Minh-Do - PeerSpot reviewer
Product Manager (Journey Expert) - ANZ Deposits at Anz
Real User
Top 10
Great automatic detection but slow performance
Pros and Cons
  • "Qualys VM's most valuable feature is automatic detection."
  • "Qualys VM should improve its methodology."

What is our primary use case?

I primarily use Qualys VM to manage vulnerability tickets.

What is most valuable?

Qualys VM's most valuable feature is automatic detection.

What needs improvement?

Qualys VM should improve its methodology.

For how long have I used the solution?

I've been working with Qualys VM for six months.

Buyer's Guide
Qualys VMDR
April 2024
Learn what your peers think about Qualys VMDR. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
768,578 professionals have used our research since 2012.

What do I think about the stability of the solution?

Qualys VM is stable but slow.

How are customer service and support?

Qualys' technical support is quite good.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup was quite straightforward.

What other advice do I have?

I would rate Qualys VM as seven out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
AVP - Information Security at a financial services firm with 10,001+ employees
Real User
Easy to use and scalable but needs to be priced more competitively
Pros and Cons
  • "It is very easy to use and there are lots of options. We can usually easily go through it and all of the things we want to configure, and we can configure everything to our specifications very easily."
  • "Sometimes we face a problem with accessing the tool and not getting an expected result. From a technology point of view, they need to look into this."

What is our primary use case?

We're primarily using the solution for vulnerability assessment of internal server as well as the external server.

What is most valuable?

The solution, overall, is very useful for our organization.

It is very easy to use and there are lots of options. We can usually easily go through it and all of the things we want to configure, and we can configure everything to our specifications very easily.

What needs improvement?

Sometimes we face a problem with accessing the tool and not getting an expected result. From a technology point of view, they need to look into this. 

They need to consider how they can improve tool usability and different scanning options. 

Sometimes we are facing issues while performing a scan and things are not correctly shown on the GUI. Even as we are doing a task, it may show up as completed, and then something is not visible. Sometimes we face other technical problems. For example, sometimes we can't go to the next page. It's limiting any positive results.

The solution needs to be easier to understand and configure.

The pricing is a bit on the higher side compared to other products in the industry.

For how long have I used the solution?

I've been dealing with the solution for the last five or six years now. It's been a while.

What do I think about the stability of the solution?

I haven't had any issues with stability. It's been okay.

What do I think about the scalability of the solution?

I don't see any issues with scalability. When we do multiple IP scans, when we require an increase in the number of IPs, we won't have any problem doing so.

How are customer service and technical support?

The technical support has been fine. We're getting the required support we need when we need it. I'd say we're pretty satisfied in that regard.

What's my experience with pricing, setup cost, and licensing?

I find the pricing to be a bit high, especially compared to the competition.

Which other solutions did I evaluate?

While we didn't evaluate other options previously, currently, we are looking at all sorts of vulnerability management solutions and that's including Kenna and RiskSense. 

Although Qualys has come up with the model, I've not really looked that far into their other offerings. There is the possibility of upgrading the model on the part of vulnerability management. We'll see if we change solutions or decide to upgrade instead.

We've also looked at Tenable, which is easier to understand and configure.

What other advice do I have?

We are a Qualys customer. We aren't a reseller or partner.

Overall I'd rate the solution seven out of ten.

We are currently looking at other options, to see if there's a better solution out there. This one has pretty good technical support and is easy to use, however, there are other issues associated with it.

Which deployment model are you using for this solution?

Private Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Qualys VMDR
April 2024
Learn what your peers think about Qualys VMDR. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
768,578 professionals have used our research since 2012.
PranjalGargava - PeerSpot reviewer
Cyber Security Engineer at a transportation company with 5,001-10,000 employees
Real User
Top 10
Helps with vulnerability scanning and understanding of cyber security controls
Pros and Cons
  • "I am impressed with the VMDR feature."
  • "The tool needs to improve the adding assets and report generation features. I would like to see the policy scan of offline appliances in the product's future releases."

What is our primary use case?

We use the solution for vulnerability and policy scan. 

How has it helped my organization?

The product has helped us understand cybersecurity controls. 

What is most valuable?

I am impressed with the VMDR feature. 

What needs improvement?

The tool needs to improve the adding assets and report generation features. I would like to see the policy scan of offline appliances in the product's future releases. 

For how long have I used the solution?

I have been using the product for three years. 

What do I think about the stability of the solution?

I would rate the product's stability a nine out of ten. 

What do I think about the scalability of the solution?

I would rate the tool's scalability an eight out of ten. My company has 10 IT specialists using the product. 

How are customer service and support?

The product's support is not very helpful. They suggest things that we already know. 

How would you rate customer service and support?

Neutral

How was the initial setup?

I would rate the product's setup an eight out of ten. The tool's deployment took one to two days to complete. 

What about the implementation team?

We deployed the solution in-house. 

What's my experience with pricing, setup cost, and licensing?

The tool's pricing is expensive and I would rate the pricing a seven out of ten. 

What other advice do I have?

I would rate the product an eight out of ten. You need to complete the training before using the product. 

Which deployment model are you using for this solution?

Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Sr Security Engineer at Jardine Matheson Limited
Real User
Top 20
Reliable solution with good vulnerability management
Pros and Cons
  • "Qualys VM's best features are vulnerability management and customizable scoring."
  • "Qualys VM's vulnerability scan could be improved, especially the number of CVE numbers it can manage at a time."

What is our primary use case?

I use Qualys VM for vulnerability scanning, enterprise management, web application scanning, and patch deployment.

What is most valuable?

Qualys VM's best features are vulnerability management and customizable scoring.

What needs improvement?

Qualys VM's vulnerability scan could be improved, especially the number of CVE numbers it can manage at a time. It could also be more user-friendly. In the next release, Qualys VM should include threat intelligence and external test service management.

For how long have I used the solution?

I've been using Qualys VM for around six months.

What do I think about the stability of the solution?

Qualys VM is stable and reliable.

What do I think about the scalability of the solution?

Qualys VM is quite easy to scale.

How are customer service and support?

Qualys' customer service could be better.

How would you rate customer service and support?

Neutral

How was the initial setup?

The initial setup was not user-friendly.

Which other solutions did I evaluate?

I evaluated Tenable but chose Qualys VM because of its management features.

What other advice do I have?

I would rate Qualys VM eight out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Senior Security Consultant at a tech services company with 10,001+ employees
Consultant
Excellent continuous monitoring, helpful technical support, easy to scale, and simple to install
Pros and Cons
  • "The most recent is VMDR, which provides a comprehensive overview of how to detect, patch, and remediate specific vulnerabilities."
  • "Qualys currently does not have any features for scanning SCADA, IoT, and Industrial Control Systems."

What is our primary use case?

Qualys' main function is to scan IT systems. It does the scanning of computer systems.

What is most valuable?

Continuous Monitoring is excellent because it is entirely dependent on the agent, and the Agent Scan, is also quite good. 

I also like the asset tagging, asset grouping features, and the dashboard, because we can customize and create our own dashboard. That's quite good. 

The most recent is VMDR, which provides a comprehensive overview of how to detect, patch, and remediate specific vulnerabilities. That is also an excellent module.

What needs improvement?

The dashboard itself could be improved, while we can customize it, they can create different tabs where we can see the trending vulnerabilities, how many there are, or how many have been fixed, as in the most recent scan report, so that trend analysis is a little easier.

Aside from that, the solution itself is fairly generic in nature. What they can do is pretty much customize everything and provide a relevant solution for everything. For example, because Qualys has a Cloud Agent that scans a system's entire inventory. As a result, they can test their use cases to determine whether or not a vulnerability has been confirmed. If they can do so, they can also provide us with a straightforward solution to a specific problem rather than a generic one. That could be one area where they can improve. 

Qualys does not currently have an IoT, SCADA vulnerability assessment, they can significantly improve their IoT, SCADA, and ICS (Industrial Control Systems) vulnerability assessment technique. When you compare with Tenable SC it has more features than Qualys VM.

If you see power grids, large oil stations, they fall under SCADA and Industrial Control Systems. These systems are very different from standard IT systems. Qualys currently does not have any features for scanning SCADA, IoT, and Industrial Control Systems.

I believe they can improve on the addition of devices. Assume I have two lakhs of devices that cannot all be added at the same time. For example, if I have two lakhs of devices, and two lakhs of those devices have a Cloud Agent, adding all of those devices at once is not easy. We have to add it 1,000 at a time, which takes a long time when there are two lakhs of assets to add. If we do 1,000 at a time, we'll have to do it for around two lakhs, which is quite difficult.

They can increase their frequency of working faster, similar to the time constraint they currently have. The second thing they can improve is the addition of assets. They can almost completely automate the process of adding assets, or they can increase the maximum number of assets that can be added in one go. They are only allowed to add 1,000 assets. If I want to add two lakh assets, it will be extremely difficult to do so by adding 1,000, at a time.

That is a fairly technical issue. Most of the false positives reported by Qualys or the inability to detect a cumulative patch update, if any, are the few things that they can improve and incorporate. 

As I previously stated, it would be extremely beneficial if they could implement scanning, vulnerability scanning of IoT systems, Industrial Control Systems, and SCADA devices.

For how long have I used the solution?

I have been working with Qualys VM for approximately four years.

We have been using multiple Qualys modules, such as VMDR, Cloud Agent, AssetView, and Continuous Monitoring. The most recent version that we are using is 4.14.

What do I think about the stability of the solution?

It's reasonably steady. When we say stable version, there is also room for improvement in that Qualys will not be able to handle large amounts of data at once. When you do billions of scans, such as a scan for millions of devices, it becomes extremely slow, and gathering data and populating the report becomes extremely tedious. 

What do I think about the scalability of the solution?

Scalability is quite good. We can pretty much rely on the tool. It is easy to scale. 

If the organization grows, we can pretty much scale it to most of the areas. The only problem is that they must primarily work on Industrial Control Systems and lightweight devices such as CCTV cameras, and lightweight devices. As a result, they are required to work in that field, otherwise, it is pretty good.

Based on my previous experience, there were approximately 300 or more users using Qualys in organizations with a population of more than two lakh people. Currently, I see that approximately 400 users are using it, and the size of the organization is significantly larger than the previous one.

We use this solution daily.

How are customer service and support?

Technicals support is pretty good. Since I've been working in this, they've been friendly and straightforward, and we were able to get the most out of them.

We have suggested areas for improvement, and they have been working on them. They always make a good impression on us.

Which solution did I use previously and why did I switch?

As a consultant, I've worked on a variety of projects in a variety of organizations.

How was the initial setup?

The initial setup is simple and straightforward.

What about the implementation team?

We initially had assistance from the vendor, but once we had a good understanding of it, we scaled it in our organization.

Which other solutions did I evaluate?

Because I've been using Qualys for quite some time, I was looking for a comparison of several solutions such as Tenable SC, Rapid7, InsightVM, and Tenable Nessus. I was curious to know if there were any other tools that were better than Qualys.

I was looking for more information about Tenable SC and wanted to compare it to Qualys in more detail, with parameters such as, how the false positives are detected in Tenable SC and how good it is in comparison to Qualys. In a similar manner, in comparison to Qualys, we learn about its usability, interface, and how user-friendly it is. Those are the few things I was looking for, and I'm still looking for more information about Tenable right now.

What other advice do I have?

They have the ability to improve SCADA. SCADA stands for Supervisory Control and Data Acquisition, and IoT stands for Internet of Things scanning.

Recommending this solution would depend on the organization, the requirements, and the devices they have.

For a typical IT system, it is very good to go with this solution. Microsoft, Deloitte, and the majority of organizations still use it, it is pretty much good to go. But, once again, it is entirely dependent on how the organization is, what type of devices they have, and what kind of scans they would like to have, it is entirely dependent.

In a broad sense, it is a good solution to go with.

I would rate Qualys VM an eight out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Microsoft Azure
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Lead Cyber Security engineer at a manufacturing company with 10,001+ employees
Real User
Provides an overview of the inventory assessment process and can be accessed across the company
Pros and Cons
  • "It gives a very good overview of the inventory assessment process, and it can be accessed across our company because it's a global tool."
  • "It's not very user-friendly at times and requires in-depth understanding. So, a layman or someone new to Qualys won't be able to easily understand it. You need education to use the solution."

What is our primary use case?

We use Qualys Asset Inventory for doing infrastructure level scans or server inventory, or saving the server database or asset database.

How has it helped my organization?

Good Posture of Servers database. Gives easy access of all hardware details. 

What is most valuable?

I think it's a good tracking mechanism, and it gives a good infrastructure level scan, which helps us to maintain the assets and the asset inventory or gives us a good understanding of both. 

It gives a very good overview of the inventory assessment process.

IT Manages assets in your account that you want to scan for security and
compliance, define asset tags and AWS connectors.

Modules supported
VM, PC, SCA, CERTVIEW, CLOUDVIEW

It can be accessed across our company because it's a global tool.

What needs improvement?

One thing that can be improved is the flexibility and the fact that Qualys Asset Inventory provides too much detail, which makes it not very easy to understand. It's not very user-friendly at times and requires in-depth understanding. So, a layman or someone new to Qualys won't be able to easily understand it. You need education to use the solution.

As for additional features, the first thing would be providing call support whenever we require any kind of help with issues that have been identified. The second would be a simple reporting structure.

For how long have I used the solution?

I've been using Qualys Asset Inventory within the last 12 months.

What do I think about the stability of the solution?

Stability-wise, Qualys Asset Inventory is always stable, and for this particular asset inventory, it is a good tool. We have not had any kind of issues, and as of now, it's a stable environment.

What do I think about the scalability of the solution?

We currently have 50 plus users and have no plans to increase usage at present. 

How are customer service and technical support?

Most of the time technical support has been through emails; calling is a back feature. It's not as easy compared to that of Veracode.

How was the initial setup?

The initial setup was quite complex and took two to three months, including customization and testing.

What's my experience with pricing, setup cost, and licensing?

The license is on a yearly basis.

What other advice do I have?

If you are familiar with or have hands on experience with Qualys Asset Inventory, this is a better tool. It will give you in-depth details of all the assets, and the managing inventory will be better. It will also give you advanced features compared to those of other inventory tools.

I would rate Qualys Asset Inventory at eight on a scale from one to ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Jan Vobruba - PeerSpot reviewer
Infrastructure Security Consultant at ANECT
Real User
Top 5
Easy to use, well supported with continually improving functionality
Pros and Cons
  • "Provides great functionality."
  • "Finding things in management can be quite difficult."

What is our primary use case?

Our customers use Qualys for vulnerability management, it's a way for them to discover the kinds of vulnerabilities they have on their systems. We are a partner with Qualys and I'm an infrastructure security consultant. We currently have 20 clients using Qualys. 

How has it helped my organization?

The functionality continues to improve and knowing when there are security issues is very helpful. 

What is most valuable?

I like the Qualys Cloud Agent because it's very easy to use. It has a low impact and is supported on Windows, Linux, and others. I deploy process scanners, which are usually connected to core switches so customers can replicate all the connections. Almost all our customers try to use the agents because they're already installed and integrated into the cloud and communicate with Qualys management. There are no problems and it's really better than using some virtual appliance to scan the various kinds of assets. Qualys has a lot of information and it's great to integrate with the Central Management Database.

What needs improvement?

If you're not overly experienced and you're looking for something in their management, it can sometimes be quite difficult because they can move buttons around without sending an update. Previously, if you deployed the Cloud Agent, you could define which tech would be under the agent and where it would be deployed. It now requires some text preparation and the Cloud Agent then downloads the specific profile defined without any indication that this might happen. If you are not using vulnerability management, you are not able to create the correct patch process for all applications stored on the system.

It would be helpful if Qualys would integrate with more systems like ServiceNow, Jira, and so on, to create some tickets and integrate them into the active directory, because each group works differently and if you need to prepare a ticket, it must be defined to a specific group of people. Qualys just created a kit on ServiceNow, but it doesn't have the correct group of people in the active directory.

For how long have I used the solution?

I've been using this solution for three years. 

What do I think about the scalability of the solution?

The solution is scalable. If you need more resources they can be added to the backend, depending on the circumstances and requirements. If you are able to deploy in the VMDR licensing, you are able to deploy unlimited virtual active appliances to discounted appliances. It all depends on your resources. 

How was the initial setup?

Each customer is different and if you need to deploy a more active virtual process that will affect the implementation. If a customer wants to use policy compliance on their machines that can add to deployment time too. I tend to deploy myself because I'm usually making the POCs of Qualys.

What's my experience with pricing, setup cost, and licensing?

I believe the annual cost is approximately $40 per asset in VMDR, although it also depends on the circumstances. It contains all the features one needs although if you need synchronization with ServiceNow and CMDB, there is an additional cost. 

Which other solutions did I evaluate?

I constantly speak to other companies to find out what they're doing and what the differences are between the different products. My job is to find the best solution for my customers so it's important to know what's on the market.

What other advice do I have?

I rate this solution eight out of 10. 

Disclosure: My company has a business relationship with this vendor other than being a customer: partner
PeerSpot user
IRM Technical Consultant at Shell
Real User
Vulnerability scanner with good dashboard presentation and clear reporting
Pros and Cons
  • "What I like about Qualys VM is the dashboard presentation. It's very good."
  • "The customer support is very bad."

What is our primary use case?

The primary use cases of this solution are as a scanner. We use it with Azure and AWS. For on-premises, we use physical scanners all over the globe. We have deployed our external scanners in approximately 70 regions.

What is most valuable?

What I like about Qualys VM is the dashboard presentation. It's very good.

The reporting capability and executive reporting are very good.

What needs improvement?

Customer support needs to be improved because it was not to our SLA standards.

Suddenly, the scan engine will go down. We don't know what the reason is, or how it goes down. Because of that, the business is impacted.

I had a look at the PCI reports  (policy compliance reports) and I have heard that most memberships have been taken by Azure, although I was not aware of that. I would like to see more documentation or awareness.

For how long have I used the solution?

I have worked with Qualys VM for the last two years.

What do I think about the stability of the solution?

This solution is stable.

What do I think about the scalability of the solution?

The scalability is good.

How are customer service and technical support?

The customer support is very bad. When we submit a ticket, we do not get a response immediately.

Which solution did I use previously and why did I switch?

Previously, I have used Rapid 7 Nexpose. They are similar solutions although what Qualys is providing, it provides well but requires less. Qualys reporting is better.

Nexpose has upgraded too, and now their reporting is also very good.

How was the initial setup?

The initial setup was straightforward and we didn't have any issues with it.

What other advice do I have?

If you are comparing Nexpose and Qualys, I would prefer Qualys. The UI is good and whatever reports you are getting, are very clear. If you present it to management, the reports are good. They require an executive report that highlights the vulnerability and how many servers are affected. You can customize it also.

Nexpose is coming out with new features, but Qualys has already implemented them.

I would rate this solution an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Buyer's Guide
Download our free Qualys VMDR Report and get advice and tips from experienced pros sharing their opinions.
Updated: April 2024
Buyer's Guide
Download our free Qualys VMDR Report and get advice and tips from experienced pros sharing their opinions.