No more typing reviews! Try our Samantha, our new voice AI agent.
Sushant Samantara - PeerSpot reviewer
IT Manager at a consultancy with 10,001+ employees
Real User
Top 20
Nov 7, 2024
Helps us minimize attack surfaces by identifying root accounts and encryption issues
Pros and Cons
  • "TotalCloud has been excellent in providing us with immediate access to all the products and features we need, such as CSPM, TruRisk Insights, and compliance reports, including CIS and HIPAA."
  • "Although TotalCloud is a helpful tool, some of its advanced features are still under development."

What is our primary use case?

We utilize all three major cloud platforms: Azure, GCP, and AWS, with over 500 subscriptions and accounts onboarded in the public cloud. To manage these, we employ TotalCloud to evaluate, compare, and monitor the security compliance posture of each cloud account, enabling us to rectify and mitigate any misconfigurations. We are currently exploring TotalCloud's advanced features, such as CWP, TruRisk Insight, and Cloud Detection and Response, and have successfully implemented FlexScan, which has yielded excellent results in securing our Internet-facing VMs and headsets.

We are using cloud-based network tools to improve our security posture, but it was initially difficult to gain a consolidated view of our security status. To address this, we implemented Qualys TotalCloud and integrated our subscriptions from Azure, AWS, and GCP. This provides a unified dashboard displaying the compliance posture of our entire cloud infrastructure, allowing us to prioritize tasks and identify areas for immediate improvement. The tool also details the technical steps required to enhance our security posture, which has significantly contributed to increasing our cloud compliance from 60 percent to 90 percent.

How has it helped my organization?

TotalCloud provides written explanations to guide remediation and eliminate cyber risks. While all cloud platforms offer security features, it's challenging to consolidate them into a single dashboard. Qualys TotalCloud effectively addresses this by consolidating multiple cloud platforms and subscriptions onto one dashboard. This allows users to quickly identify and mitigate misconfigurations and risks, simplifying security management.

Before implementing TotalCloud, our compliance rate was approximately 50 to 60 percent. However, after adopting the platform, it has increased to 80 to 90 percent. TotalCloud also helps us minimize attack surfaces by identifying root accounts and encryption issues, thereby enhancing our overall security by 40 percent.

TotalCloud offers a unified platform for assessing vulnerabilities and threats across both IaaS and PaaS environments. This unified view has improved our cloud security posture management.

We gain a single, prioritized view of risks through TotalCloud's TruRisk Insights feature. This feature considers not only the QDA score but also factors in cost and other relevant elements to provide a comprehensive risk assessment. From a potentially overwhelming list of findings, TruRisk Insights prioritizes the most critical risks, allowing us to focus our efforts and resources on addressing these high-priority tasks efficiently.

A single, prioritized view of risk streamlines the risk assessment process by eliminating the need to consolidate multiple sources. This comprehensive view is instrumental in communicating with other business customers who may be unaware of potential risks or misconfigurations within their resources. By identifying and informing them of these issues, we can guide them towards compliance and ensure a more secure environment.

TruRisk Insights provides valuable findings by identifying vulnerabilities and misconfigurations, displaying them on a dashboard, and offering deeper insights into the attack surface. It analyzes not only internet-facing devices but also those indirectly connected, providing a comprehensive understanding of potential risks. This is crucial because even devices not directly connected to the internet can be vulnerable if they have an attack surface. TruRisk Insights also offers mitigation strategies, making it a highly useful tool for managing security risks.

With the VMDR feature enabled and the Qualys Agent installed on various assets, we can identify existing vulnerabilities. TruRisk Insights then calculates risk scores, prioritizes tasks, and presents the number of findings. This allows us to focus on mitigating high-priority vulnerabilities while deferring those with lower priority, ultimately reducing overall risk.

TruRisk Insights provides device details, allowing for containerization of misconfigured devices. This process involves isolating problematic devices and rectifying misconfigurations, ultimately enhancing our security posture.

What is most valuable?

TotalCloud has been excellent in providing us with immediate access to all the products and features we need, such as CSPM, TruRisk Insights, and compliance reports, including CIS and HIPAA. This easy access to crucial information and tools has dramatically improved our efficiency and ability to meet various compliance standards.

What needs improvement?

Although TotalCloud is a helpful tool, some of its advanced features are still under development. For example, the Cloud Detection and Response feature is currently only fully functional for AWS, while support for GCP and Azure is still in progress. Additionally, while the detection component of CDR is robust, the automated response and remediation functionality is yet to be available.

Buyer's Guide
Qualys TotalCloud
September 2026
Learn what your peers think about Qualys TotalCloud. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
914,805 professionals have used our research since 2012.

For how long have I used the solution?

I have been using TotalCloud for two years.

What do I think about the stability of the solution?

I would rate the stability of Qualys TotalCloud ten out of ten.

What do I think about the scalability of the solution?

I would rate the scalability of Qualys TotalCloud ten out of ten. We have been able to increase accounts easily whenever needed.

How are customer service and support?

Qualys' customer support is good, though occasional backend consultations can cause minor delays. Overall, the service is commendable.

Which solution did I use previously and why did I switch?

Prior to adopting Qualys, we relied solely on native cloud security measures provided by Azure, AWS, and GCP, rather than employing any third-party solutions.

How was the initial setup?

The initial deployment was straightforward due to my 17-year tenure in IT. Understanding security compliance facilitated the use and exploration of Qualys. While experts might encounter challenges, the product and backend teams have been highly supportive and accessible. Qualys has also been responsive within its SLAs.

What was our ROI?

We are constantly exploring new features and collaborating with Qualys to ensure we derive value. The finance team handles specifics on cost-effectiveness, but regular engagements with our TAM and product engineers suggest beneficial ROI.

What's my experience with pricing, setup cost, and licensing?

Pricing is managed by our finance team; however, Qualys TotalCloud offers cost-effective licensing flexibility. Existing VMware licenses can be switched to cloud features, eliminating the need for new purchases, which distinguishes it from other products.

What other advice do I have?

I would rate Qualys TotalCloud ten out of ten.

We are evaluating and implementing TotalCloud Detection and Response, a cutting-edge Cloud Detection and Response solution that utilizes AI and machine learning. This comprehensive product enhances our security posture and threat detection capabilities within the cloud environment.

We operate a SaaS platform with multiple locations, including an MSP involving 12 to 15 data centers globally. While we utilize sensors at our facilities, this won't hinder operations, as the geographically diverse data centers ensure easy management. We have 20 users of Qualys TotalCloud in our department.

Qualys maintains TotalCloud and provides notification of maintenance windows to minimize disruption during working hours.

Qualys TotalCloud significantly aided in maintaining and managing compliance scores, making it a highly recommended solution. The platform's exceptional accessibility, including comprehensive technical and TAM support, coupled with consistent availability and reachability, solidifies its value. Advocating for Qualys, I encourage others to utilize this robust platform.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
reviewer2788209 - PeerSpot reviewer
Senior Technical Program /Product Manager at a transportation company with 10,001+ employees
Real User
Top 10
Dec 22, 2025
Automated vulnerability detection has improved risk visibility but container security still needs work
Pros and Cons
  • "Generally, Qualys is very good at detections, whether on cloud or on-prem, and the agent allows deployment on both infrastructures, providing continuous monitoring of your assets, which is a key selling point for us."
  • "The downside is only in container security, but it has not been a long time since they introduced these models."

What is our primary use case?

We have experience with Veracode and other SCA solutions, but I'm not interested in participating in any campaign. Other than Snyk, we use Qualys for Vulnerability Management, specifically the VMDR solution. TrueRisk Management is not what we use; it's an extension to VMDR, but what we actually use is the main module of Qualys, which is Vulnerability Management, Detection, and Response.

We are not using TrueRisk at all because we have our own framework and we use Qualys Detection Score for everything. We do use Qualys TotalCloud for continuous monitoring. The main use case with Qualys TotalCloud is that VMDR provides a direct solution for on-prem systems and it offers a similar solution for cloud infrastructure including AWS, Azure, and GCP, along with an option to scan containers and other related resources.

The features I value about using Qualys include container scanning; they did give us some requested features, but maturity-wise, they are not there yet with respect to container scanning. The solution is maybe slightly expensive, but it's not as expensive as other tools such as Wiz. Generally, Qualys is very good at detections, whether on cloud or on-prem. The agent allows deployment on both infrastructures, providing continuous monitoring of your assets, which is a key selling point for us.

What is most valuable?

The features I value about using Qualys include container scanning; they provided us with some requested features, but maturity-wise, they are not there yet with respect to container scanning.

The solution is slightly expensive, but it's not as expensive as other tools such as Wiz. Generally, Qualys is very good at detections, whether on cloud or on-prem. The agent allows deployment on both infrastructures, providing continuous monitoring of your assets, which is a key selling point for us.

Detections get updated in Qualys with a unique identifier called QID. Whenever there's new information, such as a new CVE, Qualys processes that and generates a QID. Since our agents are installed across our infrastructure, they identify vulnerabilities based on the agent information, and any new detections also get updated to a manifest that runs every four hours, checking for new vulnerabilities.

The single prioritized view of risk helps reduce the work significantly; Qualys Detection Score not only considers the basic CVSS score but also factors in threat information and the exploitability factor, which helps us prioritize effectively. We also have another separate framework we developed that we use on top of this.

What needs improvement?

The downside is only in container security, but it has not been a long time since they introduced these models. Our use cases were edge use cases, so they had to develop some features for us, but they are indeed doing a good job.

How are customer service and support?

I would rate their support a seven on a scale of one to ten. For working with the people from Qualys, I would say seven is an accurate rating.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Before switching to Qualys, we were doing everything completely manual, and we wanted a more automated solution, which prompted us to switch.

How was the initial setup?

Our experience with the setup and deployment was quite good; Qualys was supportive, and we met with them twice a week while setting up the scanners and operations.

What about the implementation team?

The setup was done by us while Qualys guided us, as they do not have access to our infrastructure for deployments.

What's my experience with pricing, setup cost, and licensing?

Regarding pricing and setup cost, it was not the most expensive. While checking tools for container scanning, we considered Wiz and a startup, but we believe having one tool for as much as possible makes tracking and monitoring easier. We had Qualys agents installed everywhere, which facilitated the shift to container scanning.

What other advice do I have?

Qualys TotalCloud does help guide remediation paths and eliminate cyber risks. I would rate this solution a seven overall.

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Qualys TotalCloud
September 2026
Learn what your peers think about Qualys TotalCloud. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
914,805 professionals have used our research since 2012.
Sourav Dadhwal - PeerSpot reviewer
Cyber Expert at National Electronic Register Of Jain Manuscripts
Real User
Top 5
Dec 23, 2025
Unified cloud security has delivered strong compliance reporting and streamlined audit workflows
Pros and Cons
  • "If someone were to ask me to review Qualys TotalCloud, I would summarize it as an end-to-end solution for cloud security with visibility and governance-grade controls without needing to manage multiple disconnected tools."
  • "I think Qualys TotalCloud needs to improve its handling of zero-day vulnerabilities and supply chain management because modern ransomware attacks not only target prime critical infrastructures but also the supply chain system."

What is our primary use case?

I have approximately three to four years of experience working with Qualys TotalCloud.

I have been using Qualys TotalCloud while working with EY, Ernst & Young, where I utilize cloud tools for Qualys, employing two types of tools: one for policy and compliance, for security and compliance audits, and another for security audits such as vulnerability assessments and risk assessments. Based on that tool, it is very easy to go through the inventory and easily deploy the compliance policies as needed while also receiving comprehensive assessment scores.

I use Qualys TotalCloud primarily for compliance and cloud security, and I am also getting certified from Qualys in both compliance auditing and vulnerability management, making me a certified specialist for Qualys.

In Qualys TotalCloud, everything is in a single platform and as a unified CNAP application, it combines CSPM, CWPM, CIEMs, and workload securities with a lightweight agent that covers everything, including cloud resources, configuration, misconfigurations, and shadow assets, allowing us to work around AWS, Azure, and GCP platforms while generating compliance reports and providing end-users with easy access to dashboard audit reports and executive views.

What is most valuable?

To eliminate cyber risk, I think the best method in Qualys TotalCloud is correlating vulnerability exposure and configuration with identity instead of just CVs, making it the perfect option for use within Qualys TotalCloud. If someone were to ask me to review Qualys TotalCloud, I would summarize it as an end-to-end solution for cloud security with visibility and governance-grade controls without needing to manage multiple disconnected tools. In comparison to other tools such as Prisma, Wiz, and Defender, Qualys TotalCloud helps unify vulnerability and threat assessment in IaaS and SaaS environments because it has an intuitive web interface that is simple enough for anyone to learn with just a few hours of preliminary training, allowing users to easily deploy initial assets and policy configurations as needed while generating customized reports.

I have compared Qualys TotalCloud with other vendors such as Prisma, Wiz, and Defender, noting that despite some limitations in those other tools, Qualys TotalCloud performs exceptionally well across various compliance requirements, offering a simple interface for customizing reports while meeting auditors' needs with regulatory benchmarks, including CIS, NIST, ISO, and PCI.

Qualys TotalCloud provides a single unified dashboard for all types of reports, executive views, and dashboards, allowing you to easily access key summaries and recommendations.

What needs improvement?

I think Qualys TotalCloud needs to improve its handling of zero-day vulnerabilities and supply chain management because modern ransomware attacks not only target prime critical infrastructures but also the supply chain system. If Qualys TotalCloud can solely assess risks based on initially added assets, there may be vulnerabilities within supporting firms that go undetected.

What do I think about the stability of the solution?

For stability, I would rate Qualys TotalCloud a nine out of ten. While there may be occasional disruptions due to internet connectivity issues, the application supports both offline and online functionality, maintaining operability even under hybrid working conditions.

What do I think about the scalability of the solution?

Qualys TotalCloud is highly scalable, rated at ten out of ten, facilitating easy scale-up or scale-down based on audit and compliance needs.

How are customer service and support?

I rate the technical support from Qualys TotalCloud a perfect ten out of ten because whenever we log incidents, all service level agreements are met within half an hour, with prompt provision of root cause analyses by the support teams.

How would you rate customer service and support?

Positive

What other advice do I have?

I have limited feedback on how Qualys TotalCloud helps my cloud security posture management, but it works well with misconfiguration detections and provides deep mapping with CIS, NIST, ISO frameworks, PCI compliance, and regulatory benchmarks.

In terms of pricing, compared with the top market leaders in Gartner's reports, I find Qualys TotalCloud to have a reasonable standard rate, which is not too hard to access. They have also introduced use case basis rates that allow auditors to purchase specific instances of the cloud service, leading to a flexible pay-per-usage model.

Overall, deploying Qualys TotalCloud across all cloud platforms is very easy.

We handle clients of all sizes, including direct work with government entities, and are currently deployed in various states within government and public sectors.

Vendor maintenance, such as patches for Qualys TotalCloud, is conducted promptly. I observe that if a zero-day vulnerability emerges, the vendor deploys patches as per market recommendations without significant delays.

While we do not work directly with Qualys in our organization, I utilize it during audit activities at client premises alongside various other tools such as Metasploit, Rapid7, and others that I prefer not to disclose. We can deploy Qualys TotalCloud where needed, particularly for presentation layers, while other tools handle deeper network layer security requirements.

I recommend Qualys TotalCloud, having written various articles on it. I suggest potential users align their use cases with its capabilities before deciding, as a proof of concept could be beneficial.

I have given this review an overall rating of eight out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Group IT Cloud and Cybersecurity Engineer at Safetykleen
Real User
Top 10
Sep 28, 2025
Has supported vulnerability detection and device inventory but needs better automation and risk prioritization
Pros and Cons
  • "Once you have your vulnerabilities fixed and your patches pushed out using Qualys TotalCloud, then you are able to eliminate threats and cyber risk."
  • "I sometimes have difficulty detecting or uninstalling certain versions of applications, which I have to do manually."

What is our primary use case?

I use Qualys TotalCloud for vulnerability as a service, vulnerability management as a service. I use it to check my devices to see if they're free from vulnerabilities, to send updates, and also as a form of inventory for the devices.

What is most valuable?

I can use Qualys TotalCloud to uninstall unwanted devices, which is great. I can also use the feature of seeing what my vulnerabilities are, a form of inventory, and knowing the criticals and the less criticals. Once you have your vulnerabilities fixed and your patches pushed out using Qualys TotalCloud, then you are able to eliminate threats and cyber risk. Qualys TotalCloud is also used to provide unified vulnerability and threat assessment across both IaaS and SaaS.

What needs improvement?

I sometimes have difficulty detecting or uninstalling certain versions of applications, which I have to do manually. More advanced features or AI could improve this process. A single prioritized view of risk is also lacking, which could enhance decision-making. Additionally, it could use improvements to perform actions without requiring manual intervention.

For how long have I used the solution?

I have been using Qualys TotalCloud for one year now.

What do I think about the stability of the solution?

It is stable. I have not had any issues with it.

How are customer service and support?

I rate the documentation they provide or the knowledge base between five to seven.

How would you rate customer service and support?

Negative

Which solution did I use previously and why did I switch?

I have done POC with Okta and CrowdStrike. Qualys TotalCloud focuses on vulnerability management and security features. Okta focuses more on identities and IAMs. CrowdStrike is more of intrusion detection and assessment.

How was the initial setup?

The application was quite easy to deploy in over 3,000 applications using Qualys TotalCloud.

What about the implementation team?

It's just me using Qualys TotalCloud. The users don't really have anything to do with it. I do all the admin side from my end.

What was our ROI?

The return on investment I've seen in the past year with Qualys TotalCloud is quite significant, around 10% to 20%.

What's my experience with pricing, setup cost, and licensing?

Qualys TotalCloud's pricing is fair. It is not expensive and is affordable.

What other advice do I have?

Cloud security posture changes with time when using Qualys TotalCloud. It depends on how early you detect threats and fix them. Qualys TotalCloud doesn't provide a single prioritized view of risk. The product does what it says it's going to do, so I recommend it. I rate Qualys TotalCloud six out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
PeerSpot user
Security Consultant at a tech vendor with 10,001+ employees
Real User
Top 5
Jul 22, 2026
Reporting has improved visibility into risk exposure but still needs fewer false positives and better support
Pros and Cons
  • "I depend heavily on the reports that I have from this tool."
  • "To be honest, I would move out from this tool because it does not give a full view of vulnerability."

What is our primary use case?

My main use case for Qualys TotalCloud is vulnerability management and exposure management. I use this tool to evaluate the exposure risk of the environment and identify all the weaknesses present in the environment.

What is most valuable?

I depend heavily on the reports that I have from this tool. In fact, this is the main tool that I use for reporting in the environment across most of the customer environments. However, I encounter a lot of false positives that require extensive testing to ensure the tool is reporting accurately. This process takes a significant amount of time. Additionally, the number of possible vulnerabilities that the tool identifies is not comparable to other players on the market. This impacts my ability to deliver the exact exposure view or risk that I am looking for.

What needs improvement?

To be totally honest, I do not have any best features because I have had a bad experience using this tool, especially regarding vulnerability management and exposure management.

Getting all the information together in the tool is challenging. When I try to reach out to the support teams to get help and feedback to understand how the tool works in greater depth, the quality of support and knowledge of the people who work on the support team, as well as the supposed senior engineers, has not been satisfactory.

I spend a lot of time doing reviews because I perform a mix of agent scans and authenticated scans. Sometimes the merge of data between those two scans does not work properly, resulting in a lot of false positives that require manual validation. I spend considerable time reviewing the content that comes from the tool. I do not have one hundred percent confidence that I am getting the real output from the tool.

First of all, I believe that the support team needs to be more senior and not engage in robotic interactions with customers. Additionally, regarding feature requests and issues that I am working on with the support team, I see a lack of care from the support team in dealing with those issues.

To be honest, I would move out from this tool because it does not give a full view of vulnerability. It does not provide a full perspective of the risk to my environment or the possible ways that I would be exploited by a hacker. It does not give me a full perspective of the exposure view for vulnerability management. If I consider the cloud aspects, I also need to get insights from other modules from the tool to give me a full perspective of my risk in the environment.

For how long have I used the solution?

I have been using Qualys TotalCloud for four years.

What do I think about the scalability of the solution?

To me and my perspective, it is too hard to get what I am looking for and build reports from the tool to get the visibility and view that I need. Most of the time I need to export the data and use it in another third-party tool, such as Power BI, to get the visibility and view that I am looking for.

How are customer service and support?

Regarding Qualys TotalCloud's AI capabilities, I do see that it is not true AI. It feels to me that I am working with a chat that does not give insights based on the findings or the information that I get from the tool. It is not a real agentic AI. It is more a chatbot.

How was the initial setup?

Qualys TotalCloud is deployed in my organization as a public cloud.

What other advice do I have?

My overall review rating for Qualys TotalCloud is seven out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Jul 22, 2026
Flag as inappropriate
PeerSpot user
Project Management Director at a tech services company with 201-500 employees
Real User
Top 5
Feb 4, 2026
Contextual risk insights have reduced my workload and provided clearer remediation paths
Pros and Cons
  • "Qualys TotalCloud provides unified vulnerability and threat assessment for IaaS and SaaS and a single prioritized view of risk, which helps reduce my workload by not having to combine multiple sources."
  • "In my opinion, what can be improved in Qualys TotalCloud includes pricing and container scanning."

What is our primary use case?

Qualys TotalCloud provides container security, vulnerability management, posture management, and more.

What is most valuable?

Qualys TotalCloud saves about a third of resources. Qualys TotalCloud provides written explanations to guide remediation paths and eliminate cyber risk, and I appreciate the written explanation and the visualization of attack paths.

Qualys TotalCloud provides unified vulnerability and threat assessment for IaaS and SaaS. Qualys TotalCloud provides a single prioritized view of risk, which helps reduce my workload by not having to combine multiple sources.

What needs improvement?

In my opinion, what can be improved in Qualys TotalCloud includes pricing and container scanning.

For how long have I used the solution?

I started working with Qualys TotalCloud approximately one year ago.

What do I think about the stability of the solution?

I assess Qualys TotalCloud as stable, and I would rate it an 8, with 10 being the best.

What do I think about the scalability of the solution?

I would rate Qualys TotalCloud a 7 for scalability on a scale from 1 to 10.

How are customer service and support?

I would rate the technical support for Qualys TotalCloud about a 7 on a scale from 1 to 10.

How would you rate customer service and support?

Positive

How was the initial setup?

It is easy to deploy Qualys TotalCloud.

What's my experience with pricing, setup cost, and licensing?

Qualys TotalCloud is on the pricier side, and I would rate the pricing around an 8 on a scale from 1 to 10.

Which other solutions did I evaluate?

I compare Qualys TotalCloud with other solutions and other vendors as a good contender, though I acknowledge there are differences. In comparison with other vendors, including Microsoft, Qualys TotalCloud holds its own but presents distinct features.

What other advice do I have?

I do use the TruRisk Insight feature with Qualys TotalCloud. I assess the comprehensiveness and the range of risks found with TruRisk Insights as adequate.

The TruRisk Insights feature has found a small number of assets with high vulnerability scores. The effect of TruRisk Insights on security posture is significant, as it provides better awareness and focus on critical risks.

I would recommend this product to other users, and my advice would include doing a proof of concept to see if it fits their needs. I would rate this product an 8 overall.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company has a business relationship with this vendor other than being a customer. MSP
Last updated: Feb 4, 2026
Flag as inappropriate
PeerSpot user
Prajwal Chougale - PeerSpot reviewer
SOC L2 Analyst at a tech services company with 51-200 employees
MSP
Top 5Leaderboard
Aug 17, 2026
Centralized visibility has streamlined cloud security posture and accelerated vulnerability remediation
Pros and Cons
  • "Qualys TotalCloud has positively impacted our organization by helping us save time and manage all assets and remediation, allowing us to achieve quarterly and half-yearly goals."
  • "Regarding improvements to Qualys TotalCloud, I suggest that user navigation can be enhanced because initially, many users found it complicated and had trouble understanding the platform due to information being spread across multiple tabs."

What is our primary use case?

I primarily use Qualys TotalCloud for Cloud Security Posture Management, vulnerability management, asset visibility, and continual monitoring of cloud assets, maintaining the cloud resources that we use.

One of the main advantages for us is having multiple security capabilities available through this tool, instead of maintaining several completely separate tools for each one of them, such as vulnerability management, audit asset visibility, and cloud security management.

During our security rehearsal or weekly customer meetings, we need to check about site compliance, and Qualys TotalCloud was very helpful because instead of using other tools where we had to pull reports from different sources, we could check compliance all in one place.

When one hundred fifty vulnerabilities were identified on cloud, production, or any endpoint, it was useful for us to identify which asset was affected and to look at the details and share the findings with the customer and the remediation infrastructure team.

What is most valuable?

Qualys TotalCloud offers several valuable features, including monitoring visibility as an EDR tool and cloud asset inventory capabilities, which help in centralized asset management and prioritizing risk.

It is particularly useful because it gives us visibility across cloud resources from different environments in one place, making it easy for organizations to understand their security postures without manual checking with cloud consoles.

The vulnerability management capabilities are another strong point where we can review security risks for vulnerabilities on cloud workloads and prioritize issues based on CVSS scores.

When we were using different cloud solutions, it was tedious to find compliance for assets, especially during monthly meetings.

Qualys TotalCloud is very useful in day-to-day security operations, particularly at monthly review meetings. It was helpful to maintain all the assets in one place, and when investigating vulnerabilities, we can first identify affected cloud assets from the inventory and look at their release details and security findings which helps in understanding the actual scope of an issue and identifying which team needs to take action.

I believe it saves us more time because we do not have to gather asset information from different sources and tools. We can search and filter inventory, group assets, and use asset context to move quickly from understanding what an asset is to identifying required security patches.

Qualys TotalCloud has positively impacted our organization by helping us save time and manage all assets and remediation, allowing us to achieve quarterly and half-yearly goals.

It has improved our visibility and made vulnerability management more structured, helping us reach our remediation goals while reducing manual effort from security reporting and patch management.

Before implementing Qualys TotalCloud, we used to have around ten thousand vulnerabilities on critical servers, and after using it, we reduced the vulnerabilities by thirty to forty percent in just two months.

We could identify vulnerabilities and their affected assets within five to ten minutes. This has also improved our investigation efficiency, allowing the team to spend more time on actual remediation rather than data collection.

What needs improvement?

Regarding improvements to Qualys TotalCloud, I suggest that user navigation can be enhanced because initially, many users found it complicated and had trouble understanding the platform due to information being spread across multiple tabs.

Making some dashboards and reports customizable would also help, as different teams have their own requirements.

I have covered most of the necessary improvements regarding navigation and customizable dashboards, which would help make work easier.

For how long have I used the solution?

I have been working as a SOC analyst for almost three years.

What other advice do I have?

Most recommendations and findings are accurate and reliable. While the AI output is helpful, it is crucial to validate actions against actual safety configurations, as human intelligence is still necessary in decision-making.

My advice for others considering using Qualys TotalCloud is that if you want all vulnerability management and cloud asset management in one place, then it is the best solution. Good configuration makes finding vulnerabilities and managing alerts much easier.

My overall rating for this product is nine out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Aug 17, 2026
Flag as inappropriate
PeerSpot user
HASHIM JUNAID - PeerSpot reviewer
Service Manager, Security Operations at CDA IT SOLUTIONS
Real User
Top 20
Nov 7, 2024
Enables you to address zero-day issues before a patch is released
Pros and Cons
  • "I appreciate TotalCloud's real-time protection and remediation features. The remediation options include automated one-click remedies and custom changes that help manage vulnerabilities efficiently."
  • "TotalCloud could improve the classification of vulnerabilities. Specifically, it could enhance the categorization of what aspects fall under patches resolved by OS or software updates and what pertains to configuration adjustments."

What is our primary use case?

All our cloud products are onboarded to Qualys TotalCloud, which scans for and provides information on vulnerabilities. We also get PCI-compliant images. TotalCloud helps with cloud security, including detecting and managing vulnerabilities, which is valuable for our remediations.

How has it helped my organization?

TotalCloud helps remedy zero-day vulnerabilities with its patchless remediation. Large enterprises face many zero-day threats, and TotalCloud can fix them before the patches are released to the public. TotalCloud provides a unified view of vulnerabilities in infrastructure as a service and software as a service. They've also integrated AI-based protection against data theft and leakage. Having this together on one dashboard is a significant advantage. We realized the benefits immediately. Our client is a Fortune 500 company, so we run scans daily and see the changes. 

What is most valuable?

I appreciate TotalCloud's real-time protection and remediation features. The remediation options include automated one-click remedies and custom changes that help manage vulnerabilities efficiently. 

The security scan helps with compliance and includes API-based integration. The TotalCloud agents are a great innovation in cloud security, and they'll soon implement the risk operation center, a cloud management portal that aids integration with many connectors to other solutions, such as ServiceNow. This will improve cloud management for large enterprises. 

TotalCloud's written explanations of attack paths for vulnerabilities are amazing. It's a huge advantage of the platform. TruRisk can address critical vulnerabilities regardless of whether there is a patch. 

You can automatically map vulnerabilities to patches or mitigation controls to apply agents or agentless mitigation for zero-day issues. TruRisk is built into the VMDR module, so we don't need to purchase a different product. The range of risks TruRisk covers is comprehensive. It has transformed our remediation strategy into a patchless one. You can use it for patch-based or patchless remediation, but patchless is more beneficial for larger enterprises. However, it's equally beneficial for startups and small businesses because it's so comprehensive. 

What needs improvement?

TotalCloud could improve the classification of vulnerabilities. Specifically, it could enhance the categorization of what aspects fall under patches resolved by OS or software updates and what pertains to configuration adjustments.

For how long have I used the solution?

I have been a Qualys customer for 10 years and used TotalCloud for about a year.

What do I think about the stability of the solution?

TotalCloud is very stable, with no lagging or crashing issues noted.

What do I think about the scalability of the solution?

TotalCloud is fully scalable and effectively supports our needs.

How are customer service and support?

I rate Qualys support nine out of 10. Qualys's tech support is highly responsive, providing multiple ways to interact with them. They arrange Webex sessions for real-time issue resolution and promptly respond to emails. The quality of customer service has improved significantly over the past eight years.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup was pretty easy. We have deployed across various regions, including the United States and Europe, in development and cloud environments. A six-person high-level implementation team handled it, so I can't say how long it took, but I know it was completed by the deadline. 

What about the implementation team?

We have an in-house six-member team for multiple proofs of concept and implementations. It does not require multiple people, but they also manage operations.

What's my experience with pricing, setup cost, and licensing?

The pricing for TotalCloud is attractive and competitive in the market. Given the features, especially the dashboard, I have no concerns regarding pricing.

What other advice do I have?

Users should manage their assets effectively to utilize TotalCloud efficiently, as asset management is crucial. 

The users, they should be prepared with their, you know, how with their assets. So they should manage their assets properly. With that, they can utilize the TotalCloud efficiently. Asset management is the key.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
reviewer2706300 - PeerSpot reviewer
Cyber Security Specialist at a financial services firm with 10,001+ employees
Real User
Top 5
May 24, 2025
A centralized tool for vulnerability and misconfiguration management in a multiple cloud environment
Pros and Cons
  • "The best features in Qualys TotalCloud include the total asset management of the cloud environment. It is very easy to export the report and see the vulnerabilities related to the cloud specifically."
  • "I would definitely recommend Qualys TotalCloud to other users."
  • "The onboarding process is a bit difficult. In the initial phase, it is very difficult to understand the features, what the dashboard contains, and what criteria they are using."

What is our primary use case?

We are managing AWS, Azure, as well as Google Cloud services in the cloud. We have different applications using those. We were previously checking the configurations manually. Qualys is helping us identify vulnerabilities related to the cloud. It identifies if something is misconfigured or if any AWS key or private key is exposed. We receive this information from Qualys TotalCloud.

How has it helped my organization?

Qualys TotalCloud provides written explanations to help guide the remediation paths and eliminate cyber risk. We are using TruRisk for the remediations. The TruRisk shows anything critical, and we can then focus on that. We also assess manually whether an asset is a critical target or not.

Qualys TotalCloud provides a single, prioritized view of risk. We are using CIS-CAT standards to harden our clouds, such as AWS, Google Cloud, and Azure. We are able to analyze the scans and identify which policies have failed and how we can remediate them. We can customize policies as per our organization's requirements. That is very helpful for us.

With the TruRisk Insights feature, security has significantly improved. In six months of using it, we see that everything is under control. We've solved many problems related to asset management, cloud configuration, and the new asset identification. If an application team has onboarded any cloud asset, we can see that. We have that information now. 

What is most valuable?

The best features in Qualys TotalCloud include the total asset management of the cloud environment. It is very easy to export the report and see the vulnerabilities related to the cloud specifically. We can segregate that particular report and give it to the appropriate team for remediation. Before, we were doing it manually. From the whole sheet, we had to find out the cloud vulnerabilities and check manually if it was a cloud vulnerability.

It is very helpful for us to generate reports related to the cloud vulnerabilities.

What needs improvement?

The onboarding process is a bit difficult. In the initial phase, it is very difficult to understand the features, what the dashboard contains, and what criteria they are using. This information is very difficult to understand as a newcomer to Qualys TotalCloud. Once we learn it, it becomes easy. It is hard for a complete newcomer. 

For how long have I used the solution?

I have been using Qualys TotalCloud for the last six months. There was one Qualys conference, and after that, we purchased it. Our management people were there, and they saw the usage of Qualys TotalCloud and how we could secure the cloud environment. They looked at how we can identify cloud vulnerabilities. That's why they decided to use this product.

What do I think about the stability of the solution?

Qualys TotalCloud is stable. We didn't experience any lag or slowness issues. They inform us beforehand that maintenance is scheduled, and there might be some slowness. Apart from that, there are no issues. I would rate it a ten out of ten for stability.

What do I think about the scalability of the solution?

For scalability, I would rate it a ten out of ten. It does not matter how many assets we have; it's very manageable. It's centralized.

Our environment consists of multiple clouds and multiple locations. We have only three members using Qualys TotalCloud. The team is narrow. After six months, more users will come since they're having different customizations available.

How are customer service and support?

The support from Qualys TotalCloud is a ten out of ten. The support team is very helpful in every aspect. If we get any issues, we can directly communicate with them. They have been helpful from day one. They have been solving issues efficiently.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Before using Qualys TotalCloud, we were using the cloud-native tools. For example, for AWS, we used the AWS console. We were doing the misconfiguration identification manually, checking everything manually. If any new policies or vulnerabilities came, we needed to check those manually. They provided some advice, and we relied on them, but we don't need to depend on them anymore. Qualys TotalCloud is identifying everything, and we take action based on that.

How was the initial setup?

The deployment was handled by a third-party vendor. They completed it within one week because they had expertise in that. Afterward, they did a knowledge transfer with us about how we can deploy and the process involved.

Qualys TotalCloud does not require any maintenance as it is based on the cloud.

What's my experience with pricing, setup cost, and licensing?

It isn't cheap, but it's reasonable. It helps us to manage things with very few resources. 

What other advice do I have?

Currently, AI access is restricted in our environment. We are testing the outcomes and possibilities. Within two months, we may start using GenAI.

I would definitely recommend Qualys TotalCloud to other users. If someone is looking for a centralized management tool while using different cloud platforms, Qualys TotalCloud is very helpful. It helps manage and identify vulnerabilities and misconfigurations. It helps with asset management. It helps understand how many AWS or Google Cloud instances are in the environments.

I would rate Qualys TotalCloud a ten out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Google
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Mahmoud Younes - PeerSpot reviewer
Cyber Security Architects at VaporVM
Real User
Top 5Leaderboard
Mar 19, 2026
Accurate vulnerability reports have improved patch management and strengthened security posture
Pros and Cons
  • "If I had to say something positive about the product that brings me the biggest benefit, I would say it has accurate reports, gets new update CVEs, zero-day attack detection, and is easy to manage with its GUI."
  • "The price is very expensive, actually."

What is our primary use case?

I am working with Qualys TotalCloud for vulnerability management, and the major use cases are patch management and scanning.

What is most valuable?

If I had to say something positive about the product that brings me the biggest benefit, I would say it has accurate reports, gets new update CVEs, zero-day attack detection, and is easy to manage with its GUI. Qualys TotalCloud does provide written explanations to help guide remediation paths and thus eliminate cyber risk. When it provides written explanations with guidance to remediate a path and eliminate cyber risk, it helps in general and helps a lot. The product does have a so-called TruRisk Insights feature, but I do not have experience with it. Qualys TotalCloud for vulnerability management provides unified vulnerability and threat assessment across both IaaS and SaaS, and I think overall it helps with security posture management. It is very good for patching vulnerabilities and getting zero-day attacks with accurate reports, not like Nessus. With Nessus, if you start to scan, it gives you many vulnerabilities, but it is not accurate and shows old vulnerabilities. If you compare it with Qualys TotalCloud, it is accurate and has updated CVEs. It saves a lot of time.

What needs improvement?

If Qualys could add some new features to Qualys TotalCloud in future releases, the results for the report and remediation should be more clear and very straightforward. Once we export the report, sometimes we do not get the correct path to patching the vulnerability.

For how long have I used the solution?

I have been working with the product for around two years, and in general, I have been in this domain with security products for around 12 or 13 years.

What do I think about the stability of the solution?

Qualys TotalCloud is stable.

What do I think about the scalability of the solution?

Regarding scalability, I would rate it seven out of ten. The reason I rate it seven points, not ten points, is that it is not that easy to manage. The problem when I manage it basically is that you need someone who has some experience to manage it, as it is not user-friendly.

How are customer service and support?

The technical support from Qualys is good, to be honest.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Apart from Tenable and Qualys, I did not work with any other competitors. I only worked with these two and OpenVAS, which is an open-source solution for vulnerability assessment.

How was the initial setup?

The installation of Qualys TotalCloud is very straightforward, and you can easily install the agent for Windows, Linux, and Mac.

What was our ROI?

I cannot provide information about seeing ROI with Qualys TotalCloud.

What's my experience with pricing, setup cost, and licensing?

The price is very expensive, actually.

Which other solutions did I evaluate?

If I compare Qualys TotalCloud with other vendors, I compare it with Nessus and Tenable. If I compare Qualys TotalCloud and Tenable, I would say Qualys TotalCloud is better in terms of functionality, and Tenable is better in terms of price.

What other advice do I have?

We are using Qualys TotalCloud Vulnerability Management and web applications, enterprise solutions, plus Nessus also. For vulnerability management, we installed an agent for each machine and servers and start scanning to get the vulnerabilities.

If I speak about some negative sides of Qualys TotalCloud, I think the negative side is the license. It accounts for approximately 30 percent of the concerns.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Mar 19, 2026
Flag as inappropriate
PeerSpot user
Buyer's Guide
Download our free Qualys TotalCloud Report and get advice and tips from experienced pros sharing their opinions.
Updated: September 2026
Buyer's Guide
Download our free Qualys TotalCloud Report and get advice and tips from experienced pros sharing their opinions.