No more typing reviews! Try our Samantha, our new voice AI agent.

FortiCNAPP vs WithSecure Elements Exposure Management (XM) comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Feb 22, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Qualys TotalCloud
Sponsored
Ranking in Vulnerability Management
10th
Ranking in Cloud Security Posture Management (CSPM)
7th
Average Rating
8.6
Reviews Sentiment
7.2
Number of Reviews
41
Ranking in other categories
Container Security (11th), Cloud Workload Protection Platforms (CWPP) (7th), SaaS Security Posture Management (SSPM) (2nd), Cloud-Native Application Protection Platforms (CNAPP) (6th)
FortiCNAPP
Ranking in Vulnerability Management
29th
Ranking in Cloud Security Posture Management (CSPM)
13th
Average Rating
8.2
Reviews Sentiment
6.7
Number of Reviews
17
Ranking in other categories
Container Security (17th), Cloud Workload Protection Platforms (CWPP) (13th), Cloud-Native Application Protection Platforms (CNAPP) (12th), Compliance Management (9th)
WithSecure Elements Exposur...
Ranking in Vulnerability Management
77th
Ranking in Cloud Security Posture Management (CSPM)
38th
Average Rating
10.0
Reviews Sentiment
6.6
Number of Reviews
1
Ranking in other categories
Continuous Threat Exposure Management (CTEM) (26th)
 

Mindshare comparison

As of August 2026, in the Vulnerability Management category, the mindshare of Qualys TotalCloud is 1.2%, up from 1.0% compared to the previous year. The mindshare of FortiCNAPP is 1.9%, up from 1.1% compared to the previous year. The mindshare of WithSecure Elements Exposure Management (XM) is 0.5%, up from 0.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Vulnerability Management Mindshare Distribution
ProductMindshare (%)
Qualys TotalCloud1.2%
FortiCNAPP1.9%
WithSecure Elements Exposure Management (XM)0.5%
Other96.4%
Vulnerability Management
 

Featured Reviews

RO
IT Security Expert at Alior Bank S.A.
Unified risk scoring has improved our cloud visibility and simplifies remediation priorities
Qualys TotalCloud provides unified vulnerability and threat assessment across both IAS and SaaS. This solution provides a single prioritized view of risk, which helps reduce the work I would have to do. We are no longer based on CVSS; we are based on Qualys risk scoring, which is based on CVSS plus internal findings made by Qualys, and then assigns its own score. The TruRisk insight feature has found a small number of assets with high vulnerability scores, though I am cautious since some information is classified. Qualys TotalCloud has positively impacted our bank's performance, and we have definitely seen benefits after implementing this solution.
Charl Pinches - PeerSpot reviewer
Solutions Sales Specialist at a outsourcing company with 1,001-5,000 employees
Cloud risk has become visible and security teams prioritize and act on threats efficiently
FortiCNAPP can be improved because the platform can feel complex at the start, especially for teams new to CNAP tooling. Some users mention that they found the interface and data models less intuitive than expected, and I have had situations where reporting and alert configurations might require time. Regarding other improvements needed for FortiCNAPP, the majority of the time is that reporting and alert configuration might require time to tune properly. This is the significant issue, combined with the fact that some users find the interface and data model less intuitive than expected. Regarding FortiCNAPP's AI capabilities, I think there might be a bit of improvement needed. However, since Fortinet is a security vendor overall, keeping the data safe is not a problem. I know they have invested a lot in getting it to a place where it is a trusted platform.
PP
System Specialist at Fix-Forum Oy
Stable, scalable, and can be deployed on both cloud and on-premises
We usually need the solution to have extra protection against data breaches, as we have seen with our customers. The solution is deployed on the public cloud The solution works both outside and on-premises of the company, thus preventing secondary breaches from reaching the company's data. The…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Qualys TotalCloud's most valuable features are its security capabilities that help identify and mitigate risk factors."
"One of Qualys' best features is its categorization, which allows us to see the types of assets, their security postures, and the AI-powered version of the tool."
"Qualys TotalCloud provides a single, prioritized view of risk, reducing the workload associated with consolidating multiple sources for risk prioritization."
"It is a cloud-native app that integrates with both IaaS and SaaS. It seamlessly integrates with other platforms."
"Qualys TotalCloud has significantly reduced our workload in terms of managing risks, helping us to be more efficient and save substantial resources."
"Qualys TotalCloud's most valuable feature is its ability to link clusters of assets, providing a clear model of deployments, vulnerabilities, and statuses."
"The agent and agentless scanning in TotalCloud, particularly the FlexScan method, is incredibly valuable. With traditional scanning approaches, we had to give IP ranges and whitelist IPs. All that is now simplified. FlexScan requires minimal intervention, and after configuration, it automatically collects data and performs necessary scans."
"The most valuable feature of Qualys TotalCloud is the visibility it provides."
"FortiCNAPP definitely brings time-saving benefits, and security is the main concern for the company."
"Lacework is helping a lot in reducing the noise of the alerts. Usually, whenever you have a tool in place, you have a lot of noise in terms of alerts, but the time for an engineer to look into those alerts is limited. Lacework is helping us to consolidate the information that we are getting from the agents and other sources. We are able to focus only on the things that matter, which is the most valuable thing for us. It saves time, and for investigations, we have the right context to take action."
"FortiCNAPP has positively impacted my organization by providing centralized visibility and consolidating our cloud security posture management, helping us identify misconfigurations and public accessibility issues, which allowed us to enhance IAM governance and visibility on vulnerabilities."
"The most valuable feature is Lacework's ability to distill all the security and audit logs. I recommend it to my customers. Normally, when I consult for other customers that are getting into the cloud, we use native security tools. It's more of a rule-based engine."
"For the most part, out-of-the-box, it tells you right away about the things you need to work on. I like the fact that it prioritizes alerts based on severity, so that you can focus your efforts on anything that would be critical/high first, moderate second, and work your way down, trying to continue to improve your security posture."
"The compliance reports are definitely most valuable because they save time and are accurate. So, instead of relying on a human going through and checking or providing me with a report, I could just log into Lacework and see for myself."
"The automated policy recommendations when pushing any firewall policies using Fortinet were really good and performed their job effectively."
"FortiCNAPP is a competitive and robust solution, the only one in the IT sphere that addresses all quadrants in the Gartner Quadrants."
"The solution works both outside and on-premises of the company, thus preventing secondary breaches from reaching the company's data."
 

Cons

"In my opinion, what can be improved in Qualys TotalCloud includes pricing and container scanning."
"The support process is inefficient due to the excessive number of replies required when submitting tickets."
"To improve the user experience, reporting could be simplified for better comprehension by end users and project managers, facilitating issue resolution."
"TotalCloud could improve the classification of vulnerabilities. Specifically, it could enhance the categorization of what aspects fall under patches resolved by OS or software updates and what pertains to configuration adjustments."
"The areas in the solution that have room for improvement include the UI/UX design, which should be improved, and they should integrate more artificial intelligence into the product."
"Their support could be improved."
"The cost of Qualys TotalCloud is high and could be more competitive."
"The price is very expensive, actually."
"I would like to see a remote access assistance feature. And the threat-hunting platform could be better."
"Policy implementation is quite complex, and the stability will take more time for the solutions."
"I am not fully satisfied with FortiCNAPP because the product has limited functions and it requires the use of other Fortinet tools for complete capabilities."
"The customer support for FortiCNAPP is fine, though it can take time as we need to engage with AWS first, but I would rate it around 7 or 8 out of 10."
"A feature that I have requested from them is the ability to sort alerts and policies based on a security framework. Right now, when you go into alerts, you have hundreds and hundreds of them that you have to manually pick. It would be useful to have categories for CIS Benchmark or SOC 2 and be able to display all the alerts and policies for one security framework."
"The vulnerability part is not systematically organized; it is all clumsy in the web UI, and it is not user-friendly."
"Lacework lacks remediation features, but I believe they're working on that. They're focused on the reporting aspect, but other features need to improve. They're also adding some compliance features, so it's not worth saying they need to get better at it."
"FortiCNAPP can be improved because the platform can feel complex at the start, especially for teams new to CNAP tooling."
"The cost of the solution has room for improvement."
 

Pricing and Cost Advice

"While Qualys TotalCloud's pricing is currently acceptable, it is becoming increasingly expensive and may soon be considered overpriced."
"The cost is high, but it meets our organizational needs."
"Qualys TotalCloud is expensive, but it offers a premier solution with no headaches."
"It isn't cheap, but it's reasonable. It helps us to manage things with very few resources."
"Qualys TotalCloud is cost-efficient and was selected for its value compared to other products."
"I am not sure about the pricing. From what I understand, it is a bit on the higher side, but I do not have the exact numbers."
"Qualys TotalCloud offers competitive pricing given its comprehensive suite of features, including integration, assessment, remediation, and detection capabilities, all within a single platform."
"Although Qualys TotalCloud is relatively expensive due to its unique automation features, its cost-effectiveness is rated an eight out of ten, with ten being the most costly."
"The licensing fee was approximately $80,000 USD, per year."
"The pricing has gotten better. That scenario was somewhat unstable. They have a rather interesting licensing structure. I believe you get 200 resources per "Lacework unit." It was difficult, in the beginning, to figure out exactly what a "resource" was... That was a problem until about a year or so ago. They have improved it and it has stabilized quite a bit."
"It is slightly expensive. It depends on how big your environment is, but it is expensive. Right now, we are spending a lot of money. We have covered all of the cloud providers and most of our colocation facilities as well, so we cannot complain, but it is slightly expensive. It is not super expensive."
"My smaller deployments cost around 200,000 a year, which is probably not as expensive as Wiz."
"The cost of the solution is mid-ranged but worth the price."
report
Use our free recommendation engine to learn which Vulnerability Management solutions are best for your needs.
908,858 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Manufacturing Company
13%
Outsourcing Company
12%
Comms Service Provider
10%
Financial Services Firm
10%
Construction Company
9%
Financial Services Firm
8%
Comms Service Provider
8%
Computer Software Company
7%
No data available
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business11
Midsize Enterprise5
Large Enterprise30
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise5
Large Enterprise8
No data available
 

Questions from the Community

What needs improvement with Qualys TotalCloud?
To be totally honest, I do not have any best features because I have had a bad experience using this tool, especially...
What is your primary use case for Qualys TotalCloud?
My main use case for Qualys TotalCloud is vulnerability management and exposure management. I use this tool to evalua...
What is your experience regarding pricing and costs for Lacework?
We purchased the Fortinet firewall and services from a vendor, not through any other marketplaces.
What needs improvement with Lacework?
FortiCNAPP can be improved because the platform can feel complex at the start, especially for teams new to CNAP tooli...
What is your primary use case for Lacework?
My main use case for FortiCNAPP, from my previous experience distributing it or now as a reseller, is for anyone who'...
Ask a question
Earn 20 points
 

Also Known As

Qualys TotalCloud with FlexScan
Polygraph, FortiCNP, Lacework
No data available
 

Interactive Demo

Demo not available
Demo not available
 

Overview

 

Sample Customers

Information Not Available
J.Crew, AdRoll, Snowflake, VMWare, Iterable, Pure Storage, TrueCar, NerdWallet, and more.
Information Not Available
Find out what your peers are saying about Wiz, Tenable, Qualys and others in Vulnerability Management. Updated: July 2026.
908,858 professionals have used our research since 2012.