Senior Cyber Security Specialist at a tech services company with 1,001-5,000 employees
Real User
The reporting and GUI need improvement but it's reliable
Pros and Cons
  • "Qualys VM is very stable."
  • "The reporting and the GUI need improvements."

What is our primary use case?

It was responsible for vulnerability scanning. It enforces vulnerability management websites.

What needs improvement?

The reporting and the GUI need improvements. Tenable dominated in these two areas: reporting and graphical user interface.

For how long have I used the solution?

Qualys VM was used once for one of our customers.

We were using the latest version.

What do I think about the stability of the solution?

Qualys VM is very stable.

Buyer's Guide
Qualys VMDR
April 2024
Learn what your peers think about Qualys VMDR. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
769,236 professionals have used our research since 2012.

What do I think about the scalability of the solution?

I didn't have all of the necessary information regarding the scalability or how to scale this solution, but all vulnerability management solutions have the same idea. 

I believe that it is easy to scale.

How are customer service and support?

I did not contact technical support.

Which solution did I use previously and why did I switch?

I have also used Rapid7, which is very similar to Qualys VM.

Scaling is more difficult with Rapid7. When it comes to scaling, Rapid7 is not my first choice.

How was the initial setup?

I did not implement this solution, I performed one scan for our client.

What other advice do I have?

We have regulations in place in Saudi Arabia and Egypt that require all vulnerability management solutions to be implemented on-premise.

I would recommend this solution to others but Tenable is my preferred option.

I would rate Qualys VM a five out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Chief Information Officer/Senior Vice President at a tech services company with 51-200 employees
Real User
Helps prioritize which security patches need to be deployed on specific equipment
Pros and Cons
  • "The prioritization feature is great. I think it has all of the advanced features that we need."
  • "It's too early for me to say if there is any room for improvement since we're in the first couple of months of using this solution."

What is our primary use case?

It's used for vulnerability assessments, assessment of IT equipment, PCs, servers. It's supposed to help prioritize which security patches need to be deployed on that equipment.

What is most valuable?

The prioritization feature is great. I think it has all of the advanced features that we need.

What needs improvement?

It's too early for me to say if there is any room for improvement since we're in the first couple of months of using this solution. So far, we've been pretty happy about it. Nothing comes to mind that is negative.

Given that it's really new, we're really trying to use all of the features and get a good comfort level and gain more experience in it. For this reason, I can't speak negatively of it, yet.

For how long have I used the solution?

We've been using Qualys for roughly six to seven years, but we've only been using Qualys VMDR for a few months.

What do I think about the stability of the solution?

Qualys VMDR is very stable.

What do I think about the scalability of the solution?

Qualys VMDR is definitely scalable.

How are customer service and technical support?

They provide a lot of free virtual training to really understand the technology and the solution. That's a plus for them.

Which solution did I use previously and why did I switch?

I used to work with QualysGuard VM — an older version. The earlier version didn't have the detection response that we needed, that's why this time it has the detection response. VMDR is the evolution of the solution.

How was the initial setup?

The initial setup was pretty straightforward. Deployment was quick.

What about the implementation team?

We implemented this solution ourselves.

What other advice do I have?

Overall, on a scale from one to ten, I would give this solution a rating of eight. For us, it's just more of gathering more experience. The more we learn, I think we'll appreciate it, and then maybe from that point, we'll be able to say it's a nine, or a ten. It's more on us versus the solution.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Qualys VMDR
April 2024
Learn what your peers think about Qualys VMDR. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
769,236 professionals have used our research since 2012.
it_user254967 - PeerSpot reviewer
Linux Administrator at a comms service provider with 501-1,000 employees
Vendor
The users on the forums are very knowledgeable, but the reporting in the solution is lacking.

What is most valuable?

The reporting and vulnerability analysis features.

How has it helped my organization?

Vulnerability scans are easily managed and maintained using Qualys. What used to be a manual process is now automatic. When we have an issue, I can easily see what production systems are affected and I can easily pinpoint a solution to mitigate the issue.

What needs improvement?

The reporting is lacking a little, and it would be nice to have reports sent via email. Often times we have to manually generate the reports after a vulnerability is fixed and a scan has to be re-run.

For how long have I used the solution?

I've used it for three years.

What was my experience with deployment of the solution?

We did not.

What do I think about the stability of the solution?

Our Qualys box is hardware and it's very easy to set up and maintain. It's very little maintenance, and the most time consuming part is setting up everything initially, such as what subnets you want to scan, what reports you want to run, etc.

What do I think about the scalability of the solution?

We have over 15,000 devices and had no issues with scaling up our Qualys infrastructure.

How are customer service and technical support?

Customer Service:

I have never had to interact with them. I get most of the information on the forums, and even there the responses are lighting fast. As far as actually talking to someone, I personally have never had to speak to Qualys support.

Technical Support:

It's great. The users on the forums are very knowledgeable and eager to help. If I need a quick answer I will always get one from the support forum.

Which solution did I use previously and why did I switch?

We used Nessus before. It was a manual process and very time consuming. I like Nessus, but it was very tedious to get it to function automatically.

How was the initial setup?

There are always complexities to every setup. I think the biggest issue was the learning curve. Having to learn all the new pieces and how they fit into our environment was probably the single biggest hurdle we had to face.

What about the implementation team?

We did it in-house.

Which other solutions did I evaluate?

We looked at Metasploit Expose but the price was too much for what we needed.

What other advice do I have?

Do your research and see how this product would best fit into your environment.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
PeerSpot user
Shared Information Security Officer at a university with 1,001-5,000 employees
Real User
It is a totally vendor-managed appliance. It distributes administration functions based on access roles.

What is most valuable?

  • Totally vendor-managed appliance
  • Highly scalable and deployable portal interface
  • Ability to easily distribute administration functions based on access roles

How has it helped my organization?

It provides fully automated internal and external vulnerability management.

What needs improvement?

Streamline PCI integration and attestation.

For how long have I used the solution?

I have used it for five years.

What do I think about the scalability of the solution?

I have not encountered any scalability issues.

How are customer service and technical support?

Technical staff are excellent.

Which solution did I use previously and why did I switch?

We previously used Rapid 7. The product was not staying current with shifting trends, sales staff were pushy and management were arrogant.

How was the initial setup?

Initial setup was simple.

What's my experience with pricing, setup cost, and licensing?

Negotiate for the pricing model that fits your budget. The vendor is willing to customize pricing.

Which other solutions did I evaluate?

Before choosing this product, we evaluated Rapid 7, Nessus.

What other advice do I have?

Take your time and have each vendor set up an actual proof of concept, rather than just relying on a demo. Get your network and support staff engaged in the process early on because they will be instrumental in deployment and support. Know what you’re trying to accomplish.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Director Transformación Digital at oesia
Real User
A feature-rich, complete product, and the multilingual technical support is good
Pros and Cons
  • "I like Qualys because it is a very complete product, more so than Tenable."

    What is our primary use case?

    We use this product for vulnerability management.

    What is most valuable?

    I like Qualys because it is a very complete product, more so than Tenable. It has vast capabilities.

    For how long have I used the solution?

    We have been working with Qualys VM for a very short time, perhaps six months.

    What do I think about the stability of the solution?

    This is a stable solution.

    What do I think about the scalability of the solution?

    Scalability-wise, this is a good product.

    How are customer service and technical support?

    The technical support is very good and they have it both in Spanish and English.

    Which solution did I use previously and why did I switch?

    We are also working with Tenable SC. Qualys is both more complete and for us, better in terms of pricing.

    How was the initial setup?

    For a beginning, the initial setup is complex. You have to have some knowledge for setting it up and using it.

    What's my experience with pricing, setup cost, and licensing?

    The price of Qualys for us is better than Tenable, although that is only because we are partners. The retail price of Qualys is higher than that of tenable. The pricing and licensing for Qualys could be improved.

    What other advice do I have?

    Overall, this is a good product and I recommend it, mainly because of the capabilities and the management using a single console. I can even create a calendar for activities from the main screen.

    I would rate this solution a nine out of ten.

    Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
    PeerSpot user
    it_user254970 - PeerSpot reviewer
    Technical Services Manager at a tech company with 10,001+ employees
    Vendor
    It is very simple and yet an effective way to do vulnerability assessment.

    What is most valuable?

    • Vulnerability assessment
    • Asset management
    • WAS

    How has it helped my organization?

    Since this is a SaaS based solution, the vulnerability scan with the external scanners as well as the reporting has improved a lot. The reporting is very granular and you can please higher management with your reports.

    What needs improvement?

    None, as the product is great.

    For how long have I used the solution?

    I've used it for four years.

    What do I think about the stability of the solution?

    Stability of the product is very high, I have never seen it unavailable.

    How are customer service and technical support?

    Customer Service:

    The support needs to improve a lot, their response is absolutely slow. I have had terrible experience with support over the years.

    Technical Support:

    I would rate it great because of its improvement since I have had terrible experiences in the past.

    Which solution did I use previously and why did I switch?

    We used McAfee Vulnerability Manager/Foundstone and had to switch because this is a SaaS based solution and has more features/capabilities.

    How was the initial setup?

    The initial setup is very simple in terms of configuring the appliance.

    What about the implementation team?

    We installed it ourselves,

    What other advice do I have?

    I would definitely recommmend using this product, as this is very simple and yet an effective way to do vulnerability assessment.

    .

    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    Senior Consultant at a tech services company with 11-50 employees
    Consultant
    Top 20
    Connects threat intelligence information with identified vulnerabilities, so you can prioritize vulnerabilities according to actual attacks
    Pros and Cons
    • "The most valuable feature is the connection of threat intelligence information with identified vulnerabilities, which means you can prioritize vulnerabilities according to actual attacks."
    • "Some of the older features could be polished instead of focusing on releasing new features."

    What is our primary use case?

    I primarily use Qualys VM for vulnerability management, security configuration, and management and asset inventory.

    What is most valuable?

    The most valuable feature is the connection of threat intelligence information with identified vulnerabilities, which means you can prioritize vulnerabilities according to actual attacks.

    What needs improvement?

    Some of the older features could be polished instead of focusing on releasing new features.

    For how long have I used the solution?

    I've been using Qualys VM for around eighteen years.

    What do I think about the stability of the solution?

    We've had no problems with stability.

    What do I think about the scalability of the solution?

    Qualys VM is quite easy to scale, and you can cover a large number of instances.

    How are customer service and support?

    The technical support is pretty good, though sometimes the response time could be better.

    How would you rate customer service and support?

    Positive

    How was the initial setup?

    The initial setup is quite simple.

    What's my experience with pricing, setup cost, and licensing?

    Qualys VM is better suited for medium to large companies because the price can be too much for smaller customers. With the SaaS version, you're buying a license for use per asset, so the price can differ, and there are additional fees for features like patch management and EDR policy compliance.

    Which other solutions did I evaluate?

    We also tested Tenable and Rapid7.

    What other advice do I have?

    I would rate Qualys VM as nine out of ten.

    Which deployment model are you using for this solution?

    Public Cloud
    Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
    PeerSpot user
    PeerSpot user
    Junior Information Security Analyst at Visma
    Real User
    Detects new hosts along with vulnerabilities
    Pros and Cons
    • "Monitors workstations and servers for vulnerabilities and creates reports."
    • "Performs automated, regular scans in the network."
    • "Detects new hosts along with vulnerabilities."
    • "Improve the API speed."
    • "Make some minimal dashboard improvements."
    • "Improve the user interface."

    What is our primary use case?

    Our primary use case is to manage vulnerabilities, scan web applications, and report assets throughout the network. Also, we create reports based on this data. 

    How has it helped my organization?

    • Tracks workstations and servers.
    • Monitors workstations and servers for vulnerabilities and creates reports.
    • Performs automated, regular scans in the network.
    • Detects new hosts along with vulnerabilities.

    What is most valuable?

    The Qualys Agent is most valuable for getting insight into what is happening on what device with all its metadata.

    What needs improvement?

    • Improve the API speed. 
    • Make some minimal dashboard improvements.
    • Improve the user interface.

    For how long have I used the solution?

    Less than one year.
    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    Buyer's Guide
    Download our free Qualys VMDR Report and get advice and tips from experienced pros sharing their opinions.
    Updated: April 2024
    Buyer's Guide
    Download our free Qualys VMDR Report and get advice and tips from experienced pros sharing their opinions.