Sign in Agent Mode
Categories
Your Saved List Become a Channel Partner Sell in AWS Marketplace Amazon Web Services Home Help

Reviews from AWS customer

10 AWS reviews

External reviews

23 reviews
from

External reviews are not included in the AWS star rating for the product.


    ShantanuChoubal

Boosted cloud security with enhanced asset categorization and AI-powered insights

  • November 22, 2024
  • Review from a verified AWS customer

What is our primary use case?

We use Qualys TotalCloud to assess the security posture of our cloud-hosted environment. This tool allows us to access real-time data, categorize assets, prioritize critical vulnerabilities, and establish regular patching policies to mitigate our overall vulnerability risk.

We are eager to utilize Qualys TotalCloud to create a ticketing system integrated with our SecOps module, such as ServiceNow or a similar tool. This integration will enable automated ticket creation following assessments and vulnerability identification within our environments. The system should assign tickets to respective team members, prioritize fixes, and provide comprehensive dashboards for tracking progress and visualizing generated reports.

How has it helped my organization?

Qualys TotalCloud provides written explanations to help with remediation paths and eliminate cyber risk, significantly reducing our time spent on these tasks. It ensures that we can minimize manual efforts and prioritize security issues identified by the platform, allowing us to focus on critical areas and improve overall efficiency.

Qualys TotalCloud has significantly improved our organization by automating our reporting processes, reducing the time spent on report creation from two hours to less than fifteen to twenty minutes. It offers complete visibility of our cloud environment, which aids in prioritizing vulnerabilities and security risks effectively.

It provides unified vulnerability and threat assessments across both Infrastructure as a Service and Software as a Service, significantly improving our overall cloud security posture management. Compared to our previous Managed Cloud environment, even within this organization, we have made substantial progress. Previously, we relied on different tools with limited features for vulnerability posture management. However, with Qualys TotalCloud, we have implemented new policies and processes for remediation, resulting in a 70 to 90 percent improvement in our security standards.

Qualys TotalCloud offers a consolidated, prioritized view of risk across our chosen scope, allowing us to focus on specific vulnerabilities and security threats within a single dashboard. This streamlined approach eliminates the need to collate data from multiple sources, improving efficiency and providing comprehensive visibility into our cloud environment.

TruRisk Insights considers multiple factors, including Qualys detection score, asset scoring, risk, and CVSS scoring, to generate a comprehensive priority rating. Additionally, customization options allow for incorporating factors like internet exposure, public accessibility, or intranet presence, further refining the risk scoring and prioritization process.

Vulnerability identification is inconsistent, especially for assets with high vulnerability scores. This is influenced by the environment and project of the asset, and potential oversight during migration between versions. This may lead to a few individuals discovering significant vulnerabilities. However, Qualys' TruRisk Insights can identify the post-migration version of an asset, enabling us to determine the specific vulnerability and appropriate remediation actions, such as patching.

TruRisk Insights has significantly improved our security posture by automating our reporting process. Previously, creating reports required manually identifying assets, categorizing their environment, and calculating scores in Excel, which was time-consuming. Now, with TruRisk Insights, we can generate reports in less than 20 minutes by simply using the Qualys TotalCloud console to download the desired information.

What is most valuable?

One of Qualys' best features is its categorization, which allows us to see the types of assets, their security postures, and the AI-powered version of the tool. The AI enhancements simplify vulnerability management by eliminating the need for SQL queries to create policies. Now, we can simply input our requirements, such as critical vulnerabilities in the production environment or specific operating systems, and the tool generates the results accordingly. Additionally, we can create custom dashboards to monitor specific areas of interest, like vulnerabilities affecting a particular OS, exposed ports, majorly targeted vulnerabilities, or the most exploited vulnerabilities in the environment.

What needs improvement?

Two areas for improvement in Qualys TotalCloud are the speed of the public cloud platform and vulnerability detection. While the public cloud platform is necessary due to the lack of a private cloud infrastructure, page load speeds could be faster. Additionally, vulnerability detection needs improvement, as it currently takes several days for new vulnerabilities to be added to the knowledge base, hindering prompt detection and remediation. Ideally, updates should be more immediate, enabling quicker implementation of solutions.

For how long have I used the solution?

I have been using Qualys TotalCloud for two to three years.

What do I think about the stability of the solution?

The stability is excellent, with well-planned maintenance schedules communicated in advance by Qualys. This ensures business continuity and preparedness for any planned downtime.

What do I think about the scalability of the solution?

I would rate the scalability of Qualys TotalCloud nine out of ten.

How are customer service and support?

The Qualys customer support is exceptional.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?


How was the initial setup?

The deployment was straightforward, taking less than a day.

What about the implementation team?

The implementation involved four or five team members on our side. It's unclear how many were involved from the Qualys side.

What was our ROI?

Regarding return on investment, it is going well, although we are yet to complete year-end assessments. Qualys TotalCloud has saved us approximately 15 to 20 percent of our efforts.

What's my experience with pricing, setup cost, and licensing?

Although Qualys TotalCloud is relatively expensive due to its unique automation features, its cost-effectiveness is rated an eight out of ten, with ten being the most costly.

Which other solutions did I evaluate?

We evaluated other solutions such as Rapid7 and Falcon CrowdStrike. However, Qualys provides more comprehensive features.

What other advice do I have?

I would rate Qualys TotalCloud a nine out of ten.

We recommend and provide Qualys TotalCloud to our clients in various locations. We also utilize it internally across our global organization, spanning multiple countries in Asia, Europe, the US, and other regions. Therefore, Qualys TotalCloud is deployed globally. We have approximately 850 users with varying levels of access. Many have read-only access to view reports and the status of their environment. However, only a limited number of users have the necessary permissions to perform scans and make changes. The majority of users have read-only access.

Qualys TotalCloud, while generally reliable, occasionally requires maintenance and may experience downtime. Qualys performs its quarterly maintenance, but infrequent issues can arise, perhaps once or twice a year, causing crashes or slowdowns within the system. These rare instances may result in limited or delayed portal access, hindering report generation and dashboard viewing.

As a satisfied user, I recommend Qualys TotalCloud to other organizations or clients. I see myself as biased because I am a fan of the product and extensively use it.


    reviewer2060841

Comprehensive dashboards enhance cloud asset visibility and prompt issue remediation

  • November 15, 2024
  • Review provided by PeerSpot

What is our primary use case?

Qualys TotalCloud offers comprehensive visibility into all cloud environment assets, allowing for the identification of failing assets under policies and controls to ensure compliance and generate related reports.

We implemented Qualys TotalCloud to improve control over our publicly exposed assets, centralizing alerts and remediation efforts.

How has it helped my organization?

TotalCloud provides written explanation to help guide remediation paths and eliminate cyber risk.

TotalCloud has greatly enhanced the organization by helping identify misconfigurations and vulnerabilities that weren't visible before. It provides visibility and remediation, primarily for production and non-production environments, thus improving our overall security posture.

TotalCloud offers vulnerability and threat assessment for both Infrastructure as a Service and Software as a Service environments through a dedicated module designed to identify vulnerabilities in both.

TotalCloud has improved our security posture by simplifying the identification of misconfigurations and vulnerabilities in our resources, enabling us to quickly remediate any risks.

TotalCloud provides a single, prioritized view of risk, reducing the workload associated with consolidating multiple sources for risk prioritization. This efficiency saves us approximately 20 to 30 percent in costs.

What is most valuable?

The dashboards are particularly valuable as they offer a comprehensive view of the environment, highlighting any misconfigurations. The remediation features allow configurations to address issues promptly.

What needs improvement?

There is a resource-finding window in Qualys TotalCloud. We encountered challenges identifying the correct resource category for certain items, such as those in containers or storage. Specifically, we struggled to formulate effective queries within those modules to determine the properties of the items. Qualys could improve by enhancing the user interface to allow for easier query building, enabling users to simply click on UI elements and add them to the query.

For how long have I used the solution?

I have been using TotalCloud for three years.

What do I think about the stability of the solution?

I rate the stability of Qualys TotalCloud eight out of ten.

What do I think about the scalability of the solution?

I rate the scalability of Qualys TotalCloud nine out of ten.

How are customer service and support?

The technical support team is strong and helpful in solving issues promptly.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?


How was the initial setup?

The initial setup was straightforward, with deployment taking about a week.

What about the implementation team?

The deployment primarily involved five to six core team members, with additional support from various departments for broader organizational implementation.

What was our ROI?

TotalCloud has yielded significant cost savings by reducing manual effort by 20 to 30 percent and generating overall savings of 30 to 40 percent across various departments.

What's my experience with pricing, setup cost, and licensing?

Qualys TotalCloud is cost-efficient and was selected for its value compared to other products.

Which other solutions did I evaluate?

We conducted a proof of concept with Check Point and Trend Micro. However, we ultimately chose Qualys due to its superior visibility and broader range of options, despite some challenges with its user interface.

What other advice do I have?

I would rate Qualys TotalCloud eight out of ten.

I'm interested in Qualys TotalCloud incorporating orchestration capabilities to automate manual tasks and eliminate the need for transferring information and performing actions manually. Ideally, this would involve a workflow feature. While exploring options, I found that TruRisk Insights or another module might already offer this functionality.

Qualys TotalCloud is deployed in multiple locations globally, supporting approximately 200 users.

Qualys TotalCloud is designed to require minimal maintenance.

I recommend TotalCloud for its simple onboarding and cost efficiency, providing a holistic view of cloud assets.


    Himanshun Singh

Integrated cloud capabilities improvr vulnerability tracking and policy management

  • November 12, 2024
  • Review provided by PeerSpot

What is our primary use case?

Our primary use case for Qualys TotalCloud is its multi-cloud capabilities. The platform's cloud-based architecture allows us to utilize agents across various hosts and domains, eliminating the need for physical scanners or storage and streamlining our security operations.

We implemented TotalCloud because it is entirely cloud-based, eliminating the need for deploying additional resources, scanners, or storage. This centralized platform simplifies troubleshooting, vulnerability assessment, and remediation, streamlining our security processes.

How has it helped my organization?

Qualys TotalCloud offers comprehensive guidance for addressing cyber risks through clear remediation steps. The platform provides a centralized solution for vulnerability assessment, identification, and remediation, streamlining the entire security process.

Over the past four years of using Qualys, I've witnessed continuous improvements to their technologies. Initially offering only VMDR, they now provide ADR, SCA policies, EDR, and numerous other features. Their detection capabilities, particularly on the Windows side, have also seen significant advancements. While previously facing challenges with Linux identification, Qualys now demonstrates accurate identification with minimal false positives. Qualys TotalCloud boasts a 99.999 percent true positive rate in Windows environments.

Qualys TotalCloud offers a unified view of vulnerabilities across both Infrastructure as a Service and Software as a Service environments. Its integration of AI and anomaly detection databases significantly enhances its ability to identify and prioritize potential security threats.

The unified view integrates multiple policy standards into its modules, eliminating the need to consult various sources. By simply importing the policies, we obtain the desired results. Additionally, TotalCloud can scan for vulnerabilities and assess policies, thereby removing the necessity for deploying separate tools. It efficiently gathers all the required data from a single agent.

TotalCloud offers a centralized, prioritized view of risk tailored to specific needs. Customization of risk assessments is possible through factors such as vulnerability identification, organizational treatment, and asset criticality, each classified as critical, high, or medium. Further organization is achieved using tags or groups. This streamlined approach eliminates the need to consolidate multiple sources for risk prioritization. While organizations often utilize ticketing systems like ServiceNow and Jira integrated with Qualys for simplified workflows, Qualys also provides a reporting mechanism for those without a dedicated ticketing solution.

Qualys TotalCloud simplifies vulnerability assessment and policy management by providing everything in one straightforward interface.

TruRisk Insights, based on our critical asset assessment, provides improved results by enabling a more comprehensive understanding of risk and vulnerability, leading to better-informed decisions and more effective mitigation strategies.

TruRisk Insights enhances our security posture by combining multiple factors: attack vectors, criticality assessments, asset criticality evaluations, and analysis of the top ten Common Vulnerabilities and Exposures. This comprehensive approach provides a more accurate and holistic view of our security risks.

What is most valuable?

TotalCloud offers a comprehensive suite of features, including EDR, XDR, and TrueRisk, providing a centralized platform for managing vulnerabilities and security risks. This integrated approach streamlines vulnerability tracking and combines solutions like VMDR and Cloud Agent, simplifying security management for users.

What needs improvement?

Qualys TotalCloud needs to improve its accuracy for non-Windows operating systems. Specifically, it should refine its policies and enhance support for Linux and Mac platforms.

For how long have I used the solution?

I have been using Qualys TotalCloud for approximately one year.

What do I think about the stability of the solution?

The stability of Qualys TotalCloud is excellent, and I would rate it as ten out of ten.

What do I think about the scalability of the solution?

The scalability of Qualys TotalCloud is excellent, and I would rate it as ten out of ten.

How are customer service and support?

The technical support for Qualys TotalCloud is superb.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Prior to using TotalCloud, I utilized Rapid7 and Nessus for vulnerability management. While Nessus excelled in assessments with minimal false positives, I found Qualys to offer a more comprehensive solution.

How was the initial setup?

The initial deployment is straightforward and typically takes one to two hours to complete. The process involves downloading the agent and accessing the server where it will be deployed. With admin access, deployment can be completed in as little as two minutes per agent.

What was our ROI?

Qualys TotalCloud has saved us about 30 to 40 percent in time and resources.

What's my experience with pricing, setup cost, and licensing?

Qualys TotalCloud offers competitive pricing given its comprehensive suite of features, including integration, assessment, remediation, and detection capabilities, all within a single platform.

What other advice do I have?

I would rate Qualys TotalCloud ten out of ten.

Qualys TotalCloud is deployed in multiple departments and utilized by over 100 users.

Qualys TotalCloud is SaaS-based, so all maintenance is handled by Qualys. The agents update automatically, eliminating the need for user intervention. Reinstallation is only necessary in the rare event of agent corruption.

I would definitely recommend Qualys to others. It is a strong competitor in today's market.


    reviewer2592729

A comprehensive solution with brilliant dashboards and in-depth insights

  • November 11, 2024
  • Review provided by PeerSpot

What is our primary use case?

We use it for API licenses, VMDR, and dashboards based on risk assessments.

How has it helped my organization?

As a cybersecurity team, we have many challenges related to internal and external risks, and Qualys TotalCloud helps us mitigate these risks from hackers and other potential threats. Additionally, we use the Web Application Scanning tool to scan each system used by employees and the API licenses for detailed risk analysis.

It is a comprehensive solution that covers everything from risk management to patch management under one roof. This convenience allows us to focus less on handling individual security solutions and more on other business activities. It is also affordable for us.

It provides unified vulnerability and threat assessment across both IaaS and SaaS. This capability is very important. Recently, servers and systems of a company were affected in large numbers. Because of Qualys TotalCloud, our business or employees were not at all affected. Our production did not stop.

What is most valuable?

Web Application Scanning is valuable as it scans every system or application used by our employees and gives results quickly.

Its dashboards are brilliant. It provides in-depth insights. TruRisk scores help us understand our security posture better. The API licenses that we have are helpful in detailed risk analysis. We can see every detail of the risk. We can see from whom we are getting the risk and what we can do to mitigate a risk. These are the useful features of Qualys TotalCloud. Overall, it helps us identify and treat risks effectively.

What needs improvement?

With the growing integration of AI, I would like Qualys to enhance its service offerings to better accommodate AI-related risks. They recently launched a new product that captures AI aspects, but staying updated with more solutions would be beneficial.

For how long have I used the solution?

I have been working with Qualys TotalCloud for the past two to three years. Our organization has been using Qualys products and services even before my time with the company, possibly for ten to fifteen years.

What do I think about the stability of the solution?

Qualys TotalCloud is very stable, and I have extensive experience with it, which has been positive. I would rate it a ten out of ten for stability.

What do I think about the scalability of the solution?

Qualys TotalCloud scales well. I would rate its scalability a ten out of ten.

Our clients are enterprise businesses with about 100,000 employees. Qualys TotalCloud covers the whole organization. All of the systems and employees are covered.

How are customer service and support?

The technical support from Qualys is excellent, always available 24/7 for any urgent needs. I would rate their customer service and support a ten out of ten.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We did not use a different vendor for similar purposes.

How was the initial setup?

The initial setup of Qualys TotalCloud is good and efficient. It does not take long. It takes us only a few days or a week.

Like everything else, it needs some maintenance, but the Qualys team is always ready to provide help with that on time. There are never delays from their side. When it comes to maintenance, I am happy with the service maintenance service from Qualys.

What was our ROI?

Qualys TotalCloud has significantly reduced our workload in terms of managing risks, helping us to be more efficient and save substantial resources. It has saved about 90% of our time. Our risk level is very low.

What's my experience with pricing, setup cost, and licensing?

Qualys TotalCloud offers good pricing that is affordable and competitive with the market. Our partnership also provides us with additional benefits.

What other advice do I have?

I would strongly recommend a Web Application Firewall (WAF) for any business or individual because it protects your information and prevents numerous risks associated with Internet use.

I would rate Qualys TotalCloud a ten out of ten.


    reviewer2590986

Focuses on identifying data leakage vulnerabilities and managing compliance risks

  • November 05, 2024
  • Review provided by PeerSpot

What is our primary use case?

Our primary function for Qualys TotalCloud is managing SaaS applications within cloud environments. It focuses on identifying data leakage vulnerabilities and managing compliance risks.

How has it helped my organization?

Qualys TotalCloud offers written explanations to guide remediation and mitigate cyber risks. These explanations are crucial because they allow us to simulate the attack steps within a virtualized environment, fostering quicker comprehension and facilitating strategic responses as needed.

Qualys TotalCloud has provided frequent updates and support, drastically changing and enhancing the solution with additional features.

Qualys TotalCloud has offered unified vulnerability and threat assessment across both IaaS and SaaS environments, improving the organization's cloud security posture. This solution has instilled confidence in using the cloud infrastructure by overcoming challenges related to exposure and open internet access.

Qualys TotalCloud offers a unified, prioritized view of risk by combining the features of a compliance manager with other security management tools. This approach helps our organization effectively identify, assess, and prioritize risks, ultimately improving our overall security posture. The centralized platform provides a comprehensive view of risk while reducing the manual effort involved in identification. Previously, manual identification often failed to uncover risks that are now easily revealed by the platform.

The TruRisk Insights feature identifies assets with high vulnerability scores and the authorities to whom penalties may be owed.

TruRisk Insights has successfully identified all assets, including those with high vulnerability scores. We are able to use the information to quickly check for patches or fixes and address critical vulnerabilities.

The TruRisk Insights feature has improved our security posture by 80 percent.

What is most valuable?

Qualys TotalCloud's most valuable features are its security capabilities that help identify and mitigate risk factors. By providing a comprehensive view of the cloud environment's security, it detects malware, data leakages, and vulnerabilities. Additionally, the solution offers visualized attack paths to facilitate better understanding and implementation of security strategies.

What needs improvement?

Qualys TotalCloud has the potential to improve by integrating a hybrid platform for comprehensive management of both on-premises and cloud infrastructures. Additionally, enhancing clarity regarding its compliance capabilities would be beneficial, as the current scope is limited in geographic coverage. Expanding these features to provide a more comprehensive compliance solution would be advantageous.

For how long have I used the solution?

I have been using Qualys TotalCloud for over six months to a year.

What do I think about the stability of the solution?

I would rate the stability of Qualys TotalCloud nine out of ten.

What do I think about the scalability of the solution?

I would rate the scalability of Qualys TotalCloud nine out of ten.

How are customer service and support?

While customer service is satisfactory, providing necessary support, frequent updates, and beneficial training, more communication from the vendor would be appreciated.

How would you rate customer service and support?

Neutral

How was the initial setup?

The initial setup of Qualys TotalCloud took two months and involved four to five people. The setup process was straightforward.

What about the implementation team?

The implementation team consisted of four to five full-time employees who were involved in deploying the solution over a period of two months.

What other advice do I have?

I would rate Qualys TotalCloud eight out of ten.

We have Qualys TotalCloud deployed in multiple departments.

Qualys TotalCloud requires maintenance for servers, licensing, and additional features.

I would recommend Qualys TotalCloud to other users due to its scalability, insightful risk analysis, and overall effectiveness.


    SubhashMuthareddy

Gives us a holistic understanding of our cybersecurity posture

  • November 04, 2024
  • Review provided by PeerSpot

What is our primary use case?

Our client environment is a hybrid model, consisting of both on-premises and cloud assets. For this environment, we utilize Qualys TotalCloud to manage vulnerabilities, secure containers, and protect cloud workloads.

How has it helped my organization?

Qualys TotalCloud offers written explanations to guide remediation paths, leveraging its extensive knowledge base.

TotalCloud provides a unified vulnerability and threat assessment, which has improved our security posture. It offers a holistic understanding of our cybersecurity posture and gives us a single, prioritized view of risk, reducing the work we must do to compile multiple sources.

Initially, we were unfamiliar with TotalCloud's capabilities, having previously relied on Qualys. We placed our trust in Qualys's assessment of TotalCloud, and it took three to four months before we realized the benefits of the platform.

TotalCloud provides a unified vulnerability and threat assessment across IaaS and SaaS, giving us a holistic understanding of our cybersecurity posture.

The single prioritized view of risk TotalCloud provides helps reduce the work we have to do to mitigate risk.

Qualys TruRisk offers a comprehensive approach to risk assessment that goes beyond the limitations of the outdated CVSS score. By incorporating an Exploit Prediction Scoring System, TruRisk provides a more accurate and holistic score, reflecting the true criticality of a vulnerability and enabling timely remediation.

TruRisk has identified a small number of assets with high vulnerability scores. To improve our cybersecurity posture, we can prioritize these assets based on their vulnerability level rather than address all assets.

What is most valuable?

Qualys TotalCloud's most valuable feature is its agent versatility. Deploying a single agent provides comprehensive visibility across various cloud aspects, including workload protection, security posture management, and container security. This eliminates the need for multiple agents, streamlining the process and enhancing vulnerability detection.

What needs improvement?

Some major banks and insurance companies require an on-premises solution for comprehensive vulnerability management, which TotalCloud does not offer. Therefore, Qualys TotalCloud is not a suitable option for these institutions.

The cost of Qualys TotalCloud is high and could be more competitive.

For how long have I used the solution?

I have been using TotalCloud for approximately one year.

What do I think about the stability of the solution?

Qualys TotalCloud is quite stable, and there are no issues with lagging, crashing, or downtime. It offers 99.9 percent uptime.

What do I think about the scalability of the solution?

Qualys TotalCloud is scalable and can grow with our needs.

Which solution did I use previously and why did I switch?

The company employs various vulnerability management solutions based on cost-effectiveness and client preferences for on-premises options. These solutions include Tenable, SecPoint, and Zoho ManageEngine, used in conjunction with Qualys.

How was the initial setup?

The initial setup is straightforward. It does not take more than an hour and can be managed by one person.

What about the implementation team?

The implementation is a one-person job. It does not require a team.

What's my experience with pricing, setup cost, and licensing?

Qualys TotalCloud is expensive, but it offers a premier solution with no headaches.

What other advice do I have?

I would rate Qualys TotalCloud eight out of ten.

Qualys deals with the maintenance of TotalCloud.

I recommend new users to follow the Qualys TotalCloud documentation carefully as it is comprehensive and will guide you in deploying the solution easily.


    Reviewer34543

Streamlined onboarding elevates client cloud operations

  • November 01, 2024
  • Review provided by PeerSpot

What is our primary use case?

We typically onboard all clients in both cloud using Qualys TotalCloud and on-premises environments.

How has it helped my organization?

We began to see the benefits of Qualys TotalCloud within the first month, despite initially having few clients with cloud-based environments. Most of our clients were on-premises, limiting our exposure to TotalCloud's capabilities. However, in recent months, we've gained more experience with the platform as we've acquired clients utilizing cloud assets. This increased usage has highlighted the tool's increasing user-friendliness, particularly noticeable in the improved query functionality, which was initially quite challenging.

Qualys TotalCloud provides a unified vulnerability and threat assessment across both IS and SaaS.

Qualys TotalCloud provides a single prioritized view of risk. We can prioritize the threats with TruRisk. A single prioritized view of risk reduces effort by allowing us to accept certain risks as exceptions, focusing only on the critical ones. This streamlined approach saves time and resources for both us and our clients. This saves us around 20 percent of our costs.

Qualys' TruRisk Insights provides comprehensive risk assessment using its own risk calculation system. This system automatically generates an asset risk score based on the criticality of assets and any provided context. By analyzing vulnerabilities and their potential impact on the environment, TruRisk effectively flags them, allowing for a comprehensive approach to risk prioritization. For instance, high-severity vulnerabilities with high CVSS scores affecting multiple assets would be prioritized for remediation. The system's ability to flag vulnerabilities based on the environment and asset criticality makes it a reliable tool for risk management.

TruRisk Insights sometimes identifies assets with high vulnerability scores. For clients onboarded in TotalCloud, patching is managed by the client, while for on-premise clients, patch management is handled using Qualys. Monthly and weekly reports are provided to all clients, highlighting high vulnerabilities and major risks based on asset criticality. Remediation steps, available through Qualys, are included in the reports to assist clients in addressing identified vulnerabilities.

TruRisk Insights has improved our security posture by providing a genuine number of critical vulnerabilities that need to be addressed immediately based on risk level.

What is most valuable?

I appreciate Qualys TotalCloud's ability to onboard any type of device with ease, including containers. This user-friendly platform provides a comprehensive inventory of all assets and allows for customized policy and control design, a feature I find unmatched by other tools.

What needs improvement?

Qualys's ticketing system can be confusing when assigning tasks to individuals, and support could be improved by offering instant call solutions with engineers in addition to ticket replies.

For how long have I used the solution?

I have been using Qualys TotalCloud for almost two years.

What do I think about the stability of the solution?

I would rate the stability of Qualys TotalCloud eight out of ten.

What do I think about the scalability of the solution?

I would rate the scalability of Qualys TotalCloud eight out of ten.

How are customer service and support?

The support process is inefficient due to the excessive number of replies required when submitting tickets. A more efficient solution would be to provide instant call options with engineers, comparable to features offered by other tools.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

We switched from Rapid7 to Qualys because the latter offers a more comprehensive suite of modules, greater flexibility, and more advanced querying capabilities.

How was the initial setup?

The initial setup of Qualys TotalCloud is easy. If all the required information is available, it takes less than an hour to deploy.

What about the implementation team?

Deployment and other technical tasks are generally handled by two people, but the reporting team consists of many people.

What was our ROI?

Though I'm not deeply involved with the financial aspects, I estimate that at least twenty percent of costs are saved thanks to Qualys.

What other advice do I have?

I would rate Qualys TotalCloud nine out of ten.

Our clients consist of small and medium businesses.

I highly recommend Qualys TotalCloud to other users. Their strong technical team consistently delivers high-quality solutions and demonstrates a commitment to ongoing research and improvement, effectively addressing problems in a timely and long-lasting manner.


    Sushant Samantara

Helps us minimize attack surfaces by identifying root accounts and encryption issues

  • October 31, 2024
  • Review from a verified AWS customer

What is our primary use case?

We utilize all three major cloud platforms: Azure, GCP, and AWS, with over 500 subscriptions and accounts onboarded in the public cloud. To manage these, we employ TotalCloud to evaluate, compare, and monitor the security compliance posture of each cloud account, enabling us to rectify and mitigate any misconfigurations. We are currently exploring TotalCloud's advanced features, such as CWP, TruRisk Insight, and Cloud Detection and Response, and have successfully implemented FlexScan, which has yielded excellent results in securing our Internet-facing VMs and headsets.

We are using cloud-based network tools to improve our security posture, but it was initially difficult to gain a consolidated view of our security status. To address this, we implemented Qualys TotalCloud and integrated our subscriptions from Azure, AWS, and GCP. This provides a unified dashboard displaying the compliance posture of our entire cloud infrastructure, allowing us to prioritize tasks and identify areas for immediate improvement. The tool also details the technical steps required to enhance our security posture, which has significantly contributed to increasing our cloud compliance from 60 percent to 90 percent.

How has it helped my organization?

TotalCloud provides written explanations to guide remediation and eliminate cyber risks. While all cloud platforms offer security features, it's challenging to consolidate them into a single dashboard. Qualys TotalCloud effectively addresses this by consolidating multiple cloud platforms and subscriptions onto one dashboard. This allows users to quickly identify and mitigate misconfigurations and risks, simplifying security management.

Before implementing TotalCloud, our compliance rate was approximately 50 to 60 percent. However, after adopting the platform, it has increased to 80 to 90 percent. TotalCloud also helps us minimize attack surfaces by identifying root accounts and encryption issues, thereby enhancing our overall security by 40 percent.

TotalCloud offers a unified platform for assessing vulnerabilities and threats across both IaaS and PaaS environments. This unified view has improved our cloud security posture management.

We gain a single, prioritized view of risks through TotalCloud's TruRisk Insights feature. This feature considers not only the QDA score but also factors in cost and other relevant elements to provide a comprehensive risk assessment. From a potentially overwhelming list of findings, TruRisk Insights prioritizes the most critical risks, allowing us to focus our efforts and resources on addressing these high-priority tasks efficiently.

A single, prioritized view of risk streamlines the risk assessment process by eliminating the need to consolidate multiple sources. This comprehensive view is instrumental in communicating with other business customers who may be unaware of potential risks or misconfigurations within their resources. By identifying and informing them of these issues, we can guide them towards compliance and ensure a more secure environment.

TruRisk Insights provides valuable findings by identifying vulnerabilities and misconfigurations, displaying them on a dashboard, and offering deeper insights into the attack surface. It analyzes not only internet-facing devices but also those indirectly connected, providing a comprehensive understanding of potential risks. This is crucial because even devices not directly connected to the internet can be vulnerable if they have an attack surface. TruRisk Insights also offers mitigation strategies, making it a highly useful tool for managing security risks.

With the VMDR feature enabled and the Qualys Agent installed on various assets, we can identify existing vulnerabilities. TruRisk Insights then calculates risk scores, prioritizes tasks, and presents the number of findings. This allows us to focus on mitigating high-priority vulnerabilities while deferring those with lower priority, ultimately reducing overall risk.

TruRisk Insights provides device details, allowing for containerization of misconfigured devices. This process involves isolating problematic devices and rectifying misconfigurations, ultimately enhancing our security posture.

What is most valuable?

TotalCloud has been excellent in providing us with immediate access to all the products and features we need, such as CSPM, TruRisk Insights, and compliance reports, including CIS and HIPAA. This easy access to crucial information and tools has dramatically improved our efficiency and ability to meet various compliance standards.

What needs improvement?

Although TotalCloud is a helpful tool, some of its advanced features are still under development. For example, the Cloud Detection and Response feature is currently only fully functional for AWS, while support for GCP and Azure is still in progress. Additionally, while the detection component of CDR is robust, the automated response and remediation functionality is yet to be available.

For how long have I used the solution?

I have been using TotalCloud for two years.

What do I think about the stability of the solution?

I would rate the stability of Qualys TotalCloud ten out of ten.

What do I think about the scalability of the solution?

I would rate the scalability of Qualys TotalCloud ten out of ten. We have been able to increase accounts easily whenever needed.

How are customer service and support?

Qualys' customer support is good, though occasional backend consultations can cause minor delays. Overall, the service is commendable.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Prior to adopting Qualys, we relied solely on native cloud security measures provided by Azure, AWS, and GCP, rather than employing any third-party solutions.

How was the initial setup?

The initial deployment was straightforward due to my 17-year tenure in IT. Understanding security compliance facilitated the use and exploration of Qualys. While experts might encounter challenges, the product and backend teams have been highly supportive and accessible. Qualys has also been responsive within its SLAs.

What was our ROI?

We are constantly exploring new features and collaborating with Qualys to ensure we derive value. The finance team handles specifics on cost-effectiveness, but regular engagements with our TAM and product engineers suggest beneficial ROI.

What's my experience with pricing, setup cost, and licensing?

Pricing is managed by our finance team; however, Qualys TotalCloud offers cost-effective licensing flexibility. Existing VMware licenses can be switched to cloud features, eliminating the need for new purchases, which distinguishes it from other products.

What other advice do I have?

I would rate Qualys TotalCloud ten out of ten.

We are evaluating and implementing TotalCloud Detection and Response, a cutting-edge Cloud Detection and Response solution that utilizes AI and machine learning. This comprehensive product enhances our security posture and threat detection capabilities within the cloud environment.

We operate a SaaS platform with multiple locations, including an MSP involving 12 to 15 data centers globally. While we utilize sensors at our facilities, this won't hinder operations, as the geographically diverse data centers ensure easy management. We have 20 users of Qualys TotalCloud in our department.

Qualys maintains TotalCloud and provides notification of maintenance windows to minimize disruption during working hours.

Qualys TotalCloud significantly aided in maintaining and managing compliance scores, making it a highly recommended solution. The platform's exceptional accessibility, including comprehensive technical and TAM support, coupled with consistent availability and reachability, solidifies its value. Advocating for Qualys, I encourage others to utilize this robust platform.


    HASHIM JUNAID

Enables you to address zero-day issues before a patch is released

  • October 30, 2024
  • Review provided by PeerSpot

What is our primary use case?

All our cloud products are onboarded to Qualys TotalCloud, which scans for and provides information on vulnerabilities. We also get PCI-compliant images. TotalCloud helps with cloud security, including detecting and managing vulnerabilities, which is valuable for our remediations.

How has it helped my organization?

TotalCloud helps remedy zero-day vulnerabilities with its patchless remediation. Large enterprises face many zero-day threats, and TotalCloud can fix them before the patches are released to the public. TotalCloud provides a unified view of vulnerabilities in infrastructure as a service and software as a service. They've also integrated AI-based protection against data theft and leakage. Having this together on one dashboard is a significant advantage. We realized the benefits immediately. Our client is a Fortune 500 company, so we run scans daily and see the changes.

What is most valuable?

I appreciate TotalCloud's real-time protection and remediation features. The remediation options include automated one-click remedies and custom changes that help manage vulnerabilities efficiently.

The security scan helps with compliance and includes API-based integration. The TotalCloud agents are a great innovation in cloud security, and they'll soon implement the risk operation center, a cloud management portal that aids integration with many connectors to other solutions, such as ServiceNow. This will improve cloud management for large enterprises.

TotalCloud's written explanations of attack paths for vulnerabilities are amazing. It's a huge advantage of the platform. TruRisk can address critical vulnerabilities regardless of whether there is a patch.

You can automatically map vulnerabilities to patches or mitigation controls to apply agents or agentless mitigation for zero-day issues. TruRisk is built into the VMDR module, so we don't need to purchase a different product. The range of risks TruRisk covers is comprehensive. It has transformed our remediation strategy into a patchless one. You can use it for patch-based or patchless remediation, but patchless is more beneficial for larger enterprises. However, it's equally beneficial for startups and small businesses because it's so comprehensive.

What needs improvement?

TotalCloud could improve the classification of vulnerabilities. Specifically, it could enhance the categorization of what aspects fall under patches resolved by OS or software updates and what pertains to configuration adjustments.

For how long have I used the solution?

I have been a Qualys customer for 10 years and used TotalCloud for about a year.

What do I think about the stability of the solution?

TotalCloud is very stable, with no lagging or crashing issues noted.

What do I think about the scalability of the solution?

TotalCloud is fully scalable and effectively supports our needs.

How are customer service and support?

I rate Qualys support nine out of 10. Qualys's tech support is highly responsive, providing multiple ways to interact with them. They arrange Webex sessions for real-time issue resolution and promptly respond to emails. The quality of customer service has improved significantly over the past eight years.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup was pretty easy. We have deployed across various regions, including the United States and Europe, in development and cloud environments. A six-person high-level implementation team handled it, so I can't say how long it took, but I know it was completed by the deadline.

What about the implementation team?

We have an in-house six-member team for multiple proofs of concept and implementations. It does not require multiple people, but they also manage operations.

What's my experience with pricing, setup cost, and licensing?

The pricing for TotalCloud is attractive and competitive in the market. Given the features, especially the dashboard, I have no concerns regarding pricing.

What other advice do I have?

Users should manage their assets effectively to utilize TotalCloud efficiently, as asset management is crucial.

The users, they should be prepared with their, you know, how with their assets. So they should manage their assets properly. With that, they can utilize the TotalCloud efficiently. Asset management is the key.


    Harshal Mahajan

We can now know the exact risk to our organization which helps with risk prioritization and also saves time

  • October 30, 2024
  • Review provided by PeerSpot

What is our primary use case?

Qualys TotalCloud is a comprehensive solution that provides cloud security, cloud-related metrics, and a better understanding of our Cloud Security Posture Management (CSPM). Vulnerability assessment and our progress in terms of vulnerability remediation are also included.

How has it helped my organization?

By implementing Qualys TotalCloud, we wanted a single pane of glass for our cloud-related functions. We wanted to be able to see the security posture and compliance status and also do a vulnerability assessment or remediation. Qualys TotalCloud fulfills all these needs.

QFlow helps automate our remediation efforts. We can automatically do the remediation of vulnerabilities.

Previously, for Azure scanning, there was a very limited scope. We also did not have much scope for compliance. We wanted to have something that could give us this combination of vulnerability assessment and compliance posture. Our compliance posture has improved. We got to know where we are not compliant. All these things have contributed to our organization.

Qualys TotalCloud provides unified vulnerability and threat assessment across both IaaS and SaaS. It also provides a single, prioritized view of risk. Previously, we used to follow a traditional method of severity-based remediation, but now, the technology has evolved. With TruRisk, we can now know the exact risk to our organization. It helps with risk prioritization and also saves time.

Qualys has been a market leader for more than 20 years. They have vast information resources. They collect the data for us. We do not have to go out and search for vulnerabilities.

What is most valuable?

The agent and agentless scanning in TotalCloud, particularly the FlexScan method, is incredibly valuable. With traditional scanning approaches, we had to give IP ranges and whitelist IPs. All that is now simplified. FlexScan requires minimal intervention, and after configuration, it automatically collects data and performs necessary scans. We need to do some configuration in the connector, and it handles the rest of the things. Data compliance, vulnerability assessment, and remediation parts are taken care of by Qualys. We get all the required data. The connector collects all the metadata for our cloud environment. Scans are performed automatically. There is no intervention from our side.

What needs improvement?

There is room for improvement in vulnerability scanning, particularly for PaaS environments. Currently, Qualys does not have full access to these instances, which limits its effectiveness. We rely on other solutions like Microsoft's Defender for these scenarios and hope Qualys can improve its assessment capabilities for PaaS services.

For how long have I used the solution?

As an organization, we have been using Qualys TotalCloud for more than three to four years. It was previously known by a different name. They have now standardized all cloud security-related things under TotalCloud.

What do I think about the stability of the solution?

Qualys TotalCloud is quite stable. I would rate its stability as an eight out of ten.

What do I think about the scalability of the solution?

I would rate its scalability a seven out of ten as there are some aspects we need to explore further.

How are customer service and support?

Their customer support needs improvement. It is not up to mark. While we do get responses, the quality varies considerably based on the expertise of the support individual. We get a better response from a senior person, but we struggle a bit with a less experienced person. It can take three to four days to get an initial reply. I would rate their support a seven out of ten.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

We also use Microsoft Defender.

How was the initial setup?

We have a hybrid model. Its deployment is neither easy nor complex. It was a mid-level effort.

We have one tenant, and under that, we have multiple departments such as HR. There are only a few departments that are focused on Azure. Rest all are on-prem. Most things are on-prem, but something that is critical is hybrid. We have five to six people working with Qualys.

It does not require any maintenance from our side.

What other advice do I have?

It is a good product for organizations looking to have a comprehensive view of their vulnerability assessment, remediation, and compliance posture. It is an effective solution.

I would rate Qualys TotalCloud an eight out of ten.