A decent vulnerability scan platform
November 06, 2019

A decent vulnerability scan platform

Anonymous | TrustRadius Reviewer
Score 7 out of 10
Vetted Review
Verified User

Overall Satisfaction with Qualys Cloud Platform (formerly Qualysguard)

We use Qualys as the main vulnerability scanner. It is used to scan the on-premise devices such as servers, switches, etc.
We have several scanners deployed in different locations in order to cover all sites, and scheduled scans that run on a periodic basis.
Qualys helps us to prioritize the mitigation, it includes not only OS patches, but also 3rd party software.
  • Cloud-based management.
  • Detailed info about the findings: reason, effect, risk, mitigations, etc.
  • Clear UI.
  • Additional modules can be added to the same management interface.(single point of management).
  • Notices some findings which were not clear why they appear(suspected false positive).
  • Working with Qualys support(for example due to the previous point) wasn't the best experience. the response was very slow.
  • Qualys limit the daily API requests. In case you need more, it will cost.
  • It depends on your industry, you may be obligated to have a scheduled scan on your network.
  • The pricing module is per IP - so if the network is large and centralized you should expect to pay more.
I had a bad experience with Qualys' support, slow response, and cumbersome troubleshooting process.
In one case I had to escalate to 3rd level support, which also took a lot of time.

Do you think Qualys TruRisk Platform delivers good value for the price?

Not sure

Are you happy with Qualys TruRisk Platform's feature set?

Yes

Did Qualys TruRisk Platform live up to sales and marketing promises?

Yes

Did implementation of Qualys TruRisk Platform go as expected?

Yes

Would you buy Qualys TruRisk Platform again?

Yes

Installation: Qualys is a cloud-based service (cloud management), in case you require an offline solution, Qualys is not the solution for you.
You can scan all types of devices: servers, endpoints, network equipment, FW, and much more, including Cloud workloads (they have a dedicated appliance for IaaS).
For endpoints, it's better to use their Agent in order to avoid running the scans over the network. this has an additional cost.
For Compliance needs, Qualys is good enough.