Try our new research platform with insights from 80,000+ expert users
it_user297117 - PeerSpot reviewer
Information Risk Analyst at a healthcare company with 1,001-5,000 employees
Vendor
Aug 23, 2015
We've gained insight into vulnerabilities across our environment, but reports should be more customizable.

What is most valuable?

The vulnerability scanning feature is valuable.

How has it helped my organization?

QualysGuard has provided us with a valuable insight into vulnerabilities across our environment. Before the use of this product, we had no way of identifying or tracking vulnerabilities.

What needs improvement?

The reporting capabilities are good but I would like to be able to make more customized reports. In addition, I would like to be able to assign a numerical asset value to critical hosts.

For how long have I used the solution?

I've used it for six years.

Buyer's Guide
Qualys VMDR
January 2026
Learn what your peers think about Qualys VMDR. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,757 professionals have used our research since 2012.

What was my experience with deployment of the solution?

No issues encountered, it went very smoothly.

What do I think about the stability of the solution?

No issues encountered.

What do I think about the scalability of the solution?

No, as it's very easy to add additional hosts.

How are customer service and support?

Customer Service:

8/10.

Technical Support:

8/10.

Which solution did I use previously and why did I switch?

We didn't use a previous solution.

How was the initial setup?

It was straightforward.

What about the implementation team?

It was implemented in-house.

Which other solutions did I evaluate?

We also looked at Nessus.

What other advice do I have?

Make sure you take advantage of authenticated scans and it is also very helpful if you have a complete server inventory.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user268167 - PeerSpot reviewer
Senior System Engineer at a comms service provider with 1,001-5,000 employees
Vendor
Jul 7, 2015
It's easy to download/install the correct patch, but the reporting could be improved.

What is most valuable?

The feature where the solutions to issues are mentioned in the reports.

How has it helped my organization?

It's easy to reach the current location and download/install the correct patch.

What needs improvement?

The feature where the solutions to issues are mentioned in the reports could be improved.

For how long have I used the solution?

I've been using it for over three years.

What was my experience with deployment of the solution?

No issues encountered.

What do I think about the stability of the solution?

No issues encountered.

What do I think about the scalability of the solution?

No issues encountered.

How are customer service and technical support?

Customer Service:

7/10.

Technical Support:

5/10,

Which solution did I use previously and why did I switch?

No previous solution was used.

What about the implementation team?

It was implemented by the vendor.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Qualys VMDR
January 2026
Learn what your peers think about Qualys VMDR. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,757 professionals have used our research since 2012.
it_user259977 - PeerSpot reviewer
Analista de Seguridad TI at a manufacturing company with 1,001-5,000 employees
Real User
Jun 24, 2015
It's worth the investment, but score calculation needs to be improved. I had to manually re-calculate scoring at times.

What is most valuable?

The interface is pretty good, as all the instructions are clear enough. The way you can create groups or scheduling scans and reports is a very good feature, and the CSV reports have very good information.

How has it helped my organization?

In this case, my last employer was a Qualys partner and the consultancy was extra. But, the reports and the way the information is, helped a lot. Also, with this information concise presentations were sent to the CIO every month.

What needs improvement?

I think the only area to improve it is the way the scores are calculated. That was the only problem I had and because of that, all scores had to be rectified manually.

For how long have I used the solution?

I was using both Multimedios Redes (Enterprise version) and Lamosa for three years. I also used PC, PCI, and WAS.

What was my experience with deployment of the solution?

No issues were encountered.

What do I think about the stability of the solution?

Maybe one or two times, but they were caused by scheduled windows, but these problems were fixed very quickly.

What do I think about the scalability of the solution?

No issues were encountered.

How are customer service and technical support?

Customer Service:

Very good! I think I would give them 10/10 because in Latin America the service was excellent.

Technical Support:

Again, I would give them 10/10, as the documentation is so good and all is clear, but if you have a doubt, technical support was always concise and had a quick answer. Also the community helps a lot.

Which solution did I use previously and why did I switch?

I did not personally, but the technical contacts that worked for my customers tried another solutions, and they chose Qualys for the easy way it manages the processes.

How was the initial setup?

The initial setup was very easy, with no complications found when the instructions were followed. Also, this activity was done with a physical and virtual appliance, and both ways were very easy to follow.

What was our ROI?

I was the vendor team, but I can give you the answer from the actual companies I worked for. The administrators, before Qualys, did not care so much about security, patching, etc.; but, after Qualys they changed their minds. Security took a very important role and of course they reduced, a lot, the chances of being hacked or attacked. It also helped, at this point, to be verified by auditors.

What's my experience with pricing, setup cost, and licensing?

It's worth it, really, when you see the complete picture and see all the factors. It is a very good investment. Qualys is a very good tool and very easy to use and it is also better to have an annual subscription rather than paying for a scan.

Which other solutions did I evaluate?

My customers evaluated Foundstone and Rapid7, and possibly others.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user259962 - PeerSpot reviewer
Manager System Security at a comms service provider with 1,001-5,000 employees
Vendor
Jun 23, 2015
The installation of the local hardware scanner appliance is easy, but the asset tagging needs lots of improvements.

What is most valuable?

  • Vulnerability management
  • Policy compliance
  • Scalability

How has it helped my organization?

As a leading IT services organization, it is very important for us to have a proactive identification/assessment of vulnerabilities. We also need to be able to remedy them in a timely manner before they exploit our security configuration compliance, and then harden our security for both system/network devices and applications. We need to do this both before and after placing them in production environment.

With QualsyGuard we have been able to achieve this by utilizing its modules, such as vulnerability management, policy compliance, web scanning, malware detection, and asset tagging.

What needs improvement?

As users of Qualys for the last three years, we have identified and shared many areas where Qualys needed to have improvements, including --

  • Vulnerability database having some false positives, although this is rare;
  • Web scan module requires authentication to access basic web forms;
  • Asset tagging needs lots of improvements as it's currently a complex technique; and
  • For policy compliance, they need to add more leading IT standards with regards to all the leading IT service provides like Juniper, Cisco, Microsoft, etc.

For how long have I used the solution?

I've been using this product for the last three years.

What do I think about the stability of the solution?

This is a very stable product and we haven't faced any issues since its deployment apart from announced downtimes for upgrades and improvements.

What do I think about the scalability of the solution?

No issues encountered.

How are customer service and technical support?

Customer Service:

Support is available 24/7 via phone and e-mail. Remote session support is also available.

Technical Support:

They have excellent expertise.

Which solution did I use previously and why did I switch?

No previous solution was used.

How was the initial setup?

It's easy as it is a SaaS, cloud-based service. The installation of the local hardware scanner appliance is also easy.

What about the implementation team?

We used a vendor team who was excellent.

What was our ROI?

I cannot give you the exact ROI on this, but as a large information and communication technology service provider, a 24/7 service availability that leads to customer satisfaction is our key goal. Regular VM and compliance assessment results in the complete hardening of our critical assets defending us against any exploits that leads to unavailability of our services.

Which other solutions did I evaluate?

No, because it was already in use at our parent company and it was providing good results for a low price as well.

What other advice do I have?

  • Collect complete asset inventory details (asset type, service/application details, administrator details etc.).
  • Provide awareness session to the support team about Qualys, its usage, and functionality.
  • Prepare OLAs and SOPs for better co-ordination between the teams.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user216711 - PeerSpot reviewer
it_user216711Product Manager with 1,001-5,000 employees
Real User

Yes, this review is helpful.

it_user254613 - PeerSpot reviewer
Security Consultant at a tech services company with 51-200 employees
Consultant
Jun 21, 2015
The reporting features needs to be improved, but you don't need to spend a lot of time on the deployment.

What is most valuable?

The fact that it's on the cloud, so there's no configuration whatsoever on my physical machine except for the VM scanner.

How has it helped my organization?

It now takes less time to run a vulnerability assessment for our client. I do not have to bring two laptops anymore to my clients sites.

What needs improvement?

Maybe the reporting features. It is too granular, so that if someone new wants to get familiar with it, they will have a hard time. A few more tutorials or guide on screen would also be appreciated.

For how long have I used the solution?

I've been using the consultant edition for two years.

What was my experience with deployment of the solution?

During the internal scanner deployment, but the issue was mostly not the product, but more the network architecture of our client.

What do I think about the stability of the solution?

No issues encountered.

What do I think about the scalability of the solution?

No issues encountered.

How are customer service and technical support?

Customer Service:

9/10

Technical Support:

9/10

Which solution did I use previously and why did I switch?

Rapid 7 Nexpose. To use the software, it takes a whole laptop just to run it, and the results have too much redundancy. Additionally, the scan rate is very slow compared to Qualys, and furthermore it is too expensive when compared to Qualys.

How was the initial setup?

It's very straightforward. Basically you can scan anything external/internet facing within five minutes. For internal scans you have to deploy the internal scanner which can be done in five minutes if the network architecture is not too complex.

What about the implementation team?

It was done In-house, but the help we get from their Singapore support team is awesome.

Which other solutions did I evaluate?

  • Nessus
  • Nexpose

What other advice do I have?

Use it. It is a great product. Many people are sceptical that their scan results are in the cloud. But if you want something affordable and that works like a charm, go for Qualys. Less headaches and easy to achieve ROI as you don't spend much on the deployment or maintenance.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: We have been doing some road-shows, & conferences in Malaysia to introduce Qualys.
PeerSpot user
it_user255882 - PeerSpot reviewer
Customer Technical Leader for Galeries Lafayette at a tech company with 10,001+ employees
Vendor
Jun 17, 2015
The GUI needs work, but the vulnerabilities are kept up to date.

What is most valuable?

The top one for me is that the vulnerabilities are kept up to date.

How has it helped my organization?

It has reduced the cost of ownership for the engineers who can launch scans on the customers’ networks.

What needs improvement?

I’m convinced it could be possible to do a simpler interface.

For how long have I used the solution?

I used it for about four years.

What was my experience with deployment of the solution?

No issues encountered.

What do I think about the stability of the solution?

There is an issue with the web browser, but it's not an issue with the product itself.

What do I think about the scalability of the solution?

No issues encountered.

How are customer service and technical support?

Customer Service:

9/10.

Technical Support:

8/10.

Which solution did I use previously and why did I switch?

I switched due to the cost.

How was the initial setup?

It was simple because it's only used for external scans.

What's my experience with pricing, setup cost, and licensing?

You have to find the best solution regarding functions and cost.

Which other solutions did I evaluate?

  • Tripwire
  • Nessus
  • Accunetix
  • OIpenvas

What other advice do I have?

  • Take your time
  • Study all the functionalities of the product
  • Try to set it up in a lab first before your production environment.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user254973 - PeerSpot reviewer
Manager Information Security at a healthcare company with 10,001+ employees
Real User
Jun 16, 2015
There are some stability issues with reporting, but it's straightforward to implement.

What is most valuable?

Vulnerability management.

How has it helped my organization?

It has helped to automate the vulnerability management program, increasing the security posture and helped us to identify the security risks in our infrastructure.

What needs improvement?

Web application security model needs some work.

For how long have I used the solution?

I've been using it for four years, including including VM, PCI, WAS and MDS features.

What was my experience with deployment of the solution?

No issues encountered.

What do I think about the stability of the solution?

There's been a few times, related to reporting, that we've had issues, but overall it's stable.

How are customer service and technical support?

Customer Service:

Excellent, the Qualys support team always helps on a priority basis.

Technical Support:

Excellent!

Which solution did I use previously and why did I switch?

No previous solution was used.

How was the initial setup?

It was straightforward.

What about the implementation team?

It was done in-house.

Which other solutions did I evaluate?

No other options were looked at.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user254970 - PeerSpot reviewer
Technical Services Manager at a tech company with 10,001+ employees
Vendor
Jun 16, 2015
It is very simple and yet an effective way to do vulnerability assessment.

What is most valuable?

  • Vulnerability assessment
  • Asset management
  • WAS

How has it helped my organization?

Since this is a SaaS based solution, the vulnerability scan with the external scanners as well as the reporting has improved a lot. The reporting is very granular and you can please higher management with your reports.

What needs improvement?

None, as the product is great.

For how long have I used the solution?

I've used it for four years.

What do I think about the stability of the solution?

Stability of the product is very high, I have never seen it unavailable.

How are customer service and technical support?

Customer Service:

The support needs to improve a lot, their response is absolutely slow. I have had terrible experience with support over the years.

Technical Support:

I would rate it great because of its improvement since I have had terrible experiences in the past.

Which solution did I use previously and why did I switch?

We used McAfee Vulnerability Manager/Foundstone and had to switch because this is a SaaS based solution and has more features/capabilities.

How was the initial setup?

The initial setup is very simple in terms of configuring the appliance.

What about the implementation team?

We installed it ourselves,

What other advice do I have?

I would definitely recommmend using this product, as this is very simple and yet an effective way to do vulnerability assessment.

.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Qualys VMDR Report and get advice and tips from experienced pros sharing their opinions.
Updated: January 2026
Buyer's Guide
Download our free Qualys VMDR Report and get advice and tips from experienced pros sharing their opinions.