About Qualys Cloud Platform

Monitors the vulnerability management process, tracks remediation and ensures policy compliance.

Learn more about Qualys Cloud Platform

Pros:

Third, it contains tons of apps that extends its capabilities (e.g. Asset management app, web application scanning, PCI compliance monitoring, etc.).

Cons:

There is no MSI file to deploy the software via GPO.

Qualys Cloud Platform ratings

Average score

Ease of Use
3.8
Customer Service
3.8
Features
3.9
Value for Money
3.6

Likelihood to recommend

6.7/10

Qualys Cloud Platform has an overall rating of 3.6 out of 5 stars based on 18 user reviews on Capterra.

Have you used Qualys Cloud Platform before?

Share your experiences with other software buyers.

Filter reviews (18)

Héctor joel B.
Héctor joel B.
Ingeniero de Implementación y Soporte in Venezuela
Verified LinkedIn User
Computer & Network Security, 11-50 Employees
Used the Software for: 2+ years
Reviewer Source

Qualys the best vulnerability scanner

5 3 years ago

Comments: Based on the experience I have with Qualys, it is very impressive to capture the vulnerabilities, this compiles a complete report of the risks that your infrastructure has, in addition the patches have very precise information that allows you to carry out the remediation very effectively. The analyzes are detailed and very complete, it works very well to carry out the compliance stages of PCI, CIS, etc... Providing a great guarantee that periodically your organization has an armored infrastructure.

Pros:

In the firts instance we could see its operation inside a beast and we were amazed, its different configurations to make scans allows to obtain much more complete results than other programs. Qualys as a pentesting tool allows you to analyze those areas of greatest risk within your organization to remedy them. The ability to perform scans for a particular plugin is one of the features that other software should envy to Qualys. Your reports have a very detailed information that allows you to quickly identify vulnerabilities.

Cons:

I have no negative comments, it has worked very well in the company and with our allies.

Verified Reviewer
Security Consultant in Canada
Verified LinkedIn User
Computer & Network Security, 11-50 Employees
Used the Software for: 2+ years
Reviewer Source

Alternatives Considered:

In my oppinion, the best vulnerability management solution in the market

5 2 years ago

Pros:

From my years of experience with vulnerability management solutions, Qualys is the best one in the market. First, it is really easy to set up, specially the cloud solution. In less than few hours you can start scanning your environment. Second, it's vulnerability database is constantly updated with the latest vulnerabilities. Third, it contains tons of apps that extends its capabilities (e.g. Asset management app, web application scanning, PCI compliance monitoring, etc.) ...

Cons:

The price tag is not the cheapest one. Their licensing model is per IP on the scope, not per live IPs. So for example, if you have three /24 networks with one server each, you will be paying to scan 765 IPs (255*3) instead of only 3 IPs.

Safi R.
Information Security in US
Financial Services, 201-500 Employees
Used the Software for: 6-12 months
Reviewer Source

Qualys VM

3 3 years ago

Comments: They need to make the product better .. Focus ion ease of use. Get a focus group going.

Pros:

Agent deployment is simple. The software offers much if configured right. I dislike the add on services model.

Cons:

False positives. If a later software update rectifies an older vulnerability then there is no need to show asset is vulnerable. Vuln that shows up in Asset View is different in Vuln View.. Why? Salesperson quit after the sale which sucked. Replacement helped but was not focused on us.

Verified Reviewer
Information Security Adminstrator in South Africa
Verified LinkedIn User
Information Technology & Services, 51-200 Employees
Used the Software for: 2+ years
Reviewer Source

Alternatives Considered:

Qualys VM Review

4 2 years ago

Comments: It is one of the better solutions I have worked with. There are false-positives however this is common to most vulnerability scanners. This is one of the top 3 vulnerability scanners I would recommend. Take the time to understand what you require from the product and start building your tasks and reporting around it. The product will proof extremely valuable.

Pros:

The interface is nice and clean. Free online training with labs aids in understanding the product. Easy deployment of agents on both Windows and Linux endpoints.

Cons:

Configuring scans was not the easiest of tasks to perform initially. I recommend doing the free online training first before embarking with the deployment. Reporting needs to be improved especially the look and feel of the .PDF reports. Scheduling tasks I found limited as I wanted a particular scan to run 2 days out of the month and was unable to do so. Instead I had to create 2 tasks. Could not find an option to create custom usernames.

Verified Reviewer
Sr. UNIX Systems Admin in US
Verified LinkedIn User
Computer Software, 1,001-5,000 Employees
Used the Software for: 1+ year
Reviewer Source

Vulnerability scanning

4 2 years ago

Comments: Overall it has been very positive and we will continue to use it. It has helped us greatly lock down our environment.

Pros:

Qualys gives high-quality reports in an easy to read format. The agent has been easy to install and has not caused any issues.

Cons:

We have had some instances where scan attempts ended up causing confusion or application outages when they were not designed to handle the scans.

Tejas G.
Tejas G.
Associate Security Consultant in India
Verified LinkedIn User
Computer & Network Security, 51-200 Employees
Used the Software for: 1+ year
Reviewer Source

Great cloud based vulnerability scanning tool.

4 4 years ago

Comments: Great vulnerability scanner to provide accurate vulnerability findings.

Pros:

Qualysguard performs scan based on IP addresses rather than URL’s. It easily accessible from anywhere as its as cloud based scanner. Qualysguard supports scheduling of the scan for target system based on particular time and date and it also acknowledges and share the mail once the scan is completed. It can also perform the scan and give vulnerabilities as per compliance standards such as PCI DSS.

Cons:

Qualysguard doesn’t support scan for URL’s as we only need to provide IP address of the URL to perform the scan. This tool might be costly for small scale organizations.

Timothy G.
Timothy G.
Network Specialist in US
Verified LinkedIn User
Information Technology & Services, 51-200 Employees
Used the Software for: 1-5 months
Reviewer Source

A great VM Solution

4 2 years ago

Comments: Once you have the software set up, it is wonderful to use. There are improvements that can be made but this is a great solution for the money. Happy with the product so far.

Pros:

The solution is very detailed in what information it collects. The Cloud agent runs as a service on the endpoints and references back to the cloud periodically (the interval is customizable). The GUI is very nice and they are updating things constantly. It is easy to see our Security stance from the different modules.

Cons:

There is no MSI file to deploy the software via GPO! Also, for me, the assetview module shows a different number of assets than the VMDR asset tab. Why there is a difference, I don't know.

Verified Reviewer
Server, storage and messaging team leader in Poland
Verified LinkedIn User
Automotive
Used the Software for: 1+ year
Reviewer Source

Lots of promises, great marketing. Real quality rather low. Decided to find something better.

2 4 years ago

Comments: That was my first contact with vulnerability management. Perhaps it's a good software for start or for small companies. I was able to recognize my needs and it helped a lot to find a professional solution.

Pros:

Lots of features, agent available, flexible pricing. Software as a service, so you don't need any infrastructure.

Cons:

Useless unprofessional support, unable to solve any of my issues. They were closing unresolved issues. Lot of false positives. Support couldn't solve them, I got promises that it will be fixed in next release. Awful and unreliable reporting (errors on dashboards etc.). Very expensive. They're not using real cloud but couple of concentrators in different regions. Not useful for global customers. They promise they don't have access to customer data, but they request that to solve problems.

Tony F.
Datacenter Manager in US
Newspapers, 1,001-5,000 Employees
Used the Software for: 2+ years
Reviewer Source

Nice Tool for Security Scanning

3 3 years ago

Comments: We used Qualys for performing security scans on all Windows and Linux based servers being prepped for deployment so we had no vulnerabilities on servers being brought onto the production networks. Nice piece of mind and accountability for us as a deployment group.

Pros:

convenient web based scanning utility for our enterprise

Cons:

frequently had password issues trying to use a group account

Ramona E.
Ramona E.
Product Specialist & Software Engineer in Netherlands
Verified LinkedIn User
Industrial Automation, 11-50 Employees
Used the Software for: 1-5 months
Reviewer Source

Confusing vulnerability scanner/manager

2 3 years ago

Comments: We use this to regularly check our most important servers and determine their cybersecurity maturity.

Pros:

Once you get the hang of the interface, it generates results with more depth than most vulnerability assesment tools. Support is quick to respond to any queries, even during a trial period.

Cons:

The interface and the amount of options is confusing, to put it mildly. There are many different steps to take and many different, seemingly similar, scan options to choose from. It takes a significant amount of time to set up.

Verified Reviewer
Senior Information Technology Security Consultant in India
Verified LinkedIn User
Hospital & Health Care, 501-1,000 Employees
Used the Software for: 2+ years
Reviewer Source

Nice tool for Vulnerability Management.

4 3 years ago

Comments: Overall We are happy, Web interface is very interactive and training are awesome.

Pros:

Easy to implement, enabling sensors are not much techie.

Cons:

Sometime handling false positive detection are really a tough task.

Verified Reviewer
Associate Consultant in India
Verified LinkedIn User
Computer Software, 51-200 Employees
Used the Software for: 1+ year
Reviewer Source

Best paid tool for doing Vulnerability Scans

5 4 years ago

Comments: Costly tool but it is worth the money

Pros:

It can scan the systems based on various unique standards like PCI DSS which other scanners by competitors doesn't have . We can define various scanning profiles for doing vulnerability scans . It supports scan based on IP rather than URL. As it is a cloud based scanner it can be accessed from anywhere. I like the feature that it has option to schedule scans in future.

Cons:

It can't perform credentialed based scans for external or public facing IP’s Does Not support URL based vulnerability scans for application.

Verified Reviewer
Senior ICT Advisor - Innovation & Security in Netherlands
Verified LinkedIn User
Public Policy, 501-1,000 Employees
Used the Software for: 6-12 months
Reviewer Source

Useful Vulnerabilty Management option

4 3 years ago

Pros:

Detailed explanations and possible resolutions for vulnerabilities that are detected by the Cloud Agents.

Cons:

I have used other solutions as well on the same machines and they seem to detect quite a few different vulnerabilities, it seems neither give a rather complete list, so it's a good idea to use multiple solutions from different vendors with a different focus to get a clear insight in the ones that are classified as higher risks.

Suchibrato M.
Security Analyst in India
Semiconductors, 1,001-5,000 Employees
Used the Software for: 1+ year
Reviewer Source

Qualys VM review - Analyst perspective

4 2 years ago

Pros:

The tool is feature-rich, and managing the software is easy. Scans are easy to initiate and it doesnt cause any hassle for first-timers

Cons:

UI is lacklustre. Overall the tool is a bit slower in accessing compared to its competition

Joevanne V.
IT Security Engineer in US
Used the Software for: 2+ years
Reviewer Source

Very outdated user interface

2 5 years ago

Pros:

The platform provides pretty up to date scanning capabilities. Reporting contains direct links to available exploits.

Cons:

Very out dated user interface. Reporting modules have to be purchase separately along with actual scanners

Verified Reviewer
CISO in US
Verified LinkedIn User
Outsourcing/Offshoring, 1,001-5,000 Employees
Used the Software for: 6-12 months
Reviewer Source

Vulnerability Management

5 3 years ago

Pros:

Works well and is a trusted source. Their scanning engine gives you some level organization independence (not entirely).

Cons:

It is expensive, and you have to open up your organization to their IP's or put an in-house relay server.

Graham N.
Graham N.
Owner in UK
Information Technology & Services, 2-10 Employees
Used the Software for: 1-5 months
Reviewer Source

Incompetent badly supported rubbish.

1 4 years ago

Pros:

Nothing - I hate it.

Cons:

Their ridiculous false positives - apparently it's a critical incompliance that certain options aren't set in the gdm config file /etc/gdm.conf. Fair enough - if gdm was installed. A simple check that the file exists first would eliminate this and (of our 80+ compliance errors) most others. Complaining about mount options on non-existent filesystems, or that /etc/gshadow didn't match a regex - or did, I'm not sure from the report. The file has mode 0000 (so no permissions set at all). The fix was to chown root:root /etc/gshadow* Trust these amateurs at your own risk. If they are as incompetent as this, what are they missing?

Tony M.
IT Manager in UK
Real Estate, 2-10 Employees
Used the Software for: 6-12 months
Reviewer Source

Best vulnerability scanning tool out there

4 last year

Pros:

Detects the most vulns from a range of scanners tested.

Cons:

Reporting needs to be improved. This is a flaw in all VM tools though.