
With our vulnerability management platform, I used to get reports weekly, but with Vulcan Cyber, I get them daily.
Our security team probably spends 15 minutes instead of two hours daily notifying the teams.
The biggest return on investment with Vulcan Cyber is in time savings and prioritization efficiency, as teams can focus quickly on high-risk vulnerabilities instead of manually reviewing thousands of findings.
They are helpful, respond to my queries, and can answer any question.
Qualys's tech support is highly responsive, providing multiple ways to interact with them.
Qualys' customer service provides quality answers, but the response time is long, even though it is within the SLA.
The support team was knowledgeable and offered a variety of quick resolution options.
Their SMEs have sufficient knowledge, and if they are not the right contact, they quickly redirect us to someone who can help resolve issues.
I would rate their customer support a ten out of ten.
We do not necessarily have visibility of when those feature requests are going into the development pipeline.
It would enhance my experience if Vulcan informed customers of forthcoming maintenance or changes that might cause website downtime.
Their technical support team is very good, knowledgeable, and helpful.
We started our organization about nine months back. We started with about 30 users, and we now have more than 100 users.
Our organization currently uses it to manage over 1200 web applications.
It is absolutely scalable, and I would rate its scalability as nine out of ten.
We have about 300,000 assets installed with agents worldwide.
The scalability is excellent as we manage more than one hundred thousand assets, including over one hundred thousand endpoints, approximately 2,600 servers, and more than 1,200 network devices.
Qualys Cybersecurity Asset Management has proven to be a highly scalable solution for us over the past couple of years.
We have a lot of assets under management, and it effectively scales up to accommodate hundreds or even thousands of assets.
I'd rate the scalability ten out of ten.
I would rate it ten out of ten for scalability, as integration with multiple connectors is possible without exceeding licensing limits.
Overall, the support provided has been excellent.
It is a stable solution, which is why we chose it.
Continuous monitoring is crucial to ensure system stability and avoid vulnerabilities or threats.
I would rate the stability of Qualys CSAM a ten out of ten.
The product stability has notably declined over the last two months, and the performance to fulfill a page request is very slow compared to its previous performance.
They are constantly adding capabilities.
It would be better if Vulcan notified me, the customer, about upcoming maintenance or changes, indicating when the website might be down.
The product's stability is commendable, with no noticeable lags or slowness.
I would rate it a nine out of ten in terms of stability.
Ideally, the scanner should automatically detect and scan all subdomains, even if not explicitly defined, ensuring comprehensive vulnerability assessment.
Ideally, updates should be more immediate, enabling quicker implementation of solutions.
Our goal is to integrate all these functions into Qualys, creating a single dashboard for comprehensive security monitoring and management.
Qualys is currently not able to identify assets lacking DNS information.
Features enhancing the interaction with IT or security teams should be added, such as a ticketing feature that, if an issue arises in the CSAM module, enables direct ticket creation in systems like ServiceNow.
If there's one key aspect to focus on, it's discovery—the ability to identify assets that you are not aware of, even when you can see they are present.
It would be beneficial if the platform allowed remote access to devices for immediate remedies.
Providing real-world examples of how to construct a ticket format for Jira, Azure DevOps, or ServiceNow with specific examples would help us understand how it might work in our environment.
Having it more customized or providing more customization options for me would be beneficial.
Qualys TotalCloud's pricing is currently acceptable, it is becoming increasingly expensive.
Pricing is managed by our finance team; however, Qualys TotalCloud offers cost-effective licensing flexibility.
Qualys TotalCloud is expensive, but it offers a premier solution with no headaches.
A cost-effective solution.
I believe that the stability and reliability of Qualys offer great value for the money.
A monthly subscription starting at approximately $72 per month, depending on the specific package and features included.
For our use case, the solution is lacking some features, and the cost savings don't make it worth it.
Pricing typically depends on the scale of integrated assets.
This view of risk helps reduce the work we would have to do to combine multiple sources to prioritize risk.
It will help cybersecurity professionals monitor the cloud and find vulnerabilities.
We are enjoying the new feature, FlexScan, which is valuable for Internet-facing VMs.
By correlating this with QDS scores, we can accurately assess the risk level of high or low QDS scores associated with each asset and monitor them accordingly.
The most valuable feature is the real-time visibility Qualys CyberSecurity Asset Management provides into all assets across our development and operational environments.
It also performs scans to identify any vulnerabilities, which helps to take proactive measures before those vulnerabilities are identified by any attacker.
It offers a comprehensive view of the assets and their associated vulnerabilities, which aids in assessing and mitigating threats.
The automation capabilities using the Vulcan API platform or the API feature allow me to easily automate scripts and reports and schedule them.
Instead of having 100 vulnerabilities and not knowing how to prioritize and assign all your FTEs there, you now have only ten that you know you need to fix, and you're assigning the right number of FTEs.
| Product | Mindshare (%) |
|---|---|
| Qualys CyberSecurity Asset Management | 1.3% |
| Qualys TotalCloud | 1.2% |
| Vulcan Cyber | 0.8% |
| Other | 96.7% |


| Company Size | Count |
|---|---|
| Small Business | 12 |
| Midsize Enterprise | 5 |
| Large Enterprise | 31 |
| Company Size | Count |
|---|---|
| Small Business | 8 |
| Midsize Enterprise | 2 |
| Large Enterprise | 23 |
| Company Size | Count |
|---|---|
| Small Business | 1 |
| Large Enterprise | 11 |
Qualys TotalCloud enhances security posture across cloud environments with continuous monitoring, vulnerability management, and risk visualization, ensuring efficient threat assessment and automated remediation for improved cyber risk reduction.
Qualys TotalCloud offers a robust suite of security tools essential for organizations managing multi-cloud infrastructures. By integrating cloud accounts and automating workflows, it supports AWS, Azure, and GCP, offering comprehensive vulnerability management and zero-day detection. The platform's user-friendly design, combined with its extensive risk management and unified threat assessment capabilities, enables organizations to prioritize and remediate vulnerabilities effectively. TruRisk Insights provides clear insights on cyber risks, while the automation options streamline patch management and scanning processes. API integration across IaaS and SaaS environments further enhances resource allocation efficiency and saves time, addressing misconfigurations across cloud environments.
What are the most important features of Qualys TotalCloud?Qualys TotalCloud is deployed in sectors needing rigorous vulnerability management, such as finance and healthcare. Companies utilize it to secure multi-cloud environments like AWS, Azure, and GCP, focus on compliance, and integrate security into CI/CD pipelines to detect and remedy threats pre-deployment.
Qualys CyberSecurity Asset Management provides key features including asset inventory management, end-of-life tracking, dynamic tagging, and integration with CMDB, offering extensive visibility and support for proactive threat response.
Qualys offers comprehensive visibility across hardware and software assets, aiding in tracking unauthorized applications and facilitating automated vulnerability remediation. Its user-friendly interface and dynamic risk scoring enhance security posture management. Users leverage it for vulnerability management and compliance, benefiting from real-time risk identification and efficient operations in cloud and on-premises environments.
What are the key features of Qualys CyberSecurity Asset Management?Cybersecurity teams in various industries, such as financial services, healthcare, and manufacturing, utilize Qualys to manage technical debt through end-of-life tracking and facilitate robust patch management. It supports compliance and visibility initiatives, essential for maintaining data integrity and operational security in dynamic environments.
Vulcan Cyber centralizes data from multiple scanners for a unified view, helping prioritize crucial vulnerabilities efficiently and enabling advanced analytics through seamless integration with numerous tools.
Vulcan Cyber offers a holistic vulnerability and asset management platform, integrating findings from scanners such as Wiz and BlackRock and aligning with Jira and ServiceNow for efficient ticketing. It automates processes and enhances threat analysis through its intuitive interface, allowing users to manage vulnerabilities and assets efficiently, even in post-merger scenarios. Users can centralize scanner data, ensuring streamlined processes and comprehensive reporting. Despite its performance and interface speed challenges, Vulcan Cyber remains a valuable tool for managing risk-based notifications and stakeholder communications.
What features define Vulcan Cyber?Industries employing Vulcan Cyber for vulnerability management experience streamlined processes concerning scanner data centralization and asset assessment post-merger. Its integration with service solutions like Jira fosters efficient ticketing and communication, improving risk assessments and remediation actions.
We monitor all Vulnerability Management reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.