We typically onboard all clients in both cloud using Qualys TotalCloud and on-premises environments.
Qualys TotalCloud
QualysExternal reviews
External reviews are not included in the AWS star rating for the product.
Streamlined onboarding elevates client cloud operations
What is our primary use case?
How has it helped my organization?
We began to see the benefits of Qualys TotalCloud within the first month, despite initially having few clients with cloud-based environments. Most of our clients were on-premises, limiting our exposure to TotalCloud's capabilities. However, in recent months, we've gained more experience with the platform as we've acquired clients utilizing cloud assets. This increased usage has highlighted the tool's increasing user-friendliness, particularly noticeable in the improved query functionality, which was initially quite challenging.
Qualys TotalCloud provides a unified vulnerability and threat assessment across both IS and SaaS.
Qualys TotalCloud provides a single prioritized view of risk. We can prioritize the threats with TruRisk. A single prioritized view of risk reduces effort by allowing us to accept certain risks as exceptions, focusing only on the critical ones. This streamlined approach saves time and resources for both us and our clients. This saves us around 20 percent of our costs.
Qualys' TruRisk Insights provides comprehensive risk assessment using its own risk calculation system. This system automatically generates an asset risk score based on the criticality of assets and any provided context. By analyzing vulnerabilities and their potential impact on the environment, TruRisk effectively flags them, allowing for a comprehensive approach to risk prioritization. For instance, high-severity vulnerabilities with high CVSS scores affecting multiple assets would be prioritized for remediation. The system's ability to flag vulnerabilities based on the environment and asset criticality makes it a reliable tool for risk management.
TruRisk Insights sometimes identifies assets with high vulnerability scores. For clients onboarded in TotalCloud, patching is managed by the client, while for on-premise clients, patch management is handled using Qualys. Monthly and weekly reports are provided to all clients, highlighting high vulnerabilities and major risks based on asset criticality. Remediation steps, available through Qualys, are included in the reports to assist clients in addressing identified vulnerabilities.
TruRisk Insights has improved our security posture by providing a genuine number of critical vulnerabilities that need to be addressed immediately based on risk level.
What is most valuable?
I appreciate Qualys TotalCloud's ability to onboard any type of device with ease, including containers. This user-friendly platform provides a comprehensive inventory of all assets and allows for customized policy and control design, a feature I find unmatched by other tools.
What needs improvement?
Qualys's ticketing system can be confusing when assigning tasks to individuals, and support could be improved by offering instant call solutions with engineers in addition to ticket replies.
For how long have I used the solution?
I have been using Qualys TotalCloud for almost two years.
What do I think about the stability of the solution?
I would rate the stability of Qualys TotalCloud eight out of ten.
What do I think about the scalability of the solution?
I would rate the scalability of Qualys TotalCloud eight out of ten.
How are customer service and support?
The support process is inefficient due to the excessive number of replies required when submitting tickets. A more efficient solution would be to provide instant call options with engineers, comparable to features offered by other tools.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
We switched from Rapid7 to Qualys because the latter offers a more comprehensive suite of modules, greater flexibility, and more advanced querying capabilities.
How was the initial setup?
The initial setup of Qualys TotalCloud is easy. If all the required information is available, it takes less than an hour to deploy.
What about the implementation team?
Deployment and other technical tasks are generally handled by two people, but the reporting team consists of many people.
What was our ROI?
Though I'm not deeply involved with the financial aspects, I estimate that at least twenty percent of costs are saved thanks to Qualys.
What other advice do I have?
I would rate Qualys TotalCloud nine out of ten.
Our clients consist of small and medium businesses.
I highly recommend Qualys TotalCloud to other users. Their strong technical team consistently delivers high-quality solutions and demonstrates a commitment to ongoing research and improvement, effectively addressing problems in a timely and long-lasting manner.
Enables you to address zero-day issues before a patch is released
What is our primary use case?
All our cloud products are onboarded to Qualys TotalCloud, which scans for and provides information on vulnerabilities. We also get PCI-compliant images. TotalCloud helps with cloud security, including detecting and managing vulnerabilities, which is valuable for our remediations.
How has it helped my organization?
TotalCloud helps remedy zero-day vulnerabilities with its patchless remediation. Large enterprises face many zero-day threats, and TotalCloud can fix them before the patches are released to the public. TotalCloud provides a unified view of vulnerabilities in infrastructure as a service and software as a service. They've also integrated AI-based protection against data theft and leakage. Having this together on one dashboard is a significant advantage. We realized the benefits immediately. Our client is a Fortune 500 company, so we run scans daily and see the changes.
What is most valuable?
I appreciate TotalCloud's real-time protection and remediation features. The remediation options include automated one-click remedies and custom changes that help manage vulnerabilities efficiently.
The security scan helps with compliance and includes API-based integration. The TotalCloud agents are a great innovation in cloud security, and they'll soon implement the risk operation center, a cloud management portal that aids integration with many connectors to other solutions, such as ServiceNow. This will improve cloud management for large enterprises.
TotalCloud's written explanations of attack paths for vulnerabilities are amazing. It's a huge advantage of the platform. TruRisk can address critical vulnerabilities regardless of whether there is a patch.
You can automatically map vulnerabilities to patches or mitigation controls to apply agents or agentless mitigation for zero-day issues. TruRisk is built into the VMDR module, so we don't need to purchase a different product. The range of risks TruRisk covers is comprehensive. It has transformed our remediation strategy into a patchless one. You can use it for patch-based or patchless remediation, but patchless is more beneficial for larger enterprises. However, it's equally beneficial for startups and small businesses because it's so comprehensive.
What needs improvement?
TotalCloud could improve the classification of vulnerabilities. Specifically, it could enhance the categorization of what aspects fall under patches resolved by OS or software updates and what pertains to configuration adjustments.
For how long have I used the solution?
I have been a Qualys customer for 10 years and used TotalCloud for about a year.
What do I think about the stability of the solution?
TotalCloud is very stable, with no lagging or crashing issues noted.
What do I think about the scalability of the solution?
TotalCloud is fully scalable and effectively supports our needs.
How are customer service and support?
I rate Qualys support nine out of 10. Qualys's tech support is highly responsive, providing multiple ways to interact with them. They arrange Webex sessions for real-time issue resolution and promptly respond to emails. The quality of customer service has improved significantly over the past eight years.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup was pretty easy. We have deployed across various regions, including the United States and Europe, in development and cloud environments. A six-person high-level implementation team handled it, so I can't say how long it took, but I know it was completed by the deadline.
What about the implementation team?
We have an in-house six-member team for multiple proofs of concept and implementations. It does not require multiple people, but they also manage operations.
What's my experience with pricing, setup cost, and licensing?
The pricing for TotalCloud is attractive and competitive in the market. Given the features, especially the dashboard, I have no concerns regarding pricing.
What other advice do I have?
Users should manage their assets effectively to utilize TotalCloud efficiently, as asset management is crucial.
The users, they should be prepared with their, you know, how with their assets. So they should manage their assets properly. With that, they can utilize the TotalCloud efficiently. Asset management is the key.
We can now know the exact risk to our organization which helps with risk prioritization and also saves time
What is our primary use case?
Qualys TotalCloud is a comprehensive solution that provides cloud security, cloud-related metrics, and a better understanding of our Cloud Security Posture Management (CSPM). Vulnerability assessment and our progress in terms of vulnerability remediation are also included.
How has it helped my organization?
By implementing Qualys TotalCloud, we wanted a single pane of glass for our cloud-related functions. We wanted to be able to see the security posture and compliance status and also do a vulnerability assessment or remediation. Qualys TotalCloud fulfills all these needs.
QFlow helps automate our remediation efforts. We can automatically do the remediation of vulnerabilities.
Previously, for Azure scanning, there was a very limited scope. We also did not have much scope for compliance. We wanted to have something that could give us this combination of vulnerability assessment and compliance posture. Our compliance posture has improved. We got to know where we are not compliant. All these things have contributed to our organization.
Qualys TotalCloud provides unified vulnerability and threat assessment across both IaaS and SaaS. It also provides a single, prioritized view of risk. Previously, we used to follow a traditional method of severity-based remediation, but now, the technology has evolved. With TruRisk, we can now know the exact risk to our organization. It helps with risk prioritization and also saves time.
Qualys has been a market leader for more than 20 years. They have vast information resources. They collect the data for us. We do not have to go out and search for vulnerabilities.
What is most valuable?
The agent and agentless scanning in TotalCloud, particularly the FlexScan method, is incredibly valuable. With traditional scanning approaches, we had to give IP ranges and whitelist IPs. All that is now simplified. FlexScan requires minimal intervention, and after configuration, it automatically collects data and performs necessary scans. We need to do some configuration in the connector, and it handles the rest of the things. Data compliance, vulnerability assessment, and remediation parts are taken care of by Qualys. We get all the required data. The connector collects all the metadata for our cloud environment. Scans are performed automatically. There is no intervention from our side.
What needs improvement?
There is room for improvement in vulnerability scanning, particularly for PaaS environments. Currently, Qualys does not have full access to these instances, which limits its effectiveness. We rely on other solutions like Microsoft's Defender for these scenarios and hope Qualys can improve its assessment capabilities for PaaS services.
For how long have I used the solution?
As an organization, we have been using Qualys TotalCloud for more than three to four years. It was previously known by a different name. They have now standardized all cloud security-related things under TotalCloud.
What do I think about the stability of the solution?
Qualys TotalCloud is quite stable. I would rate its stability as an eight out of ten.
What do I think about the scalability of the solution?
I would rate its scalability a seven out of ten as there are some aspects we need to explore further.
How are customer service and support?
Their customer support needs improvement. It is not up to mark. While we do get responses, the quality varies considerably based on the expertise of the support individual. We get a better response from a senior person, but we struggle a bit with a less experienced person. It can take three to four days to get an initial reply. I would rate their support a seven out of ten.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
We also use Microsoft Defender.
How was the initial setup?
We have a hybrid model. Its deployment is neither easy nor complex. It was a mid-level effort.
We have one tenant, and under that, we have multiple departments such as HR. There are only a few departments that are focused on Azure. Rest all are on-prem. Most things are on-prem, but something that is critical is hybrid. We have five to six people working with Qualys.
It does not require any maintenance from our side.
What other advice do I have?
It is a good product for organizations looking to have a comprehensive view of their vulnerability assessment, remediation, and compliance posture. It is an effective solution.
I would rate Qualys TotalCloud an eight out of ten.
Linking asset clusters enhances deployment security awareness
What is our primary use case?
We use Qualys TotalCloud to monitor deployments across our pipelines, controllers, AC, and AKS instances. This tool identifies vulnerabilities before deployment, addressing a previous gap in our system management. By integrating TotalCloud, we have significantly reduced vulnerabilities in our deployment pipeline.
How has it helped my organization?
The vulnerability reports we receive primarily include remediation guidance or steps provided by the vendors. While we haven't acquired Qualys Patch Management yet, we're in the process of doing so. However, the reports offer sufficient information on remediating vulnerabilities, including identification and replication steps. This documentation is typically sourced directly from official vendors like Cisco or Microsoft, ensuring its genuineness. Qualys provides these official vendor documents, making their solutions and remediation strategies reliable. Although rare, occasional inaccuracies occur, which is common with any technology.
We realized the benefits of Qualys TotalCloud after gaining an understanding of how its various components, such as VMDR, eSAM, and eSAM modules, integrate with our systems. The addition of API testing capabilities further enhances this solution, allowing us to leverage TotalCloud for comprehensive security management. We are also exploring the newly launched Risk Operation Center module, which provides insights similar to a SOC by identifying vulnerabilities that could potentially exploit our environment.
Qualys VMDR solutions provide a comprehensive view of vulnerabilities identified by TotalCloud, encompassing vulnerability management, web application firewall, and secure configuration modules. All identified vulnerabilities are collectively displayed within these modules, offering a monthly overview of the organization's current security posture.
The severity levels are visible in the single preauthorized risk view. Customizable dashboards offer various templates for display and presentation, tailored to customer requirements, including the option for hardened dashboards.
TruRisk has identified a small number of assets with high vulnerability scores. Public-facing assets require immediate patching, while less critical assets are isolated before patching.
TruRisk currently provides real-time scenario analysis. We have real-time vulnerability detection and a real-time patch management solution operating actively within our infrastructure, not just theoretically within Qualys. This gives us a clear picture of our operational status and how everything functions within our infrastructure. While not achieving one hundred percent visibility, we have approximately 97 percent comprehensive monitoring of our infrastructure and its performance.
What is most valuable?
Qualys TotalCloud's most valuable feature is its ability to link clusters of assets, providing a clear model of deployments, vulnerabilities, and statuses. This enhanced visibility significantly improves our understanding of our infrastructure, addressing a previous deficiency.
What needs improvement?
Qualys TotalCloud's increasing complexity, due to the development and deployment of multiple solutions, is making the GUI difficult to navigate. A simplified interface would greatly benefit users.
For how long have I used the solution?
I have been using Qualys TotalCloud for more than half a year.
What do I think about the stability of the solution?
Overall, Qualys TotalCloud is good when it comes to stability. It performs well without significant issues.
What do I think about the scalability of the solution?
The solution scales quite easily.
How are customer service and support?
The support is not up to the mark and seems to be overburdened. The closure time for support tickets often exceeds a week, sometimes extending to more than two weeks, particularly for bugs.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
During a proof of concept, I evaluated Prisma, but despite offering comparable features, it lacked certain key aspects, leading us to ultimately select Qualys TotalCloud.
How was the initial setup?
The initial setup of TotalCloud was sound and straightforward, and knowing the process made deployment easy. The only challenge was due to the number of servers we were running.
What about the implementation team?
The implementation was completed in-house.
What's my experience with pricing, setup cost, and licensing?
While Qualys TotalCloud's pricing is currently acceptable, it is becoming increasingly expensive and may soon be considered overpriced.
Which other solutions did I evaluate?
I evaluated Prisma during our proof of concept phase.
What other advice do I have?
I would rate Qualys TotalCloud eight out of ten.
While TruRisk Insights effectively identifies a wide range of risks, I still have a lingering feeling that I might be missing something. I tend to be cautious and need strong assurance before feeling confident in any path forward. Although TruRisk brings most potential issues to my attention, I sometimes feel the need to investigate further myself. This may be a personal quirk, but I believe TruRisk is performing well and fulfilling its intended purpose.
Apart from agent updates, Qualys TotalCloud does not require maintenance.
For new users, I recommend not jumping directly onto Qualys TotalCloud. Instead, take the time to get familiar with the GUI and control locations first. This will make handling other operations much easier.
Provides unified vulnerability and threat assessment across both IaaS and SaaS
How has it helped my organization?
Qualys TotalCloud provides a holistic view and insights into vulnerabilities, helping identify and track risks effectively.
It provides unified vulnerability and threat assessment across both IaaS and SaaS.
It helps to prioritize risks. The TruRisk Insights feature is particularly helpful in providing a comprehensive range of risks. We also have a TruRisk score for vulnerabilities. We can filter vulnerabilities based on the TruRisk score. For example, we can filter vulnerabilities with a TruRisk score of 500 to 700 and prioritize them.
What is most valuable?
The most valuable feature is the consolidated information that it provides from various platforms. We can find most of the things related to vulnerability management in one place.
What needs improvement?
There is room for improvement in the support. When deploying a Qualys solution at any client location, effective support should be there for all modules.
For how long have I used the solution?
We have been using it for seven months.
What do I think about the stability of the solution?
Qualys TotalCloud is stable. I would rate it a nine out of ten for stability.
What do I think about the scalability of the solution?
It is scalable. I would rate it a nine out of ten for scalability.
As of now, we are only using it at multiple locations in India. We have about seven members working with Qualys.
How are customer service and support?
Their support could be improved. I would rate their support a six out of ten due to availability issues.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
We were using another solution. That solution was more environment-specific, whereas Qualys provides a hybrid approach. It is better in terms of vulnerability correlation and prioritization.
How was the initial setup?
The deployment is easy. It takes about a month if everything is already in place.
In terms of maintenance, we just have to ensure that all the risks are identified and the reporting and configurations are correct. These are our daily operations.
What other advice do I have?
If you want a single-page view of vulnerabilities in your environment, you should go with Qualys TotalCloud. The correlation is very good.
Qualys TotalCloud is a comprehensive solution. Expert knowledge is required to implement it according to the organization's needs. It should be aligned with the organization's requirements. It is a continuous learning and improvement process.
I would rate Qualys TotalCloud an eight out of ten.
Enhanced security with automated scans and efficient risk management
What is our primary use case?
Our organization utilizes a multi-cloud environment primarily consisting of AWS and Azure, with limited GCP instances. To meet audit, compliance, and monthly scanning requirements, we employ Qualys TotalCloud. This involves deploying Qualys cloud agents and conducting regular scans of containerized environments, including registry-based scanning, Linux modules, and Docker instances. These scans may be triggered by ad-hoc requests, audit requirements, or compliance obligations.
How has it helped my organization?
Qualys TotalCloud offers comprehensive explanations and remediation steps for identified issues. Although it includes the FAST management module with built-in remediation capabilities, our organization hasn't subscribed to it, as the standard solution already provides adequate remediation guidance.
We realized the benefits of Qualys TotalCloud within three weeks, once we gained full visibility. The platform offers various features beyond a single module, including Security Assessment Questionnaires, reporting, and asset management. Integrating these features into our daily workflow, alongside other web application modules and the VMDR, took some time. We dedicated one to two hours daily to TotalCloud, and it took approximately two weeks to become proficient with the navigation and delivery methods within this cloud security module of the Qualys platform.
Qualys TotalCloud offers a comprehensive vulnerability and threat assessment through unified scanning and reporting. While we conduct the scans and generate reports, regular customer feedback is crucial as they analyze the raw data, except for critical cases where we intervene due to workload constraints. Customers have reported a positive experience with the report's readability and level of detail, comparing favorably to others they use. Furthermore, Qualys's extensive knowledge base ensures thorough vulnerability identification across VMs and infrastructure with 99.9 percent accuracy. In my five years of experience, only one or two issues arose, unrelated to TotalCloud specifically.
Qualys TotalCloud provides a single, prioritized view based on requirements such as identifying the most vulnerable assets and calculating the average time to remediate vulnerabilities. It also offers insights into organizational risk scores and utilizes a TrueRisk scoring system to assess and prioritize vulnerabilities effectively.
We've had extensive discussions internally about Qualys' TrueRisk formula, which calculates risk by considering the vulnerability's CVE, CVSS score, asset risk rating, exploitability, and code maturity. While we can see the sources for this information in the details tab, we haven't found any discrepancies in their scoring over the past year. Therefore, we consider Qualys' TrueRisk score reliable and use it to prioritize ticketing in ServiceNow, automatically assigning high and critical tickets for scores above 80 and 90. We trust Qualys as a source of truth, with over 95 percent confidence in their accuracy, and expect this to increase as the product matures.
Qualys TotalCloud TrueRisk has significantly improved our organization's security posture by providing automated and scheduled scans. It has also offered us a clearer understanding of our infrastructure, enabling us to prioritize our time more effectively. The platform's automation and API integrations have reduced the manual effort required for monitoring, leading to a more efficient audit and compliance management process. Additionally, the integration feature with Power BI and other tools enables us to visualize data more accurately, which we find unique and valuable.
What is most valuable?
Qualys TotalCloud's most valuable features are its cloud security posture management, Kubernetes, and container security capabilities. The platform's cloud-native, zero-touch infrastructure enables complete automation and API integration, minimizing manual intervention and allowing for efficient resource allocation. This automation frees up time for in-depth infrastructure analysis and improvement. Additionally, integrating Qualys with Power BI through a custom feature provides comprehensive, automated dashboards for enhanced data visualization and analysis, a rare implementation even among large organizations. TotalCloud centralizes all applications, including virtualization, into a single platform. The customizable dashboards within TotalCloud, similar to those in Qualys VMDR, offer further flexibility and insight.
What needs improvement?
A feature improvement could be the inclusion of Windows OS support for container security, as it is currently only supported for Linux. We would like to see Windows-based sensors available in Qualys, as this would make the platform more versatile and support a broader range of environments.
For how long have I used the solution?
I have been using Qualys TotalCloud for over one and a half years.
What do I think about the stability of the solution?
I have not experienced any stability issues with Qualys TotalCloud. There have been no crashes or lags, and the experience has been smooth and reliable.
What do I think about the scalability of the solution?
As our current deployment is small-scale, we have not faced any scalability issues. We plan to expand our deployment and believe the solution will scale well.
How are customer service and support?
I have contacted Qualys support on several occasions and found their quality to be commendable. They provide helpful documentation and proactively engage in follow-up calls to ensure any outstanding issues are resolved.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
While I am aware that our product management team uses Nessus, our IT team exclusively uses Qualys TotalCloud for our needs. We have found it to provide comprehensive features suited to our infrastructure requirements.
In my experience using Nessus and Tenable for six months and Qualys for four and a half years, I found Qualys's user interface to be superior. Navigation and visualization in Qualys were consistently smooth and intuitive, with a well-designed help section offering clear guidance. Overall, my user experience with Qualys was positive, combining technical functionality with ease of use.
How was the initial setup?
The initial deployment of Qualys TotalCloud was straightforward and swift. We completed the small-scale deployment within one or two weeks.
What about the implementation team?
Our in-house team handled the implementation, with no third-party involvement. The deployment on a small scale required approximately two people.
What other advice do I have?
I would rate Qualys TotalCloud nine out of ten.
No maintenance is required from our end.
My advice for new users is to follow Qualys' training materials for VMDR, vulnerability management, and container and cloud security modules. This will improve their user experience and technical understanding.
Helps manage compliance and gives a consolidated view of our security posture
What is our primary use case?
We are using the Cloud Security Posture Management (CSPM) and the Cloud Detection and Response (CDR) module. CSPM helps manage configuration compliance, and we have configured FlexScan in our environment for Internet-facing VMs.
We are in the process of evaluating further advanced features like Cloud Detection and Response and IAC.
How has it helped my organization?
TotalCloud provides written explanations to help guide remediation paths and eliminate cyber risk. These explanations are very helpful because not everyone is well-versed in the technology. We have different layers of team. Everyone does not know the technology well. The explanations help across the board.
It provides a single, prioritized view of risk. That is absolutely what we want. We want everything organized in one place. It helps to focus on high risks.
Qualys TotalCloud has helped us view our risk structure, vulnerabilities, and security posture. It does require some fine-tuning, but we do see very good results.
Our risk team uses TruRisk insights, and we have heard very positive feedback about it.
What is most valuable?
CSPM is currently the most used feature, and we are enjoying the new feature, FlexScan, which is valuable for Internet-facing VMs. With everything moving to the cloud, it is something interesting.
What needs improvement?
We are still exploring it. Currently, we only have two modules. Overall, we are satisfied with it. However, the response part of the Cloud Detection and Response (CDR) module can be improved. It is not yet in place according to requirements; it is not completely available even though the module has been released.
For how long have I used the solution?
We have been using TotalCloud for approximately one and a half years, but we have been using Qualys products for the last 10 to 12 years.
What do I think about the stability of the solution?
I would rate it a seven out of ten in terms of stability.
What do I think about the scalability of the solution?
I would rate it a nine out of ten for scalability. It has been fairly scalable for our needs.
How are customer service and support?
The support from Qualys is excellent. They meet delivery timelines very well, and the response times are satisfactory.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We have been a Qualys customer for a long time and have not yet used any alternatives to TotalCloud.
How was the initial setup?
FlexScan was a bit tricky, but CSPM was fine. Overall, it was easy. It took us approximately three months to fully align and deploy.
It took us some time to realize the benefits of TotalCloud. Being a new product, it took us some time to adapt and fine-tune TotalCloud to our infrastructure and security requirements. Once we went through that cycle, we started seeing its benefits.
What about the implementation team?
We received support from Qualys. Our TAM helped us in arranging resources.
What's my experience with pricing, setup cost, and licensing?
As a middle management member, I do not have direct pricing knowledge, but based on the knowledge from our meetings, its pricing is competitive.
What other advice do I have?
We are yet to explore it fully. I would rate TotalCloud an eight out of ten.
Offers a unified vulnerability and threat assessment across our entire environment
What is our primary use case?
We utilize Qualys TotalCloud for vulnerability management and continuous monitoring, conducting daily scheduled scans on our assets. Detected vulnerabilities are reported to end users, project team managers, and other relevant stakeholders.
How has it helped my organization?
We saw the benefits of Qualys TotalCloud after a few months of use.
Qualys TotalCloud offers a unified vulnerability and threat assessment across our entire environment, but we primarily utilize it to monitor and protect our internet-facing assets.
Qualys TotalCloud offers a centralized view of risk, displaying all vulnerabilities for a specific asset or the entire organization in a single dashboard. This unified perspective is valuable for both the leadership team, who use it in weekly meetings to monitor overall security posture and vulnerability trends, and individual units, who receive weekly reports detailing their specific security status. Currently, our organization maintains a strong security posture with no critical or high vulnerabilities, demonstrating the effectiveness of this approach.
What is most valuable?
I appreciate several aspects of Qualys TotalCloud. Primarily, we use it to inventory new assets and leverage its reporting and detection features to analyze payloads and identify vulnerabilities. The platform's unified view of the organization proves particularly valuable for leadership team meetings.
What needs improvement?
We often encounter challenges with IP whitelisting and scanners, primarily due to limitations on our end, not Qualys'. To improve the user experience, reporting could be simplified for better comprehension by end users and project managers, facilitating issue resolution. Additionally, enhancing the UI's readability for those without a security background would be beneficial. Finally, a valuable feature addition would be the automatic detection of subdomains, even if they aren't explicitly defined in the main domain. We use a VAS module for vulnerability scanning, but encounter issues when adding subdomains. Developers question why the main domain and subdomains show different vulnerabilities. Reports indicate that the main domain routes scans to the subdomains, leading to inconsistencies. Ideally, the scanner should automatically detect and scan all subdomains, even if not explicitly defined, ensuring comprehensive vulnerability assessment.
For how long have I used the solution?
I have been using Qualys TotalCloud for at least two or three years.
What do I think about the stability of the solution?
I have not experienced any crashes with Qualys TotalCloud. Occasional minor bugs, such as report downloading errors, have been resolved quickly by their support team. Overall, the support provided has been excellent.
What do I think about the scalability of the solution?
Scalability is a key strength of Qualys TotalCloud. Our organization currently uses it to manage over 1200 web applications, and we plan to expand our license coverage to include even more.
How are customer service and support?
I have received a few support tickets. I even spoke with someone from the technical side, with whom I interact regularly to resolve scanning or team detection issues. I've been very happy with their support compared to other tools I use. The support team responds quickly and their debugging is excellent, going in-depth to resolve issues. We're very satisfied.
How would you rate customer service and support?
Positive
What other advice do I have?
I would rate Qualys TotalCloud nine out of ten.
Qualys TotalCloud requires inventory maintenance, currently managed by a separate team responsible for monitoring ASM attack access. This team manually adds any newly discovered assets to the inventory. Automated detection of new assets has not yet been explored. Continuous efforts are focused on improving the configuration and maintenance processes.
My advice is to familiarize yourself with Qualys TotalCloud, as it has a learning curve. While it offers a multitude of tools and UI options, achieving 100 percent utilization takes time and practice. We are still in the process of exploring and incorporating its many features into our workflow.
Daily reporting enables timely security actions
What is our primary use case?
We use Qualys TotalCloud for patching and vulnerability management. We implemented it to improve patching and compliance for security purposes.
How has it helped my organization?
Qualys TotalCloud has been beneficial for our organization. We are getting a lot of functions in the portal for security assessment related to the third party. It tells us about vulnerabilities in the servers.
The vulnerability information available through the portal reduces my cyber risk. Qualys TotalCloud has improved our security posture. We receive daily security and vulnerability reports, which we act upon. We can remediate the issues on time.
I knew about the benefits of this product before buying it. We started seeing its benefits within two to three days of deployment.
What is most valuable?
One of the features I appreciate is the ability to generate daily reports without relying on anyone else. This feature has been very beneficial as it allows us to address security gaps and remediate them promptly.
What needs improvement?
I have been using Qualys TotalCloud for onyly two months. It has been working very well, but it would be helpful if the dashboard could generate reports tailored to specific compliance needs. For example, in India, we have to comply with RBI and SEBI guidelines. It would be great to have reports related to RBI and SEBI compliances.
For how long have I used the solution?
I have been using Qualys TotalCloud for not more than two months.
What do I think about the stability of the solution?
I would rate its stability as nine out of ten. It is a stable solution, which is why we chose it.
What do I think about the scalability of the solution?
I would rate its scalability a nine out of ten. The solution scales well.
We started our organization about nine months back. We started with about 30 users, and we now have more than 100 users. At first, we had one branch, but now, we have four branches. Some branches are based in India, and some are out of India.
How are customer service and support?
We have been working with it for only about two months. We have not used technical support. We have been in contact with presales and the deployment team. We have not had the need to engage with their customer support.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
We did not use any other solution before implementing Qualys TotalCloud. We have started a new organization where I have taken full services from Qualys. We chose Qualys based on familiarity from past experiences in other organizations.
How was the initial setup?
The initial setup was straightforward.
It is an easy product. I was familiar with it from the previous organization. Other colleagues were not very familiar, but they were able to understand it. It is not command-based. It is GUI-based.
Its implementation took 10 to 15 days. We are a small organization. We do not have a large number of APIs and servers. There is no issue.
It does not require any maintenance from our side.
What was our ROI?
The solution is proving beneficial, allowing us to remediate vulnerabilities before any issues arise. Daily reports alleviate all the concerns that we had previously. We have seen more than 50% improvement.
What's my experience with pricing, setup cost, and licensing?
The cost is high, but it meets our organizational needs.
What other advice do I have?
It is a very good solution. I would rate it a nine out of ten.
Provides extensibility, custom controls, and good overview
What is our primary use case?
We use Qualys TotalCloud for compliance monitoring and compliance checking.
How has it helped my organization?
TotalCloud provides written explanations to help guide remediation paths and eliminate cyber risk. It is very satisfactory.
I could see its benefits immediately after the deployment. I was using another product, and I was trying to switch over to this product.
TruRisk Insights provides a good view of the situation from different perspectives, such as the policy compliance side, the vulnerability side, and a few others. It gives us a better view of what is going on versus just piecemeal from one UI to another and then trying to make sense and sorting things or combining data together.
TruRisk Insights feature found a small number of assets with high vulnerability scores. I reported them to the owner, and then they are going to work on it.
TruRisk Insights are a good indicator, but long term, the managers still want to use the ServiceNow integration. We have this in our back pocket to verify.
What is most valuable?
The most valuable feature is the extensibility. I can create custom controls and rely on Qualys TotalCloud to provide me with updated controls as they come from CS benchmarks.
What needs improvement?
I have already put in a few feature requests. There are features that I would like to have. I would like the ability to disable certain default built-in policies as they can be misleading when creating dashboards. That is the top one.
Additionally, I would like the ability to generate reports on a schedule and send them via email to the scheduler.
It is a bit cumbersome to apply some of the features built into policy compliance.
TotalCloud provides a single, prioritized view of risk, but it can be better. I was hoping that they would integrate TruRisk into it, but that is forthcoming. I have already put in the request a while back to add TruRisk, and they are working on it.
For how long have I used the solution?
I have been using the solution for around two years.
What do I think about the stability of the solution?
I have not seen any events like lagging, crashing, or downtime.
What do I think about the scalability of the solution?
It is very scalable, and I would rate it a ten out of ten for scalability.
How are customer service and support?
I usually do not have to contact support. I last contacted them a month or two months ago. They usually respond within 48 hours. I can always escalate as needed. It is not an issue. Overall, their support is top-notch.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I used Dome9 which is under Check Point. I switched to TotalCloud because of better extensibility.
How was the initial setup?
We had some challenges with permissions, but other than that, it was fine. Its implementation took about 60 days.
It requires maintenance on our end. We need to maintain the permissions and the connections to whatever AWS accounts we need to have scanned.
What about the implementation team?
We had an in-house team involved along with Qualys support. Three people were required for the deployment.
What's my experience with pricing, setup cost, and licensing?
The pricing is comparable. It is built into our other product, so I cannot piecemeal it. It is a part of our subscription.
What other advice do I have?
New users should have a deeper understanding of how to use the cloud API because the extensibility is based on that. If they do not understand how to use the API, it would not be effective for them.
TotalCloud provides unified vulnerability and threat assessment across both IaaS and SaaS, but we do not use that. We do not have a use case for that.
I would rate TotalCloud an eight out of ten.