

Vulcan Cyber and Qualys CyberSecurity Asset Management are key contenders in cybersecurity management. Qualys seems to have the upper hand with its expansive features and comprehensive asset inventory capabilities, providing a holistic view of vulnerabilities and risks.
Features: Vulcan Cyber offers robust automation, centralizing signals for effective prioritization and categorization of vulnerabilities. It integrates diverse vulnerability data to help stakeholders assess threats. Qualys CyberSecurity Asset Management delivers an extensive asset inventory, incorporating dynamic tagging and software lifecycle insights. Its asset discovery and TruRisk scoring offer a comprehensive view of hardware and software vulnerabilities with detailed tagging and customizable options.
Room for Improvement: Vulcan Cyber should enhance connector maintenance, UI and dashboard performance, and tackle bulk data management for better organization and documentation. Qualys needs a refreshed user interface, more flexible scan configurations, and improved integration with non-standard tools. Enhancing dynamic tagging and customizing reports would elevate user experience.
Ease of Deployment and Customer Service: Vulcan Cyber provides flexible deployment with on-premises and public cloud options, although it requires more timely support resolutions. Qualys supports various cloud setups, including public, hybrid, and private clouds. While generally responsive, its complex integrations sometimes lead to service delays.
Pricing and ROI: Vulcan Cyber offers competitive pricing that enhances efficiency for security personnel, despite some missing features. Conversely, Qualys, although costly for smaller entities, delivers excellent value with detailed features. Its transparent pricing and flexibility yield significant value despite higher costs, aiding asset management processes effectively.
Improvements to our security infrastructure contributed to overall business growth of approximately 150 percent over the past year.
By automating tasks, it significantly reduces the human resources required, leading to increased efficiency and productivity.
It has reduced the number of development and scripting hours along with maintenance hours.
With our vulnerability management platform, I used to get reports weekly, but with Vulcan Cyber, I get them daily.
Our security team probably spends 15 minutes instead of two hours daily notifying the teams.
The support team was knowledgeable and offered a variety of quick resolution options.
Their SMEs have sufficient knowledge, and if they are not the right contact, they quickly redirect us to someone who can help resolve issues.
I would rate their customer support a ten out of ten.
We do not necessarily have visibility of when those feature requests are going into the development pipeline.
It would enhance my experience if Vulcan informed customers of forthcoming maintenance or changes that might cause website downtime.
Their technical support team is very good, knowledgeable, and helpful.
We have about 300,000 assets installed with agents worldwide.
The scalability is excellent as we manage more than one hundred thousand assets, including over one hundred thousand endpoints, approximately 2,600 servers, and more than 1,200 network devices.
Qualys Cybersecurity Asset Management has proven to be a highly scalable solution for us over the past couple of years.
We have a lot of assets under management, and it effectively scales up to accommodate hundreds or even thousands of assets.
I'd rate the scalability ten out of ten.
I would rate it ten out of ten for scalability, as integration with multiple connectors is possible without exceeding licensing limits.
I would rate the stability of Qualys CSAM a ten out of ten.
The product stability has notably declined over the last two months, and the performance to fulfill a page request is very slow compared to its previous performance.
They are constantly adding capabilities.
It would be better if Vulcan notified me, the customer, about upcoming maintenance or changes, indicating when the website might be down.
The product's stability is commendable, with no noticeable lags or slowness.
I would rate it a nine out of ten in terms of stability.
Qualys is currently not able to identify assets lacking DNS information.
Features enhancing the interaction with IT or security teams should be added, such as a ticketing feature that, if an issue arises in the CSAM module, enables direct ticket creation in systems like ServiceNow.
If there's one key aspect to focus on, it's discovery—the ability to identify assets that you are not aware of, even when you can see they are present.
It would be beneficial if the platform allowed remote access to devices for immediate remedies.
Providing real-world examples of how to construct a ticket format for Jira, Azure DevOps, or ServiceNow with specific examples would help us understand how it might work in our environment.
Having it more customized or providing more customization options for me would be beneficial.
A cost-effective solution.
I believe that the stability and reliability of Qualys offer great value for the money.
A monthly subscription starting at approximately $72 per month, depending on the specific package and features included.
For our use case, the solution is lacking some features, and the cost savings don't make it worth it.
By correlating this with QDS scores, we can accurately assess the risk level of high or low QDS scores associated with each asset and monitor them accordingly.
The most valuable feature is the real-time visibility Qualys CyberSecurity Asset Management provides into all assets across our development and operational environments.
It also performs scans to identify any vulnerabilities, which helps to take proactive measures before those vulnerabilities are identified by any attacker.
It offers a comprehensive view of the assets and their associated vulnerabilities, which aids in assessing and mitigating threats.
The automation capabilities using the Vulcan API platform or the API feature allow me to easily automate scripts and reports and schedule them.
Instead of having 100 vulnerabilities and not knowing how to prioritize and assign all your FTEs there, you now have only ten that you know you need to fix, and you're assigning the right number of FTEs.
| Product | Mindshare (%) |
|---|---|
| Qualys CyberSecurity Asset Management | 1.3% |
| Vulcan Cyber | 0.6% |
| Other | 98.1% |

| Company Size | Count |
|---|---|
| Small Business | 8 |
| Midsize Enterprise | 2 |
| Large Enterprise | 23 |
| Company Size | Count |
|---|---|
| Small Business | 1 |
| Large Enterprise | 10 |
Qualys CyberSecurity Asset Management provides key features including asset inventory management, end-of-life tracking, dynamic tagging, and integration with CMDB, offering extensive visibility and support for proactive threat response.
Qualys offers comprehensive visibility across hardware and software assets, aiding in tracking unauthorized applications and facilitating automated vulnerability remediation. Its user-friendly interface and dynamic risk scoring enhance security posture management. Users leverage it for vulnerability management and compliance, benefiting from real-time risk identification and efficient operations in cloud and on-premises environments.
What are the key features of Qualys CyberSecurity Asset Management?Cybersecurity teams in various industries, such as financial services, healthcare, and manufacturing, utilize Qualys to manage technical debt through end-of-life tracking and facilitate robust patch management. It supports compliance and visibility initiatives, essential for maintaining data integrity and operational security in dynamic environments.
Vulcan Cyber is used by leading cyber security organizations to manage exposure risk created by unmitigated infrastructure, application, code and cloud vulnerabilities.
The Vulcan Cyber ExposureOS starts by correlating and normalizing risk and asset data aggregated from hundreds of vulnerability scanners, asset repositories and threat intelligence feeds. These signals are then used to create a singular view of your organization's attack surfaces to make exposure risk and vulnerability prioritization accurate and actionable.
Vulcan Cyber ExposureOS reduces mean time to remediation by fostering efficient collaboration among security teams, asset and remediation owners through orchestrated workflows and automated remediation tasks.
Use Vulcan Cyber to measure security posture improvement, efficacy of vulnerability risk mitigation campaigns, and compliance with SLAs and regulatory frameworks such as PCI DSS, DORA, NIS2 and HIPPA.
Vulcan Cyber is the only vulnerability risk management solution provider to be named a "Leader" in both the Forrester Wave and Omdia Universe evaluations in 2023.
We monitor all Vulnerability Management reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.