No more typing reviews! Try our Samantha, our new voice AI agent.

BMC Helix Cloud Security vs VMware Aria Automation comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Qualys TotalCloud
Sponsored
Ranking in Cloud Security Posture Management (CSPM)
8th
Average Rating
8.6
Reviews Sentiment
7.3
Number of Reviews
39
Ranking in other categories
Vulnerability Management (11th), Container Security (11th), Cloud Workload Protection Platforms (CWPP) (8th), SaaS Security Posture Management (SSPM) (1st), Cloud-Native Application Protection Platforms (CNAPP) (6th)
BMC Helix Cloud Security
Ranking in Cloud Security Posture Management (CSPM)
38th
Average Rating
8.0
Reviews Sentiment
7.5
Number of Reviews
5
Ranking in other categories
Cloud Workload Protection Platforms (CWPP) (25th)
VMware Aria Automation
Ranking in Cloud Security Posture Management (CSPM)
20th
Average Rating
8.0
Reviews Sentiment
6.8
Number of Reviews
172
Ranking in other categories
Cloud Management (3rd), Configuration Management (8th), Network Automation (5th), Cloud Infrastructure Entitlement Management (CIEM) (6th)
 

Mindshare comparison

As of June 2026, in the Cloud Security Posture Management (CSPM) category, the mindshare of Qualys TotalCloud is 1.6%, up from 1.2% compared to the previous year. The mindshare of BMC Helix Cloud Security is 0.8%, up from 0.3% compared to the previous year. The mindshare of VMware Aria Automation is 1.0%, up from 0.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Cloud Security Posture Management (CSPM) Mindshare Distribution
ProductMindshare (%)
Qualys TotalCloud1.6%
VMware Aria Automation1.0%
BMC Helix Cloud Security0.8%
Other96.6%
Cloud Security Posture Management (CSPM)
 

Featured Reviews

RO
IT Security Expert at Alior Bank S.A.
Unified risk scoring has improved our cloud visibility and simplifies remediation priorities
Qualys TotalCloud provides unified vulnerability and threat assessment across both IAS and SaaS. This solution provides a single prioritized view of risk, which helps reduce the work I would have to do. We are no longer based on CVSS; we are based on Qualys risk scoring, which is based on CVSS plus internal findings made by Qualys, and then assigns its own score. The TruRisk insight feature has found a small number of assets with high vulnerability scores, though I am cautious since some information is classified. Qualys TotalCloud has positively impacted our bank's performance, and we have definitely seen benefits after implementing this solution.
DG
Portfolio Manager/ Helix Administrator at Frontier Communications
A highly scalable and straightforward solution with a knowledgeable support team
We work on a third-party shared environment. It wouldn’t have been feasible for a smaller company. My company was actually the first one to do it. Just like any cloud security, it pays to do your research and have complimentary security involved. The product can’t be the be-all and end-all tool for your security. Overall, I rate the solution a nine out of ten.
VasilisGiannitsiotis - PeerSpot reviewer
Senior IT at ITSolutions
Automation has streamlined complex financial workflows but still needs more intuitive orchestration
Something to improve in VMware Aria Automation would be related to VCF 9, as I do not know what it is trying to bring because they exposed it as the solution of everything. So VCF 9 will bring VCF Automation and VCF Operations, the new product line of VMware. I have not seen what this brings or what else it includes. Maybe in the area of vRealize Orchestrator, this would be beneficial because VRO can do everything. Perhaps a more user-friendly way to use that tool would be helpful because the possibilities there are endless. I am looking for more user-friendly navigation in VMware Aria Automation.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Its excellent graphical interface makes the scanning process simple."
"The vulnerability management feature is the one I like the most because it provides a clear picture of all vulnerabilities."
"Qualys TotalCloud has positively impacted our bank's performance, and we have definitely seen benefits after implementing this solution."
"TotalCloud's best feature is the integration of cloud accounts. It helps with the risk and security posture management of our cloud infrastructure."
"Vulnerability and threat detection and assessment of the criticality of the vulnerabilities exposed are most valuable."
"Qualys TotalCloud fulfills all these needs."
"The dashboards are particularly valuable as they offer a comprehensive view of the environment, highlighting any misconfigurations."
"I would definitely recommend it because it is easy to handle any cloud resources."
"The cool feature of Helix Cloud Security is that you can do all that — understand and remediate issues — in one dashboard, based on the different policies that are available for security, out-of-the-box."
"The most valuable aspects of BMC Helix Cloud Security are its security features and regulatory compliance capabilities."
"It is a good tool to make sure that your containers are safe and sound."
"It's also multi-cloud. You can look at several cloud providers: AWS, Azure, or GCP."
"The best feature is time to value. With very minimal effort, you are able to have a cohesive view into your security posture on one or multiple cloud accounts, particularly if you are dealing with multicloud. If you have Azure and AWS deployments, you might have multiple subscriptions in Azure and usually multiple accounts in AWS. You may even be doing some GCP work (around Google Cloud Platform). It's very difficult to manage a common set of policies, even less reporting, across multiple subscriptions, accounts, and cloud environments. What BMC Helix Cloud Security does is provide a unified view or single pane of glass as to your baseline. Then, it also facilitates the ability for Level 1 or 2 operations support to take action and report on security vulnerabilities."
"Using this solution is an eye-opener; having that holistic view is the biggest eye-opener because you understand, from any of your connected cloud accounts, what your vulnerabilities are with it."
"With very minimal effort, you are able to have a cohesive view into your security posture on one or multiple cloud accounts, particularly if you are dealing with multicloud."
"Role-based security is a valuable feature."
"The setup was complex in many ways. The first reason is that we have many teams who work on it so it gets complicated gathering all of the people. The second reason is that it can be complicated to install it quickly, within a reasonable amount of time."
"SaltStack being so fast makes it very convenient and practical; allows me to get information about my servers in no time."
"It improves the work, making it better."
"The automation really is priceless."
"The benefits are that it gives you a heads-up display and dashboard of the way everything's running. The ability to automate around those tasks is really where we get the value."
"It is also intuitive and user-friendly... With vRealize, we can have a Help Desk individual, who might not be that techy, provision the different elements quite easily, with no almost training at all."
"We use it as a self-service customer portal for all of our present customers, and so far it's going pretty well with a lot fewer tickets and much faster onboarding."
"I find the system to be intuitive and user-friendly. In general, I'm quite happy with the entire setup. Once you configure the system, navigating the portal is pretty simple. They use a lot of the vSphere UI interface structure so it's intuitive, especially if you have used anything vSphere-related before."
 

Cons

"The response part of the Cloud Detection and Response (CDR) module can be improved."
"In my opinion, what can be improved in Qualys TotalCloud includes pricing and container scanning."
"It has been working very well, but it would be helpful if the dashboard could generate reports tailored to specific compliance needs. For example, in India, we have to comply with RBI and SEBI guidelines. It w"
"There is room for improvement in the support."
"The cloud licensing unit system is unclear, especially since "units" aren't well-defined."
"The areas in the solution that have room for improvement include the UI/UX design, which should be improved, and they should integrate more artificial intelligence into the product."
"The cost of Qualys TotalCloud is high and could be more competitive."
"Enhancing clarity regarding its compliance capabilities would be beneficial, as the current scope is limited in geographic coverage."
"We've had some issues with connectors; the connectors have seemed to cause a little bit of trouble, perhaps with the APIs trying to scan the environment."
"I think its TOA interfaces are still not that comfortable. The UI could be more user-friendly, easier to use."
"I want the role-based security feature to be improved."
"The biggest challenge now, which is a good problem to have, with BMC Helix is content."
"Every organization out there doesn't rely on just one control body. They use FISMA control. They may use HIPAA, CIS, PCI, or SOX, then blend them. One of the things that is now in big demand for BMC Helix Cloud Security is content. That's the next journey in its lifespan, making it easier for the community to share and collaborate on content for security controls that can be measured and remediated."
"The UI could be more user-friendly."
"BMC Helix Cloud Security has room for improvement in terms of integrating its various features."
"We've had some with issues connectors. The connectors have seemed to have caused a little bit of trouble, perhaps with the APIs trying to scan the environment. The only time I've had to reach out to tech support was for that. It seems it may not have been scanning correctly or I wasn't seeing data within a specific time. But we've set up a couple of connectors in the past couple of weeks and they actually scanned the AWS environment and we had data within about 10 minutes. It's working a lot faster and I think they're making improvements as they go."
"As a product, it is complicated to integrate and automate with other products."
"There are still some issues such that, if you are going to go 100% cloud, if you don't want anything on-premise, there are some other solutions that might have a leg up."
"There is some performance lag, but that could be on our end."
"Not as good, but there are some components in vRA that you can scale out a lot more quickly than other pieces."
"That ServiceNow implementation is a little rough, but those guys in Ohio are doing a great job on it."
"For the administrator, it can be a little challenging. For the administrator, there are a lot of moving parts. It is fine once you figure out where the knobs are you need to twiddle, but it can be a challenge to get it up and running."
"It's not cheap."
"There is an area of improvement. For example, you are migrating from a customer's existing data center to a new target data center. To facilitate this transition, you'll initially need to evaluate the customer's aging hardware hosting VMware, which is nearing the end of its operational life. The customer expresses the intention to upgrade to a newer version, necessitating an overhaul of everything in the new data center. As a Systems Integrator (SI), consultant, or architect, your recommendation would be to acquire the latest hardware with a specified configuration and then install VMware on top of it. However, there's a crucial aspect related to the infrastructure requirements for VMware to run seamlessly on that hardware. If there's an opportunity to potentially reduce these infrastructure prerequisites, it would be highly beneficial."
 

Pricing and Cost Advice

"Qualys TotalCloud is expensive, but it offers a premier solution with no headaches."
"TotalCloud's price is about right where I would expect it to be."
"The pricing for TotalCloud is attractive and competitive in the market. Given the features, especially the dashboard, I have no concerns regarding pricing."
"The cost is high, but it meets our organizational needs."
"Although Qualys TotalCloud is relatively expensive due to its unique automation features, its cost-effectiveness is rated an eight out of ten, with ten being the most costly."
"Qualys TotalCloud is cost-efficient and was selected for its value compared to other products."
"Its price seems higher compared to other tools, but it is worth it. If they could adjust the pricing and make it comparable with other tools, that would be great."
"Qualys TotalCloud offers competitive pricing given its comprehensive suite of features, including integration, assessment, remediation, and detection capabilities, all within a single platform."
"It is a subscription model with term licensing that is usually yearly. This includes, not only the product, but support and maintenance. It is based on cloud assets. Therefore, if you have 100 cloud assets, those cloud assets are measured based on evaluation or transactions. For example, if I'm evaluating that cloud asset for CIS compliance, PCI compliance, and AWS best practices, that asset gets evaluated three times, as those are three transactions. However, the license model is based on peak asset usage. So, over a year, if you deploy 100, 1000, 500, and then 2000 assets, you will be charged for the 2000 peak of assets managed by Helix Cloud Security."
"The pricing is based on an annual subscription, upfront, and it's based on cloud assets. Whether your assets are in Azure and AWS combined, the tool tells you how many assets are being scanned and that's the number used for pricing."
"vRealize automation really should be a front door to the whole VMware suite of products."
"The solution has helped to increase infrastructure, agility, speed, and provisioning in the time to market."
"I'm very interested in the integration with Puppet. However, my organization doesn't have the funding for something like Puppet right now. If VMware would integrate that feature set (Puppet) into vRA. That would be very awesome."
"There is confusion between licensing levels. There are three different licensed versions of vRealize Automation, and there are different things which can happen in each of them."
"The tool is expensive since it is an enterprise product."
"We do plan to see ROI with any new implementation of new technologies being implemented within our environment."
"It is an expensive product. After VMware's acquisition by Broadcom, there was a rise in the price of VMware Aria Automation."
"Better pricing is always handy, but I feel it's at the right price point."
report
Use our free recommendation engine to learn which Cloud Security Posture Management (CSPM) solutions are best for your needs.
900,747 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Manufacturing Company
18%
Financial Services Firm
14%
Construction Company
7%
Comms Service Provider
7%
Construction Company
16%
Comms Service Provider
13%
Performing Arts
9%
Manufacturing Company
9%
Financial Services Firm
11%
Manufacturing Company
9%
Computer Software Company
7%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business10
Midsize Enterprise3
Large Enterprise29
No data available
By reviewers
Company SizeCount
Small Business33
Midsize Enterprise24
Large Enterprise131
 

Questions from the Community

What needs improvement with Qualys TotalCloud?
Areas that need improvement in every solution include the remediation part. The remediation steps should be simple en...
What is your primary use case for Qualys TotalCloud?
Our use case involves the assets that we have under cloud, the assets exposed to the internet, and the internal appli...
Ask a question
Earn 20 points
What's the difference between VMware vRA (automation) and vROps (operations)?
vROP is a virtualization management solution from VMWare. It is efficient and easy to manage. You can find anything y...
Is there any way to try VMware Aria Automation for free?
When it comes to VMware Aria Automation, you have three choices for free runs: Hands-on Lab (HOL) Advanced lab A fre...
Which sectors can benefit the most from VMware Aria Automation?
I was looking at VMware Aria Automation case studies recently and I got the impression that three main kinds of compa...
 

Also Known As

Qualys TotalCloud with FlexScan
TrueSight Cloud Security, SecOps Policy Service
VMware vRealize Automation, vRA, VMware DynamicOps Cloud Suite, SaltStack
 

Overview

 

Sample Customers

Information Not Available
NHS, Vodafone, Kansas City Life, SKY Italia, Cybera
Rent-a-Center, Amway, Vistra Energy, Liberty Mutual
Find out what your peers are saying about BMC Helix Cloud Security vs. VMware Aria Automation and other solutions. Updated: April 2026.
900,747 professionals have used our research since 2012.