

Qualys VMDR and BMC Helix Discovery compete in the cybersecurity and IT asset management sectors, respectively. Qualys VMDR has the upper hand in comprehensive vulnerability management, while BMC Helix Discovery excels in asset visibility and service mapping.
Features: Qualys VMDR is known for its robust vulnerability management, rapid updates to vulnerabilities, and comprehensive reporting capabilities. It is cloud-based, offering scalability and ease of use with valuable integrations. BMC Helix Discovery shines in asset discovery, dependency mapping, and integrating with ITSM solutions like ServiceNow, supporting automated service mapping and customization capabilities.
Room for Improvement: Qualys VMDR users suggest enhancing reporting, integration with third-party solutions, and customization in dashboards. False positives and wider assessments for IoT and SCADA systems are notable concerns. BMC Helix Discovery users highlight the need for improved stability and scalability in monitoring tools and better integration with CMDBs, along with modernization in customization and mapping for diverse asset types.
Ease of Deployment and Customer Service: Qualys VMDR supports deployment across private, public, and hybrid cloud environments and is noted for a seamless setup, though customer support varies in response time. BMC Helix Discovery offers flexible on-premises and hybrid cloud deployment and generally high customer support, making it favorable in complex technical integrations.
Pricing and ROI: Qualys VMDR is considered expensive, particularly for smaller enterprises, but its value is seen in vulnerability reduction and security enhancement. BMC Helix Discovery is viewed as less expensive, with more predictable pricing for mid-sized companies and complex licensing potentially increasing costs. Both solutions demonstrate good ROI through improved security management and risk reduction.
BMC Helix Discovery has delivered a very good return, and we cannot stop using it at this moment.
We saw a return on investment through significant savings in time, money, and resources.
When opening a severity one ticket, they respond within four to six hours, which is commendable.
The response has been satisfactory, though improvements could be made in response time and overall competence.
We usually get on calls with tech support, and they are very helpful.
The response time takes a while.
The technical support provided by Qualys is pretty good.
Scalability depends on the license and the number of assets being monitored.
Qualys VMDR can handle scalability, although increasing the inventory can raise the licensing costs.
Qualys VMDR's scalability is good, and the customer support is good.
In the past four to six years, I cannot recall encountering any bugs.
Qualys VMDR is stable.
I would like to see a lower price and better technical support.
It uses a Berkeley database, and the query language is not easy to master for performing complex queries.
It does not automate patching unless the patch management module is purchased separately.
If AI features were integrated, it could enhance the capabilities significantly.
One area where Qualys VMDR can be improved is the missing feature for deploying agents for over 1,000 assets, as we need to do it manually.
The price is about twelve per license per year, and the support is included.
I would rate the pricing between seven to eight out of ten.
I have a notion that Qualys might be more expensive than Rapid7.
Qualys offers better pricing and is feature-packed compared to other tools.
This is very useful for compliance as it helps in audits by providing a comprehensive view of all assets and software.
The best aspect of BMC Helix Discovery is its flexibility. You can perform scanning at any time, and it provides substantial data for extraction.
What we're looking for and trying to move towards is autonomous operations so that AI is implemented to suggest resolutions and to quickly identify faults or repeated patterns with no human intervention.
The prioritization of vulnerabilities has improved our remediation efforts by around thirty to thirty-five percent.
It impacts my workflow overall, with the patch management features as it has the missing patches listed in detail, making it easier to get a comprehensive report and providing some dashboards that offer visual representation.
Qualys VMDR's continuous monitoring capabilities help us respond to emergent threats by enabling my team to reach out to the security engineers whenever there is any detection of a vulnerability, informing them about it, and creating an incident.
| Product | Market Share (%) |
|---|---|
| Qualys VMDR | 2.5% |
| BMC Helix Discovery | 5.3% |
| Other | 92.2% |

| Company Size | Count |
|---|---|
| Small Business | 11 |
| Midsize Enterprise | 5 |
| Large Enterprise | 13 |
| Company Size | Count |
|---|---|
| Small Business | 20 |
| Midsize Enterprise | 12 |
| Large Enterprise | 70 |
BMC Discovery, formerly ADDM, is a digital enterprise management solution that automates asset discovery and application dependency mapping to build a holistic view of all your data center assets and the relationships between them.
Vulnerability Management, Detection, and Response (VMDR) is a cornerstone product of the Qualys TruRisk Platform and a global leader in the enterprise-grade vulnerability management (VM) vendor space. With VMDR, enterprises are empowered with visibility and insight into cyber risk exposure - making it easy to prioritize vulnerabilities, assets, or groups of assets based on business risk. Security teams can take action to mitigate risk, helping the business measure their actual risk exposure over time.
Qualys VMDR offers an all-inclusive risk-based vulnerability management solution to prioritize vulnerabilities and assets based on risk and business criticality. VMDR seamlessly integrates with configuration management databases (CMDB), Qualys Patch Management, Custom Assessment and Remediation (CAR), Qualys TotalCloud and other Qualys and non-Qualys solutions to facilitate vulnerability detection and remediation across the entire enterprise.
With VMDR, users are empowered with actionable risk insights that translate vulnerabilities and exploits into optimized remediation actions based on business impact. Qualys customers can now aggregate and orchestrate data from the Qualys Threat Library, 25+ threat intelligence feeds, and third-party security and IT solutions, empowering organizations to measure, communicate, and eliminate risk across on-premises, hybrid, and cloud environments.
We monitor all IT Asset Management reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.