We changed our name from IT Central Station: Here's why
Global Infrastructure Architect at a energy/utilities company with 5,001-10,000 employees
Real User
Top 20
Good technical support that is always there when you need them, but the prioritization of vulnerabilities needs to be improved
Pros and Cons
  • "Technical support is great and we've never really had a problem."
  • "We are moving away from Qualys to Defender ATP because I find that Defender ATP is much better at prioritizing the vulnerabilities that I should be looking at."

What is our primary use case?

We are currently using Qualys for vulnerability detection, as part of our security solution. We're moving towards Defender ATP because I am looking more at the Operational Technology (OT) side of things than I am at the Information Technology (IT) side.

What is most valuable?

What I like best about this product is that it does what it is supposed to do, which is vulnerability scanning.

What needs improvement?

We are moving away from Qualys to Defender ATP because I find that Defender ATP is much better at prioritizing the vulnerabilities that I should be looking at.

In general, I would like to see some better analytics and prioritization of vulnerabilities.

For how long have I used the solution?

We have been working with Qualys VM for three years.

What do I think about the stability of the solution?

Qualys VM is a stable solution.

What do I think about the scalability of the solution?

This is a stable product.

How are customer service and technical support?

Technical support is great and we've never really had a problem. They're always there if we need them.

Which solution did I use previously and why did I switch?

We did not work with another similar solution prior to Qualys.

How was the initial setup?

The initial setup is straightforward.

Our setup involved some on-premises deployments but ultimately, it uses the cloud.

What's my experience with pricing, setup cost, and licensing?

They have recently changed the pricing model, which is now better than it was before.

Which other solutions did I evaluate?

Right now, we don't have anything in our OT environment, and this is what I am particularly interested in. I am currently having discussions about new solutions with Qualys, Tenable, and Forescout.

What other advice do I have?

I would rate this solution a seven out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Omar ORta
Director Transformación Digital at oesia
Real User
Top 20
A feature-rich, complete product, and the multilingual technical support is good
Pros and Cons
  • "I like Qualys because it is a very complete product, more so than Tenable."

    What is our primary use case?

    We use this product for vulnerability management.

    What is most valuable?

    I like Qualys because it is a very complete product, more so than Tenable. It has vast capabilities.

    For how long have I used the solution?

    We have been working with Qualys VM for a very short time, perhaps six months.

    What do I think about the stability of the solution?

    This is a stable solution.

    What do I think about the scalability of the solution?

    Scalability-wise, this is a good product.

    How are customer service and technical support?

    The technical support is very good and they have it both in Spanish and English.

    Which solution did I use previously and why did I switch?

    We are also working with Tenable SC. Qualys is both more complete and for us, better in terms of pricing.

    How was the initial setup?

    For a beginning, the initial setup is complex. You have to have some knowledge for setting it up and using it.

    What's my experience with pricing, setup cost, and licensing?

    The price of Qualys for us is better than Tenable, although that is only because we are partners. The retail price of Qualys is higher than that of tenable. The pricing and licensing for Qualys could be improved.

    What other advice do I have?

    Overall, this is a good product and I recommend it, mainly because of the capabilities and the management using a single console. I can even create a calendar for activities from the main screen.

    I would rate this solution a nine out of ten.

    Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
    Learn what your peers think about Qualys VM. Get advice and tips from experienced pros sharing their opinions. Updated: January 2022.
    565,304 professionals have used our research since 2012.
    IT Consultant Supervisor at a financial services firm with 5,001-10,000 employees
    Consultant
    Top 20
    Scans our security posture and has very good scalability

    What is our primary use case?

    We use Qualys to check the status of our security posture.

    How has it helped my organization?

    Qualys help identifies the weakness in our critical infrastructure and provides guidelines how to address them.

    What is most valuable?

    maybe compliance monitoring.

    What needs improvement?

    Reporting can be improved more. It should generate much more stuff like field reports. Though the reports generally meet our need we hope we can customize it better.

    For how long have I used the solution?

    2 years

    What do I think about the stability of the solution?

    very satisfactory

    What do I think about the scalability of the solution?

    Its scalability is a four or five out of five. 

    How are customer service and technical support?

    We haven't had problems…

    What is our primary use case?

    We use Qualys to check the status of our security posture.

    How has it helped my organization?

    Qualys help identifies the weakness in our critical infrastructure and provides guidelines how to address them.

    What is most valuable?

    maybe compliance monitoring.

    What needs improvement?

    Reporting can be improved more. It should generate much more stuff like field reports. Though the reports generally meet our need we hope we can customize it better.

    For how long have I used the solution?

    2 years

    What do I think about the stability of the solution?

    very satisfactory

    What do I think about the scalability of the solution?

    Its scalability is a four or five out of five. 

    How are customer service and technical support?

    We haven't had problems up until this point that required technical support. The solution can run by itself and generate reports. We didn't have any issues that would need us to call technical support.

    Which solution did I use previously and why did I switch?

    None

    How was the initial setup?

    Simple and straightforward

    What about the implementation team?

    in-house.

    What was our ROI?

    acceptable.

    What's my experience with pricing, setup cost, and licensing?

    I would give the pricing three out of five.

    Which other solutions did I evaluate?

    No.

    What other advice do I have?

    I would like for Qualys to have the ability to scan OT operation technology assets as well. 

    If it can I would rate it 8 out of 10. 

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    Senior Cyber Security Specialist at a tech services company with 1,001-5,000 employees
    Real User
    Top 5Leaderboard
    The reporting and GUI need improvement but it's reliable
    Pros and Cons
    • "Qualys VM is very stable."
    • "The reporting and the GUI need improvements."

    What is our primary use case?

    It was responsible for vulnerability scanning. It enforces vulnerability management websites.

    What needs improvement?

    The reporting and the GUI need improvements. Tenable dominated in these two areas: reporting and graphical user interface.

    For how long have I used the solution?

    Qualys VM was used once for one of our customers.

    We were using the latest version.

    What do I think about the stability of the solution?

    Qualys VM is very stable.

    What do I think about the scalability of the solution?

    I didn't have all of the necessary information regarding the scalability or how to scale this solution, but all vulnerability management solutions have the same idea. 

    I believe that it is easy to scale.

    How are customer service and support?

    I did not contact technical support.

    Which solution did I use previously and why did I switch?

    I have also used Rapid7, which is very similar to Qualys VM.

    Scaling is more difficult with Rapid7. When it comes to scaling, Rapid7 is not my first choice.

    How was the initial setup?

    I did not implement this solution, I performed one scan for our client.

    What other advice do I have?

    We have regulations in place in Saudi Arabia and Egypt that require all vulnerability management solutions to be implemented on-premise.

    I would recommend this solution to others but Tenable is my preferred option.

    I would rate Qualys VM a five out of ten.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    Flag as inappropriate
    Consultant at a tech services company with 11-50 employees
    Reseller
    Provides excellent security for scanning, flexible with good integration

    What is our primary use case?

    We are consultants and resellers of Qualys VM. 

    What is most valuable?

    I like the solution's web application security for scanning, the solution is flexible with good integration. 

    What needs improvement?

    I'd like to see additional security for the app. The product lacks integrations for third party solutions or automation integration for other tools.

    For how long have I used the solution?

    I've been using this solution for six months. 

    What do I think about the stability of the solution?

    The product is 100% stable. There are five users in the company who deal with operations and security analysis. There are four people in the company who deploy and provide support.

    How are customer service and technical support?

    I've never used the…

    What is our primary use case?

    We are consultants and resellers of Qualys VM. 

    What is most valuable?

    I like the solution's web application security for scanning, the solution is flexible with good integration. 

    What needs improvement?

    I'd like to see additional security for the app. The product lacks integrations for third party solutions or automation integration for other tools.

    For how long have I used the solution?

    I've been using this solution for six months. 

    What do I think about the stability of the solution?

    The product is 100% stable. There are five users in the company who deal with operations and security analysis. There are four people in the company who deploy and provide support.

    How are customer service and technical support?

    I've never used the technical support. Documentation is simple and complete. 

    Which solution did I use previously and why did I switch?

    I've previously worked with Tenable IO and Rapid 7. We switched because of Qualys's web application feature.

    How was the initial setup?

    The initial setup is straightforward. Initial deployment takes between two and four hours. We did it ourselves. 

    What other advice do I have?

    I would recommend this solution. 

    I would rate this solution a 10 out of 10. 

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Microsoft Azure
    Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
    Senior Vice President | Information Security at a financial services firm with 1,001-5,000 employees
    Real User
    Very intuitive, easy going and simple to use

    What is our primary use case?

    I used this solution for one of my clients and the primary use case was for the compliance mode and scanning. We are customers of Qualys and I am senior vice president information security.

    What is most valuable?

    I found the solution quite intuitive and easy going. I have worked with other similar tools and found this simple to use. 

    What needs improvement?

    I felt hindered sometimes within reports in that they were lacking somewhat on the customization side in terms of making use of the data. The cloud user interface could be a little more responsive. It was a click and then a wait. 

    For how long have I used the solution?

    I used this solution recently for about five months. 

    What do I think about the stability of the solution?

    There were a…

    What is our primary use case?

    I used this solution for one of my clients and the primary use case was for the compliance mode and scanning. We are customers of Qualys and I am senior vice president information security.

    What is most valuable?

    I found the solution quite intuitive and easy going. I have worked with other similar tools and found this simple to use. 

    What needs improvement?

    I felt hindered sometimes within reports in that they were lacking somewhat on the customization side in terms of making use of the data. The cloud user interface could be a little more responsive. It was a click and then a wait. 

    For how long have I used the solution?

    I used this solution recently for about five months. 

    What do I think about the stability of the solution?

    There were a couple of small bugs but the solution was stable. 

    What other advice do I have?

    I would recommend this solution and rate it a nine out of 10. 

    Which deployment model are you using for this solution?

    Private Cloud
    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    Flag as inappropriate
    Consultant at a media company with 51-200 employees
    Consultant
    Enables us to check the validity of legacy applications, infrastructure, and simple data operating systems

    What is our primary use case?

    I use Qualys to review the validity of legacy applications, infrastructure, and simple data operating systems.

    What needs improvement?

    The ability to manage user accounts and give rights to the operator to know about abnormalities of applications is something that needs improvement.  The pricing is also expensive.

    For how long have I used the solution?

    I have been using Qualys for four years. 

    What do I think about the stability of the solution?

    It's stable.

    How are customer service and technical support?

    I haven't needed to use technical support. 

    How was the initial setup?

    The initial setup was good. We didn't have any problems with it. 

    What other advice do I have?

    I would rate Qualys VM a ten out of ten. 

    What is our primary use case?

    I use Qualys to review the validity of legacy applications, infrastructure, and simple data operating systems.

    What needs improvement?

    The ability to manage user accounts and give rights to the operator to know about abnormalities of applications is something that needs improvement. 

    The pricing is also expensive.

    For how long have I used the solution?

    I have been using Qualys for four years. 

    What do I think about the stability of the solution?

    It's stable.

    How are customer service and technical support?

    I haven't needed to use technical support. 

    How was the initial setup?

    The initial setup was good. We didn't have any problems with it. 

    What other advice do I have?

    I would rate Qualys VM a ten out of ten. 

    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    Product Categories
    Vulnerability Management
    Buyer's Guide
    Download our free Qualys VM Report and get advice and tips from experienced pros sharing their opinions.