FireMon vs. Qualys TruRisk Platform

Overview
ProductRatingMost Used ByProduct SummaryStarting Price
FireMon
Score 7.9 out of 10
Enterprise companies (1,001+ employees)
FireMon is a real-time security policy management solution built for today’s complex multi-vendor, enterprise environments. Supporting the latest firewall and policy enforcement technologies spanning on-premises networks to the cloud, FireMon delivers visibility and control across the entire IT landscape to automate policy changes, meet compliance standards, to minimize policy-related risk. Since creating their policy management solution in 2004, FireMon states they've helped…N/A
Qualys TruRisk Platform
Score 6.0 out of 10
N/A
Qualys TruRisk Platform (formerly Qualys Cloud Platform, or Qualysguard), from San Francisco-based Qualys, is network security and vulnerability management software featuring app scanning and security, network device mapping and detection, vulnerability prioritization schedule and remediation, and other features to provide vulnerability management and network attack surface reduction.N/A
Pricing
FireMonQualys TruRisk Platform
Editions & Modules
No answers on this topic
No answers on this topic
Offerings
Pricing Offerings
FireMonQualys TruRisk Platform
Free Trial
YesNo
Free/Freemium Version
NoNo
Premium Consulting/Integration Services
NoNo
Entry-level Setup FeeOptionalNo setup fee
Additional Details
More Pricing Information
Community Pulse
FireMonQualys TruRisk Platform
Considered Both Products
FireMon
Chose FireMon
FireMon gives us more flexibility when deploying the solution. Integrates with cutting-edge security solutions
Chose FireMon
We have only used firemon and there hasn't been a need to consider other products as we are satisfied with what Firemon can do.
Chose FireMon
Firewall Rule analyzer was used before I joined the company, but I have no experience with it.
Chose FireMon
OSSEC is open source and FM is much better from GUI and supportability stand points. Tufin and FireMon are very comparable
Chose FireMon
Best Compliance and Auditing tool to to identify the traffic that is hitting this rule.
Chose FireMon
I was not involved on the decision but having multiple brands in the company make sense to use a tool such as Firemon because it integrates easily with multiple vendors.
Chose FireMon
Infoblox DDI (BloxOne), Palo Alto Networks Prisma Cloud, Palo Alto Panorama, Palo Alto Networks Threat Protection, Palo Alto Networks WildFire, Palo Alto Networks Next-Generation Firewalls - PA Series and Fortinet FortiGate
Chose FireMon
Algosec and Tufin both are good tools but the cost involved for what they offer as services led us to go with Firemon.
Chose FireMon
i was not involved in the selection however i am quite happy with FireMon as the replacement of our aging product.
Chose FireMon
We have stuck with FireMon, and there is no reason to leave.
Chose FireMon
The Dell product ran on its own hardware, which failed often. The reports were not available to us in real-time, we had to request them. Many false detections of issues.
Chose FireMon
Both perform admirably with regards to providing that single pane of glass and visibility in a normalized view. They both provide great insight into where your organization stands in terms of compliance controls. In terms of upgrading and scalability, I would have to give the …
Chose FireMon
I has worked with Algosec and while they are very similar product, I find the FireMon is easier to understand and get rolling with. While both require some learning, FireMon is by far the easier one. Once you have an understanding of how things are arranged and labeled you can …
Chose FireMon
FireMon has the most supported devices.
The UI is easy to use and intuitive.
There is a comprehensive list of built in compliance controls that are missing in the competition.
Chose FireMon
To be blunt, at the time of purchase most of these products appeared to do the same things in the same ways. What really brought us to the table with FireMon six years ago was their willingness to earn our business, and to this day they remain just as committed to keeping our …
Chose FireMon
FireMon is way more flexible and the interface is tremendously better than any existing ones.
Chose FireMon
Algosec is a great tool, lower in cost as well.

FireMon has alot of capabilites, but our organization is not ready or have a use case yet for those features.
Chose FireMon
Tufin works much better with CheckPoint.
Chose FireMon
They are two very well done tools, FireMon is better suited for firewall rules evaluation, configuration and review, Tenable.io is better suited for CIS benchmarking. We ended up using both of them in the end, it really depends of your needs and what you are looking for, the …
Chose FireMon
Nothing like FireMon. We have other tools but 99% of them are looking at specific areas and not the enterprise security on a dashboard.
Chose FireMon
We performed a head-to-head PoC between FireMon and AlgoSec several years ago. Both platforms were well developed, but FireMon had the upper hand in three areas:
  1. Its UI was more unified and intuitive across the different components and products
  2. The reporting was better suited …
Chose FireMon
AlgoSec and Tufin both have initial issues during the POC stage, and FireMon even though with the changes they have made still works better and is more user friendly.
Qualys TruRisk Platform
Chose Qualys TruRisk Platform
As described before Qualys is used to scan periodically the environment in order to check if there are some packages (Linux) or Applications (Windows) outdated, generating reports to the Service Owners, fulfilling what's is expected from us, attending all our expectations …
Chose Qualys TruRisk Platform
When making the decision to use Qualys Cloud Platform we considered ManageEngine Patch Manager Plus and Kaseya VSA. We moved forward with Qualys Cloud Platform as it had multiple other options and features along with the costing provided as compared to others. Qualys Cloud …
Chose Qualys TruRisk Platform
I have not used other products like qualys cloud platform so I can't comment on how it compares, but I can say that we are happy with this solution that we currently have in place.
Chose Qualys TruRisk Platform
Qualys is quite user friendly and gives more easy information related to asset and risk an asset possess. Plus high quality of support as well as ease of use. Qualys is single suite for multiple task for your organization like VMDR rather than using multiple tools for different …
Chose Qualys TruRisk Platform
We find that Nessus is a great product, on par if not slightly better compared to Qualys in terms of their pricing model. However, Qualys Cloud Platform has better quality reporting, and offers great tips and suggestions on quickly closing a gap and eliminating the risk. In our …
Chose Qualys TruRisk Platform
As compared with Tenable, Qualys has multiple benefits and features which help ease the management of compliance. Tenable has only vulnerability management, but the Qualys tools landscape comprises a bouquet of tools spanning endpoint security, network security, compliances, …
Chose Qualys TruRisk Platform
Qualys Cloud Platform is the best tool available in the market considering the following factors - (1) simplify security operations and lower the cost of compliance (2) Visibility of cloud security configuration issues (3)User friendly interface with flexible options …
Chose Qualys TruRisk Platform
Qualys is more user friendly than tenable in view of creating and managing assets, option profiles as well as remediation provision and reporting service. As far as cost of these tools concern, qualys is less costlier than tenable vm tool. Qualys UI is better than tenable. You …
Chose Qualys TruRisk Platform
The VMware Carbon Black suite of products is highly superior than Qualys. This is what our organization has switched to and we couldn't be happier. It feels much more modern and easier to use/naviagte than Qualys. They also offer great threat detection on the end-user's …
Chose Qualys TruRisk Platform
We actually moved out of Qualys Web Application Scanning to a different product as we found better options that helped us address the specific concerns we had. The concerns were around scan duration, coverage, and the ability of the scanner to learn an application's nature and …
Chose Qualys TruRisk Platform
Azure Security Center
Chose Qualys TruRisk Platform
Identity Automation RapidIdentity
Chose Qualys TruRisk Platform
Deploying Qualys is really easy, in less than a day you can have everything ready for scanning. Also, Qualys has tons of reports and has tons of extension apps (such as the Asset Management App, which I love).
Chose Qualys TruRisk Platform
We really have not used or evaluated other commercial platforms other the Qualys. This was the only comprehensive platform that was in use in the organization for many years. Prior to a greater adoption by IT personnel in the use of Qualys, IT staff would routinely help to …
Chose Qualys TruRisk Platform
Qualysguard gave us the tools we needed that were benificial to our job without us having to do too much manual interaction such as with NMap, Metasploit , etc. It was a very efficient platform that I would go to again.
Chose Qualys TruRisk Platform
My previous organization was in the healthcare industry and we actually had Qualysguard, eEye, and Nessus because our customers required specific scan reports from those solutions. However, from a usability perspective, Qualysguard was the best solution.
Chose Qualys TruRisk Platform
While all of the alternative solutions mentioned here are great products, the features and usability that Qualys Private Cloud brought to the table worked out to be the best fit for my organization.
Features
FireMonQualys TruRisk Platform
Threat Intelligence
Comparison of Threat Intelligence features of Product A and Product B
FireMon
-
Ratings
Qualys TruRisk Platform
8.7
Ratings
8% above category average
Network Analytics00 Ratings8.90 Ratings
Threat Recognition00 Ratings8.30 Ratings
Vulnerability Classification00 Ratings8.80 Ratings
Automated Alerts and Reporting00 Ratings9.00 Ratings
Threat Analysis00 Ratings8.20 Ratings
Threat Intelligence Reporting00 Ratings8.90 Ratings
Automated Threat Identification00 Ratings8.70 Ratings
Vulnerability Management Tools
Comparison of Vulnerability Management Tools features of Product A and Product B
FireMon
-
Ratings
Qualys TruRisk Platform
8.5
Ratings
3% above category average
IT Asset Realization00 Ratings8.80 Ratings
Authentication00 Ratings7.90 Ratings
Configuration Monitoring00 Ratings8.50 Ratings
Web Scanning00 Ratings8.80 Ratings
Vulnerability Intelligence00 Ratings8.60 Ratings
Best Alternatives
FireMonQualys TruRisk Platform
Small Businesses
NinjaOne
NinjaOne
Score 9.0 out of 10
Action1
Action1
Score 9.5 out of 10
Medium-sized Companies
Cisco Meraki MX
Cisco Meraki MX
Score 9.0 out of 10
Action1
Action1
Score 9.5 out of 10
Enterprises
Cisco Meraki MX
Cisco Meraki MX
Score 9.0 out of 10
CrowdStrike Falcon
CrowdStrike Falcon
Score 9.0 out of 10
All AlternativesView all alternativesView all alternatives
User Ratings
FireMonQualys TruRisk Platform
Likelihood to Recommend
7.9
(0 ratings)
8.6
(0 ratings)
Likelihood to Renew
6.8
(0 ratings)
-
(0 ratings)
Usability
7.3
(0 ratings)
2.0
(0 ratings)
Availability
7.3
(0 ratings)
-
(0 ratings)
Performance
9.1
(0 ratings)
-
(0 ratings)
Support Rating
7.7
(0 ratings)
5.0
(0 ratings)
Implementation Rating
9.1
(0 ratings)
-
(0 ratings)
Product Scalability
7.9
(0 ratings)
-
(0 ratings)
User Testimonials
FireMonQualys TruRisk Platform
Likelihood to Recommend
FireMon is best used in a large environment (for example, I have >100
firewalls in my environment). It's best used when trying to improve
security posture and showing changes in firewall security over time. It
might not be the best choice for smaller environments or those that aren't concerned about security management.
Read full review
It is well suited for environments that are looking for a solution that is top notch for vulnerability scanning, and is the most accurate at doing so. It would also fit environments that have a lot of endpoints to scan or like to have scanning done on an automatic basis. It is less appropriate in environments that want to use a platform right away, without getting training in how to use it, or reading documentation on the product.
Read full review
Pros
  • PCI Reporting - After identifying which firewalls and rulesets are in scope, producing a report artifact to satisfy PCI requirements on Firewall reviews is literally a two-click operation.
  • Storing Rule Metadata - FireMon stores metadata (prefilled fields, standard fields, and custom fields) for each rule in each policy which is valuable for context during firewall reviews in particular
  • API - FireMon exposes most if not all of its functionality via REST API
Read full review
  • Attestation is so easy with Qualys. I find this one feature makes the investment worth the cost
  • Ease of use. Within an hour of first installing, a person can be running compliance tests without a hitch.
  • Great training materials and support. I have never had to take more than twenty minutes to solve a problem either through support or the forums.
Read full review
Cons
  • Some features could be added to the existing functionality which include NAT rules usage
  • Rule expiration normalization from firewalls rather than entering them in rule documentation
  • .csv exports of the files from the firewall pane only gives usage for 30 days by default and that should be increased
Read full review
  • Notices some findings which were not clear why they appear(suspected false positive).
  • Working with Qualys support(for example due to the previous point) wasn't the best experience. the response was very slow.
  • Qualys limit the daily API requests. In case you need more, it will cost.
Read full review
Likelihood to Renew
Once all the customization has been completed, the business is starting to see the return on investment. The visibility it provides into the network gear that is owned by other IT groups is immeasurable and has allowed us to apply standards across the board. The only thing I have concern with is their support documentation.
Read full review
No answers on this topic
Usability
It save me time and I'm able to have the review - review the rule independently with using my time.
Read full review
Again, the usability of Qualys has been a pinpoint for this entire review. It was easily the worst thing about the product and because of this, I would not recommend Qualys to anybody in my field. This should be something that Qualys strives to improve if they wish to stay in business.
Read full review
Reliability and Availability
FireMon has been relatively stable overall. However, there have been a handful of times where we had issues with the console. For example, we couldn't update which devices to include in a security assessment. The initial suggestion from support was to just reboot it. It seems like there weren't many other options available such as to restart services before going to the extreme of a complete reboot.
Read full review
No answers on this topic
Performance
I'm not sure we have the largest implementation of FireMon out there but we do have a few 1000 devices being probed by FireMon. Overall, the system's performance has been rock solid. The console refreshes quickly and reports are generated within an expected timeframe.
Read full review
No answers on this topic
Support Rating
FireMon technical support is awesome! They respond quickly to our requests and they are well trained and very knowledgeable about the tool. Some issues have to be referred to the development team, but technical support largely provides solutions for any issues that we may have.
Read full review
They had a support page within the WAS to report any concerns or seek help. But the UI of that is not smooth. Regardless support staff were pretty responsive and helpful. They scheduled calls to understand and address our problems. Email support is good as well.
Read full review
Implementation Rating
Implementation is fairly simple. Most issues can be resolved by referencing manuals.
Read full review
No answers on this topic
Alternatives Considered
I has worked with AlgoSec and while they are very similar product, I find the FireMon is easier to understand and get rolling with. While both require some learning, FireMon is by far the easier one. Once you have an understanding of how things are arranged and labeled you can easily import firewalls and begin to work on them to improve them
Read full review
We find that Nessus is a great product, on par if not slightly better compared to Qualys in terms of their pricing model. However, Qualys Cloud Platform has better quality reporting, and offers great tips and suggestions on quickly closing a gap and eliminating the risk. In our organization, both products are great and meet our expectations, but due to pricing, we favor Nessus slightly more.
Read full review
Scalability
Firemon Is easily scalable and maintainable with any size team. Although it requires some tech debt, it is well worth the time to invest to ensure compliance is visible and reports are accurate. Although our environment is very large we do not fully utilize the scalability of the Firemon product.
Read full review
No answers on this topic
Return on Investment
  • It helps us save us time in determining what change was made and by whom.
  • Real time alerting is a great convenience in helping us know if something went wrong, we can immediately review the last report to determine what has changed.
  • Allows us to determine what rules are not used and if said rules are still required.
Read full review
  • The most important thing that happens with this program is to automate one hundred percent the security of my system since this program is in charge of supervising each of the applications and websites in detail.
  • One of the purposes for which we trust Qualys Cloud Platform is to keep our system clean and secure; the ability of this software to manage our vulnerability makes us more cautious about working with it.
Read full review
ScreenShots