it_user297117 - PeerSpot reviewer
Information Risk Analyst at a healthcare company with 1,001-5,000 employees
Vendor
We've gained insight into vulnerabilities across our environment, but reports should be more customizable.

What is most valuable?

The vulnerability scanning feature is valuable.

How has it helped my organization?

QualysGuard has provided us with a valuable insight into vulnerabilities across our environment. Before the use of this product, we had no way of identifying or tracking vulnerabilities.

What needs improvement?

The reporting capabilities are good but I would like to be able to make more customized reports. In addition, I would like to be able to assign a numerical asset value to critical hosts.

For how long have I used the solution?

I've used it for six years.

Buyer's Guide
Qualys VMDR
April 2024
Learn what your peers think about Qualys VMDR. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
769,334 professionals have used our research since 2012.

What was my experience with deployment of the solution?

No issues encountered, it went very smoothly.

What do I think about the stability of the solution?

No issues encountered.

What do I think about the scalability of the solution?

No, as it's very easy to add additional hosts.

How are customer service and support?

Customer Service:

8/10.

Technical Support:

8/10.

Which solution did I use previously and why did I switch?

We didn't use a previous solution.

How was the initial setup?

It was straightforward.

What about the implementation team?

It was implemented in-house.

Which other solutions did I evaluate?

We also looked at Nessus.

What other advice do I have?

Make sure you take advantage of authenticated scans and it is also very helpful if you have a complete server inventory.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user268167 - PeerSpot reviewer
Senior System Engineer at a comms service provider with 1,001-5,000 employees
Vendor
It's easy to download/install the correct patch, but the reporting could be improved.

What is most valuable?

The feature where the solutions to issues are mentioned in the reports.

How has it helped my organization?

It's easy to reach the current location and download/install the correct patch.

What needs improvement?

The feature where the solutions to issues are mentioned in the reports could be improved.

For how long have I used the solution?

I've been using it for over three years.

What was my experience with deployment of the solution?

No issues encountered.

What do I think about the stability of the solution?

No issues encountered.

What do I think about the scalability of the solution?

No issues encountered.

How are customer service and technical support?

Customer Service:

7/10.

Technical Support:

5/10,

Which solution did I use previously and why did I switch?

No previous solution was used.

What about the implementation team?

It was implemented by the vendor.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Qualys VMDR
April 2024
Learn what your peers think about Qualys VMDR. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
769,334 professionals have used our research since 2012.
it_user255882 - PeerSpot reviewer
Customer Technical Leader for Galeries Lafayette at a tech company with 10,001+ employees
Vendor
The GUI needs work, but the vulnerabilities are kept up to date.

What is most valuable?

The top one for me is that the vulnerabilities are kept up to date.

How has it helped my organization?

It has reduced the cost of ownership for the engineers who can launch scans on the customers’ networks.

What needs improvement?

I’m convinced it could be possible to do a simpler interface.

For how long have I used the solution?

I used it for about four years.

What was my experience with deployment of the solution?

No issues encountered.

What do I think about the stability of the solution?

There is an issue with the web browser, but it's not an issue with the product itself.

What do I think about the scalability of the solution?

No issues encountered.

How are customer service and technical support?

Customer Service:

9/10.

Technical Support:

8/10.

Which solution did I use previously and why did I switch?

I switched due to the cost.

How was the initial setup?

It was simple because it's only used for external scans.

What's my experience with pricing, setup cost, and licensing?

You have to find the best solution regarding functions and cost.

Which other solutions did I evaluate?

  • Tripwire
  • Nessus
  • Accunetix
  • OIpenvas

What other advice do I have?

  • Take your time
  • Study all the functionalities of the product
  • Try to set it up in a lab first before your production environment.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user251121 - PeerSpot reviewer
Senior IT Security Analyst at a tech services company with 501-1,000 employees
Consultant
The IT infrastructure needs work but WAF has improved our vulnerability identification.

What is most valuable?

WAF integration is valuable.

How has it helped my organization?

We can now perform vulnerability scans with WAF integration. The WAF has improved the vulnerability identification and reports to the SOC and CSO.

What needs improvement?

The IT infrastructure, especially server administration, needs to be improved.

For how long have I used the solution?

I've used it for two years.

What was my experience with deployment of the solution?

There was only one related, and that need work on our technology. As the solution is cloud based, we needed to adapt our internal policies.

What do I think about the stability of the solution?

There were no issues.

What do I think about the scalability of the solution?

This been done without a problem.

How are customer service and technical support?

Customer Service:

It's good.

Technical Support:

It's good.

Which solution did I use previously and why did I switch?

There was no previous solution, but I did execute several POCs.

How was the initial setup?

It was a regular setup for the configuration, but the official training was necessary.

What's my experience with pricing, setup cost, and licensing?

We also looked at Nessus and GFI Languard.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Senior Information Security Engineer at a financial services firm with 501-1,000 employees
Real User
It is a stable product. Tech support is quick to respond to any inquiries.
Pros and Cons
  • "There are fewer false positives when using this solution."
  • "Tech support is helpful."
  • "I do not like that all of the data is stored on the cloud."

What is our primary use case?

It mainly scans the model against all of our online websites.

How has it helped my organization?

There are fewer false positives when using this solution. We are also cutting the need for news monitoring with this solution.

What is most valuable?

We find all of the features useful. 

What needs improvement?

One note for room for improvement is that all of the data is stored on the cloud. I think it would be better if they came up with a big box that could store the data and collect data from, it would be a huge improvement.

For how long have I used the solution?

Three to five years.

What do I think about the stability of the solution?

It is an extremely impressive and stable product. I would give it a 99% out of 100%. It is very close to being perfect.

What do I think about the scalability of the solution?

I have had no issues with scalability. Initially, we had some issues with the dashboard, but eventually, it set and stabilized. There was an issue with the data dashing between the two models initially, but it was resolved.

How is customer service and technical support?

The tech support is helpful. When we initially open a ticket, we get response within five minutes. Then, they open a case and we receive input from tech support within 24-48 hours with a Q-ID.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user924705 - PeerSpot reviewer
Information Security Officer at Zamil
Real User
Threat detection tells us which machines are infected with a vulnerability
Pros and Cons
  • "They also have threat detection which maps threats. There is a feed that comes from Qualys when a new vulnerability is found. It tells us which machines are infected with that vulnerability."
  • "What we have found is that the solution is not closely tied with the patch management. It is okay with newer ones, like Windows 10 machines; it gives the correct patch. But for Windows 7 or Windows Server 2008, it does not give us the correct patch so we have to manually identify the patches. This is a major problem."

What is most valuable?

The first thing we like is the scanner, the device which checks vulnerability management.

They also have threat detection which maps threats. There is a feed that comes from Qualys when a new vulnerability is found. It tells us which machines are infected with that vulnerability. If there is a new attack, we definitely know that it is happening, what is happening in our environment.

What needs improvement?

What we have found is that the solution is not closely tied with the patch management. It is okay with newer ones, like Windows 10 machines; it gives the correct patch. But for Windows 7 or Windows Server 2008, it does not give us the correct patch so we have to manually identify the patches. This is a major problem.

For how long have I used the solution?

This is the third year we are using Qualys. This year we included one more module, the patching module.

What do I think about the stability of the solution?

It's stable. Every month we scan more than 5,000 IP addresses and we are able to detect vulnerabilities.

How are customer service and technical support?

Our experience is that the problems we send them take too much time to resolve. For example, we opened a case for the problem I mentioned earlier, the vulnerabilities with Windows 7 and Server 2008 where it's trying the wrong patch. It took them a long time to even give us the correct explanation. So this is a problem.

How was the initial setup?

The initial setup was very easy. We just needed to download the virtual machine. There is a key and we just needed to provide a proxy setting. That's it.

We did all the configuration as a one-time job where we defined our subnet and mapped. We needed to schedule the scan and the map and we needed to schedule a group of, say, Windows. It was just a one-time job where needed to configure the query and run it. It created a report and sent it to the administrators. After that one-time job, everything happens automatically.

What about the implementation team?

We did it on our own.

What other advice do I have?

I would recommend Qualys because it's very easy to use. It does not require many specific skills. We are always on the latest version because Qualys provides automatic updates.

We have a virtual appliance in each site and that sends the logs to the cloud. We have the consoles on the cloud which enable us to query and scan. All this happens through the cloud.

We only have one administrator for the solution who monitors and checks if there is anything to be aware of. It sends the reports to all the different administrators, such as network, Linux, and Windows administrators and they take it from there.

We also have Qualys configuration management module. If there are any particular issues in any servers or in any network, it gives us a report to suggest and rectify the issues. It tells us what changes are needed to on that device.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Network and security Pre-sales Engineer at a tech services company with 51-200 employees
MSP
A reliable, affordable, safe, scalable, and easy-to-use solution for vulnerability management and policy compliance
Pros and Cons
  • "There are many features. Its reliability, ease of installation, ease of use, and the richness of the information provided are the most valuable features."
  • "Its integration with ServiceNow and other similar products is complicated and can be improved. It should also have virtual batching. They should support more standards and compliance requirements and more customizations. For policy compliance, they can add the standards required by the countries in the Middle East. Each country generates its own standards and frameworks, and those frameworks should be there in all products, not only in Qualys. The market here is huge, especially in the cybersecurity field. Qatar has a framework for Qatar 2022, and each and every company in the public or private sector has to follow the Qatar 2022 framework."

What is our primary use case?

We are a system integrator. We implement Qualys for our customers for vulnerability management and policy compliance. We are not using Qualys as a product in our company. We have public, private, and hybrid cloud as well as on-premises deployments.

What is most valuable?

There are many features. Its reliability, ease of installation, ease of use, and the richness of the information provided are the most valuable features.

What needs improvement?

Its integration with ServiceNow and other similar products is complicated and can be improved. It should also have virtual batching.

They should support more standards and compliance requirements and more customizations. For policy compliance, they can add the standards required by the countries in the Middle East. Each country generates its own standards and frameworks, and those frameworks should be there in all products, not only in Qualys. The market here is huge, especially in the cybersecurity field. Qatar has a framework for Qatar 2022, and each and every company in the public or private sector has to follow the Qatar 2022 framework. 

For how long have I used the solution?

I have been using this solution for three years.

What do I think about the stability of the solution?

Qualys is a reliable, strong, and solid product. 

What do I think about the scalability of the solution?

It is scalable. The main advantage of Qualys is that it is a cloud-based solution because of which you can scale it up or down according to your needs. It is very quick and flexible.

How are customer service and technical support?

Because we are in the Middle East, we deal with the office in Dubai. You cannot imagine how supportive they are. They are amazing in their response.

How was the initial setup?

The initial setup was easy. It has great hardware. Its deployment was easier than Rapid7, which is a bit complicated. Tenable is less complicated, but Qualys is faster and easier to deploy than Tenable. 

I deployed Qualys in two hours. It is easy to install, manage, and go through. There are multiple tabs, and everything is understandable.

What's my experience with pricing, setup cost, and licensing?

Qualys is cheaper and more affordable than other solutions.

What other advice do I have?

I would recommend Qualys because it is a reliable, affordable, and very safe product. It can have everything that you are looking for.

I would rate Qualys VM an eight out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer: partner
PeerSpot user
it_user298425 - PeerSpot reviewer
Network and Lotus Notes Administrator at a insurance company with 1,001-5,000 employees
Vendor
It updates quickly and works without its presence being felt, but the problem-solving documentation needs improvement.

What is most valuable?

It gets up to date very fast.

How has it helped my organization?

Users do not feel any QualysGuard presence.

What needs improvement?

Solution for fixing problems need to be better documented, such as in a step by step way.

For how long have I used the solution?

I've used it for three years.

What was my experience with deployment of the solution?

No issues encountered.

What do I think about the stability of the solution?

No issues encountered.

What do I think about the scalability of the solution?

No issues encountered.

How are customer service and technical support?

Customer Service:

8/10.

Technical Support:

7/10.

Which solution did I use previously and why did I switch?

No previous solution was used.

What other advice do I have?

I strongly recommend that you use this solution.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free Qualys VMDR Report and get advice and tips from experienced pros sharing their opinions.
Updated: April 2024
Buyer's Guide
Download our free Qualys VMDR Report and get advice and tips from experienced pros sharing their opinions.