Try our new research platform with insights from 80,000+ expert users

Qualys TotalCloud vs Rapid7 InsightCloudSec comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 9, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
7.2
SentinelOne Singularity Cloud Security automates operations, improving compliance, reducing costs, and boosting productivity by up to 40%.
Sentiment score
6.4
Qualys TotalCloud enhances efficiency, reduces workloads and costs, achieving substantial ROI through automation and strategic engagements.
Sentiment score
6.0
Rapid7 InsightCloudSec saves costs, reduces risks, automates tasks, and streamlines compliance, enhancing security and operational efficiency.
The detailed information PingSafe gives about how to fix vulnerabilities reduces the time spent on remediation by about 70 to 80 percent.
Security and Compliance Manager at Bidgely
After implementing SentinelOne, it takes about five to seven minutes.
Cloud engineer at a construction company with 5,001-10,000 employees
Our ability to get in and review our vulnerability stance, whether daily, monthly, weekly, or whatever it might be, has drastically improved over our prior provider.
IT Support Specialist at a non-tech company with 201-500 employees
It has saved about 90% of our time.
Senior Consultant at a consultancy with 10,001+ employees
TotalCloud has generated overall savings of 30 to 40 percent across various departments.
Security Manager at a consultancy with 10,001+ employees
CallStream helps us integrate and automate tasks.
Senior Security Consultant at CyberNxt Solutions LLP
By catching issues early, Rapid7 InsightCloudSec helps us prevent costly breaches or regulatory fines; for example, automating patching and misconfiguration audits can save thousands in operational overhead.
Site Reliability Engineer at a comms service provider with 501-1,000 employees
It provides a good security posture and helps handle misconfigurations and day-to-day remediations.
Senior Cloud Security Engineer at a educational organization with 10,001+ employees
I can confirm money and time savings with Rapid7 InsightCloudSec, as we can scan the entire IP range simultaneously instead of manually checking each asset for vulnerabilities.
Junior systems engineer at a tech services company with 11-50 employees
 

Customer Service

Sentiment score
7.8
SentinelOne's Cloud Security users praise fast, effective support with proactive assistance and efficient issue resolution across multiple channels.
Sentiment score
7.4
Qualys TotalCloud's customer service is praised for effectiveness but faces criticism for delayed responses and varying support staff expertise.
Sentiment score
4.9
Rapid7 InsightCloudSec customer service receives mixed reviews, excelling in responsiveness but needing improvement in communication and local presence.
When we send an email, they respond quickly and proactively provide solutions.
Security and Compliance Manager at Bidgely
They took direct responsibility for the system and could solve queries quickly.
Senior DevOps Engineer at a tech services company with 501-1,000 employees
Having a reliable team ready and willing to assist with any issues is essential.
Director, DevOps at Relay Network
They are helpful, respond to my queries, and can answer any question.
Developer at a consultancy with 10,001+ employees
Qualys's tech support is highly responsive, providing multiple ways to interact with them.
Service Manager, Security Operations at CDA IT SOLUTIONS
Qualys' customer service provides quality answers, but the response time is long, even though it is within the SLA.
Works at a consultancy with 10,001+ employees
On a scale of 1 to 10, the customer support would be rated a 10, as responses are typically received within about half an hour to an hour when creating a ticket.
Senior Platform Engineer Lead at a tech services company with 1,001-5,000 employees
They have excellent support with internal Slack channels and are directly reachable through Teams.
Senior Cloud Security Engineer at a educational organization with 10,001+ employees
I interacted with customer support after an endpoint compromise incident, and they responded quickly and provided clear insights that were essential for resolving the situation.
Platform Engineer at Cedar Gate Technologies, LLC
 

Scalability Issues

Sentiment score
8.1
Users praise SentinelOne Singularity Cloud Security's scalable integration, adaptability, and high ratings, ideal for diverse organization sizes.
Sentiment score
8.1
Qualys TotalCloud is praised for seamless scalability, effectively managing deployments and applications across diverse environments and growing enterprises.
Sentiment score
5.8
Rapid7 InsightCloudSec is a scalable, adaptable SaaS tool providing reliable cloud visibility but may require specific configurations.
I would rate it a 10 out of 10 for scalability.
IT Engineer at a venture capital & private equity firm with 1,001-5,000 employees
Scalability is no longer a concern because Cloud Native Security is a fully cloud-based resource.
CISO at a computer software company with 201-500 employees
I would rate the scalability of PingSafe 10 out of 10.
Sr DevOps Engineer at a media company with 51-200 employees
We started our organization about nine months back. We started with about 30 users, and we now have more than 100 users.
CIO at a venture capital & private equity firm with 11-50 employees
Our organization currently uses it to manage over 1200 web applications.
Analyst, Information Security at Infosys
It is absolutely scalable, and I would rate its scalability as nine out of ten.
retired at a consultancy with 10,001+ employees
I have not experienced performance issues as I add more assets, and everything operates smoothly within one console.
Junior systems engineer at a tech services company with 11-50 employees
 

Stability Issues

Sentiment score
8.2
SentinelOne Singularity Cloud Security offers high stability, rare glitches, and 100% uptime, outperforming previous tools in reliability and performance.
Sentiment score
8.4
Qualys TotalCloud is praised for its high stability, minimal downtime, and smooth performance with effective maintenance and bug fixes.
Sentiment score
8.0
Users are pleased with Rapid7 InsightCloudSec's stability, though some experience slight slowness due to its SaaS platform.
SentinelOne Singularity Cloud is incredibly reliable.
Security Analyst at Intersistemi Italia s.p.a.
We contacted Cloud Native Security, and they addressed it in a day.
DevSecOps Engineer at a tech company with 1,001-5,000 employees
The only downtime we had was when switching from V1 to V2 but it was smooth.
Cloud Security Specialist at a insurance company with 10,001+ employees
Overall, the support provided has been excellent.
Analyst, Information Security at Infosys
It is a stable solution, which is why we chose it.
CIO at a venture capital & private equity firm with 11-50 employees
Continuous monitoring is crucial to ensure system stability and avoid vulnerabilities or threats.
Developer at a consultancy with 10,001+ employees
Rapid7 InsightCloudSec works without any stability issues so far.
Junior Security Analyst at a financial services firm with 51-200 employees
 

Room For Improvement

SentinelOne Singularity needs better container security, integrations, and usability enhancements, addressing reporting, costs, and documentation issues.
Qualys TotalCloud users report unclear licensing, challenging dashboard, needed feature enhancements, UI improvements, platform support, and pricing concerns.
Rapid7 InsightCloudSec needs UI/UX improvements, better third-party integration, enhanced reporting, and refined risk prioritization and detection capabilities.
If they can merge Kubernetes Security with other modules related to Kubernetes, that would help us to get more modules in the current subscription.
IT Engineer at a venture capital & private equity firm with 1,001-5,000 employees
As organizations move to the cloud, a cloud posture management tool that offers complete cloud visibility becomes crucial for maintaining compliance.
CISO at a computer software company with 201-500 employees
I would also like to see Cloud Native Security offer APIs that allow us to directly build dashboards within the platform.
Senior Cybersecurity Engineer at a computer software company with 11-50 employees
Ideally, the scanner should automatically detect and scan all subdomains, even if not explicitly defined, ensuring comprehensive vulnerability assessment.
Analyst, Information Security at Infosys
Ideally, updates should be more immediate, enabling quicker implementation of solutions.
Project Lead at Persistent Systems
Our goal is to integrate all these functions into Qualys, creating a single dashboard for comprehensive security monitoring and management.
Senior Information Security Engineer at a consultancy with 10,001+ employees
Rapid7 InsightCloudSec already provides us real-time feedback loops, but if it also provides real-time feedback to the developers, then it would help the application shift left, meaning the security will shift left as well.
Site Reliability Engineer at a comms service provider with 501-1,000 employees
Rapid7 InsightCloudSec needs improvements such as AI-driven risk prioritization, proactive cloud risk modeling, advanced IAM privilege analysis, multi-cloud attack path mapping, pre-built automated hardening, defining stronger policy as code support, better container and serverless coverage, and cost optimization insight along with safe auto-remediation with rollback improvements.
Cybersecurity analyst at Cornerstone OnDemand
If you can improve the traditional detection rules to reflect current detection rules, it would make it significantly easier for us to manage, as we constantly need to check legacy rules to update or possibly turn them off. Updating the legacy rules should be a priority.
SOC analyst at a media company with 1,001-5,000 employees
 

Setup Cost

SentinelOne Singularity Cloud is valued for its adaptable pricing and cost-effectiveness, notably through AWS partnerships, against competitors.
Qualys TotalCloud pricing is seen as either expensive or competitive, with features and flexibility justifying the cost for enterprises.
Rapid7 InsightCloudSec offers competitive, cost-efficient cloud security management with reasonable pricing, seamless licensing, and straightforward setup.
With very little negotiation involved, we just let them know what we could pay and they were willing to meet us at slightly above what we paid with Sophos, which was still very fair for what we were looking at.
IT Support Specialist at a non-tech company with 201-500 employees
There are some tools that are double the cost of Cloud Native Security.
IT Engineer at a venture capital & private equity firm with 1,001-5,000 employees
I recall Cloud Native Security charging a slightly higher premium previously.
Senior Cybersecurity Engineer at a computer software company with 11-50 employees
Qualys TotalCloud's pricing is currently acceptable, it is becoming increasingly expensive.
Senior Manager at a financial services firm with 10,001+ employees
Pricing is managed by our finance team; however, Qualys TotalCloud offers cost-effective licensing flexibility.
IT Manager at a consultancy with 10,001+ employees
Qualys TotalCloud is expensive, but it offers a premier solution with no headaches.
Vice President at Inspira Enterprise
It is cheaper.
Senior Cloud Security Engineer at a educational organization with 10,001+ employees
The more numbers you have, the less costly the product becomes, as licensing operates on volume.
Junior systems engineer at a tech services company with 11-50 employees
While it was not overly expensive, I do wish for more discounts for bulk purchases since we have implemented it widely across our cloud security posture.
Platform Engineer at Cedar Gate Technologies, LLC
 

Valuable Features

SentinelOne Singularity Cloud Security offers real-time threat detection, automated remediation, and seamless cloud integration with advanced security features.
Qualys TotalCloud provides comprehensive security management with automatic detection, real-time protection, and integrated dashboards, enhancing visibility and reducing workloads.
Rapid7 InsightCloudSec enhances security with frameworks, threat detection, automation, and AI log searches, boosting efficiency and response speed.
This helps visualize potential attack paths and even suggests attack paths a malicious actor might take.
Security Engineer-DevSecOps at a computer software company with 51-200 employees
The infrastructure-as-code feature is helpful for discovering open ports in some of the modules.
DevSecOps Engineer at a tech company with 1,001-5,000 employees
This tool has been helpful for us. It allows us to search for vulnerabilities and provides evidence directly on the screen.
Cloud Security Specialist at a insurance company with 10,001+ employees
This view of risk helps reduce the work we would have to do to combine multiple sources to prioritize risk.
Works at a consultancy with 10,001+ employees
It will help cybersecurity professionals monitor the cloud and find vulnerabilities.
Developer at a consultancy with 10,001+ employees
We are enjoying the new feature, FlexScan, which is valuable for Internet-facing VMs.
Senior Consultant at a consultancy with 10,001+ employees
Using Rapid7 InsightCloudSec alongside our ManageEngine patch management module positively impacts my organization by scanning assets deeply and providing all identified vulnerabilities, from zero-day to any vulnerabilities on an asset, addressing those that ManageEngine might not identify.
Junior systems engineer at a tech services company with 11-50 employees
Rapid7 InsightCloudSec has helped us save thirty percent time in our log retrievals, and it completely changed log searching, making it really fast when we search for logs, with no prior knowledge required.
Site Reliability Engineer at a comms service provider with 501-1,000 employees
Rapid7 InsightCloudSec positively impacts my organization by integrating tightly with my existing vulnerability management process and workflows, particularly in creating a new project and implementing trigger-based scanning.
Assistant Vice President for Security Operation Center at Sohar International Bank
 

Categories and Ranking

SentinelOne Singularity Clo...
Sponsored
Ranking in Cloud Security Posture Management (CSPM)
3rd
Ranking in Cloud-Native Application Protection Platforms (CNAPP)
3rd
Average Rating
8.6
Reviews Sentiment
7.7
Number of Reviews
116
Ranking in other categories
Vulnerability Management (4th), Cloud and Data Center Security (3rd), Container Security (3rd), Cloud Workload Protection Platforms (CWPP) (4th), Compliance Management (2nd), AI Software Development (1st), AI Observability (2nd)
Qualys TotalCloud
Ranking in Cloud Security Posture Management (CSPM)
8th
Ranking in Cloud-Native Application Protection Platforms (CNAPP)
7th
Average Rating
8.6
Reviews Sentiment
7.5
Number of Reviews
35
Ranking in other categories
Vulnerability Management (10th), Container Security (12th), Cloud Workload Protection Platforms (CWPP) (8th), SaaS Security Posture Management (SSPM) (2nd)
Rapid7 InsightCloudSec
Ranking in Cloud Security Posture Management (CSPM)
14th
Ranking in Cloud-Native Application Protection Platforms (CNAPP)
10th
Average Rating
7.8
Reviews Sentiment
6.3
Number of Reviews
13
Ranking in other categories
Cloud Management (13th), AI Observability (6th)
 

Mindshare comparison

As of January 2026, in the Cloud Security Posture Management (CSPM) category, the mindshare of SentinelOne Singularity Cloud Security is 4.0%, up from 2.1% compared to the previous year. The mindshare of Qualys TotalCloud is 1.3%, up from 1.0% compared to the previous year. The mindshare of Rapid7 InsightCloudSec is 1.6%, up from 1.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Cloud Security Posture Management (CSPM) Market Share Distribution
ProductMarket Share (%)
SentinelOne Singularity Cloud Security4.0%
Qualys TotalCloud1.3%
Rapid7 InsightCloudSec1.6%
Other93.1%
Cloud Security Posture Management (CSPM)
 

Featured Reviews

SC
Information Security Engineer at DataVigilant Infotech
Enables us to prioritize and effectively address critical security issues
Evidence-based reporting helps us to prioritize and solve critical security issues. The new visualization feature demonstrates how an attacker can enter the system, highlighting the potential path that can be exploited and outlining all the steps the attacker could take. With that visibility, we can ensure the perimeter is strong and attackers cannot enter, thus reducing the risk. It has helped us prioritize issues. The visibility into how an attack could happen is valuable. For example, it highlights the system vulnerability and outlines where an attack could propagate. The visualization helps me to prioritize remediation, and if I don't know where to start, I can check to see the score that enables me to prioritize issues. I am using infrastructure-as-code scanning, and it's one of the useful features. In pre-production, it identifies embedded secrets and misconfigurations, including issues with Kubernetes or some privileged containers. This feature allows us to pass the audit and secure IaC code so that it isn't easily exploitable by attackers. We can more proactively work to identify and resolve vulnerabilities by using the dashboard and the alerting system that SentinelOne provides. It helps us with audits and compliance. We can show the compliance in percentage. We can confidently say that our company or infrastructure is very secure. It has improved our security posture by 30% to 35%. It has reduced our false positives by 30%. It has helped teams collaborate better. The security team manages SentinelOne Singularity Cloud Security, and when it flags vulnerabilities, they are forwarded to DevOps for remediation. Previously, we needed to identify and report the issues, but there would be lapses in communication. Now, there is a centralized dashboard that anyone can look at and see the open issues and work on them.
AN
Cyber Security Specialist at UBS Financial
A centralized tool for vulnerability and misconfiguration management in a multiple cloud environment
Qualys TotalCloud provides written explanations to help guide the remediation paths and eliminate cyber risk. We are using TruRisk for the remediations. The TruRisk shows anything critical, and we can then focus on that. We also assess manually whether an asset is a critical target or not. Qualys TotalCloud provides a single, prioritized view of risk. We are using CIS-CAT standards to harden our clouds, such as AWS, Google Cloud, and Azure. We are able to analyze the scans and identify which policies have failed and how we can remediate them. We can customize policies as per our organization's requirements. That is very helpful for us. With the TruRisk Insights feature, security has significantly improved. In six months of using it, we see that everything is under control. We've solved many problems related to asset management, cloud configuration, and the new asset identification. If an application team has onboarded any cloud asset, we can see that. We have that information now.
Arun Babu - PeerSpot reviewer
SOC analyst at a media company with 1,001-5,000 employees
Daily endpoint monitoring has improved investigations and saved time but detection rules still need tuning
It is important to note that Rapid7 InsightCloudSec's features are not 100% precise, but I find about 70% of the time it is satisfactory. I would like to suggest that you improve it to be more precise, ideally making it 100% if possible. Some cases in Rapid7 InsightCloudSec indicate that the log is not enough, as they mostly just generate alerts, and the synchronization between data connectors is often problematic, particularly in terms of not being in sync always, especially between the AD and Rapid7 alerts, which generates numerous false positives. Additionally, the traditional rules should be updated, as this is a main point worth mentioning since we spend a lot of time fine-tuning these traditional rules. I suggest improving the legacy detection rules. If there are any authentication cases, such as impossible travel activity where a user has their SharePoint hosted in a different location, Rapid7 can often trigger alerts, creating confusion as we cannot fine-tune it properly. Another issue is with honeypot access. We sometimes lack necessary logs because Defender's advanced threat protection scanning gets detected as honeypot activity by Rapid7, leading to annoying and noisy alerts that we need to constantly close. If you can improve the traditional detection rules to reflect current detection rules, it would make it significantly easier for us to manage, as we constantly need to check legacy rules to update or possibly turn them off. Updating the legacy rules should be a priority.
report
Use our free recommendation engine to learn which Cloud Security Posture Management (CSPM) solutions are best for your needs.
881,082 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
14%
Computer Software Company
12%
Manufacturing Company
10%
Government
6%
Financial Services Firm
16%
Manufacturing Company
11%
Computer Software Company
10%
Government
9%
Insurance Company
10%
Manufacturing Company
9%
Financial Services Firm
8%
Computer Software Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business48
Midsize Enterprise20
Large Enterprise54
By reviewers
Company SizeCount
Small Business8
Midsize Enterprise2
Large Enterprise25
By reviewers
Company SizeCount
Small Business5
Midsize Enterprise5
Large Enterprise8
 

Questions from the Community

What do you like most about PingSafe?
The dashboard gives me an overview of all the things happening in the product, making it one of the tool's best featu...
What is your experience regarding pricing and costs for PingSafe?
I think the pricing of SentinelOne Singularity Cloud Security is a bit high.
What needs improvement with PingSafe?
We did not try to use the threat investigations feature from SentinelOne Singularity Cloud Security.Drift detection w...
What is your experience regarding pricing and costs for Qualys TotalCloud?
Regarding pricing and setup cost, it was not the most expensive. While checking tools for container scanning, we cons...
What needs improvement with Qualys TotalCloud?
I think Qualys TotalCloud needs to improve its handling of zero-day vulnerabilities and supply chain management becau...
What is your primary use case for Qualys TotalCloud?
I have approximately three to four years of experience working with Qualys TotalCloud. I have been using Qualys Total...
What do you like most about Rapid7 InsightCloudSec?
The tool provides centralized visibility through dashboards and alerts, allowing customers to receive reports on clou...
What is your experience regarding pricing and costs for Rapid7 InsightCloudSec?
The pricing, setup cost, and licensing for Rapid7 InsightCloudSec are reasonable, and since our organization is growi...
What needs improvement with Rapid7 InsightCloudSec?
I would say that because Rapid7 InsightCloudSec does not have automatic patching capabilities, it provides recommenda...
 

Also Known As

PingSafe
Qualys TotalCloud with FlexScan
DivvyCloud
 

Overview

 

Sample Customers

Information Not Available
Information Not Available
Fannie Mae, 3M, PizzaHut, Spotify, Autodesk, Discovery
Find out what your peers are saying about Qualys TotalCloud vs. Rapid7 InsightCloudSec and other solutions. Updated: December 2025.
881,082 professionals have used our research since 2012.