No more typing reviews! Try our Samantha, our new voice AI agent.

BMC Helix Cloud Security vs OpenNebula comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Qualys TotalCloud
Sponsored
Average Rating
8.6
Reviews Sentiment
7.3
Number of Reviews
39
Ranking in other categories
Vulnerability Management (11th), Container Security (11th), Cloud Workload Protection Platforms (CWPP) (8th), Cloud Security Posture Management (CSPM) (8th), SaaS Security Posture Management (SSPM) (1st), Cloud-Native Application Protection Platforms (CNAPP) (6th)
BMC Helix Cloud Security
Average Rating
8.0
Reviews Sentiment
7.5
Number of Reviews
5
Ranking in other categories
Cloud Workload Protection Platforms (CWPP) (25th), Cloud Security Posture Management (CSPM) (38th)
OpenNebula
Average Rating
8.2
Reviews Sentiment
7.0
Number of Reviews
15
Ranking in other categories
Cloud Management (17th)
 

Mindshare comparison

Cloud Workload Protection Platforms (CWPP) Mindshare Distribution
ProductMindshare (%)
BMC Helix Cloud Security1.2%
Microsoft Defender for Cloud13.2%
AWS GuardDuty10.4%
Other75.2%
Cloud Workload Protection Platforms (CWPP)
Cloud Management Mindshare Distribution
ProductMindshare (%)
OpenNebula1.7%
VMware Aria Automation5.5%
IBM Turbonomic4.7%
Other88.1%
Cloud Management
 

Featured Reviews

RO
IT Security Expert at Alior Bank S.A.
Unified risk scoring has improved our cloud visibility and simplifies remediation priorities
Qualys TotalCloud provides unified vulnerability and threat assessment across both IAS and SaaS. This solution provides a single prioritized view of risk, which helps reduce the work I would have to do. We are no longer based on CVSS; we are based on Qualys risk scoring, which is based on CVSS plus internal findings made by Qualys, and then assigns its own score. The TruRisk insight feature has found a small number of assets with high vulnerability scores, though I am cautious since some information is classified. Qualys TotalCloud has positively impacted our bank's performance, and we have definitely seen benefits after implementing this solution.
DG
Portfolio Manager/ Helix Administrator at Frontier Communications
A highly scalable and straightforward solution with a knowledgeable support team
We work on a third-party shared environment. It wouldn’t have been feasible for a smaller company. My company was actually the first one to do it. Just like any cloud security, it pays to do your research and have complimentary security involved. The product can’t be the be-all and end-all tool for your security. Overall, I rate the solution a nine out of ten.
FOURES Jean-Philippe - PeerSpot reviewer
Products Manager at a tech services company with 501-1,000 employees
Reliable, simple to manage, and offers great technical support
The support of VXLAN fits with our network management. Thanks to this we can propose mixed solutions using virtual resources on OpenNebula and bare metal servers hosted in our facilities linked to each other on the sale network. This use case is very useful when some applications need bare metal power (Kubernetes workers, huge databases, AI models computations, et cetera). The cluster management is very useful for splitting our different clusters (mutual vs dedicated). We can manage deployments and capacity planning without pain. The API is also really simple and it helped us to develop the Terraform provider to manage OpenNebula like any other cloud infrastructure.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It is a cloud-native app that integrates with both IaaS and SaaS. It seamlessly integrates with other platforms."
"Qualys TotalCloud has improved our security posture."
"The dashboards are particularly valuable as they offer a comprehensive view of the environment, highlighting any misconfigurations."
"Qualys TotalCloud's most valuable feature is its agent versatility."
"The most valuable feature is the consolidated information that it provides from various platforms."
"I like the web API security and IoT scanning features the most. The user-friendly design of TotalCloud's interface enables customers to navigate it and use its full potential easily"
"One of the features I appreciate is the ability to generate daily reports without relying on anyone else."
"Qualys TotalCloud has helped us view our risk structure, vulnerabilities, and security posture."
"It is a good tool to make sure that your containers are safe and sound."
"It's also multi-cloud. You can look at several cloud providers: AWS, Azure, or GCP."
"The best feature is time to value. With very minimal effort, you are able to have a cohesive view into your security posture on one or multiple cloud accounts, particularly if you are dealing with multicloud. If you have Azure and AWS deployments, you might have multiple subscriptions in Azure and usually multiple accounts in AWS. You may even be doing some GCP work (around Google Cloud Platform). It's very difficult to manage a common set of policies, even less reporting, across multiple subscriptions, accounts, and cloud environments. What BMC Helix Cloud Security does is provide a unified view or single pane of glass as to your baseline. Then, it also facilitates the ability for Level 1 or 2 operations support to take action and report on security vulnerabilities."
"The features that I've found most valuable are its container security aspect. I also like its vulnerability management tools."
"The most valuable aspects of BMC Helix Cloud Security are its security features and regulatory compliance capabilities."
"The cool feature of Helix Cloud Security is that you can do all that — understand and remediate issues — in one dashboard, based on the different policies that are available for security, out-of-the-box."
"Using this solution is an eye-opener; having that holistic view is the biggest eye-opener because you understand, from any of your connected cloud accounts, what your vulnerabilities are with it."
"With very minimal effort, you are able to have a cohesive view into your security posture on one or multiple cloud accounts, particularly if you are dealing with multicloud."
"I'll definitely recommend OpenNebula because it's an open-source solution that's effortless to set up, and the total cost of ownership is low."
"It's easy to integrate OpenNebula with our IT systems."
"The service feature appeals most to us, thus it is the most valuable."
"OpenNebula has very good integration with SAP Storage, is easy to use, has a good UI, and is very scalable."
"For the entire data center, as a private cloud, I believe that user management, expert management, and the virtual data center is completely magic for the users."
"The solution provides templates for configurations that can easily be exchanged to VMs."
"For our use case, we found the solution to be the best fit when dealing with infrastructure services."
"It has enabled us to decrease the optics by around 55 to 60%."
 

Cons

"Their support could be improved."
"Qualys' customer service provides quality answers, but the response time is long, even though it is within the SLA."
"Areas that need improvement in every solution include the remediation part. The remediation steps should be simple enough for everyone to understand."
"It has been working very well, but it would be helpful if the dashboard could generate reports tailored to specific compliance needs. For example, in India, we have to comply with RBI and SEBI guidelines. It w"
"TotalCloud could improve its scanning of niche devices like Wi-Fi dongles and USB modems because they are often untested. It covers everything else, like laptops, mobile devices, and Bluetooth IoT devices. They can improve on the small IoT devices because hackers and testers use these."
"The cost of Qualys TotalCloud is high and could be more competitive."
"Qualys TotalCloud's increasing complexity, due to the development and deployment of multiple solutions, is making the GUI difficult to navigate."
"It is already perfect, but they can bring some newer dashboards and customization options for the dashboard. It would be great to be able to include on-prem assets on the dashboard."
"BMC Helix Cloud Security has room for improvement in terms of integrating its various features."
"I think its TOA interfaces are still not that comfortable. The UI could be more user-friendly, easier to use."
"We've had some issues with connectors; the connectors have seemed to cause a little bit of trouble, perhaps with the APIs trying to scan the environment."
"The biggest challenge now, which is a good problem to have, with BMC Helix is content."
"The UI could be more user-friendly."
"Every organization out there doesn't rely on just one control body. They use FISMA control. They may use HIPAA, CIS, PCI, or SOX, then blend them. One of the things that is now in big demand for BMC Helix Cloud Security is content. That's the next journey in its lifespan, making it easier for the community to share and collaborate on content for security controls that can be measured and remediated."
"I want the role-based security feature to be improved."
"We've had some with issues connectors. The connectors have seemed to have caused a little bit of trouble, perhaps with the APIs trying to scan the environment. The only time I've had to reach out to tech support was for that. It seems it may not have been scanning correctly or I wasn't seeing data within a specific time. But we've set up a couple of connectors in the past couple of weeks and they actually scanned the AWS environment and we had data within about 10 minutes. It's working a lot faster and I think they're making improvements as they go."
"They should add more features like object storage."
"There are no payment gateways in OpenNebula."
"Most of the competitors are offering some sort of billing software to transform their installation to work as a small-sized public cloud, but those offerings from OpenNebula are still missing."
"The UI, monitoring, and alerting could benefit from further improvements."
"Backup features are only available in the enterprise edition. The community version lacks a good solution for making backups."
"An area for improvement in OpenNebula is the number of features it has. The solution doesn't have that many cloud features compared to other solutions. You'd say, "Okay, simplicity over a rich feature list?" Some say, "No, I need a big machine or a cloud interface for my customers to manage resources. I don't have to go and do it for them." Some people do it that way, and it works, but I'd like to improve the limited features in OpenNebula."
"The front-facing API can be improved to support lots of requests when the platform is huge with lots of virtual resources."
"Hosting platforms are limited so the deployment process needs improvement."
 

Pricing and Cost Advice

"The pricing for TotalCloud is attractive and competitive in the market. Given the features, especially the dashboard, I have no concerns regarding pricing."
"TotalCloud's price is about right where I would expect it to be."
"While Qualys TotalCloud's pricing is currently acceptable, it is becoming increasingly expensive and may soon be considered overpriced."
"Qualys TotalCloud offers good pricing that is affordable and competitive with the market. Our partnership also provides us with additional benefits."
"Although Qualys TotalCloud is relatively expensive due to its unique automation features, its cost-effectiveness is rated an eight out of ten, with ten being the most costly."
"Qualys TotalCloud offers competitive pricing given its comprehensive suite of features, including integration, assessment, remediation, and detection capabilities, all within a single platform."
"It isn't cheap, but it's reasonable. It helps us to manage things with very few resources."
"Its price seems higher compared to other tools, but it is worth it. If they could adjust the pricing and make it comparable with other tools, that would be great."
"It is a subscription model with term licensing that is usually yearly. This includes, not only the product, but support and maintenance. It is based on cloud assets. Therefore, if you have 100 cloud assets, those cloud assets are measured based on evaluation or transactions. For example, if I'm evaluating that cloud asset for CIS compliance, PCI compliance, and AWS best practices, that asset gets evaluated three times, as those are three transactions. However, the license model is based on peak asset usage. So, over a year, if you deploy 100, 1000, 500, and then 2000 assets, you will be charged for the 2000 peak of assets managed by Helix Cloud Security."
"The pricing is based on an annual subscription, upfront, and it's based on cloud assets. Whether your assets are in Azure and AWS combined, the tool tells you how many assets are being scanned and that's the number used for pricing."
"The solution is open source so is free."
"The licensing for OpenNebula used to be free, but now it's no longer free. A customer contacted me asking to move to another provider because of the changes in the licensing terms for OpenNebula. I have no information on how much the OpenNebula license is because the customer pays for it, and I only do the integration."
"OpenNebula gives good value for money."
"VRA is very expensive but OpenNebula is free."
"OpenNebuoa has recently come up with a new subscription model that is economical and a lot of new customers are choosing this as it is an easy subscription model."
"We use the Community Edition, rather than the Enterprise Edition."
report
Use our free recommendation engine to learn which Cloud Workload Protection Platforms (CWPP) solutions are best for your needs.
900,644 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Manufacturing Company
18%
Financial Services Firm
14%
Construction Company
7%
Comms Service Provider
7%
Construction Company
16%
Comms Service Provider
12%
Performing Arts
9%
Manufacturing Company
9%
Financial Services Firm
12%
Comms Service Provider
10%
Computer Software Company
9%
University
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business10
Midsize Enterprise3
Large Enterprise29
No data available
By reviewers
Company SizeCount
Small Business7
Midsize Enterprise6
Large Enterprise3
 

Questions from the Community

What needs improvement with Qualys TotalCloud?
Areas that need improvement in every solution include the remediation part. The remediation steps should be simple en...
What is your primary use case for Qualys TotalCloud?
Our use case involves the assets that we have under cloud, the assets exposed to the internet, and the internal appli...
Ask a question
Earn 20 points
Ask a question
Earn 20 points
 

Also Known As

Qualys TotalCloud with FlexScan
TrueSight Cloud Security, SecOps Policy Service
No data available
 

Overview

 

Sample Customers

Information Not Available
NHS, Vodafone, Kansas City Life, SKY Italia, Cybera
Akamai, BBC, Fermilab, Terradue, Surf Sara, Produban, Netways, ESA, China Mobile, BlackBerry, Deloitte, Fuze, Telefonica, Trivago, Nokia, Encore Tech, Beeks.
Find out what your peers are saying about Microsoft, Wiz, Amazon Web Services (AWS) and others in Cloud Workload Protection Platforms (CWPP). Updated: June 2026.
900,644 professionals have used our research since 2012.