No more typing reviews! Try our Samantha, our new voice AI agent.

Tenable.io Container Security vs Tufin Orchestration Suite comparison

Why PeerSpot?
Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jun 3, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Qualys TotalCloud
Sponsored
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
46
Ranking in other categories
Vulnerability Management (11th), Container Security (11th), Cloud Workload Protection Platforms (CWPP) (8th), Cloud Security Posture Management (CSPM) (8th), SaaS Security Posture Management (SSPM) (2nd), Cloud-Native Application Protection Platforms (CNAPP) (7th)
Tenable.io Container Security
Average Rating
8.0
Reviews Sentiment
6.1
Number of Reviews
9
Ranking in other categories
Container Security (26th)
Tufin Orchestration Suite
Average Rating
8.0
Reviews Sentiment
7.2
Number of Reviews
182
Ranking in other categories
Firewall Security Management (3rd)
 

Mindshare comparison

Container Security Mindshare Distribution
ProductMindshare (%)
Tenable.io Container Security1.0%
Wiz8.3%
Prisma Cloud by Palo Alto Networks7.4%
Other83.3%
Container Security
Firewall Security Management Mindshare Distribution
ProductMindshare (%)
Tufin Orchestration Suite15.3%
AlgoSec15.8%
FireMon Security Manager13.4%
Other55.5%
Firewall Security Management
 

Featured Reviews

reviewer2859021 - PeerSpot reviewer
Sr Security Engineer at a tech vendor with 5,001-10,000 employees
Risk-based triage has transformed container security and now prioritizes high-impact threats
The best features Qualys TotalCloud offers currently include managing cloud infrastructure and container security while facing major challenges such as alert fatigue. Traditional vulnerability scanners flag hundreds of CVEs on short-lived Kubernetes containers, some of which have no internet exposure or are gone before we can even triage them. I leverage Qualys TotalCloud to move beyond static CVSS. I use it to implement runtime exposure, correlation risk reprioritization, and shift-left integration. This notifies developers to fix a base image upstream rather than patching live ephemeral instances. In my work with cloud and container security, the biggest operational hurdle was alert fatigue. I use Qualys to shift left from static CVSS severity to context-aware risk prioritization. I correlated raw vulnerability data with real-time risk factors such as public network exposure, active runtime execution, or overly permissive IAM roles. This allows us to immediately drop the priority of isolated containers and escalate lower-severity CVEs that sit on an exposed, high-risk path. We can map these findings directly back to our CI/CD pipelines so developers can patch the root base images upstream. We have drastically cut down the signal-to-noise ratio, saved a lot of manual hours doing triage work, and ensured engineering effort goes directly towards high-impact risk reduction.
AS
Cyber Security Architect at a security firm with 201-500 employees
Detailed container image reports have improved vulnerability insight and support secure operations
Most valuable are the reports that are quite good, particularly the detailed ones for container image scanning. Tenable.io Container Security is giving me the vulnerability information of Docker images and the information about software bill of materials. However, my challenge at this time is that I am using all these solutions with GitLab Ultimate, and it does not support integration, so I am doing some alternate arrangements which are giving me operational complexity because I need to introduce something else instead of GitLab Ultimate. That is the primary concern regarding the benefits of real-time visibility into my containerized application security status.
Vulnerability control saves audit costs and reduces expenses for organizations
Tufin Orchestration Suite is not commonly used in Thailand due to a lack of local support, and many customers are switching to AlgoSec or other vendors. The analytics features of Tufin Orchestration Suite are challenging to use and require technical expertise, which is a concern as there is not much knowledge in this field in Thailand. The issue of technical knowledge, especially regarding English language proficiency, is significant for government and some companies, making Tufin Orchestration Suite harder to use.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Its excellent graphical interface makes the scanning process simple."
"While automatic inventory detection upon connection is a helpful feature, a truly valuable capability would be assessing an environment's security posture against Azure and CIS best practices."
"In my opinion, this is the best tool."
"I would recommend Qualys TotalCloud to other users because it is cost-efficient and has a good return on investment."
"TotalCloud provides the easiest and the best approach for cloud infrastructure management."
"The most valuable feature of Qualys TotalCloud is the visibility it provides."
"Qualys TotalCloud has positively impacted our organization by helping us save time and manage all assets and remediation, allowing us to achieve quarterly and half-yearly goals."
"By integrating TotalCloud, we have significantly reduced vulnerabilities in our deployment pipeline."
"The strong security provided by the product in the container environment is its most valuable feature."
"Nessus scanner is very effective for internal penetration testing."
"It is a scalable solution. Scalability-wise, it is a good solution."
"It helps us secure our applications from the build phase and identify the weaknesses from scratch."
"Currently, I haven't implemented the solution due to its deprecation by the site. However, I can highlight some benefits of Tenable Cloud Security, a cybersecurity solution with various features for scanning vulnerabilities in both cloud environments and on-premises container security."
"The tool's most valuable feature is scanning, reporting, and troubleshooting."
"By using Nessus, we are able to finish testing with assured results, in half the time."
"Most valuable are the reports that are quite good, particularly the detailed ones for container image scanning."
"Firewall automation was one of the biggest concerns we had, and we have largely sorted that out with this tool."
"We can get reports with Tufin at anytime. We can have automated reports, even with security and compliance."
"We've scaled it to hundreds of firewalls."
"I have seen ROI with this product; we've seen a decrease of about 50 percent in the overall time it takes to complete a firewall change."
"The most valuable function is the SecureChange where it is able to automate everything from the validation of the rules to the pushing of the rules."
"This solution definitely helps to reduce the time it takes to make changes."
"This solution was a need for our organization to stay compliant and it has helped us in this way."
"The multi-vendor support is very important for us; this is the most important feature because our system has integrations of software and hardware from many vendors, and Tufin has also integrated well, supporting our system of multiple vendors."
 

Cons

"We encountered challenges identifying the correct resource category for certain items, such as those in containers or storage."
"Customer support with Qualys TotalCloud needs a little improvement with the response times."
"From a downside perspective, the UI is not user-friendly and feels dated compared to other tools like Prisma Cloud."
"I would appreciate additional integration options to connect Qualys TotalCloud with our other vulnerability management tools."
"Overall, we are satisfied with it. However, the response part of the Cloud Detection and Response (CDR) module can be improved. It is not yet in place according to requirements; it is not completely available even though the module has been released."
"Qualys's ticketing system can be confusing when assigning tasks to individuals, and support could be improved by offering instant call solutions with engineers in addition to ticket replies."
"In TotalCloud, I would suggest improvements in policy checks to cater to various inventory types like VPCs, subnets, S3 buckets, or IAMs. There is a lack of data segregation according to criticality or inventory."
"Their support could be improved."
"I believe integration plays a crucial role for Tenable, particularly in terms of connecting with other products and various container solutions like Docker or Kubernetes. It seems that in future updates, enhanced integration is something I would appreciate. Currently, there is integration with Docker, but when it comes to Kubernetes or other container solutions, it appears to be a challenge, especially with on-prem scanners."
"The support is tricky to reach, so we would like better-oriented technical support enabled."
"I feel that in certain areas this product has false positives which the company should work on. They should also try to include business logic vulnerabilities in the scanner testing. Finally, the vulnerability assessment feature should be increased to other hardware devices, apart from firewalls."
"The initial setup is highly complex."
"I feel that in certain areas this product has false positives which the company should work on."
"The stability and setup phase of the product are areas with shortcomings where improvements are needed."
"Tenable.io Container Security should improve integration modules. It should also improve stability."
"However, my challenge at this time is that I am using all these solutions with GitLab Ultimate, and it does not support integration, so I am doing some alternate arrangements which are giving me operational complexity because I need to introduce something else instead of GitLab Ultimate."
"We've had stability issues because it's a heavy solution. It takes a long time to get up and running, and when we migrate releases, that's an issue."
"The options for certain things are pretty rigid, so they need to be more customizable."
"It could be a little more intuitive."
"It seems stable. We've had problems always with the same box, which is our SecureTrack primary. We are probably on our seventh one."
"I'd like to see automation of a number of steps."
"I feel that the user interface is a bit dated."
"Their pricing is not very transparent. This is my biggest point regarding Tufin."
"One thing it's not currently able to do is remove rules."
 

Pricing and Cost Advice

"It isn't cheap, but it's reasonable. It helps us to manage things with very few resources."
"Qualys TotalCloud offers cost-effective licensing flexibility."
"Qualys TotalCloud offers competitive pricing given its comprehensive suite of features, including integration, assessment, remediation, and detection capabilities, all within a single platform."
"The cost is high, but it meets our organizational needs."
"Its price seems higher compared to other tools, but it is worth it. If they could adjust the pricing and make it comparable with other tools, that would be great."
"TotalCloud's price is about right where I would expect it to be."
"I am not sure about the pricing. From what I understand, it is a bit on the higher side, but I do not have the exact numbers."
"Qualys TotalCloud is expensive."
"I rate the tool's pricing a three out of ten."
"I rate the product’s pricing a six out of ten."
"The solution's pricing is neither cheap nor very expensive."
"The product does not operate on a pay-per-license model."
"It's best to be an institutional buyer and directly contact the sales team as they can provide over-the-top discounts for bulk orders."
"Our licensing fees are more than $100,000 USD per year."
"The price of Tufin could be lower."
"The licensing costs are a significant amount of money."
"Our evaluation showed that Tufin's features were on par with AlgoSec, but Tufin was the better financial choice."
"Tufin and AlgoSec were pretty much in the competitive price range, but this one provided us better integration into the Check Point environment."
"We have seen ROI in operational aspects, in terms of how long it takes to resolve incidences which arise."
"We have seen ROI just in the time savings and knowledge. Knowledge is power. Having the solution do it automatically for you without you doing the work is huge. If you are spending $50,000 a year, it could have cost you a $100,000 in man-hours without it, especially if you are working with a team.."
"Licensing is available in both perpetual and subscription models, and it appears to be good for our scalable environments."
report
Use our free recommendation engine to learn which Container Security solutions are best for your needs.
913,806 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Comms Service Provider
16%
Outsourcing Company
12%
Manufacturing Company
11%
Financial Services Firm
10%
Financial Services Firm
13%
Manufacturing Company
8%
Outsourcing Company
8%
Construction Company
7%
Outsourcing Company
14%
Financial Services Firm
14%
Manufacturing Company
10%
Construction Company
10%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business14
Midsize Enterprise5
Large Enterprise34
By reviewers
Company SizeCount
Small Business2
Midsize Enterprise3
Large Enterprise4
By reviewers
Company SizeCount
Small Business29
Midsize Enterprise13
Large Enterprise153
 

Questions from the Community

What needs improvement with Qualys TotalCloud?
In terms of improvement, remediation still belongs to the cloud team, which is one of the issues we faced with Qualys...
What is your primary use case for Qualys TotalCloud?
My main use case for Qualys TotalCloud is regarding the cloud visibility that we were not having previously. Previous...
What needs improvement with Tenable.io Container Security?
Several things need improvement about Tenable.io Container Security. First, they should support GitLab Ultimate. Seco...
What is your primary use case for Tenable.io Container Security?
I have been dealing with Tenable.io Container Security for almost four to six months.
What advice do you have for others considering Tenable.io Container Security?
Tenable.io Container Security is a good product. I am currently using Tenable Enclave Security. When I say metrics, I...
What needs improvement with Tufin SecureCloud?
Tufin Orchestration Suite ( /products/tufin-orchestration-suite-reviews ) is not commonly used in Thailand due to a l...
What is your primary use case for Tufin SecureCloud?
I have primarily used Skybox and AlgoSec ( /products/algosec-reviews ). I have also interacted with FireMon for compi...
What advice do you have for others considering Tufin SecureCloud?
There is potential for improvement in explaining the analytics in the dashboard for Tufin Orchestration Suite. Tufin ...
 

Also Known As

Qualys TotalCloud with FlexScan
Tenable FlawCheck, FlawCheck
Tufin SecureCloud
 

Overview

 

Sample Customers

Information Not Available
ServiceMaster
3M, AT&T, Blue Cross Blue Shield, BNP Parabas, ConocoPhillips, Deutsche Bank, GE, IBM, Pfizer, United States Postal Service 
Find out what your peers are saying about Wiz, Palo Alto Networks, SentinelOne and others in Container Security. Updated: September 2026.
913,806 professionals have used our research since 2012.