IRM Technical Consultant at Shell
Real User
Vulnerability scanner with good dashboard presentation and clear reporting
Pros and Cons
  • "What I like about Qualys VM is the dashboard presentation. It's very good."
  • "The customer support is very bad."

What is our primary use case?

The primary use cases of this solution are as a scanner. We use it with Azure and AWS. For on-premises, we use physical scanners all over the globe. We have deployed our external scanners in approximately 70 regions.

What is most valuable?

What I like about Qualys VM is the dashboard presentation. It's very good.

The reporting capability and executive reporting are very good.

What needs improvement?

Customer support needs to be improved because it was not to our SLA standards.

Suddenly, the scan engine will go down. We don't know what the reason is, or how it goes down. Because of that, the business is impacted.

I had a look at the PCI reports  (policy compliance reports) and I have heard that most memberships have been taken by Azure, although I was not aware of that. I would like to see more documentation or awareness.

For how long have I used the solution?

I have worked with Qualys VM for the last two years.

Buyer's Guide
Qualys VMDR
April 2024
Learn what your peers think about Qualys VMDR. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
769,334 professionals have used our research since 2012.

What do I think about the stability of the solution?

This solution is stable.

What do I think about the scalability of the solution?

The scalability is good.

How are customer service and support?

The customer support is very bad. When we submit a ticket, we do not get a response immediately.

Which solution did I use previously and why did I switch?

Previously, I have used Rapid 7 Nexpose. They are similar solutions although what Qualys is providing, it provides well but requires less. Qualys reporting is better.

Nexpose has upgraded too, and now their reporting is also very good.

How was the initial setup?

The initial setup was straightforward and we didn't have any issues with it.

What other advice do I have?

If you are comparing Nexpose and Qualys, I would prefer Qualys. The UI is good and whatever reports you are getting, are very clear. If you present it to management, the reports are good. They require an executive report that highlights the vulnerability and how many servers are affected. You can customize it also.

Nexpose is coming out with new features, but Qualys has already implemented them.

I would rate this solution an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Senior Vulnerability Analyst at a comms service provider with 10,001+ employees
Real User
It has a quicker response time to incidents. And it has a stable performance record.
Pros and Cons
  • "I find the most valuable features are the continuous monitoring. Even on premises, there is constant monitoring."
  • "They have integrated with other third parties, but it is still not viable."
  • "When tested on Zero day, there were errors."

What is our primary use case?

It improves the continuous monitoring of the systems on-premises.

How has it helped my organization?

If any anomalies are there, we can easily detect with our agent based solutions, and we can isolate them quickly, and response time or any incident is much quicker than previous. Before we were taking eight hours, now we're taking around 30 minutes to respond to any incident, security and such.

What is most valuable?

I find the most valuable features are the continuous monitoring.  Even on premises, there is constant monitoring.

What needs improvement?

When tested on Zero day, there were errors.

In addition, they have integrated with other third parties, but it is still not viable. They are using their own Q id's. This sometimes leads to a false positive. And, even the updating of signatures into Qualys is not that much quicker. Maybe for Windows and Linux, it is a little quicker or networks and other devices. The signature updating is not quicker.

What do I think about the stability of the solution?

I have not experienced issues with stability of the solution. There were a few bugs, but we reported it.

What do I think about the scalability of the solution?

I did not have any issues of scalability.

How are customer service and technical support?

The tech support acted quickly and responded quickly to our tickets. There was a good response time.

Which solution did I use previously and why did I switch?

I also have previous experience with Tennable Nessus, and I find Qualys is better than Nessus, which is slow in the security center and lags a bit.

What's my experience with pricing, setup cost, and licensing?

It's good. Yes, it's competitive. We got the best price.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Qualys VMDR
April 2024
Learn what your peers think about Qualys VMDR. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
769,334 professionals have used our research since 2012.
Tim Cranny - PeerSpot reviewer
Principal at Cranny Group
Real User
Top 10
Good return on investment, ease of deployment, and metrics
Pros and Cons
  • "The Vulnerability Management and Patch Management features are the most valuable features of this solution."
  • "Endpoint stability and fault resolution could be improved."

What is our primary use case?

It is a SaaS solution with agents distributed at endpoints.

How has it helped my organization?

Qualys VM has improved the way the organization functions.

What is most valuable?

The Vulnerability Management and Patch Management features are the most valuable features of this solution.

The most valuable qualities of Qualys VM are its ease of deployment and metrics.

What needs improvement?

Endpoint stability and fault resolution could be improved.

I would like to see the solution's footprint expanded to include iOS and iPads in the next release.

One example of how it could be better would be better handling of end-of-life systems and better feedback on job failures.

For how long have I used the solution?

We have been working with Qualys VM for just over two years.

It is a cloud platform. I'm not sure if a version is associated with that. 

What do I think about the stability of the solution?

The stability of Qualys VM is quite good, but not fantastic. I would rate it an eight out of ten.

What do I think about the scalability of the solution?

The scalability of Qualys VM is very good.

This solution is used by five security or system administrators in our organization.

We have no plans to expand our usage; it is already widely deployed.

How are customer service and support?

The technical support is mediocre at best.

I would rate them a two out of five.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

We were previously using Lansweeper, which was not scalable.

How was the initial setup?

I would rate the initial setup a three out of five.

It took several weeks to deploy.

What about the implementation team?

We completed the deployment in-house.

What was our ROI?

We have seen a return on investment.

What's my experience with pricing, setup cost, and licensing?

There are no additional fees in addition to the standard licensing fees.

What other advice do I have?

I would recommend identifying the right metrics to drive the program.

I would rate Qualys VM an eight out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Sr. Manager, Vulnerability Management at a transportation company with 10,001+ employees
Real User
User-friendly, supports multiple platforms, and the VM DR capabilities are helpful
Pros and Cons
  • "The features that are most valuable are the identification, scan features, and the identification of vulnerabilities."
  • "I would like to see more accuracy in detections, better reporting capabilities, and better dashboard download capabilities."

What is our primary use case?

We are using Qualys VM, as our scanner tool. We also use it for Application Security and Policy Compliance.

We use it for the identification of vulnerabilities for all of our devices on the network. This includes Windows workstations, servers, and Linux machines. We also use it for cloud, and external use as well.

What is most valuable?

The features that are most valuable are the identification, scan features, and the identification of vulnerabilities. Recently, the VMDR additions and the threat protection has been useful.

It's pretty user-friendly.

What needs improvement?

The Patch Identifications, which are supersedence identifications, need improvement.

I would like to see more accuracy in detections, better reporting capabilities, and better dashboard download capabilities. These are things that are definitely needed.

For how long have I used the solution?

I have been using Qualys VM for more than 15 years.

We are using the latest version.

VMDR was added in July with newer enhancements.

What do I think about the stability of the solution?

It's a stable solution.

What do I think about the scalability of the solution?

It's very scalable for large networks. We have also used the agents and they work very well.

I have a team of five in our organization and external to it, there are approximately twenty-five.

How are customer service and technical support?

We engage with technical support often. There could be some improvements made.

How was the initial setup?

The initial setup is straightforward.

What's my experience with pricing, setup cost, and licensing?

It is different for every company, but for us, it's every three years. I will know more about the pricing in September because we are going to be looking at our pricing again.

We get a large volume discount, which is good.

What other advice do I have?

I would recommend this product to others who are interested in using it.

I would rate this solution an eight out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Security Specialist at a financial services firm with 1,001-5,000 employees
Real User
Top 10
Robust, good agent support, and simple to setup
Pros and Cons
  • "It's really beneficial for scanning and interacting with the agent."
  • "The disadvantage of working with Qualys is that the graphical interface is quite outdated."

What is our primary use case?

Qualys VM is used for vulnerability scanning.

What is most valuable?

It's really beneficial for scanning and interacting with the agent. 

What needs improvement?

The disadvantage of working with Qualys is that the graphical interface is quite outdated.

If you want to choose a scan result, or maybe configure an IP range or something similar, it opens up a lot of processes, or steps, which is somewhat bothersome. Because it opens several phases, it is not a single-window program. 

For how long have I used the solution?

We are testing it, as well as Rapid 7 InsightVM.

We have been testing Qualys VM for approximately five weeks.

What do I think about the stability of the solution?

Qualys VM is a stable solution.

What do I think about the scalability of the solution?

Qualys VM is a scalable product.

It works with ten assets. It works with 100 assets. It has worked with 3,000 assets. It's quite scalable.

In our organization, we have two dedicated people, and five others are only dedicated to gaining insights. 

It actually depends on how you remediate all of the vulnerabilities in Qualys since you can also set up it such that product owners, that is, the owners of the apps that are deployed on all systems, can access reports and everything. But that's not how we do things.

The security and infrastructure departments are using this solution in our organization.

How are customer service and support?

We have a dedicated Qualys team of two persons assisting us with the implementation.

Which solution did I use previously and why did I switch?

We are currently doing a proof of concept with both Qualys VM and Rapid 7 InsightVM.

How was the initial setup?

Qualys is a fully SaaS solution.

It is dependent on the configuration. When you work with the agent, you are primarily concerned with deploying the agents to all assets. However, if you want to scan based on IP, you'll run into some problems.

If you wish to scan on an IP basis, for example, you should deploy a virtual appliance. You may set up several appliances for different domains. Otherwise, you must have your network rules properly configured so that the appliance can reach every asset.

It's relatively simple to set up the basics, but if you want to scan, it really depends on how many networks and domains you have.

In a couple of weeks, you can set it up.

What's my experience with pricing, setup cost, and licensing?

It's very expensive, especially if you want to use multiple modules of Qualys.

What other advice do I have?

I think mainly decide how you want to scan: based on IP or based on an agent.

Then work with the interface and then explore how it works.

I would rate Qualys VM an eight out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Senior Manager Network Design at MEEZA, Managed IT Services Provider
Real User
Top 5Leaderboard
Versatile features, highly scalable, and beneficial reports
Pros and Cons
  • "The most valuable features of Qualys VM are its ability to do proper vulnerability assessment. It has a lot of updates for all the vulnerability databases from all over the globe. It's an amazing solution when it comes to the versatility of the features it has. Additionally, the reports are very good. It generates very detailed reports about the vulnerabilities inside the environment"
  • "Qualys VM could improve by having more skilled support personnel."

What is our primary use case?

We use bother on-premise and cloud deployments of Qualys VM. For my clients in the cloud, we use a cloud solution, which is a bring your own license model. Additionally, We have our own deployment of Qualys VM.

We are using Qualys VM to provide a VM service.

What is most valuable?

The most valuable features of Qualys VM are its ability to do proper vulnerability assessment. It has a lot of updates for all the vulnerability databases from all over the globe.  It's an amazing solution when it comes to the versatility of the features it has. Additionally, the reports are very good. It generates very detailed reports about the vulnerabilities inside the environment

For how long have I used the solution?

I have been using Qualys VM for approximately five years.

What do I think about the stability of the solution?

Qualys VM is a highly stable solution.

How are customer service and support?

Qualys VM could improve by having more skilled support personnel.

How was the initial setup?

The initial setup of Qualys VM is straightforward. The full implementation took us approximately one day.

What about the implementation team?

We have approximately 100 people who are part of our technical team. We did the implementation of this solution.

What's my experience with pricing, setup cost, and licensing?

There is a license for the use of this solution. We pay annually instead of monthly to receive a better discount on the price.

What other advice do I have?

I would recommend this solution to others.

I rate Qualys VM a nine out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Gabriel Clement - PeerSpot reviewer
Lead IT Security and Remediation at ARM Ltd
Real User
Top 5Leaderboard
Cloud-based vulnerability management solution that provides protection of our systems but could offer improved performance
Pros and Cons
  • "This solution gives us insight into our environment and improves our security. It helps us to maintain a good patching system whereby we know that XYZ is vulnerable within the system."
  • "Qualys could be improved in its overall performance compared to other vulnerability management or scanning tools."

What is our primary use case?

We use this solution to scan the servers on the network. It is used predominantly by our information security team.

How has it helped my organization?

This solution gives us insight into our environment and improves our security. It helps us to maintain a good patching system whereby we know that XYZ is vulnerable within the system. 

What is most valuable?

Qualys makes us proactive in terms of handling patching and effective when it comes to scanning out network.

What needs improvement?

Qualys could be improved in its overall performance compared to other vulnerability management or scanning tools. 

For how long have I used the solution?

I have been using this solution for five years. 

Which solution did I use previously and why did I switch?

I have previously used Nessus. Overall, Nessus is a better tool because it provides greater insight into all vulnerabilities, some of which are skipped by Qualys. 

How was the initial setup?

This solution is very easy to set up. 

What about the implementation team?

We worked with a third party to complete deployment. 

What's my experience with pricing, setup cost, and licensing?

In Nigerian Naira, we spend about roughly four to five million to use this solution and this is expensive compared to solutions like Nessus.

What other advice do I have?

I would advise others to run a proof of concept and to exhaust all functionality if considering Qualys. This may take between 15 and 60 days to complete. 

I would rate this solution a six out of ten. 

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Dharmendra Kr. Chauhan - PeerSpot reviewer
Manager|Cloud Security & Solution Architect| CloudOps|AppSec | DevSecOps | DevOps | CapOps | FinOps at Wipro
Real User
Top 5
A solution with flexible licensing, easy setup and great integration
Pros and Cons
  • "We also like the flexibility in their licensing."
  • "The IoT scan is not great."

What is our primary use case?

We use this solution mainly for vulnerability management.

What is most valuable?

Qualys is a well-known name in the market and we use it for different scenarios. We also like the flexibility in their licensing.

What needs improvement?

The IoT scan is not great and we would like to see some improvements to it.

For how long have I used the solution?

We have been using this solution for over three years.

What do I think about the stability of the solution?

It is a stable solution.

What do I think about the scalability of the solution?

It is a scalable solution. We use the test version.

How are customer service and support?

I rate the technical support an eight out of ten. They have really good support.

How would you rate customer service and support?

Positive

How was the initial setup?

I rate the initial setup a nine out of ten. It was very good and easy. 

What's my experience with pricing, setup cost, and licensing?

It has a competitive price. I rate the pricing an eight out of ten.

What other advice do I have?

I rate this solution a ten out of ten. Compared to other solutions, brand awareness and Azure integration are the strong points of Qualys VM. We would like to have some predefined parameters for the setup in regards to security and vulnerability, and how to maximize it. For example, we want scans and management with some predefined parameters that we need to have in the environment prior to deployment and initial setup.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free Qualys VMDR Report and get advice and tips from experienced pros sharing their opinions.
Updated: April 2024
Buyer's Guide
Download our free Qualys VMDR Report and get advice and tips from experienced pros sharing their opinions.