No more typing reviews! Try our Samantha, our new voice AI agent.

Cyera vs Prisma Cloud by Palo Alto Networks comparison

Why PeerSpot?
Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Feb 1, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Qualys TotalCloud
Sponsored
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
46
Ranking in other categories
Vulnerability Management (10th), Container Security (11th), Cloud Workload Protection Platforms (CWPP) (8th), Cloud Security Posture Management (CSPM) (8th), SaaS Security Posture Management (SSPM) (2nd), Cloud-Native Application Protection Platforms (CNAPP) (7th)
Cyera
Average Rating
8.4
Reviews Sentiment
7.1
Number of Reviews
5
Ranking in other categories
Data Loss Prevention (DLP) (13th), Data Governance (24th), Data Security Posture Management (DSPM) (9th), AI Data Analysis (18th), AI Security (12th), Data Security Platforms (DSP) (3rd)
Prisma Cloud by Palo Alto N...
Average Rating
8.4
Reviews Sentiment
7.1
Number of Reviews
114
Ranking in other categories
Web Application Firewall (WAF) (7th), Container Security (2nd), Cloud Security Posture Management (CSPM) (2nd), Cloud-Native Application Protection Platforms (CNAPP) (2nd), Data Security Posture Management (DSPM) (2nd)
 

Featured Reviews

reviewer2859021 - PeerSpot reviewer
Sr Security Engineer at a tech vendor with 5,001-10,000 employees
Risk-based triage has transformed container security and now prioritizes high-impact threats
The best features Qualys TotalCloud offers currently include managing cloud infrastructure and container security while facing major challenges such as alert fatigue. Traditional vulnerability scanners flag hundreds of CVEs on short-lived Kubernetes containers, some of which have no internet exposure or are gone before we can even triage them. I leverage Qualys TotalCloud to move beyond static CVSS. I use it to implement runtime exposure, correlation risk reprioritization, and shift-left integration. This notifies developers to fix a base image upstream rather than patching live ephemeral instances. In my work with cloud and container security, the biggest operational hurdle was alert fatigue. I use Qualys to shift left from static CVSS severity to context-aware risk prioritization. I correlated raw vulnerability data with real-time risk factors such as public network exposure, active runtime execution, or overly permissive IAM roles. This allows us to immediately drop the priority of isolated containers and escalate lower-severity CVEs that sit on an exposed, high-risk path. We can map these findings directly back to our CI/CD pipelines so developers can patch the root base images upstream. We have drastically cut down the signal-to-noise ratio, saved a lot of manual hours doing triage work, and ensured engineering effort goes directly towards high-impact risk reduction.
reviewer2795301 - PeerSpot reviewer
Vice President, Compliance at a manufacturing company with 1-10 employees
Data discovery has accelerated and now drives faster classification and compliance mapping
The best features Cyera offers include agentless discovery and sampling as well as AI ML-based classifications. I find myself relying on the sampling the most, which makes everything really fast, but also the auto-classification and ML-based functionalities. The main thing that stands out to me and my team about the features is the speed of integration and how fast it does the discovery on the data. Once it discovers the data, it also maps it back to a ton of compliance frameworks and best practices that I can use to operationalize. Cyera has positively impacted my organization by allowing me to identify the highest risk areas but also provide better classification of data, which then leads to better data pillar maturity. Cyera has accomplished all three outcomes: saving time, reducing risk, and improving compliance scores, as the speed at which it discovers data was significantly faster.
reviewer2776578 - PeerSpot reviewer
Cyber Security Architect at a comms service provider with 10,001+ employees
Image scanning has supported consistent security practices during cloud deployment
On a scale of ten, we would say people are happy with Prisma Cloud by Palo Alto Networks for the part we use. People are okay with it. We probably would give an eight. We don't give ten because if we don't use the other parts of Prisma Cloud by Palo Alto Networks, it's because it was difficult to implement from an operational point of view. We could have deployed the runtime monitoring with Prisma Cloud by Palo Alto Networks, but within our organization at our company, it was very difficult to find who would be the owner for the alerts. People have other tools and in the end, we don't use the full capabilities of a product that we pay for. It's partially related to the difficulty to integrate Prisma Cloud by Palo Alto Networks runtime in our company's support process. We don't use the real-time monitoring part of Prisma Cloud by Palo Alto Networks. We don't know about the automated remediation feature of Prisma Cloud by Palo Alto Networks.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"I found the initial setup user-friendly."
"The most valuable feature is the consolidated information that it provides from various platforms."
"If someone were to ask me to review Qualys TotalCloud, I would summarize it as an end-to-end solution for cloud security with visibility and governance-grade controls without needing to manage multiple disconnected tools."
"In my opinion, this is the best tool."
"Qualys TotalCloud's most valuable feature is its ability to link clusters of assets, providing a clear model of deployments, vulnerabilities, and statuses."
"I depend heavily on the reports that I have from this tool."
"Qualys TotalCloud helps you not just to identify misconfigurations, but you can actually also fix issues."
"The best feature would be the ability to create policies. It is easy to control and update policies as required."
"Cyera has an inbuilt set of policies implemented towards data security, especially cohering with Data Security Posture Management (DSPM)."
"Cyera has positively impacted my organization because we have become more compliant."
"I like how they model the data. They find data in different places that we didn't know, and they can give us a good idea if it's sensitive or not. They understand whether or not something is in the right region because, with the cloud posture management tool, we could see certain things in the infrastructure, but the way they dig into the data is what we like."
"The data discovery, data classification, and CSPM features are most valuable."
"Cyera has positively impacted my organization by allowing me to identify the highest risk areas but also provide better classification of data, which then leads to better data pillar maturity."
"Visibility and control are the most utilized features. A dashboard is available to us where we can view different categories. We can see any IAM-related risks, any discovered vulnerabilities, any incidents, or any network-level issues."
"My favorite feature is the CWPP module. We can define various kinds of rules for vulnerabilities, incidents, or suspicious activities."
"This positively affected our confidence in your security and compliance. No matter how complex the environment is, the the seamless integration from the top layer itself give us the immediate visibility on the number of services."
"With the query language, we can analyze logs and find out which IPs are malicious. It also provides a graphical representation. It provides the overall visibility and how the traffic is flowing. We can see where the malicious IP is and whether it is an insider threat or an outsider threat."
"The Twistlock vulnerability scanning tool is its most valuable feature. It provides us insight into security vulnerabilities, running inside both on-premise and public cloud-based container platforms. It is filling a gap that we have with traditional vulnerability scanning tools, where we don't have the ability to scan inside containers."
"The most valuable feature of Prisma Cloud is WAF (web application firewall)."
"The CSPM and CWPP functionalities are pretty good."
"Due to the maturity of most companies, security posture management is the most valuable feature."
 

Cons

"Their customer support needs improvement."
"An area for improvement would be to focus on risks related to AI, such as large language models and potential data leakage."
"There is room for improvement in the support."
"I chose a rating of nine out of ten because there is a complex interface that sometimes overwhelms new engineers."
"The onboarding process is a bit difficult. In the initial phase, it is very difficult to understand the features, what the dashboard contains, and what criteria they are using."
"With the growing integration of AI, I would like Qualys to enhance its service offerings to better accommodate AI-related risks."
"Although TotalCloud is a helpful tool, some of its advanced features are still under development."
"There is room for improvement in vulnerability scanning, particularly for PaaS environments. Currently, Qualys does not have full access to these instances, which limits its effectiveness."
"The licensing initially was tricky because it is based on storage as well as user count."
"They need to add a few things in the UI from an enterprise perspective. It's more along the lines of being able to self-service, have integrations, build alerts, and things like that. Outside of that, they work with us on the API and getting alerts into our SIEM and things like that. There's always a way to do something, and they're always available, which is nice."
"I would advise others looking into using Cyera to not do so."
"As a startup company, there is a long way for them to go in terms of scalability."
"There is room for improvement in making Cyera more user-friendly. Some parts were difficult to navigate, especially for those new to the IT industry."
"The remediation part could be better."
"To see the full picture, at least when I last used it in April or May, you needed to switch between the modules. To see the cloud infrastructure and pipeline configuration, you need to switch to that module. To see the code security part, you need to switch to the Code Security module. It is the same story with CSPM. Two competitors of Prisma Cloud do it in a better way. They show the full view of a risk. Prisma Cloud unfortunately lacks in that area, but they are catching up."
"A better correlation between the multiple products Prisma Cloud contains would be crucial. It would reduce the time spent looking at reports and enable you to get all the actionable insights across products. I think that Palo Alto is working on it, but they need to work faster because it doesn't make sense to have all these products in a single pane of glass without any correlation between them."
"When an account is onboarded, if it is missing any permission, it should automatically be updated with the required permissions and policies."
"Though Prisma Cloud by Palo Alto Networks provides excellent security, is a pioneer in this space, and knows what it's doing, from a user perspective, it would have been better if it was a little easier to use."
"One of the main backlogs in their development is in the area of integration. For example, we have ServiceNow in place for ticket management and Prisma Cloud is supposed to send closure emails for incidents. But from time to time, it fails to do so. We have several other mismatches between Prisma Cloud and ServiceNow."
"There I saw one feature called dummy payloads, in which we trigger the dummy payload, so it exactly gives the exploitable resources. That might be a feature that would be helpful if Prisma Cloud by Palo Alto Networks also had some kind of that feature."
"The alignment of Twistlock Defender agents with image repositories needs improvement. These deployed agents have no way of differentiating between on-premise and cloud-based image repositories. If I deploy a Defender agent to secure an on-premise Kubernetes cluster, that agent also tries to scan my ECR image repositories on AWS. So, we have limited options for aligning those Defenders with the repositories that we want them to scan. It is scanning everything rather than giving us the ability to be real granular in choosing which agents can scan which repositories."
 

Pricing and Cost Advice

"Qualys TotalCloud offers good pricing that is affordable and competitive with the market. Our partnership also provides us with additional benefits."
"Qualys TotalCloud offers competitive pricing given its comprehensive suite of features, including integration, assessment, remediation, and detection capabilities, all within a single platform."
"While Qualys TotalCloud's pricing is currently acceptable, it is becoming increasingly expensive and may soon be considered overpriced."
"The pricing for TotalCloud is attractive and competitive in the market. Given the features, especially the dashboard, I have no concerns regarding pricing."
"I am not sure about the pricing. From what I understand, it is a bit on the higher side, but I do not have the exact numbers."
"Although Qualys TotalCloud is relatively expensive due to its unique automation features, its cost-effectiveness is rated an eight out of ten, with ten being the most costly."
"Qualys TotalCloud is expensive, but it offers a premier solution with no headaches."
"Qualys TotalCloud is expensive."
"I don't know how much exactly it costs, but I know that it's a yearly thing. It's something that will cost money for any company because they're storing all this information. They're doing all this machine learning, and there are a lot of services on their backend that they got to pay for. I'm sure it gets translated back to the customers unless you have everything completely on-prem. If you're not doing much in the cloud, then I could see how it'd be cheaper, but if you have anything that's cloud-hosted and does all the work for you, there's going to be a cost associated with it."
"Compared to the competitors, they are very reasonable."
"Prisma Cloud licensing works on credits."
"The product is very expensive, but the cost is a necessary evil; I don't know how we could have any kind of cloud presence without this type of monitoring. The pricing is calculated by module and resource usage. Ultimately, it saves us money in the amount of time we would spend uncovering what it uncovers, and we might not make the required discoveries without it anyway. Prisma offers incredible value, though I wish it were cheaper."
"Prisma Cloud is affordable."
"Our licensing fees are $18,000 USD per year."
"Almost all the CSPM tools are pretty expensive."
"Prisma Cloud is remarkably expensive."
"The pricing is reasonable."
"The pricing is competitive; for the most part, the security firms have similar prices."
report
Use our free recommendation engine to learn which Data Security Posture Management (DSPM) solutions are best for your needs.
914,109 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Comms Service Provider
16%
Outsourcing Company
12%
Manufacturing Company
11%
Financial Services Firm
10%
Financial Services Firm
15%
Manufacturing Company
11%
Healthcare Company
8%
Computer Software Company
6%
Financial Services Firm
13%
Computer Software Company
8%
Manufacturing Company
8%
Outsourcing Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business14
Midsize Enterprise5
Large Enterprise34
No data available
By reviewers
Company SizeCount
Small Business37
Midsize Enterprise21
Large Enterprise58
 

Questions from the Community

What needs improvement with Qualys TotalCloud?
In terms of improvement, remediation still belongs to the cloud team, which is one of the issues we faced with Qualys...
What is your primary use case for Qualys TotalCloud?
My main use case for Qualys TotalCloud is regarding the cloud visibility that we were not having previously. Previous...
What is your experience regarding pricing and costs for Cyera ?
My experience with pricing, setup cost, and licensing for Cyera was that the licensing initially was tricky because i...
What needs improvement with Cyera ?
I think Cyera can improve by expanding beyond Israel.
What is your primary use case for Cyera ?
My main use case for Cyera is security. A quick specific example of how I use Cyera for security is scanning drives f...
What is your primary use case for Prisma Cloud by Palo Alto Networks?
Prisma Cloud helps support DevSecOps methodologies, making those responsibilities easier to manage.
What Cloud-Native Application Protection Platform do you recommend?
We like Prisma Cloud by Palo Alto Networks, since it offers us incredible visibility into our entire cloud system. We...
What do you think of Aqua Security vs Prisma Cloud?
Aqua Security is easy to use and very manageable. Its main focus is on Kubernetes and Docker. Security is a very valu...
 

Also Known As

Qualys TotalCloud with FlexScan
No data available
Prisma Public Cloud, RedLock Cloud 360, RedLock, Twistlock, Aporeto
 

Overview

 

Sample Customers

Information Not Available
Cyera's customers include the Chicago Board of Options Exchange (Cboe), Granicus, Takeda, LifeLabs, United Talent Agency, ACV Auctions, and Armis
Amgen, Genpact, Western Asset, Zipongo, Proofpoint, NerdWallet, Axfood, 21st Century Fox, Veeva Systems, Reinsurance Group of America
Find out what your peers are saying about Cyera vs. Prisma Cloud by Palo Alto Networks and other solutions. Updated: August 2026.
914,109 professionals have used our research since 2012.