Security Manager at a healthcare company with 1,001-5,000 employees
I would like to see a little more flexibility with regards to setting up profiles for vulnerabilities. For the most part, it fits our needs but a little more flexibility would be great. I would also like to have more information on AI. If we start to deploy AI in our infrastructure, does it cover that as well?
I believe it has produced less false positives compared to its competitors
Was used for scanning PCI application along with Fortify for source code scans. Was tightly integrated with Secure SDLC.
Used to crash/freeze due to poor performance, not sure about newer versions.
Two years,…
Student Worker, Information Security Office at a university with 1,001-5,000 employees
Web application vulnerability scanning of various applications from different departments
Troubleshooting failed scans and incomplete statuses
I have been using this platform to scan the application for vulnerabilities since I started in this field.
Trustwave App Scanner makes it really easy…
"The stability is great. We haven't had any issues at all with it."
Cons
"I would like to see a little more flexibility with regards to setting up profiles for vulnerabilities. "
What is our primary use case?
Vulnerability management is our primary use case.
How has it helped my organization?
It hasn't really affected the way our organization function. It just gives us preparedness, readiness. However, it has increased our staff productivity by about five percent, and it has increased the maturity of our security program.
*Disclosure: My company does not have a business relationship with this vendor other than being a customer.
We were able to unravel bugs in earlier stages of product development and thus deliver maximum value to our customer during the release to market phase.
*Disclosure: My company does not have a business relationship with this vendor other than being a customer.
We were able to unravel bugs in earlier stages of product development and thus deliver maximum value to our customer during the release to market phase.
What needs improvement?
Reporting
User experience
New user on-boarding
For how long have I used the solution?
I've been using it for five months, since January 2015.
What was my experience with deployment of the solution?
No issues encountered.
What do I think about the stability of the solution?
Yes we did, but I'm not sure if it was Hailstorm itself or the product onto which it was run.
What do I think about the scalability of the solution?
No issues encountered.
How are customer service and support?
Customer Service:
7/10.
Technical Support:
7/10.
Which solution did I use previously and why did I switch?
No previous solution was used.
How was the initial setup?
It was complex as I have to make sure all the requirements are in place before on-boarding Hailstorm.
What about the implementation team?
We used a vendor team whose expertise was 7/10.
What was our ROI?
Overall, we have experienced a better ROI since using Hailstorm.
What other advice do I have?
Go ahead and use Hailstorm as it's the best dynamic code analysis tool one can invest in and it gives a better ROI than most.
*Disclosure: My company does not have a business relationship with this vendor other than being a customer.