


XM Cyber and Vulcan Cyber are competing cybersecurity solutions in threat and vulnerability management. Vulcan Cyber seems to have the upper hand due to its comprehensive capabilities and advanced features that appeal to buyers.
Features: XM Cyber offers continuous attack simulation, automated remediation path prioritizing, and potential business impact assessment. Vulcan Cyber provides robust vulnerability management, intelligent risk prioritization, and integrated remediation automation.
Room for Improvement: XM Cyber could enhance its vulnerability management, risk prioritization, and provide more integrated remediation options. Vulcan Cyber may improve its deployment simplicity, provide more intuitive setup options, and lower its learning curve.
Ease of Deployment and Customer Service: XM Cyber offers a straightforward deployment model and intuitive setup supported by responsive customer service. Vulcan Cyber has a more complex deployment but provides in-depth guidance and supportive customer service, balancing the learning curve with comprehensive support.
Pricing and ROI: XM Cyber presents a cost-effective solution with commendable ROI, balancing pricing with significant value delivery. Vulcan Cyber demands higher upfront investment but justifies it with extensive features and enhanced risk management, potentially offering greater long-term ROI.
It has saved about 90% of our time.
TotalCloud has generated overall savings of 30 to 40 percent across various departments.
CallStream helps us integrate and automate tasks.
With our vulnerability management platform, I used to get reports weekly, but with Vulcan Cyber, I get them daily.
Our security team probably spends 15 minutes instead of two hours daily notifying the teams.
The biggest return on investment with Vulcan Cyber is in time savings and prioritization efficiency, as teams can focus quickly on high-risk vulnerabilities instead of manually reviewing thousands of findings.
There was a specific issue that our other security tooling did not pick up, but XM Cyber did.
It's reduced the timescale to remediate vulnerabilities that are identified as representing a high risk.
They are helpful, respond to my queries, and can answer any question.
Qualys's tech support is highly responsive, providing multiple ways to interact with them.
Qualys' customer service provides quality answers, but the response time is long, even though it is within the SLA.
We do not necessarily have visibility of when those feature requests are going into the development pipeline.
It would enhance my experience if Vulcan informed customers of forthcoming maintenance or changes that might cause website downtime.
Their technical support team is very good, knowledgeable, and helpful.
The customer support is fantastic; it's probably some of the best we've received across all our security vendors.
Customer support for XM Cyber is good, responsive, and it follows up on issues.
We started our organization about nine months back. We started with about 30 users, and we now have more than 100 users.
Our organization currently uses it to manage over 1200 web applications.
It is absolutely scalable, and I would rate its scalability as nine out of ten.
We have a lot of assets under management, and it effectively scales up to accommodate hundreds or even thousands of assets.
I'd rate the scalability ten out of ten.
I would rate it ten out of ten for scalability, as integration with multiple connectors is possible without exceeding licensing limits.
Its scalability is great; it's easy to deploy and fully scalable.
We have not experienced any issues with scalability or reached its limits.
Overall, the support provided has been excellent.
It is a stable solution, which is why we chose it.
Continuous monitoring is crucial to ensure system stability and avoid vulnerabilities or threats.
It would be better if Vulcan notified me, the customer, about upcoming maintenance or changes, indicating when the website might be down.
The product's stability is commendable, with no noticeable lags or slowness.
I would rate it a nine out of ten in terms of stability.
We have quite a complex and large IT estate, and we've certainly experienced no limitations or problems arising from the ability of XM Cyber's product to scale across that estate.
Ideally, the scanner should automatically detect and scan all subdomains, even if not explicitly defined, ensuring comprehensive vulnerability assessment.
Ideally, updates should be more immediate, enabling quicker implementation of solutions.
Our goal is to integrate all these functions into Qualys, creating a single dashboard for comprehensive security monitoring and management.
It would be beneficial if the platform allowed remote access to devices for immediate remedies.
Providing real-world examples of how to construct a ticket format for Jira, Azure DevOps, or ServiceNow with specific examples would help us understand how it might work in our environment.
Having it more customized or providing more customization options for me would be beneficial.
We push the boundaries with digital twins; I understand XM Cyber uses a similar concept of graph databases to map environments.
They could improve support because when we need to create a super case and escalate to resolve with technical support, they resolve our ticket in approximately two weeks.
The part that can be improved is the mobile exposure and the IBM i specific equipment.
Qualys TotalCloud's pricing is currently acceptable, it is becoming increasingly expensive.
Pricing is managed by our finance team; however, Qualys TotalCloud offers cost-effective licensing flexibility.
Qualys TotalCloud is expensive, but it offers a premier solution with no headaches.
For our use case, the solution is lacking some features, and the cost savings don't make it worth it.
Pricing typically depends on the scale of integrated assets.
We have a large, complicated estate, and in the licensing discussions, we were keen not to have the cost balloon because of the complication, the number of PCs and servers that we have.
This view of risk helps reduce the work we would have to do to combine multiple sources to prioritize risk.
It will help cybersecurity professionals monitor the cloud and find vulnerabilities.
We are enjoying the new feature, FlexScan, which is valuable for Internet-facing VMs.
It offers a comprehensive view of the assets and their associated vulnerabilities, which aids in assessing and mitigating threats.
The automation capabilities using the Vulcan API platform or the API feature allow me to easily automate scripts and reports and schedule them.
Instead of having 100 vulnerabilities and not knowing how to prioritize and assign all your FTEs there, you now have only ten that you know you need to fix, and you're assigning the right number of FTEs.
Our loss exposure amount has reduced significantly, leading to two big wins: our loss exposure amount has gone down, and we have direct savings from focusing our team's time on what's important, allowing them to work on other business benefits and generate value for the company.
By far, the best feature of XM Cyber is being able to map out the way vulnerabilities can be exploited based on what they call the choke points in the network where the path that a bad actor would take comes closest to assets within our environment that are most vulnerable but also most valuable.
XM Cyber allows us to quantify the risk, and we are able to track remediation, so we can quantify the risk at an executive level and also to a technical IT team.
| Product | Mindshare (%) |
|---|---|
| Qualys TotalCloud | 1.1% |
| Vulcan Cyber | 0.8% |
| XM Cyber | 0.9% |
| Other | 97.2% |


| Company Size | Count |
|---|---|
| Small Business | 9 |
| Midsize Enterprise | 4 |
| Large Enterprise | 29 |
| Company Size | Count |
|---|---|
| Small Business | 1 |
| Large Enterprise | 11 |
Qualys TotalCloud enhances security posture across cloud environments with continuous monitoring, vulnerability management, and risk visualization, ensuring efficient threat assessment and automated remediation for improved cyber risk reduction.
Qualys TotalCloud offers a robust suite of security tools essential for organizations managing multi-cloud infrastructures. By integrating cloud accounts and automating workflows, it supports AWS, Azure, and GCP, offering comprehensive vulnerability management and zero-day detection. The platform's user-friendly design, combined with its extensive risk management and unified threat assessment capabilities, enables organizations to prioritize and remediate vulnerabilities effectively. TruRisk Insights provides clear insights on cyber risks, while the automation options streamline patch management and scanning processes. API integration across IaaS and SaaS environments further enhances resource allocation efficiency and saves time, addressing misconfigurations across cloud environments.
What are the most important features of Qualys TotalCloud?Qualys TotalCloud is deployed in sectors needing rigorous vulnerability management, such as finance and healthcare. Companies utilize it to secure multi-cloud environments like AWS, Azure, and GCP, focus on compliance, and integrate security into CI/CD pipelines to detect and remedy threats pre-deployment.
Vulcan Cyber centralizes data from multiple scanners for a unified view, helping prioritize crucial vulnerabilities efficiently and enabling advanced analytics through seamless integration with numerous tools.
Vulcan Cyber offers a holistic vulnerability and asset management platform, integrating findings from scanners such as Wiz and BlackRock and aligning with Jira and ServiceNow for efficient ticketing. It automates processes and enhances threat analysis through its intuitive interface, allowing users to manage vulnerabilities and assets efficiently, even in post-merger scenarios. Users can centralize scanner data, ensuring streamlined processes and comprehensive reporting. Despite its performance and interface speed challenges, Vulcan Cyber remains a valuable tool for managing risk-based notifications and stakeholder communications.
What features define Vulcan Cyber?Industries employing Vulcan Cyber for vulnerability management experience streamlined processes concerning scanner data centralization and asset assessment post-merger. Its integration with service solutions like Jira fosters efficient ticketing and communication, improving risk assessments and remediation actions.
XM Cyber quantifies risk for different organizational levels, enhances patching by targeting choke points, and offers precise attack simulations, optimizing management time and vulnerability resolutions.
XM Cyber empowers organizations to identify significant risks by focusing on choke points and improving patching strategies. The platform excels in providing reliable and precise simulations, informing users about critical vulnerabilities without false positives. It enhances vulnerability management and internal reconnaissance, reducing loss exposure while supporting attack surface management. Users seek improved mobile exposure capabilities and IBM i specific solutions along with better visualization and AI integration.
What are the key features of XM Cyber?XM Cyber is deployed to manage risks in internet-exposed assets and hybrid cloud environments. Its implementation allows organizations to optimize IT resources by identifying vulnerabilities in critical attack paths, thus enhancing efficiency and supporting robust security strategies across industries.
We monitor all Vulnerability Management reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.