No more typing reviews! Try our Samantha, our new voice AI agent.

BigID Next vs Proofpoint Data Security Posture Management comparison

Why PeerSpot?
Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jul 21, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Qualys TotalCloud
Sponsored
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
46
Ranking in other categories
Vulnerability Management (11th), Container Security (11th), Cloud Workload Protection Platforms (CWPP) (8th), Cloud Security Posture Management (CSPM) (8th), SaaS Security Posture Management (SSPM) (2nd), Cloud-Native Application Protection Platforms (CNAPP) (7th)
BigID Next
Average Rating
8.2
Reviews Sentiment
7.0
Number of Reviews
15
Ranking in other categories
Data Loss Prevention (DLP) (12th), Data Governance (8th), Data Privacy Management Software (1st), Data Security Posture Management (DSPM) (5th), AI Data Analysis (8th), Data Security Platforms (DSP) (1st)
Proofpoint Data Security Po...
Average Rating
9.0
Reviews Sentiment
3.6
Number of Reviews
1
Ranking in other categories
Data Security Posture Management (DSPM) (21st), Data Security Platforms (DSP) (9th)
 

Featured Reviews

reviewer2859021 - PeerSpot reviewer
Sr Security Engineer at a tech vendor with 5,001-10,000 employees
Risk-based triage has transformed container security and now prioritizes high-impact threats
The best features Qualys TotalCloud offers currently include managing cloud infrastructure and container security while facing major challenges such as alert fatigue. Traditional vulnerability scanners flag hundreds of CVEs on short-lived Kubernetes containers, some of which have no internet exposure or are gone before we can even triage them. I leverage Qualys TotalCloud to move beyond static CVSS. I use it to implement runtime exposure, correlation risk reprioritization, and shift-left integration. This notifies developers to fix a base image upstream rather than patching live ephemeral instances. In my work with cloud and container security, the biggest operational hurdle was alert fatigue. I use Qualys to shift left from static CVSS severity to context-aware risk prioritization. I correlated raw vulnerability data with real-time risk factors such as public network exposure, active runtime execution, or overly permissive IAM roles. This allows us to immediately drop the priority of isolated containers and escalate lower-severity CVEs that sit on an exposed, high-risk path. We can map these findings directly back to our CI/CD pipelines so developers can patch the root base images upstream. We have drastically cut down the signal-to-noise ratio, saved a lot of manual hours doing triage work, and ensured engineering effort goes directly towards high-impact risk reduction.
Aniruddha Nath - PeerSpot reviewer
Senior Security Consultant at a consultancy with 10,001+ employees
Data discovery has transformed compliance workflows and automation now speeds up requests and remediation
The best feature that BigID offers is data discovery and classification, which is the most powerful engine. It allows connecting to many different data sources, ranging from cloud to on-premises to structured to unstructured data. If there is no connector available, you can build your own classifiers as well. Regarding the custom classifier option, you can build custom classifiers using regular expressions, and I have done that if you know how to create regular expressions. Custom connectors are something you create to connect to a database where the connector is not available. BigID has positively impacted my organization as it's a very powerful tool, especially with the increasing regulatory compliances for different countries such as GDPR, CCPA, and India's recent DPDPA act. Having these tools in place greatly helps organizations avoid any penal charges for not being compliant with the regulatory compliances. For example, regarding compliance or reduced risks for my clients, the DSAR process I was talking about allows organizations to respond quickly to user data deletion requests under GDPR law, which traditionally has a 30-day or 60-day timeline. In larger organizations, when the number of requests is high, it becomes tedious. However, using DSAR automation with BigID, it's almost instantaneous; instead of 30 days, you can respond in just one day to what users have requested.
EO
Senior Solutions Architect at Cyber Knight Technologies FZ LLC
AI classification has transformed data visibility and now simplifies policy‑driven protection
In my opinion, what should be improved about Proofpoint Data Security Posture Management is that it is quite advanced. I think they should ease it up a bit. When it comes to setting of policies, I wish there were a single policy that deals with multiple channels of exfiltration instead of having to do multiple policies to deal with maybe data exfiltration through web upload, data exfiltration through USB, data exfiltration through print, copy and paste, and so forth. It would have been much easier if I had one policy, and then I could turn on the light for all of these different exfiltration channels. A critical example is saying I want to put up a PII policy that will secure social security numbers. That is the condition, social security number. Then in the same policy, I should be able to state that I want this to block exfiltration through USB. However, I want it to allow uploads through web or uploads to a particular website or URL. I want it to allow that kind of granularity where you can flick around things on the same policy. Currently, with Proofpoint Data Security Posture Management, you have to build multiple policies for different channels. Most importantly, the Boolean logic in their policies is incomplete. It just has the AND function. Boolean should carry AND and OR. I am saying if this data contains PII data OR PCI data—either of them—it flags either PCI or PII. But what it has now is AND. For it to fire or trigger, both must be triggered. So if somebody puts only one, maybe PII, and does not put PCI, then it does not trigger. It should have an OR, so that I can have multiple policies and then differentiate them so that if this OR this OR this, either of these triggers. I have flagged that and raised that as a concern to the product team. I expect additional features from them in the next release, specifically the OR feature for the conditions. However, I am happy with the agent, the lightweight agent, the amount of activities it captures. Beyond just the DLP, it looks at the sites and URLs you are going to, it looks at the file renaming, it looks at the attempt to uninstall, and it looks really deep even though it is user mode. I am happy with that. The Boolean logic is what I think is incomplete at the moment.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The agent and agentless scanning in TotalCloud, particularly the FlexScan method, is incredibly valuable. With traditional scanning approaches, we had to give IP ranges and whitelist IPs. All that is now simplified. FlexScan requires minimal intervention, and after configuration, it automatically collects data and performs necessary scans."
"Qualys TotalCloud has significantly improved our organization by automating our reporting processes, reducing the time spent on report creation from two hours to less than fifteen to twenty minutes."
"The biggest strengths of Qualys TotalCloud are that it is pretty good at cloud visibility, has easy integration, and also has multi-cloud compatibility."
"The dashboards are particularly valuable as they offer a comprehensive view of the environment, highlighting any misconfigurations."
"One of the features I appreciate is the ability to generate daily reports without relying on anyone else."
"Qualys TotalCloud has improved our security posture."
"Its dashboards are brilliant. It provides in-depth insights."
"Qualys TotalCloud is overall the best tool available in the market for scanning purposes."
"The tool's most valuable feature is correlation. Using BigID's data classification capabilities has strengthened our data security. It lets me classify and connect data, which helps me manage data at various classification levels."
"BigID is more advanced than Microsoft Purview when it comes to machine learning and AI development tools."
"It provides a unified view across different databases and supports a wide range of data source types, including cloud and on-premises systems."
"Although I was serving the client rather than my own organization, BigID has made scans faster and more efficient, and the DSR results are much more accurate."
"The best feature that BigID offers is data discovery and classification, which is the most powerful engine, allowing connection to many different data sources ranging from cloud to on-premises and from structured to unstructured data, with the ability to build your own classifiers if no connector is available."
"I like BigID's in-depth discovery and scanning capabilities, especially for unstructured data. This feature is a standout compared to competitors. The tool's data classification capabilities are impressive. It offers custom classifiers and a blend of regular exploration and artificial intelligence, making it a next-generation solution. This enhances data security, and its security posture management is straightforward and user-friendly."
"One of the most valuable things in a data-focused world is a tool, a technology that's data-centric, not trying to master data management or whatever else. It's a source of truth for what data an organization holds, giving it the ability to catalog, categorize, and understand its data."
"The most valuable feature of BigID is its large number of classifiers, which allow us to scan for specific data such as SSN numbers."
"It has helped my data security strategy very well because one thing is to set static DLP rules, however, how do you start setting rules when you have little or zero visibility as to where your critical or sensitive data resides?"
 

Cons

"Qualys' customer service provides quality answers, but the response time is long, even though it is within the SLA."
"There is room for improvement in vulnerability scanning, particularly for PaaS environments. Currently, Qualys does not have full access to these instances, which limits its effectiveness."
"Areas that need improvement in every solution include the remediation part. The remediation steps should be simple enough for everyone to understand."
"The cloud licensing unit system is unclear, especially since "units" aren't well-defined."
"The cost of Qualys TotalCloud is high and could be more competitive."
"Qualys TotalCloud needs to improve its accuracy for non-Windows operating systems."
"One of the things that could be improved is the alerts. Qualys is a fantastic tool, especially with the TruRisk feature, but one challenge that most leaders face involves alert fatigue."
"We encountered challenges identifying the correct resource category for certain items, such as those in containers or storage."
"BigID is making some forays into the GRC space, and that's a natural progression. I'd like to see that improve so that data governance is better, data risk is identified, and the ability to control and mitigate it."
"The challenge we encountered was with data connection across multiple databases. We struggled with configuring the data connection successfully. However, with the assistance of dynamic teams, we resolved this issue."
"Improvement could be made in data consent management and data privacy impact assessment."
"Some users find catalog navigation challenging due to the lack of a search-by-column feature, which makes it difficult to locate specific data quickly."
"I want them to focus on data mapping, assessment, automation workflow, and privacy incident management. The privacy tools have not been widely used, and they have not invested much in privacy code privacy tools."
"The tool currently lacks security features."
"BigID needs improvement in terms of automation."
"There are some shortcomings when it comes to Calvirus authentication, which is not yet supported by BigID."
"In my opinion, what should be improved about Proofpoint Data Security Posture Management is that it is quite advanced."
 

Pricing and Cost Advice

"TotalCloud's price is about right where I would expect it to be."
"The pricing for TotalCloud is attractive and competitive in the market. Given the features, especially the dashboard, I have no concerns regarding pricing."
"Although Qualys TotalCloud is relatively expensive due to its unique automation features, its cost-effectiveness is rated an eight out of ten, with ten being the most costly."
"Qualys TotalCloud is expensive."
"Qualys TotalCloud offers competitive pricing given its comprehensive suite of features, including integration, assessment, remediation, and detection capabilities, all within a single platform."
"Qualys TotalCloud is expensive, but it offers a premier solution with no headaches."
"The cost is high, but it meets our organizational needs."
"Qualys TotalCloud offers good pricing that is affordable and competitive with the market. Our partnership also provides us with additional benefits."
"The solution is not licensed per user but rather based on capacity. For instance, organizations with large amounts of data, such as 50 GB or more, are the ones that typically qualify for BigID."
"The solution is expensive."
"The product is expensive, but so are all competitor tools"
"I think that BigID's pricing is very reasonable."
"The pricing depends. If you have thousands of data sources to connect and manage, and you struggled with an MDM package in the past, you'll find BigID valuable and even cheap. But if you're a small business, it's probably not the right tool for you."
Information not available
report
Use our free recommendation engine to learn which Data Security Posture Management (DSPM) solutions are best for your needs.
913,683 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Comms Service Provider
16%
Outsourcing Company
12%
Manufacturing Company
11%
Financial Services Firm
10%
Financial Services Firm
18%
Manufacturing Company
11%
Insurance Company
7%
Comms Service Provider
7%
Financial Services Firm
13%
Manufacturing Company
9%
Outsourcing Company
9%
Comms Service Provider
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business14
Midsize Enterprise5
Large Enterprise34
By reviewers
Company SizeCount
Small Business5
Large Enterprise11
No data available
 

Questions from the Community

What needs improvement with Qualys TotalCloud?
In terms of improvement, remediation still belongs to the cloud team, which is one of the issues we faced with Qualys...
What is your primary use case for Qualys TotalCloud?
My main use case for Qualys TotalCloud is regarding the cloud visibility that we were not having previously. Previous...
What needs improvement with BigID?
One improvement I would suggest is addressing the intermittent failures of BigID scans, as there are times when some ...
What is your primary use case for BigID?
BigID's main use case is connecting to various data sources to perform the data discovery process, classify the data ...
What advice do you have for others considering BigID?
I have covered information regarding data scanning, data classification, and the DSAR module, as these are the parts ...
Ask a question
Earn 20 points
 

Also Known As

Qualys TotalCloud with FlexScan
No data available
No data available
 

Overview

 

Sample Customers

Information Not Available
Home Depot, Grant Thornton LLP, Cimpress, Fidelity Investments
Information Not Available
Find out what your peers are saying about Wiz, Palo Alto Networks, Varonis and others in Data Security Posture Management (DSPM). Updated: September 2026.
913,683 professionals have used our research since 2012.