What is our primary use case?
We use Qualys TotalCloud for compliance monitoring and compliance checking.
How has it helped my organization?
TotalCloud provides written explanations to help guide remediation paths and eliminate cyber risk. It is very satisfactory.
I could see its benefits immediately after the deployment. I was using another product, and I was trying to switch over to this product.
TruRisk Insights provides a good view of the situation from different perspectives, such as the policy compliance side, the vulnerability side, and a few others. It gives us a better view of what is going on versus just piecemeal from one UI to another and then trying to make sense and sorting things or combining data together.
TruRisk Insights feature found a small number of assets with high vulnerability scores. I reported them to the owner, and then they are going to work on it.
TruRisk Insights are a good indicator, but long term, the managers still want to use the ServiceNow integration. We have this in our back pocket to verify.
What is most valuable?
The most valuable feature is the extensibility. I can create custom controls and rely on Qualys TotalCloud to provide me with updated controls as they come from CS benchmarks.
What needs improvement?
I have already put in a few feature requests. There are features that I would like to have. I would like the ability to disable certain default built-in policies as they can be misleading when creating dashboards. That is the top one.
Additionally, I would like the ability to generate reports on a schedule and send them via email to the scheduler.
It is a bit cumbersome to apply some of the features built into policy compliance.
TotalCloud provides a single, prioritized view of risk, but it can be better. I was hoping that they would integrate TruRisk into it, but that is forthcoming. I have already put in the request a while back to add TruRisk, and they are working on it.
For how long have I used the solution?
I have been using the solution for around two years.
What do I think about the stability of the solution?
I have not seen any events like lagging, crashing, or downtime.
What do I think about the scalability of the solution?
It is very scalable, and I would rate it a ten out of ten for scalability.
How are customer service and support?
I usually do not have to contact support. I last contacted them a month or two months ago. They usually respond within 48 hours. I can always escalate as needed. It is not an issue. Overall, their support is top-notch.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
I used Dome9 which is under Check Point. I switched to TotalCloud because of better extensibility.
How was the initial setup?
We had some challenges with permissions, but other than that, it was fine. Its implementation took about 60 days.
It requires maintenance on our end. We need to maintain the permissions and the connections to whatever AWS accounts we need to have scanned.
What about the implementation team?
We had an in-house team involved along with Qualys support. Three people were required for the deployment.
What's my experience with pricing, setup cost, and licensing?
The pricing is comparable. It is built into our other product, so I cannot piecemeal it. It is a part of our subscription.
What other advice do I have?
New users should have a deeper understanding of how to use the cloud API because the extensibility is based on that. If they do not understand how to use the API, it would not be effective for them.
TotalCloud provides unified vulnerability and threat assessment across both IaaS and SaaS, but we do not use that. We do not have a use case for that.
I would rate TotalCloud an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.