TrustRadius: an HG Insights company

Qualys TruRisk Platform Reviews and Ratings

Rating: 6 out of 10
Score
6 out of 10

Community insights

TrustRadius Insights for Qualys TruRisk Platform are summaries of user sentiment data from TrustRadius reviews and, when necessary, third party data sources.

Pros

Informative Reports: Many users have praised the informative reports generated by Qualys Cloud Platform. Several reviewers have mentioned that the platform provides detailed and comprehensive reports, allowing them to easily identify security vulnerabilities in their systems. This feature has been highly appreciated by a significant number of customers.

Accurate Vulnerability Identification: The platform's capabilities in accurately identifying security vulnerabilities have been lauded by numerous users. Reviewers have highlighted that Qualys Cloud Platform effectively scans and detects potential weaknesses in their systems, providing them with reliable information to address these issues promptly. This aspect has received positive feedback from a substantial portion of customers.

User-friendly Interface: A considerable number of reviewers have commended the user-friendly interface of Qualys Cloud Platform. Users appreciate how easy it is to navigate through the platform and access different features without any technical difficulties. This intuitive design has made it convenient for many customers to use and maximize the benefits of the platform.

Reviews

25 Reviews

Qualys Review

Rating: 8 out of 10
Incentivized

Use Cases and Deployment Scope

Qualys is used to scan periodically the environment in order to check if there are some packages (Linux) or Applications (Windows) outdated, generating reports to the Service Owners to let them know what's the current situation regarding their environment to schedule

Pros

  • OS inventory
  • Updated Database
  • Vulnerability Addressed

Cons

  • Reports should be improved
  • Knowledge Base (forums)
  • documentation

Likelihood to Recommend

In our company basically we use Qualys to scan periodically environment in order to check if there are some packages (Linux) or Applications (Windows) outdated, generating reports to the Service Owners helping them to addressing the findings scheduling to apply patches. So the tool's functionality fulfills the purpose expected from us.

Vetted Review
Qualys TruRisk Platform
3 years of experience

Qualys Cloud Platform is a great program.

Rating: 10 out of 10
Incentivized

Use Cases and Deployment Scope

The performance that we have had with this program has been great since it has been the only program that has offered us a long list of options to scan as well as manage the level of vulnerability in all the applications and websites where our system runs, thanks With the help of Qualys Cloud Platform you can see in detail all the IT services that I use the most.

Pros

  • One of the main features that I like about this program is the multiple options and powerful functions that I have at my fingertips to strengthen the security of my system.
  • Qualys Cloud Platform is a great program that gives the opportunity to all its users to keep track of each of the processes on the web, complying with the mandatory policies and manipulating the least risky applications.
  • Thanks to the support of this program, all my commercial projects on the web are entirely safe; Qualys Cloud Platform will take care of avoiding each of the threats on the web.

Cons

  • This program is really complicated, the multiple functions that are presented to us are not very clear and in some cases, it is a matter of intuition to execute a function, it is not very informative.
  • The interface of this program can be a real problem; for our taste, this program looks a bit messy, and the interface does not help or guide you to find the options you need.

Likelihood to Recommend

It is essential for a company that works largely on the web to maintain stable security and visualize the vulnerability of its state and of the web applications that are regularly put to the test; Qualys Cloud Platforms is the perfect program that will help you with these aspects, as well As long as it's priced right for its features, it's always a pleasure to recommend and showcase the great features of the Qualys Cloud Platform.

Qualys strikes again

Rating: 8 out of 10
Incentivized

Use Cases and Deployment Scope

Qualys Cloud Platform (specifically the Global AssetView module) enabled us to manage, view, and control all devices and endpoints in our organizations and sort them in various ways, push scripts selectively based on group, and generally keep things organized in a way that helped our whole team understand where everything was, and what state it was in, and address concerns immediately if need be.

Pros

  • Sorting
  • Tags
  • Patching

Cons

  • UI
  • Response Time
  • Inaccurate Updating

Likelihood to Recommend

It's a pretty good overall tool. Honestly, it becomes a scale issue. If you have less than 100 devices altogether, this is not the tool for you. There are so many ways to sort devices and keep track of important tags, but below a certain level it is entirely overkill.

Vetted Review
Qualys TruRisk Platform
2 years of experience

Qualys Cloud Platform review

Rating: 8 out of 10
Incentivized

Use Cases and Deployment Scope

We use Qualys Cloud Platform to help us to

identify vulnerabilities, monitor for threats, and respond to security

incidents.

The automation of the scanning and reporting, saves us a lot of time and makes it possible to be aware of the security level of both our internal and external systems and to detect vulnerabilities and prioritize the remediation of them.

Pros

  • automated web application scanning
  • automated reporting
  • cloud asset management
  • remediation guidance

Cons

  • 2fa options are too limited right now
  • adding domains and networks needs a better and easier way
  • discovery and scanning setup could be better integrated
  • not all modules integrate well with eachother

Likelihood to Recommend

with some training it is easy to scan your networks and find assets on your networks.

also unmanaged assets are found and the automated remediation guidance helps to quickly solve or at least remediate the vulnerability.

because the training is really needed to understand the services, it is not easy to let a colleague also use it when you're not available

Vetted Review
Qualys TruRisk Platform
6 years of experience

Integrate Security in the Early Stages of your Software Development Lifecycle

Rating: 10 out of 10
Incentivized

Use Cases and Deployment Scope

We use Qualys Cloud Platform to perform automated Web App Scans on internally developed platforms. Once set, and with the scheduled scans features, there's no more heavy lifting: just wait for the notifications either via mail or the ticketing system, download the report in pdf format, and escalate/assign to the right stakeholders.

Pros

  • Scheduled scans.
  • Detailed reports with graphs.
  • Notify when there's a [potential] vulnerability

Cons

  • Modernize the Web GUI.

Likelihood to Recommend

<div>Qualys Cloud Platform makes the dark corners of your webapp visible. What's visible can be made secure.</div><div>This allows you to focus on the important: your security and compliance posture.</div><div>With the automated scheduled scanning, reporting, and notifying you pretty much don't have any heavy lifting to do.</div><div>It also offers native integrations with the major Cloud Providers.

</div>

Vetted Review
Qualys TruRisk Platform
1 year of experience

Qualys Cloud Platform for Patch Management is a quick and effective tool to get started

Rating: 8 out of 10
Incentivized

Use Cases and Deployment Scope

We used the platform as a part of the Patch Management tool for us and our customer environments. It was good and effective tool, to work on the patching activities, with ease of access, smooth functioning. When compared to other tools this was a bit cost effective and also was worth the purchase.

Pros

  • Ease of use
  • Simplified UI
  • Simple operations

Cons

  • Have more integrations for Patching Support
  • Better customer support
  • Support for Zero Day Vulnerability patching

Likelihood to Recommend

Qualys Cloud Platform was used by us in terms of patch deployment for internal and external customers. We used it as to provide Patch management services. Qualys Cloud Platform was integral part of our whole Patch Management as service which was part of the larger officering and completed the whole security aspect.

Vetted Review
Qualys TruRisk Platform
2 years of experience

Qualys Cloud Platform is a trusted solution for global security visibility, detection and remediation

Rating: 9 out of 10
Incentivized

Use Cases and Deployment Scope

We use Qualys cloud platform to monitor our network security, monitor public and privately hosted web applications, and also for asset discovery, threat protection and compliance monitoring. It is a comprehensive security platform that gives us a global single pane of glass view into the security of our network and critical applications.

Pros

  • web application scanning
  • threat protection
  • policy compliance
  • File integrity monitoring
  • Asset discovery
  • Threat protection

Cons

  • Certificate inventory
  • PCI compliance

Likelihood to Recommend

Qualys cloud is well suited as a global solution for monitoring the security of your network. It is well suited for vulnerability scanning, policy compliance, asset discovery and threat protection as well as cloud inventory and application security scanning (for both public web apps and in-house applications). The best feature and also the one that provides us the most value is the VMDR (vulnerability management, detection and response). This is a crucial part of our overall security function. Scenarios where we find it less appropriate are in patch management.

Vetted Review
Qualys TruRisk Platform
7 years of experience

A single guard on door with thousand hands.

Rating: 9 out of 10

Use Cases and Deployment Scope

Integration was one of our key challenges as we were going through a consolidation of many tools. Bringing everything together and getting visibility in one Qualys dashboard has helped us. To secure our IT infrastructure and manage all risks related to our assets in one place is very easy now. Now we can see everything related to asset on dashboard and take action quickly.

Pros

  • Infrastructure Security
  • Network Security
  • Cloud Security
  • Asset Management

Cons

  • Patch Management
  • Application Security
  • Ghost/Shadow Asset Scanning

Likelihood to Recommend

As a member of an Endpoint security team, I worked on finding a variety and quantity of Endpoints on the network and Qualys VMDR helped us a lot to find those and do security and compliance risk. It continuously protects all your endpoints from suspicious activity and attacks from prevention to detection to response.

Automated Threat Protection reaches all corners of our organization to provide an end-to-end security solution for the 21st Century

Rating: 7 out of 10
Incentivized

Use Cases and Deployment Scope

Qualys Cloud Platform provides our organization with the tools needed to protect our organization, from end-to-end. It bolsters our security stance in a multi-faceted approach, including our IT infrastructure, our data and applications in the cloud, our endpoints, and compliance all over the world. The best feature of Qualys would be it's automated threat protection which gives us alerts &amp; warnings in realtime, leading to actionable insights that keep our business secure.

Pros

  • Real time threat protection, with alerts & remediation
  • Total visibility into the security of our organization via a single-pane
  • Easily scalable for additional infrastructure, end users, and policy updates

Cons

  • Customer support tends to be slower, often leading to the tail end of guaranteed SLA's
  • Major downside is that QCP charges you for each scanner, leading to high cost
  • False positives can end up wasting more time, rather than saving it

Likelihood to Recommend

Qualys Cloud Platform is well suited for organizations that need additional tools to secure and bolster their security from end to end. The automated, real-time threat protection is very quick to notify an admin of potential vulnerabilities and risks, as well as recommending quick fixes to resolve/close the gap before an incident occurs. QCP excels at portraying all of these in a single pane of glass, and find that the Qualys reports are more detailed than competitor product lines. One of our big issues with QCP is that you do have to pay for each scanner, which can quickly add up to large costs. For this reason, I would rate Qualys at a ~7 due to great features and functionality, but overall value could be better for a large organization. I would also say that QCP may make more sense for smaller organizations due to this pricing model.

Vetted Review
Qualys TruRisk Platform
2 years of experience

Qualys Policy Compliance - You are covered every second in this Cyber Security world.

Rating: 9 out of 10
Incentivized

Use Cases and Deployment Scope

Qualys Policy Compliance helps an organization to create policy, establish controls, write user-defined controls and manage the entire compliance of the organization. It also has an easy-to-use UI and creates a unified dashboard that helps C-level executives with decision-making based on the security posture of the organization. Based on the reports and dashboard, it's easy to take corrective action.

Pros

  • Controls Management.
  • Unified dashboard for security posture.
  • Organization security policy effectiveness.
  • Ease of configuration.

Cons

  • Some of the tasks to select sensors can be automated.
  • Controls customisation can be improved.
  • Technology support can be improved.

Likelihood to Recommend

If you have a large IT landscape of different operating systems and want a common assessment tool for vulnerabilities, and compliance and also have your own policies, you can create your own customized Compliance management view. Create your own customized controls apart from NIST, and CIS controls. Have a parallel scanner to improve scanning performance and reduce the timeline.