Try our new research platform with insights from 80,000+ expert users

Qualys CyberSecurity Asset Management vs The NodeZero Platform by Horizon3.ai comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Feb 8, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
4.9
Qualys CyberSecurity Asset Management boosts efficiency, reduces costs, enhances security, and delivers a 95% ROI with 35% cost reduction.
Sentiment score
3.0
NodeZero Platform boosts efficiency, reduces costs, and improves scalability but shows variable returns on investment for users.
Improvements to our security infrastructure contributed to overall business growth of approximately 150 percent over the past year.
Android Developer at Droidforge
By automating tasks, it significantly reduces the human resources required, leading to increased efficiency and productivity.
Senior Manager at a consultancy with 10,001+ employees
It has reduced the number of development and scripting hours along with maintenance hours.
Security Operations Manager at Solventum
A reduction in remediation time has been seen because it is finding things before they happen.
Director of Enterprise Security at a energy/utilities company with 51-200 employees
Being able to find them because there have been no eyes on that particular section so far ever, and fixing those potentially prevented those companies from getting breached.
IT Security Consultant at Systemhaus for you GmbH
So far, I have seen a return on investment with The NodeZero Platform by Horizon3.ai, as we managed to save a lot of time and effort with this because this is an autonomous tool, and our manual effort is significantly reduced because of a product of this type.
Senior Manager | Manager Security Services at RISK ASSOCIATES
 

Customer Service

Sentiment score
7.5
Qualys CyberSecurity Asset Management's customer service is highly praised for its responsiveness, effectiveness, and swift problem resolution capabilities.
Sentiment score
6.6
The NodeZero Platform by Horizon3.ai excels in customer service with swift, effective support, earning high satisfaction ratings.
The support team was knowledgeable and offered a variety of quick resolution options.
Android Developer at Droidforge
Their SMEs have sufficient knowledge, and if they are not the right contact, they quickly redirect us to someone who can help resolve issues.
Senior Information Security Engineer at a consultancy with 10,001+ employees
I would rate their customer support a ten out of ten.
Information Security Lead at a consultancy with 10,001+ employees
Overall, when it comes to The NodeZero Platform's tech support, you can reach them via a chat message on their website, and they respond almost immediately.
Director of IT Security at a manufacturing company with 1,001-5,000 employees
Previously, with time-sensitive engagements, I would worry about resolving issues before deadlines. That concern has diminished as they've become more responsive and require less escalation to engineering.
Principal Consultant at JTI Cybersecurity
The vast majority of times they are able to resolve the exact questions my team has on the first attempt, which is really good for customer or technical support.
Chief Information Officer at a construction company with 1,001-5,000 employees
 

Scalability Issues

Sentiment score
7.8
Qualys CyberSecurity Asset Management excels in scalability, supporting diverse environments with numerous users, networks, and large datasets efficiently.
Sentiment score
7.3
NodeZero Platform efficiently manages large-scale networks, ensuring seamless deployment and performance even with extensive assets and IP addresses.
We have about 300,000 assets installed with agents worldwide.
Information Security Lead at a consultancy with 10,001+ employees
The scalability is excellent as we manage more than one hundred thousand assets, including over one hundred thousand endpoints, approximately 2,600 servers, and more than 1,200 network devices.
Cyber Security Specialist at UBS Financial
Qualys Cybersecurity Asset Management has proven to be a highly scalable solution for us over the past couple of years.
Manager Information Security at a consultancy with 10,001+ employees
We have conducted pen tests in environments with hundreds of thousands of IP addresses without any scalability issues.
CEO at cybovate
We currently scan approximately 1,500-2,000 assets and haven't encountered any scaling or throughput issues.
Information Security Manager at a non-profit with 51-200 employees
Anywhere you can put a VM, you can run another concurrent scan.
Director of IT Security at a manufacturing company with 1,001-5,000 employees
 

Stability Issues

Sentiment score
7.5
Qualys CyberSecurity Asset Management is stable, highly rated, with minimal issues, and appreciated for its consistent enhancements and features.
Sentiment score
8.0
NodeZero Platform offers stable performance without crashes, with occasional long scans due to credential identification, resolved by memory adjustments.
I would rate the stability of Qualys CSAM a ten out of ten.
IT Engineer at a consultancy with 10,001+ employees
The product stability has notably declined over the last two months, and the performance to fulfill a page request is very slow compared to its previous performance.
SENIOR MANAGER, CYBERSECURITY THREAT, RISK & ARCHITECTURE at a tech vendor with 1,001-5,000 employees
They are constantly adding capabilities.
Director of Vulnerability Management at a insurance company with 1,001-5,000 employees
We have not encountered any issues on the platform regarding accessibility, performance, or stability.
CEO at cybovate
Regarding stability, it has never crashed, and there has not been any lagging from deployment or running.
Director of Enterprise Security at a energy/utilities company with 51-200 employees
I would rate the stability of The NodeZero Platform by Horizon3.ai as a ten.
Senior Manager | Manager Security Services at RISK ASSOCIATES
 

Room For Improvement

Qualys CyberSecurity Asset Management struggles with integration, configuration flexibility, tagging accuracy, and performance issues needing improvement.
Improvements in notifications, reporting, integration, and training are needed alongside enhanced testing capabilities and cost efficiency concerns.
Qualys is currently not able to identify assets lacking DNS information.
Senior Information Security Engineer at a consultancy with 10,001+ employees
Features enhancing the interaction with IT or security teams should be added, such as a ticketing feature that, if an issue arises in the CSAM module, enables direct ticket creation in systems like ServiceNow.
Senior Security Consultant at CyberNxt Solutions LLP
If there's one key aspect to focus on, it's discovery—the ability to identify assets that you are not aware of, even when you can see they are present.
Information Security Engineer at a manufacturing company with 5,001-10,000 employees
This service reveals which credentials and email addresses are available on the deep web, as well as which domains have been set up using typo-squatting techniques.
Information Security Manager at a non-profit with 51-200 employees
The one thing that is very much asked from us as a service provider is DAST testing, so when a company is building a software, they could see their current security status while they are building the application.
Offensive Security Analyst at a tech services company with 201-500 employees
One of the areas where improvement is needed is in the visibility and reporting for large enterprises.
CEO at cybovate
 

Setup Cost

Qualys offers high yet flexible pricing, valued for comprehensive features and cost-effectiveness, especially when bundled with other services.
Enterprise users value NodeZero Platform's cost-efficient pricing and flexibility, finding it cheaper and more extensive than manual pentests.
A cost-effective solution.
Senior Security Consultant at CyberNxt Solutions LLP
I believe that the stability and reliability of Qualys offer great value for the money.
Information Security Engineer at a manufacturing company with 5,001-10,000 employees
A monthly subscription starting at approximately $72 per month, depending on the specific package and features included.
Android Developer at Droidforge
The pricing is much more affordable than traditional penetration tests.
Manager, Information Technology at a performing arts with 11-50 employees
It's a bit cheaper than manual penetration testing because manual testing typically allows you to scan only a few subnets.
Works at a hospitality company with 201-500 employees
While cheaper than XM Cyber and human pen testers, it's more expensive than vulnerability managers.
CEO at cybovate
 

Valuable Features

Qualys CyberSecurity Asset Management enhances security with real-time visibility, integration, TruRisk scoring, and simplified asset and patch management.
NodeZero Platform by Horizon3.ai automates penetration testing, enhances cybersecurity, and saves time with precise remediation, scalability, and ease of use.
By correlating this with QDS scores, we can accurately assess the risk level of high or low QDS scores associated with each asset and monitor them accordingly.
Senior Information Security Engineer at a consultancy with 10,001+ employees
The most valuable feature is the real-time visibility Qualys CyberSecurity Asset Management provides into all assets across our development and operational environments.
Android Developer at Droidforge
It also performs scans to identify any vulnerabilities, which helps to take proactive measures before those vulnerabilities are identified by any attacker.
Information Security Lead at a consultancy with 10,001+ employees
When a new vulnerability, such as a zero-day exploit, is identified, they review your previous scans to determine if you might be vulnerable to it, and they proactively notify you.
Director of IT Security at a manufacturing company with 1,001-5,000 employees
The detailed reports not only list the vulnerabilities that matter, but they also include direct links to patches.
Information Security Manager at a non-profit with 51-200 employees
The NodeZero Platform's real attack capabilities help in identifying vulnerabilities on our on-prem systems because it provides actual vulnerabilities by attacking our systems.
Chief Information Security Officer at a construction company with 1,001-5,000 employees
 

Categories and Ranking

Qualys CyberSecurity Asset ...
Ranking in Vulnerability Management
10th
Average Rating
9.0
Reviews Sentiment
7.0
Number of Reviews
35
Ranking in other categories
Patch Management (4th), Cyber Asset Attack Surface Management (CAASM) (3rd), Attack Surface Management (ASM) (2nd), Software Supply Chain Security (3rd)
The NodeZero Platform by Ho...
Ranking in Vulnerability Management
8th
Average Rating
9.0
Reviews Sentiment
5.9
Number of Reviews
16
Ranking in other categories
Advanced Threat Protection (ATP) (11th), Penetration Testing Services (1st), Breach and Attack Simulation (BAS) (1st), Risk-Based Vulnerability Management (5th)
 

Mindshare comparison

As of March 2026, in the Vulnerability Management category, the mindshare of Qualys CyberSecurity Asset Management is 1.4%, up from 0.6% compared to the previous year. The mindshare of The NodeZero Platform by Horizon3.ai is 1.5%, up from 0.9% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Vulnerability Management Mindshare Distribution
ProductMindshare (%)
The NodeZero Platform by Horizon3.ai1.5%
Qualys CyberSecurity Asset Management1.4%
Other97.1%
Vulnerability Management
 

Featured Reviews

AN
Cyber Security Specialist at UBS Financial
Customized dashboards and quick deployment support comprehensive asset management
We use the True Risk Score for vulnerability prioritization, though we do not solely rely upon it since some assets may be decommissioned soon or not in use. From Qualys CyberSecurity Asset Management, we primarily focus on internet-facing assets. We have created separate tasks for internet-facing assets and track the True Risk dashboard specifically for these assets. If the True Risk Score is higher for any internet-facing assets, then we take action accordingly. The True Risk Score is very helpful for prioritization. The initial setup was straightforward and easy. We needed to create customized tags, group them twice, and validate whether the operating system detection was true positive or false positive. We encountered some false positives, which required coordination with the IT team for verification. In six months, we had approximately 20-25 machines that needed verification on a weekly basis. We coordinated with the IT team to identify the exact operating system specifications.
Hussain Z - PeerSpot reviewer
Senior Manager | Manager Security Services at RISK ASSOCIATES
Automated testing has transformed how we deliver fast, consistent security assessments
The key capabilities of the NodeZero platform by Horizon3.ai that I have found most valuable are its speed, scalability, and consistency. It is able to cover a broad scope in a relatively short period of time, which delivers significant efficiency gains when compared with traditional manual testing. It also provides a more consistent outcome, as the process is not influenced by human bias or variability. One of the most valuable features is the ability for security teams to remediate and retest vulnerabilities immediately. The one-click verification capability is particularly effective, as it allows fixes to be validated quickly without the need to rerun the entire assessment. This streamlines the remediation cycle and supports faster confirmation of security improvements. The platform’s real attack capabilities have also helped reduce false positives in the identification of vulnerabilities across our on-premises systems. Because the findings are evidence-based and validated prior to reporting, the results are more reliable and actionable. This enables us to focus our efforts on confirmed security issues that genuinely require attention, rather than spending time investigating theoretical or unverified exposures. The NodeZero platform also strengthens my understanding of potential security threats through its continuously updated capabilities. With new vulnerabilities emerging and being exploited in the wild on a regular basis, it is valuable to have a platform backed by a strong research and development function that continuously updates attack content to reflect the current threat landscape. This makes the platform effective not only as a point-in-time validation tool, but as part of an ongoing and continuous security assurance programme.
report
Use our free recommendation engine to learn which Vulnerability Management solutions are best for your needs.
884,933 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
12%
Computer Software Company
11%
Manufacturing Company
8%
Comms Service Provider
6%
Comms Service Provider
10%
Manufacturing Company
8%
Computer Software Company
8%
Government
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business8
Midsize Enterprise2
Large Enterprise23
By reviewers
Company SizeCount
Small Business10
Midsize Enterprise2
Large Enterprise7
 

Questions from the Community

What needs improvement with Qualys CyberSecurity Asset Management?
I think the one thing Qualys CyberSecurity Asset Management can do better is the package management and the updating process. Knowing that you can't update any of the packages until you've done the...
What is your primary use case for Qualys CyberSecurity Asset Management?
I primarily use it for a small, single-site, multi-source setup with multi-WAN inputs. I have a main fiber connection and a couple of failovers while managing different networks across different se...
What needs improvement with Horizon3.ai?
Improvements with The NodeZero Platform by Horizon3.ai are already underway; many people mention infrastructure testing is well-handled, but they seek better web application testing, which is curre...
What is your primary use case for Horizon3.ai?
My main use case for The NodeZero Platform by Horizon3.ai is to demo the platform to our channel partners and any end-user customers that they bring us, and also for my own benefit, as we look at o...
What advice do you have for others considering Horizon3.ai?
The way you find a vulnerability with The NodeZero Platform by Horizon3.ai, you can also fix and then verify if that vulnerability has been solved, which is the selling point itself, emphasizing ex...
 

Also Known As

No data available
Horizon3.ai
 

Overview

 

Sample Customers

Information Not Available
Government agencies, Defense Industrial Base organizations, and enterprises in regulated industries such as finance, healthcare, manufacturing, and criticalinfrastructure rely on NodeZero to meet rigorous security and compliance requirements with continuous, scheduled, and on-demand testing.
Find out what your peers are saying about Qualys CyberSecurity Asset Management vs. The NodeZero Platform by Horizon3.ai and other solutions. Updated: March 2026.
884,933 professionals have used our research since 2012.