No more typing reviews! Try our Samantha, our new voice AI agent.

Securiti vs Upwind comparison

Why PeerSpot?
Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Qualys TotalCloud
Sponsored
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
46
Ranking in other categories
Vulnerability Management (10th), Container Security (11th), Cloud Workload Protection Platforms (CWPP) (9th), Cloud Security Posture Management (CSPM) (8th), SaaS Security Posture Management (SSPM) (2nd), Cloud-Native Application Protection Platforms (CNAPP) (7th)
Securiti
Average Rating
8.2
Reviews Sentiment
6.1
Number of Reviews
10
Ranking in other categories
Data Loss Prevention (DLP) (18th), Data Governance (16th), Data Privacy Management Software (2nd), Data Security Posture Management (DSPM) (11th), Data Detection & Response (DDR) (1st), Data Security Platforms (DSP) (2nd)
Upwind
Average Rating
9.6
Reviews Sentiment
6.7
Number of Reviews
4
Ranking in other categories
Vulnerability Management (39th), Container Security (26th), Cloud Workload Protection Platforms (CWPP) (18th), API Security (11th), Cloud Security Posture Management (CSPM) (25th), Cloud-Native Application Protection Platforms (CNAPP) (15th), Attack Surface Management (ASM) (30th), Dynamic Application Security Testing (DAST) (11th), Data Security Posture Management (DSPM) (18th), Cloud Infrastructure Entitlement Management (CIEM) (8th), Cloud Detection and Response (CDR) (7th), AI Security (11th)
 

Featured Reviews

reviewer2859021 - PeerSpot reviewer
Sr Security Engineer at a tech vendor with 5,001-10,000 employees
Risk-based triage has transformed container security and now prioritizes high-impact threats
The best features Qualys TotalCloud offers currently include managing cloud infrastructure and container security while facing major challenges such as alert fatigue. Traditional vulnerability scanners flag hundreds of CVEs on short-lived Kubernetes containers, some of which have no internet exposure or are gone before we can even triage them. I leverage Qualys TotalCloud to move beyond static CVSS. I use it to implement runtime exposure, correlation risk reprioritization, and shift-left integration. This notifies developers to fix a base image upstream rather than patching live ephemeral instances. In my work with cloud and container security, the biggest operational hurdle was alert fatigue. I use Qualys to shift left from static CVSS severity to context-aware risk prioritization. I correlated raw vulnerability data with real-time risk factors such as public network exposure, active runtime execution, or overly permissive IAM roles. This allows us to immediately drop the priority of isolated containers and escalate lower-severity CVEs that sit on an exposed, high-risk path. We can map these findings directly back to our CI/CD pipelines so developers can patch the root base images upstream. We have drastically cut down the signal-to-noise ratio, saved a lot of manual hours doing triage work, and ensured engineering effort goes directly towards high-impact risk reduction.
reviewer2765175 - PeerSpot reviewer
Chief Manager (Information Technology) at a financial services firm with 10,001+ employees
Have built a zero trust foundation that protects customer data and reduces business risk
To improve Securiti, I would say that ultimately the IT team as well as the business team, there has to be an amalgamation of their thought process, convergence of their thoughts, objectives, aspirations for achieving the business objective of a particular organization. The way forward is to form the fusion team wherein there is a judicious mix of business and IT and both the teams understand each other's limitations and the aspirations and the common objectives. As far as needed improvements in Securiti, I would say that automation is key. If you look at the kind of huge amount of data which SOC integrated devices are generating in terms of alerts, automation or the appropriate use of AI is the way forward. That will lead to the overall improvement in the efficiency as well as the threat intelligence will be much more accurate. To my mind, automation with the augmented use of GenAI or the agentic AI solution is the way forward. I choose eight for Securiti because for it to be a nine or 10, ultimately the uptime has to be improved, it should be nearing 100%. Apart from that, there has to be more unified communication happening between various customer facing applications. These siloed applications having their own kind of security solutions implemented also have to be brought on a uniform platform. Until that happens, there is always a gap which has to be filled. The processes within the SOC, whether it is SIEM, NBAD, or your DAM, alert analysis, logs analysis, these have to be predictive analysis, and the thwarting of the cyber attacks still requires more effort.
Mohammed Mudasser - PeerSpot reviewer
AI/ML Engineer at a educational organization with 501-1,000 employees
Runtime context has transformed how we prioritize exploitable cloud risks and protect workloads
I appreciate runtime context, which helps connect vulnerabilities and misconfigurations with actual workload behavior and network relationships, making it easier to prioritize remediation based on real exposure rather than simply working through a long list of security findings. The best features that stand out to me are contextual vulnerability prioritization, cloud workload visibility, and runtime security. I especially value how Upwind connects vulnerabilities with actual runtime behavior, which helps focus on exploitable risk rather than working through a long list of findings. It has helped us focus on actual exploitable risk instead of treating every vulnerability equally. By considering runtime activity, exposure, reachability, and sensitive data context, the team can prioritize remediation much faster and reduce unnecessary alert noise. I also value the runtime visibility and attack path context because it connects security findings with network behavior and actual workload. This makes investigations more actionable and helps the team move from simply detecting issues to understanding their real impact. The biggest positive impact has been the prioritization of cloud security risk and improved visibility. Instead of chasing every vulnerability, we can focus on issues that are actually exposed or active at runtime, which makes the security team more efficient and remediation more targeted.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"I would definitely recommend it because it is easy to handle any cloud resources."
"The biggest strengths of Qualys TotalCloud are that it is pretty good at cloud visibility, has easy integration, and also has multi-cloud compatibility."
"It is a cloud-native app that integrates with both IaaS and SaaS. It seamlessly integrates with other platforms."
"The most valuable feature is the consolidated information that it provides from various platforms."
"I appreciate Qualys TotalCloud's ability to onboard any type of device with ease, including containers."
"Its dashboards are brilliant. It provides in-depth insights."
"The agent and agentless scanning in TotalCloud, particularly the FlexScan method, is incredibly valuable. With traditional scanning approaches, we had to give IP ranges and whitelist IPs. All that is now simplified. FlexScan requires minimal intervention, and after configuration, it automatically collects data and performs necessary scans."
"TotalCloud has been excellent in providing us with immediate access to all the products and features we need, such as CSPM, TruRisk Insights, and compliance reports, including CIS and HIPAA."
"Their data discovery is a fantastic product."
"The process mapping is a good tool. We have a nice view of their data."
"I would recommend Securiti to others with challenges like obtaining human resources for timely classification."
"With that kind of high availability and the continuous threat exposure management, CTEM, we are quite sure and we have proved our worth to the business in implementing the cyber security solutions."
"The quality of the learning that Securiti offers, especially considering that the courses are free, is incredible."
"The automated way of identifying and classifying personal information is very beneficial."
"The initial setup is easy."
"It's very scalable. I would rate it ten out of ten for scalability."
"My advice for others looking into using Upwind is that if you are seeking a strong CNAPP with an advanced runtime and strong CDR capabilities, this is the product."
"Upwind has positively impacted my organization by reducing time to action and time to response by half."
"They are a great overall cloud security platform and they continue innovating and adding new features."
"The combination of runtime visibility, security insights, and contextual risk prioritization makes it much easier to focus on the risks that actually matter."
 

Cons

"Qualys TotalCloud has the potential to improve by integrating a hybrid platform for comprehensive management of both on-premises and cloud infrastructures."
"Overall, we are satisfied with it. However, the response part of the Cloud Detection and Response (CDR) module can be improved. It is not yet in place according to requirements; it is not completely available even though the module has been released."
"Qualys TotalCloud's increasing complexity, due to the development and deployment of multiple solutions, is making the GUI difficult to navigate."
"Two areas for improvement in Qualys TotalCloud are the speed of the public cloud platform and vulnerability detection."
"Their customer support needs improvement."
"Qualys's ticketing system can be confusing when assigning tasks to individuals, and support could be improved by offering instant call solutions with engineers in addition to ticket replies."
"I sometimes have difficulty detecting or uninstalling certain versions of applications, which I have to do manually."
"The price is very expensive, actually."
"Technical support needs enhancement. It would be helpful to have better documentation and more accessible support, especially when raising support tickets."
"While the software is functionally robust and intuitive, there is a challenging learning curve."
"Technical support can be hit or miss. Some technical staff are great, but others are not very effective. On average, I would rate the technical support four out of ten."
"I would like their workflows and assessment automation to be more advanced compared to their competitors, especially under the pro core privacy module."
"It's not very fast, and it's difficult to get an answer."
"Fraud prevention could be improved. If a criminal accesses my system and obtains my information, they might commit fraud."
"With the formation and education, specifically the security education, they could update the educational video more often."
"I could see that in an environment where we had a lot of information, sometimes it was a little slow with Securiti, so I believe they could improve by making the solution faster in big environments."
"Upwind can be improved because its UI is a bit difficult to navigate."
 

Pricing and Cost Advice

"As a middle management member, I do not have direct pricing knowledge, but based on the knowledge from our meetings, its pricing is competitive."
"TotalCloud's price is about right where I would expect it to be."
"Qualys TotalCloud is cost-efficient and was selected for its value compared to other products."
"Although Qualys TotalCloud is relatively expensive due to its unique automation features, its cost-effectiveness is rated an eight out of ten, with ten being the most costly."
"Qualys TotalCloud offers cost-effective licensing flexibility."
"I am not sure about the pricing. From what I understand, it is a bit on the higher side, but I do not have the exact numbers."
"The pricing is comparable. It is built into our other product, so I cannot piecemeal it. It is a part of our subscription."
"It isn't cheap, but it's reasonable. It helps us to manage things with very few resources."
Information not available
Information not available
report
Use our free recommendation engine to learn which Data Security Posture Management (DSPM) solutions are best for your needs.
915,341 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Comms Service Provider
16%
Outsourcing Company
12%
Manufacturing Company
11%
Financial Services Firm
10%
Financial Services Firm
14%
Manufacturing Company
11%
Computer Software Company
8%
Healthcare Company
8%
Outsourcing Company
13%
Financial Services Firm
8%
Comms Service Provider
7%
Healthcare Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business14
Midsize Enterprise6
Large Enterprise35
By reviewers
Company SizeCount
Small Business2
Midsize Enterprise1
Large Enterprise7
No data available
 

Questions from the Community

What needs improvement with Qualys TotalCloud?
In terms of improvement, remediation still belongs to the cloud team, which is one of the issues we faced with Qualys...
What is your primary use case for Qualys TotalCloud?
My main use case for Qualys TotalCloud is regarding the cloud visibility that we were not having previously. Previous...
What is your experience regarding pricing and costs for Securiti?
Regarding my experience with pricing, setup cost, or licensing, I did not have much experience because I was more a t...
What needs improvement with Securiti?
I could see that in an environment where we had a lot of information, sometimes it was a little slow with Securiti, s...
What is your primary use case for Securiti?
My main use case for Securiti is that we implemented it to improve our data privacy and compliance operations across ...
What is your experience regarding pricing and costs for Upwind?
The pricing, setup cost, and licensing process were pretty reasonable.
What needs improvement with Upwind?
I would appreciate more customizable dashboards and reporting for different teams, such as security operations, engin...
What is your primary use case for Upwind?
My main use case for Upwind is cloud security and workload protection. I primarily use it to gain visibility into clo...
 

Comparisons

 

Also Known As

Qualys TotalCloud with FlexScan
No data available
Upwind Security Upwind Platform for AWS Security Hub, Upwind Security Upwind for AWS Security Hub Extended
 

Overview

 

Sample Customers

Information Not Available
Information Not Available
StockX, Yotpo, bill, Digital Turbine, nanit, CallRail, boomi
Find out what your peers are saying about Securiti vs. Upwind and other solutions. Updated: September 2026.
915,341 professionals have used our research since 2012.