No more typing reviews! Try our Samantha, our new voice AI agent.

BMC Helix Cloud Security vs Zscaler Internet Access comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Qualys TotalCloud
Sponsored
Average Rating
8.6
Reviews Sentiment
7.3
Number of Reviews
39
Ranking in other categories
Vulnerability Management (11th), Container Security (11th), Cloud Workload Protection Platforms (CWPP) (8th), Cloud Security Posture Management (CSPM) (8th), SaaS Security Posture Management (SSPM) (1st), Cloud-Native Application Protection Platforms (CNAPP) (6th)
BMC Helix Cloud Security
Average Rating
8.0
Reviews Sentiment
7.5
Number of Reviews
5
Ranking in other categories
Cloud Workload Protection Platforms (CWPP) (25th), Cloud Security Posture Management (CSPM) (38th)
Zscaler Internet Access
Average Rating
8.4
Reviews Sentiment
6.7
Number of Reviews
60
Ranking in other categories
Secure Web Gateways (SWG) (3rd), Internet Security (2nd)
 

Mindshare comparison

Cloud Workload Protection Platforms (CWPP) Mindshare Distribution
ProductMindshare (%)
BMC Helix Cloud Security1.2%
Microsoft Defender for Cloud13.2%
AWS GuardDuty10.4%
Other75.2%
Cloud Workload Protection Platforms (CWPP)
Secure Web Gateways (SWG) Mindshare Distribution
ProductMindshare (%)
Zscaler Internet Access10.0%
Cisco Umbrella9.7%
Prisma Access by Palo Alto Networks7.6%
Other72.7%
Secure Web Gateways (SWG)
 

Featured Reviews

RO
IT Security Expert at Alior Bank S.A.
Unified risk scoring has improved our cloud visibility and simplifies remediation priorities
Qualys TotalCloud provides unified vulnerability and threat assessment across both IAS and SaaS. This solution provides a single prioritized view of risk, which helps reduce the work I would have to do. We are no longer based on CVSS; we are based on Qualys risk scoring, which is based on CVSS plus internal findings made by Qualys, and then assigns its own score. The TruRisk insight feature has found a small number of assets with high vulnerability scores, though I am cautious since some information is classified. Qualys TotalCloud has positively impacted our bank's performance, and we have definitely seen benefits after implementing this solution.
DG
Portfolio Manager/ Helix Administrator at Frontier Communications
A highly scalable and straightforward solution with a knowledgeable support team
We work on a third-party shared environment. It wouldn’t have been feasible for a smaller company. My company was actually the first one to do it. Just like any cloud security, it pays to do your research and have complimentary security involved. The product can’t be the be-all and end-all tool for your security. Overall, I rate the solution a nine out of ten.
Mohan Janarthanan - PeerSpot reviewer
Associate Vice President at Novac Technology Solutions
User access management and threat prevention are enhanced with user-friendly controls
The best features Zscaler Internet Access offers include application control, tenant segregation, and PoP center regions which have low availability zones. The internet access is very successful and bandwidth speed is excellent. It also has application-based control, URL-based control, and SSL inspection capabilities, which are very useful. Additionally, the in-depth CASB segregation is very beneficial to us. One unique feature I found helpful is the tenant level restrictions, which we use to only access our organization's tenant level mail IDs, drives, and specific tenant level access while restricting public access. Zscaler Internet Access has positively impacted our organization as we have noticed substantial outputs and income. It has improved our security environment control and endpoint protection. It prevents numerous web attacks through its AI/ML incorporated capability which identifies malware, threats, and viruses. It has a toggle button to enable features entirely at the tenant level for all users onboarded into Zscaler Internet Access, resulting in much better outcomes.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The scalability is good as well. I would rate it ten out of ten."
"I found the initial setup user-friendly."
"With TotalCloud, we can scan through the API. If we are not able to deploy cloud agents on the machine, we can use the API."
"One of Qualys' best features is its categorization, which allows us to see the types of assets, their security postures, and the AI-powered version of the tool."
"Qualys TotalCloud's most valuable features are its cloud security posture management, Kubernetes, and container security capabilities."
"I would definitely recommend Qualys TotalCloud to other customers."
"If someone were to ask me to review Qualys TotalCloud, I would summarize it as an end-to-end solution for cloud security with visibility and governance-grade controls without needing to manage multiple disconnected tools."
"Its excellent graphical interface makes the scanning process simple."
"With very minimal effort, you are able to have a cohesive view into your security posture on one or multiple cloud accounts, particularly if you are dealing with multicloud."
"It is a good tool to make sure that your containers are safe and sound."
"The best feature is time to value. With very minimal effort, you are able to have a cohesive view into your security posture on one or multiple cloud accounts, particularly if you are dealing with multicloud. If you have Azure and AWS deployments, you might have multiple subscriptions in Azure and usually multiple accounts in AWS. You may even be doing some GCP work (around Google Cloud Platform). It's very difficult to manage a common set of policies, even less reporting, across multiple subscriptions, accounts, and cloud environments. What BMC Helix Cloud Security does is provide a unified view or single pane of glass as to your baseline. Then, it also facilitates the ability for Level 1 or 2 operations support to take action and report on security vulnerabilities."
"Using this solution is an eye-opener; having that holistic view is the biggest eye-opener because you understand, from any of your connected cloud accounts, what your vulnerabilities are with it."
"The cool feature of Helix Cloud Security is that you can do all that — understand and remediate issues — in one dashboard, based on the different policies that are available for security, out-of-the-box."
"The most valuable aspects of BMC Helix Cloud Security are its security features and regulatory compliance capabilities."
"It's also multi-cloud. You can look at several cloud providers: AWS, Azure, or GCP."
"Role-based security is a valuable feature."
"This solution helps you establish a secure connection from your laptop to the closest Zscaler point of presence, so you have protection anywhere in the world."
"The cloud proxy and integration are some of the key features. Since there is cloud waste, we can quickly provision it and start working on the configuration. On top of that, they have added a few more features. They have integrated CASB, and file sandboxing is part of it."
"Zscaler Internet Access's roaming user feature is most valuable and is much better compared to other secure web gateways."
"The solution’s customer service is good."
"Zscaler covers all the features needed to replace a VPN or proxy solution; they are good, and they've been on the market for 15 years now, so they are mature enough."
"The solution offers a distributed organization to master and to control all of the endpoints."
"The main benefit that we have seen is performance improvements based on not having to backhaul traffic and getting cloud services closer to the user."
"The initial setup was straightforward. The biggest thing for us was to build our own policies. The deployment itself was only a few hours."
 

Cons

"The patching process with Qualys Patch Management, which is part of TotalCloud, does not cover installing certain prerequisites on the servers or workstations. This shortcoming means we must rely on SCCM when any service stack updates or additional prerequisites are needed."
"Qualys' customer service provides quality answers, but the response time is long, even though it is within the SLA."
"An area for improvement would be to focus on risks related to AI, such as large language models and potential data leakage."
"There is room for improvement in vulnerability scanning, particularly for PaaS environments. Currently, Qualys does not have full access to these instances, which limits its effectiveness."
"The support process is inefficient due to the excessive number of replies required when submitting tickets."
"The cloud licensing unit system is unclear, especially since "units" aren't well-defined."
"I sometimes have difficulty detecting or uninstalling certain versions of applications, which I have to do manually."
"Although TotalCloud is a helpful tool, some of its advanced features are still under development."
"The UI could be more user-friendly."
"BMC Helix Cloud Security has room for improvement in terms of integrating its various features."
"Every organization out there doesn't rely on just one control body. They use FISMA control. They may use HIPAA, CIS, PCI, or SOX, then blend them. One of the things that is now in big demand for BMC Helix Cloud Security is content. That's the next journey in its lifespan, making it easier for the community to share and collaborate on content for security controls that can be measured and remediated."
"The biggest challenge now, which is a good problem to have, with BMC Helix is content."
"We've had some with issues connectors. The connectors have seemed to have caused a little bit of trouble, perhaps with the APIs trying to scan the environment. The only time I've had to reach out to tech support was for that. It seems it may not have been scanning correctly or I wasn't seeing data within a specific time. But we've set up a couple of connectors in the past couple of weeks and they actually scanned the AWS environment and we had data within about 10 minutes. It's working a lot faster and I think they're making improvements as they go."
"I think its TOA interfaces are still not that comfortable. The UI could be more user-friendly, easier to use."
"We've had some issues with connectors; the connectors have seemed to cause a little bit of trouble, perhaps with the APIs trying to scan the environment."
"I want the role-based security feature to be improved."
"The interface for administration could be better. They should upgrade the management portal."
"The main issue with Zscaler Internet Access is proxy IP detection, which sometimes makes sites inaccessible."
"The solution can be improved by advancing some of the newer technologies such as the DLP feature, and adding email security."
"There are many functionalities in Zscaler Internet Access that need improvements, such as an advanced firewall and logging capabilities to track calls."
"We use other similar products and find them to be a bit more preferable to Zscaler."
"I would like to see more training and video documentation."
"The solution's pricing is on the higher side. It would be better if it could be lower."
"Sometimes it's not easy to use during large deployments of workstations. It's a bottleneck from a network point of view."
 

Pricing and Cost Advice

"It isn't cheap, but it's reasonable. It helps us to manage things with very few resources."
"The pricing for TotalCloud is attractive and competitive in the market. Given the features, especially the dashboard, I have no concerns regarding pricing."
"TotalCloud's price is about right where I would expect it to be."
"Qualys TotalCloud is expensive, but it offers a premier solution with no headaches."
"Although Qualys TotalCloud is relatively expensive due to its unique automation features, its cost-effectiveness is rated an eight out of ten, with ten being the most costly."
"Qualys TotalCloud is expensive."
"While Qualys TotalCloud's pricing is currently acceptable, it is becoming increasingly expensive and may soon be considered overpriced."
"Qualys TotalCloud offers good pricing that is affordable and competitive with the market. Our partnership also provides us with additional benefits."
"It is a subscription model with term licensing that is usually yearly. This includes, not only the product, but support and maintenance. It is based on cloud assets. Therefore, if you have 100 cloud assets, those cloud assets are measured based on evaluation or transactions. For example, if I'm evaluating that cloud asset for CIS compliance, PCI compliance, and AWS best practices, that asset gets evaluated three times, as those are three transactions. However, the license model is based on peak asset usage. So, over a year, if you deploy 100, 1000, 500, and then 2000 assets, you will be charged for the 2000 peak of assets managed by Helix Cloud Security."
"The pricing is based on an annual subscription, upfront, and it's based on cloud assets. Whether your assets are in Azure and AWS combined, the tool tells you how many assets are being scanned and that's the number used for pricing."
"Because it's a cloud solution, we pay on a yearly basis. It is affordable and includes tech support and all features."
"​Be aware that you will need to invest some time and money to adapt your environment for Zscaler (traffic redirection, software deployment, authentication, etc).​"
"The pricing is an issue. It is expensive compared to other firewalls on the market."
"The price of Zscaler Internet Access should improve, it is expensive."
"It is quite expensive. It does its job, but it is quite expensive for what we need."
"Zscaler is an expensive solution, but it's worth the price. Their services are unmatched by competitors. Some may come with half the features that Zscaler can offer and be much cheaper. However, they do not have the global coverage that Zscaler has, and they will not provide the same low latencies and the same speeds that Zscaler can."
"It is a few pounds per user per month."
"Price-wise, the tool is reasonable compared to the other products in the market but it is not a very low-priced tool. The solution does provide value for money."
report
Use our free recommendation engine to learn which Cloud Workload Protection Platforms (CWPP) solutions are best for your needs.
900,747 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Manufacturing Company
18%
Financial Services Firm
14%
Construction Company
7%
Comms Service Provider
7%
Construction Company
16%
Comms Service Provider
13%
Performing Arts
9%
Manufacturing Company
9%
Financial Services Firm
12%
Computer Software Company
11%
Manufacturing Company
10%
Retailer
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business10
Midsize Enterprise3
Large Enterprise29
No data available
By reviewers
Company SizeCount
Small Business17
Midsize Enterprise9
Large Enterprise39
 

Questions from the Community

What needs improvement with Qualys TotalCloud?
Areas that need improvement in every solution include the remediation part. The remediation steps should be simple en...
What is your primary use case for Qualys TotalCloud?
Our use case involves the assets that we have under cloud, the assets exposed to the internet, and the internal appli...
Ask a question
Earn 20 points
Which is the better security solution - Cisco Umbrella or Zscaler?
Cisco Umbrella and Zscaler Internet Access are two broad-spectrum Internet security solutions that I have tried. Zs...
Which is better, Zscaler internet access or Netsckope CASB?
We researched Netskope but ultimately chose Zscaler. Netskope is a cloud access security broker that helps identify ...
What is your experience regarding pricing and costs for Zscaler Internet Access?
It is only for big companies currently and they only focus on that. That is one of the problems to get into the marke...
 

Also Known As

Qualys TotalCloud with FlexScan
TrueSight Cloud Security, SecOps Policy Service
ZIA
 

Overview

 

Sample Customers

Information Not Available
NHS, Vodafone, Kansas City Life, SKY Italia, Cybera
Ulster-Greene ARC, BanRegio, HDFC, Ralcorp Holdings Inc., British American Tobacco, Med America Billing Services Inc., Lanco Group, Aquafil, Telefonica, Swisscom, Brigade Group
Find out what your peers are saying about Microsoft, Wiz, Amazon Web Services (AWS) and others in Cloud Workload Protection Platforms (CWPP). Updated: June 2026.
900,747 professionals have used our research since 2012.