No more typing reviews! Try our Samantha, our new voice AI agent.

FortiCNAPP vs Sysdig Monitor comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Apr 5, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Qualys TotalCloud
Sponsored
Average Rating
8.6
Reviews Sentiment
7.3
Number of Reviews
39
Ranking in other categories
Vulnerability Management (11th), Container Security (11th), Cloud Workload Protection Platforms (CWPP) (8th), Cloud Security Posture Management (CSPM) (8th), SaaS Security Posture Management (SSPM) (1st), Cloud-Native Application Protection Platforms (CNAPP) (6th)
FortiCNAPP
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
15
Ranking in other categories
Vulnerability Management (33rd), Container Security (26th), Cloud Workload Protection Platforms (CWPP) (17th), Cloud Security Posture Management (CSPM) (21st), Cloud-Native Application Protection Platforms (CNAPP) (17th), Compliance Management (10th)
Sysdig Monitor
Average Rating
8.0
Reviews Sentiment
6.2
Number of Reviews
4
Ranking in other categories
Container Monitoring (9th)
 

Mindshare comparison

Vulnerability Management Mindshare Distribution
ProductMindshare (%)
FortiCNAPP1.8%
Wiz4.5%
Qualys VMDR3.9%
Other89.8%
Vulnerability Management
Container Monitoring Mindshare Distribution
ProductMindshare (%)
Sysdig Monitor3.1%
Dynatrace23.3%
Datadog19.8%
Other53.8%
Container Monitoring
 

Featured Reviews

RO
IT Security Expert at Alior Bank S.A.
Unified risk scoring has improved our cloud visibility and simplifies remediation priorities
Qualys TotalCloud provides unified vulnerability and threat assessment across both IAS and SaaS. This solution provides a single prioritized view of risk, which helps reduce the work I would have to do. We are no longer based on CVSS; we are based on Qualys risk scoring, which is based on CVSS plus internal findings made by Qualys, and then assigns its own score. The TruRisk insight feature has found a small number of assets with high vulnerability scores, though I am cautious since some information is classified. Qualys TotalCloud has positively impacted our bank's performance, and we have definitely seen benefits after implementing this solution.
Mark Freeborough - PeerSpot reviewer
Client Manager at MLL Telecom Ltd
Network segmentation has strengthened access control and now streamlines automated threat response
The most valuable features in FortiCNAPP include robust network segmentation and restricting access to network assets. It also supports security measures by leveraging security fabrics for better enforcement and policy enforcement. FortiCNAPP integrates with SIEM solutions, and we offer different SIEM options that work with Fortinet and AlienVault, among others, providing multiple scenarios.FortiCNAPP's automated policy recommendations significantly help improve security measures as part of an overall service wrap. When deploying a Fortinet SD-WAN or network, these tools provide greater visibility to vulnerabilities and enhanced security on the network. It functions as a proactive tool, enabling me to identify threats quickly and automate responses.
Bharath Nadar - PeerSpot reviewer
Senior Staff Site Reliability Engineer at a tech vendor with 501-1,000 employees
Centralized host monitoring has reduced operational overhead and provides trusted dashboards
Sysdig Monitor could be improved, particularly regarding application monitoring. There are specific areas or features where improvement is needed, specifically in application-level monitoring. While other monitoring solutions provide APM capabilities, Sysdig Monitor does not and targets only host-based monitoring. Many applications require APM support, and we want to introduce OpenTelemetry into some applications to gain more insights, but with Sysdig Monitor, we could not implement this functionality, so we have to opt for solutions from other vendors for those applications. Beyond the APM and OpenTelemetry support limitations, I would appreciate seeing Sysdig Monitor offer a unified solution for all monitoring needs, including logging as well, eventually bringing whole observability under one roof. That would be ideal.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The best feature would be the ability to create policies. It is easy to control and update policies as required."
"One of Qualys' best features is its categorization, which allows us to see the types of assets, their security postures, and the AI-powered version of the tool."
"We were able to realize its benefits within 24 to 48 hours."
"Qualys TotalCloud has improved our security posture."
"The most valuable feature is extensibility."
"The scalability is good as well. I would rate it ten out of ten."
"If I had to say something positive about the product that brings me the biggest benefit, I would say it has accurate reports, gets new update CVEs, zero-day attack detection, and is easy to manage with its GUI."
"One of the most valuable features of Qualys TotalCloud is FlexScan, which is specifically for internet-facing VMs. We found this feature to be very useful. It was a key differentiator for us."
"FortiCNAPP has positively impacted my organization by providing centralized visibility and consolidating our cloud security posture management, helping us identify misconfigurations and public accessibility issues, which allowed us to enhance IAM governance and visibility on vulnerabilities."
"For the most part, out-of-the-box, it tells you right away about the things you need to work on. I like the fact that it prioritizes alerts based on severity, so that you can focus your efforts on anything that would be critical/high first, moderate second, and work your way down, trying to continue to improve your security posture."
"Polygraph compliance is a valuable feature. In our perspective, it delivers significant benefits. The clarity it offers, along with the ability to identify and address misconfigurations, is invaluable. When such issues arise, we promptly acknowledge and take action, effectively collaborating with our teams and the responsible parties for those assets. This enables us to promptly manage problems as soon as they arise."
"FortiCNAPP definitely brings time-saving benefits, and security is the main concern for the company."
"The most valuable feature, from a compliance perspective, is the ability to use Lacework as a platform for multiple compliance standards. We have to meet multiple standards like PCI, SOC 2, CIS, and whatever else is out there. The ability to have reports generated, per security standard, is one of the best features for me."
"There are many valuable features that I use in my daily work. The first are alerts and the event dossier that it generates, based on the severity. That is very insightful and helps me to have a security cap in our infrastructure. The second thing I like is the agent-based vulnerability management, which is the most accurate information."
"What I personally appreciate about FortiCNAPP is that I think it is a good product and a good firewall because it usually offers many options for the company."
"The best feature, in my opinion, is the ease of use, as well as some levels of machine learning anomaly detection that they have that can detect pivotal anomalies faster."
"The ability to stop/pause and capture logs when something happens is the most valuable feature."
"Docker containers are completely supported, kind of like "first class citizens"."
"Sysdig Monitor has positively impacted my organization by significantly reducing operational costs and improving our ability to monitor our systems effectively."
"Sysdig Monitor impressed me with its in-depth visibility into my infrastructure."
 

Cons

"We encountered challenges identifying the correct resource category for certain items, such as those in containers or storage."
"The price is very expensive, actually."
"Some major banks and insurance companies require an on-premises solution for comprehensive vulnerability management, which TotalCloud does not offer."
"Qualys's ticketing system can be confusing when assigning tasks to individuals, and support could be improved by offering instant call solutions with engineers in addition to ticket replies."
"The cloud licensing unit system is unclear, especially since "units" aren't well-defined."
"Qualys TotalCloud has the potential to improve by integrating a hybrid platform for comprehensive management of both on-premises and cloud infrastructures."
"Areas that need improvement in every solution include the remediation part. The remediation steps should be simple enough for everyone to understand."
"I would like the ability to disable certain default built-in policies as they can be misleading when creating dashboards. That is the top one."
"Its integrations with third-party SIEMs can be better. That is one of the things that we discussed with them."
"The customer support for FortiCNAPP is fine, though it can take time as we need to engage with AWS first, but I would rate it around 7 or 8 out of 10."
"In general, I would not recommend Lacework right now. There are more mature solutions that would be a better fit."
"The vulnerability part is not systematically organized; it is all clumsy in the web UI, and it is not user-friendly."
"The solution lacks a cohesive data model, making extracting the necessary data from the platform challenging. It uses its own LQL query language, and each database across different layers and modules is structured differently, complicating correlation efforts. Consequently, I had to create extensive custom reports outside Lacework because their default dashboards didn't communicate risk metrics. They're addressing these issues by redesigning their tools, including introducing the dashboard, which is a step closer to actionable insights but still needs refinement."
"Lacework lacks remediation features, but I believe they're working on that. They're focused on the reporting aspect, but other features need to improve. They're also adding some compliance features, so it's not worth saying they need to get better at it."
"There are a couple of the difficulties we encounter in the realm of cybersecurity, or security as a whole, that relate to potentially limited clarity. Having the capacity to perceive the configuration aspect and having the ability to contribute to it holds substantial advantages, in my view. It ranks high, primarily due to its role in guaranteeing compliance and the potential to uncover vulnerabilities, which could infiltrate the system and introduce potential risks. I had been exploring a specific feature that captured my interest. However, just yesterday, I participated in a product update session that announced the imminent arrival of this feature. The feature involves real-time alerting. This was something I had been anticipating, and it seems that this capability is now being integrated, possibly as part of threat intelligence. While anomaly events consistently and promptly appear in the console, certain alerts tend to experience delays before being displayed. Yet, with the recent product update, this issue is expected to be resolved. Currently, a comprehensive view of all policies is available within the console. However, I want a more tailored display of my compliance posture, focusing specifically on policies relevant to me. For instance, if I'm not subject to HIPAA regulations, I'd prefer not to see the HIPAA compliance details. It's worth noting that even with this request, there exists a filtering mechanism to control the type of compliance information visible. This flexibility provides a workaround to my preference, which is why it's challenging for me to definitively state my exact request."
"Visibility is lacking, and both compliance-related metrics and IAM security control could be improved."
"It is needs to automate the actions to take when an alert is triggered."
""Events" reporting (errors, crashes, etc.) is not clear at all in a Mesos environment (i.e., it's not clear what specific container is the one that went down). In a Docker Compose environment, it may be way better."
"I had difficulty installing Sysdig Monitor on Windows."
"Sysdig Monitor could be improved, particularly regarding application monitoring."
 

Pricing and Cost Advice

"Qualys TotalCloud is expensive."
"Qualys TotalCloud is cost-efficient and was selected for its value compared to other products."
"The pricing is comparable. It is built into our other product, so I cannot piecemeal it. It is a part of our subscription."
"Qualys TotalCloud is expensive, but it offers a premier solution with no headaches."
"I am not sure about the pricing. From what I understand, it is a bit on the higher side, but I do not have the exact numbers."
"As a middle management member, I do not have direct pricing knowledge, but based on the knowledge from our meetings, its pricing is competitive."
"The pricing for TotalCloud is attractive and competitive in the market. Given the features, especially the dashboard, I have no concerns regarding pricing."
"Its price seems higher compared to other tools, but it is worth it. If they could adjust the pricing and make it comparable with other tools, that would be great."
"My smaller deployments cost around 200,000 a year, which is probably not as expensive as Wiz."
"It is slightly expensive. It depends on how big your environment is, but it is expensive. Right now, we are spending a lot of money. We have covered all of the cloud providers and most of our colocation facilities as well, so we cannot complain, but it is slightly expensive. It is not super expensive."
"The licensing fee was approximately $80,000 USD, per year."
"The pricing has gotten better. That scenario was somewhat unstable. They have a rather interesting licensing structure. I believe you get 200 resources per "Lacework unit." It was difficult, in the beginning, to figure out exactly what a "resource" was... That was a problem until about a year or so ago. They have improved it and it has stabilized quite a bit."
"Sysdig Monitor is not expensive."
report
Use our free recommendation engine to learn which Vulnerability Management solutions are best for your needs.
900,644 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Manufacturing Company
18%
Financial Services Firm
14%
Construction Company
7%
Comms Service Provider
7%
Financial Services Firm
9%
Computer Software Company
9%
Construction Company
8%
University
6%
Financial Services Firm
16%
Outsourcing Company
12%
Construction Company
11%
Manufacturing Company
10%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business10
Midsize Enterprise3
Large Enterprise29
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise5
Large Enterprise6
No data available
 

Questions from the Community

What needs improvement with Qualys TotalCloud?
Areas that need improvement in every solution include the remediation part. The remediation steps should be simple en...
What is your primary use case for Qualys TotalCloud?
Our use case involves the assets that we have under cloud, the assets exposed to the internet, and the internal appli...
What is your experience regarding pricing and costs for Lacework?
The pricing is a mediator compared to other products; it is not that much higher and not much lower than other produc...
What needs improvement with Lacework?
Policy implementation is quite complex, and the stability will take more time for the solutions. There is definitely ...
What is your primary use case for Lacework?
FortiCNAPP is mainly used from a security point of view. Some VPNs charge for their solutions, but Fortinet provides ...
What is your experience regarding pricing and costs for Sysdig Monitor?
My experience with pricing, setup cost, and licensing was good. Before moving forward with Sysdig Monitor, we analyze...
What needs improvement with Sysdig Monitor?
Sysdig Monitor could be improved, particularly regarding application monitoring. There are specific areas or features...
What is your primary use case for Sysdig Monitor?
Sysdig Monitor has become essential for overseeing a vast array of hosts and EC2 instances across our environment. We...
 

Also Known As

Qualys TotalCloud with FlexScan
Polygraph, FortiCNP, Lacework
No data available
 

Overview

 

Sample Customers

Information Not Available
J.Crew, AdRoll, Snowflake, VMWare, Iterable, Pure Storage, TrueCar, NerdWallet, and more.
SAP Concur, Goldman Sachs, Worldpay by FIS, Cisco, Experian, Home Office, Societe Generale, Sunrun. More here: https://sysdig.com/customers/
Find out what your peers are saying about Wiz, Tenable, Qualys and others in Vulnerability Management. Updated: June 2026.
900,644 professionals have used our research since 2012.