No more typing reviews! Try our Samantha, our new voice AI agent.

Skyhawk Security vs Sophos Cloud Optix comparison

Why PeerSpot?
Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Qualys TotalCloud
Sponsored
Ranking in Cloud Security Posture Management (CSPM)
8th
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
46
Ranking in other categories
Vulnerability Management (10th), Container Security (11th), Cloud Workload Protection Platforms (CWPP) (9th), SaaS Security Posture Management (SSPM) (2nd), Cloud-Native Application Protection Platforms (CNAPP) (7th)
Skyhawk Security
Ranking in Cloud Security Posture Management (CSPM)
29th
Average Rating
9.4
Reviews Sentiment
5.7
Number of Reviews
5
Ranking in other categories
Cloud Workload Protection Platforms (CWPP) (20th)
Sophos Cloud Optix
Ranking in Cloud Security Posture Management (CSPM)
21st
Average Rating
8.4
Reviews Sentiment
6.7
Number of Reviews
10
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of October 2026, in the Cloud Security Posture Management (CSPM) category, the mindshare of Qualys TotalCloud is 2.0%, up from 1.4% compared to the previous year. The mindshare of Skyhawk Security is 0.7%, up from 0.2% compared to the previous year. The mindshare of Sophos Cloud Optix is 0.6%, up from 0.5% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Cloud Security Posture Management (CSPM) Mindshare Distribution
ProductMindshare (%)
Qualys TotalCloud2.0%
Sophos Cloud Optix0.6%
Skyhawk Security0.7%
Other96.7%
Cloud Security Posture Management (CSPM)
 

Featured Reviews

reviewer2859021 - PeerSpot reviewer
Sr Security Engineer at a tech vendor with 5,001-10,000 employees
Risk-based triage has transformed container security and now prioritizes high-impact threats
The best features Qualys TotalCloud offers currently include managing cloud infrastructure and container security while facing major challenges such as alert fatigue. Traditional vulnerability scanners flag hundreds of CVEs on short-lived Kubernetes containers, some of which have no internet exposure or are gone before we can even triage them. I leverage Qualys TotalCloud to move beyond static CVSS. I use it to implement runtime exposure, correlation risk reprioritization, and shift-left integration. This notifies developers to fix a base image upstream rather than patching live ephemeral instances. In my work with cloud and container security, the biggest operational hurdle was alert fatigue. I use Qualys to shift left from static CVSS severity to context-aware risk prioritization. I correlated raw vulnerability data with real-time risk factors such as public network exposure, active runtime execution, or overly permissive IAM roles. This allows us to immediately drop the priority of isolated containers and escalate lower-severity CVEs that sit on an exposed, high-risk path. We can map these findings directly back to our CI/CD pipelines so developers can patch the root base images upstream. We have drastically cut down the signal-to-noise ratio, saved a lot of manual hours doing triage work, and ensured engineering effort goes directly towards high-impact risk reduction.
Abhimanyu Das - PeerSpot reviewer
Senior Cybersecurity Engineer at Kyndryl
Cloud threat validation has reduced alert fatigue and now focuses investigations on real attacks
Skyhawk Security is pretty solid overall, but there are a few things I wish were better. One thing would be more native integration with Microsoft security tools such as Sentinel and Defender, since those are what we use daily. Having deeper built-in integration instead of relying on generic SIM connections would save time. The training and documentation could also be more comprehensive, with more real-world use case examples specific to different industries. Additionally, having more general customization for the AI models to adjust what gets flagged as anomalous in our specific environment would help reduce alert noise. These are pretty minor improvements, and most of them are probably already in their roadmap based on their recent updates adding self-AI training and bulk status changes for their customers. I believe a mobile app would benefit SOC analysts who need to respond frequently while on the go, as most of the platform feels focused on desktop use. Having a robust mobile experience for approving automated responses and reviewing critical alerts would be really useful.
reviewer2845695 - PeerSpot reviewer
Middleware administrator at a consultancy with 201-500 employees
Centralized monitoring has strengthened cloud posture and prioritizes critical security risks
The best features Sophos Cloud Optix offers are cloud security posture management, CSPM, continuous monitoring for misconfiguration, compliance reporting, and centralized visibility across multi-cloud environments. I also find the risk prioritization helpful, as it helps me focus on the most critical security issues first, and the intuitive dashboards make it easy to understand the overall security posture. Additionally, the alerting and reporting capabilities help my team respond to issues quickly and maintain compliance with organizational security standards. Sophos Cloud Optix has positively impacted my organization by improving my visibility into cloud security and helping me identify misconfigurations before they became security incidents. It has reduced the time required to detect and investigate potential risks by providing prioritized alerts and centralized dashboards. As a result, my team responds to security issues more effectively and spends less time on manual reviews. It has also supported my compliance efforts by providing clear reporting and continuous monitoring, which has strengthened my overall cloud security posture.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Qualys TotalCloud's most valuable feature is its agent versatility."
"I highly recommend Qualys TotalCloud to other users."
"If I had to say something positive about the product that brings me the biggest benefit, I would say it has accurate reports, gets new update CVEs, zero-day attack detection, and is easy to manage with its GUI."
"I appreciate Qualys TotalCloud's ability to onboard any type of device with ease, including containers."
"Qualys TotalCloud is an excellent platform, and the beauty of the platform is that we can get all the vulnerabilities, see all the reports in a single dashboard, view them segregated, and easily learn about critical, high, and medium findings with appropriately provided remediation steps."
"Qualys TotalCloud provides unified vulnerability and threat assessment for IaaS and SaaS and a single prioritized view of risk, which helps reduce my workload by not having to combine multiple sources."
"Vulnerability and threat detection and assessment of the criticality of the vulnerabilities exposed are most valuable."
"The agent and agentless scanning in TotalCloud, particularly the FlexScan method, is incredibly valuable. With traditional scanning approaches, we had to give IP ranges and whitelist IPs. All that is now simplified. FlexScan requires minimal intervention, and after configuration, it automatically collects data and performs necessary scans."
"Skyhawk Security has positively impacted my organization because we are a small security team, and Skyhawk Security allows us to prioritize our work."
"It helps us in reaching the ISO27001 certification."
"The initial setup process is easy and intuitive."
"We fell in love at the first sight."
"Skyhawk Security has had a really positive impact on our organization, especially in reducing false positives and speeding up incident response times."
"Skyhawk Security has plenty of products and subscriptions available, and at this moment, Skyhawk Security appears to be the leading company in the cybersecurity area."
"Compared to Sophos, Symantec is like not having any protection at all, so once we deployed Sophos in multiple locations, we instantly had a sense of security."
"The most valuable feature for me would be the solution's endpoint protection."
"Sophos Cloud Optix has positively impacted my organization by improving my visibility into cloud security and helping me identify misconfigurations before they became security incidents."
"Time saving has been one of the most impactful outcomes for us, as automated compliance checks reduced manual audit preparation by about two weeks per quarter."
"The most valuable feature of Sophos Cloud Optix is the simple way to manage my devices on the network. Additionally, it is easy to navigate and has a user-friendly interface."
"I find Cloud Optix to be a valuable solution since it provides a single, unified dashboard to monitor cloud assets, such as AWS and Azure."
"Sophos Cloud Optix has positively impacted my organization by providing benefits such as better visibility into cloud assets, faster identification of misconfigurations and over-privileged access, and quick response."
"Sophos Cloud Optix impacts us positively in many ways, particularly in security, which is an important part, and it helps us save time and in optimization for performance and cost."
 

Cons

"I chose a rating of nine out of ten because there is a complex interface that sometimes overwhelms new engineers."
"A feature improvement could be the inclusion of Windows OS support for container security, as it is currently only supported for Linux."
"The support process is inefficient due to the excessive number of replies required when submitting tickets."
"The areas in the solution that have room for improvement include the UI/UX design, which should be improved, and they should integrate more artificial intelligence into the product."
"It is already perfect, but they can bring some newer dashboards and customization options for the dashboard. It would be great to be able to include on-prem assets on the dashboard."
"Their customer support needs improvement."
"We encountered challenges identifying the correct resource category for certain items, such as those in containers or storage."
"The response part of the Cloud Detection and Response (CDR) module can be improved."
"Skyhawk Security can be improved mainly by improving the UI so it is a little bit easier to use, and the speed that it takes pages to load are the main downfalls."
"The solution needs automatic testing."
"The platform’s interface needs enhancement."
"I wish there was more transparent self-service pricing information available instead of having to go through sales to get the details."
"There are times when the devices are at maximum capacity, and it takes a while before the device is updated. For example, if the device has a virus, and it's not aligned to connect to the network, even after you've scanned the device, and cleaned out the virus, once the management clears the system to allow it back on the network it takes some time. It can be frustrating when you have your line manager or in management affected trying to access the network."
"The dashboard and the process for applying policies could be more intuitive."
"The setup was a little bit complex."
"Automated fixes are helpful, but sometimes we would prefer more control over how they are applied."
"I find that Sophos Cloud Optix is stable and most of the time reliable, although there is a maintenance window almost every week, with one day dedicated to maintenance. This is somewhat inconvenient as sometimes the platform might misbehave during that time when managing threats and other activities."
"Overall, Sophos Cloud Optix is a strong cloud security platform, but there are a few areas where it could improve."
"The dashboard and the process for applying policies could be more intuitive. Cloud Optix isn't that difficult once you get the hang of it, but the IT folks managing this want it to be more user-friendly."
"I have not connected with Sophos Cloud Optix customer support yet, but I had a bad experience when our AWS cloud got compromised, leading to many resources being provisioned, and while Sophos Cloud Optix identified those resources, the resulting bill from AWS was quite high due to the usage charges, which I tried to investigate with the Sophos team, though I am not sure if they assisted with the refund."
 

Pricing and Cost Advice

"Qualys TotalCloud is expensive."
"Its price seems higher compared to other tools, but it is worth it. If they could adjust the pricing and make it comparable with other tools, that would be great."
"Qualys TotalCloud is cost-efficient and was selected for its value compared to other products."
"The pricing is comparable. It is built into our other product, so I cannot piecemeal it. It is a part of our subscription."
"Qualys TotalCloud offers cost-effective licensing flexibility."
"Qualys TotalCloud is expensive, but it offers a premier solution with no headaches."
"Qualys TotalCloud offers good pricing that is affordable and competitive with the market. Our partnership also provides us with additional benefits."
"It isn't cheap, but it's reasonable. It helps us to manage things with very few resources."
Information not available
"Regarding the pricing for Sophos Cloud Optix, I would say that it was a very good price."
report
Use our free recommendation engine to learn which Cloud Security Posture Management (CSPM) solutions are best for your needs.
915,341 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Comms Service Provider
16%
Outsourcing Company
12%
Manufacturing Company
11%
Financial Services Firm
10%
No data available
Outsourcing Company
13%
Construction Company
10%
Healthcare Company
7%
Financial Services Firm
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business14
Midsize Enterprise6
Large Enterprise35
No data available
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise2
Large Enterprise2
 

Questions from the Community

What needs improvement with Qualys TotalCloud?
In terms of improvement, remediation still belongs to the cloud team, which is one of the issues we faced with Qualys...
What is your primary use case for Qualys TotalCloud?
My main use case for Qualys TotalCloud is regarding the cloud visibility that we were not having previously. Previous...
What is your experience regarding pricing and costs for Radware Cloud Native Protector?
I do not have access to specific pricing details and licensing costs as that is managed by our management team, but I...
What needs improvement with Radware Cloud Native Protector?
Skyhawk Security is pretty solid overall, but there are a few things I wish were better. One thing would be more nati...
What is your primary use case for Radware Cloud Native Protector?
My main use case of Skyhawk Security is cutting through the massive volume of alerts I deal with daily in my SOC oper...
What needs improvement with Sophos Cloud Optix?
To improve Sophos Cloud Optix, I wish there were more workflow automation, richer alert filtering, and tighter integr...
What is your primary use case for Sophos Cloud Optix?
My main use case for Sophos Cloud Optix is cloud security posture management to secure AWS, Azure, and Google Cloud e...
What advice do you have for others considering Sophos Cloud Optix?
Regarding Sophos Cloud Optix's AI capabilities, I think it handles governance and security well since it covers concr...
 

Also Known As

Qualys TotalCloud with FlexScan
Radware Cloud Native Protector
No data available
 

Overview

Find out what your peers are saying about Skyhawk Security vs. Sophos Cloud Optix and other solutions. Updated: September 2026.
915,341 professionals have used our research since 2012.