Cyber Expert at a consultancy with 11-50 employees
Real User
Top 10
Dec 16, 2025
I have limited feedback on how Qualys TotalCloud helps my cloud security posture management, but it works well with misconfiguration detections and provides deep mapping with CIS, NIST, ISO frameworks, PCI compliance, and regulatory benchmarks. In terms of pricing, compared with the top market leaders in Gartner's reports, I find Qualys TotalCloud to have a reasonable standard rate, which is not too hard to access. They have also introduced use case basis rates that allow auditors to purchase specific instances of the cloud service, leading to a flexible pay-per-usage model. Overall, deploying Qualys TotalCloud across all cloud platforms is very easy. We handle clients of all sizes, including direct work with government entities, and are currently deployed in various states within government and public sectors. Vendor maintenance, such as patches for Qualys TotalCloud, is conducted promptly. I observe that if a zero-day vulnerability emerges, the vendor deploys patches as per market recommendations without significant delays. While we do not work directly with Qualys in our organization, I utilize it during audit activities at client premises alongside various other tools such as Metasploit, Rapid7, and others that I prefer not to disclose. We can deploy Qualys TotalCloud where needed, particularly for presentation layers, while other tools handle deeper network layer security requirements. I recommend Qualys TotalCloud, having written various articles on it. I suggest potential users align their use cases with its capabilities before deciding, as a proof of concept could be beneficial. I have given this review an overall rating of eight out of ten.
Group IT Cloud and Cybersecurity Engineer at Safetykleen
Real User
Top 10
Sep 17, 2025
Cloud security posture changes with time when using Qualys TotalCloud. It depends on how early you detect threats and fix them. Qualys TotalCloud doesn't provide a single prioritized view of risk. The product does what it says it's going to do, so I recommend it. I rate Qualys TotalCloud six out of ten.
Currently, AI access is restricted in our environment. We are testing the outcomes and possibilities. Within two months, we may start using GenAI. I would definitely recommend Qualys TotalCloud to other users. If someone is looking for a centralized management tool while using different cloud platforms, Qualys TotalCloud is very helpful. It helps manage and identify vulnerabilities and misconfigurations. It helps with asset management. It helps understand how many AWS or Google Cloud instances are in the environments. I would rate Qualys TotalCloud a ten out of ten.
I definitely recommend other organizations to have this product in their environment. The price is a factor. Smaller organizations might find it unaffordable. However, there are different options depending on the budget, such as purchasing a smaller number of licenses. I highly recommend it. I work for LTI Mindtree, a large organization. Overall, I rate the product nine out of ten.
I recommend using it for posture management if a cloud agent is available. The cloud agent collects information for vulnerabilities and makes it accessible as a single source of information. I would rate Qualys TotalCloud a nine out of ten.
Cyber Security Consultant at Systal Technology Solutions
Consultant
Top 20
Jan 29, 2025
New users should know about the architecture of Qualys TotalCloud and its components and backend infrastructure. Understanding vulnerability detection, AI, threat intelligence, attack vectors, exposure, and risk management is key. They should also read the full user manual and insights from IT professionals. They should learn how to use this solution for threat management. I would rate Qualys TotalCloud an eight out of ten.
I would recommend TotalCloud from the posture management and integration perspectives, as these areas are strong. However, due to limitations in risk and inventory management, one might consider waiting until those features are improved. Overall, I would rate TotalCloud an eight out of ten.
IT Architect at a consultancy with 10,001+ employees
Real User
Top 10
Nov 12, 2024
I would rate Qualys TotalCloud ten out of ten. Qualys TotalCloud is deployed in multiple departments and utilized by over 100 users. Qualys TotalCloud is SaaS-based, so all maintenance is handled by Qualys. The agents update automatically, eliminating the need for user intervention. Reinstallation is only necessary in the rare event of agent corruption. I would definitely recommend Qualys to others. It is a strong competitor in today's market.
Senior Consultant at a consultancy with 10,001+ employees
Real User
Top 10
Nov 11, 2024
I would strongly recommend a Web Application Firewall (WAF) for any business or individual because it protects your information and prevents numerous risks associated with Internet use. I would rate Qualys TotalCloud a ten out of ten.
Information Technology Security Analyst at a financial services firm with 10,001+ employees
Real User
Top 10
Oct 15, 2024
New users should have a deeper understanding of how to use the cloud API because the extensibility is based on that. If they do not understand how to use the API, it would not be effective for them. TotalCloud provides unified vulnerability and threat assessment across both IaaS and SaaS, but we do not use that. We do not have a use case for that. I would rate TotalCloud an eight out of ten.
IT Engineer at a consultancy with 501-1,000 employees
Real User
Top 10
Sep 2, 2024
I would rate Qualys TotalCloud eight out of ten. Qualys TotalCloud is deployed in one location, and we have two users. No maintenance is required. I recommend Qualys TotalCloud to others. It helps identify vulnerabilities present in the system and simplifies our work.
I would rate Qualys TotalCloud ten out of ten. Qualys TotalCloud is designed for continuous operation, eliminating the need for scheduled maintenance. It automatically synchronizes with your cloud environment, be it Azure, Amazon Web Services, or Google Cloud, to stay up-to-date. If you have a trusted partner familiar with Qualys, leverage their expertise. Also collaborate with the assigned Qualys Technical Account Manager. Don't hesitate to ask questions; both Qualys' TAMs and the Qualys community are valuable resources. Qualys offers free training and online documentation to help you with most tasks. I recommend Qualys TotalCloud to others.
TotalCloud is the Qualys approach to Cloud Native Application Protection Platform (CNAPP) for cloud infrastructure and SaaS environments. With TotalCloud, customers extend TruRisk insights (transparent cyber risk scoring methodology) from the Qualys Enterprise TruRisk Platform to their cloud environments allowing for a seamless unified view of cyber risk across on-prem, hybrid, and multi-cloud environments.
Features and capabilities of Qualys TotalCloud include, but are not limited...
I have limited feedback on how Qualys TotalCloud helps my cloud security posture management, but it works well with misconfiguration detections and provides deep mapping with CIS, NIST, ISO frameworks, PCI compliance, and regulatory benchmarks. In terms of pricing, compared with the top market leaders in Gartner's reports, I find Qualys TotalCloud to have a reasonable standard rate, which is not too hard to access. They have also introduced use case basis rates that allow auditors to purchase specific instances of the cloud service, leading to a flexible pay-per-usage model. Overall, deploying Qualys TotalCloud across all cloud platforms is very easy. We handle clients of all sizes, including direct work with government entities, and are currently deployed in various states within government and public sectors. Vendor maintenance, such as patches for Qualys TotalCloud, is conducted promptly. I observe that if a zero-day vulnerability emerges, the vendor deploys patches as per market recommendations without significant delays. While we do not work directly with Qualys in our organization, I utilize it during audit activities at client premises alongside various other tools such as Metasploit, Rapid7, and others that I prefer not to disclose. We can deploy Qualys TotalCloud where needed, particularly for presentation layers, while other tools handle deeper network layer security requirements. I recommend Qualys TotalCloud, having written various articles on it. I suggest potential users align their use cases with its capabilities before deciding, as a proof of concept could be beneficial. I have given this review an overall rating of eight out of ten.
Qualys TotalCloud does help guide remediation paths and eliminate cyber risks. I would rate this solution a seven overall.
Cloud security posture changes with time when using Qualys TotalCloud. It depends on how early you detect threats and fix them. Qualys TotalCloud doesn't provide a single prioritized view of risk. The product does what it says it's going to do, so I recommend it. I rate Qualys TotalCloud six out of ten.
Currently, AI access is restricted in our environment. We are testing the outcomes and possibilities. Within two months, we may start using GenAI. I would definitely recommend Qualys TotalCloud to other users. If someone is looking for a centralized management tool while using different cloud platforms, Qualys TotalCloud is very helpful. It helps manage and identify vulnerabilities and misconfigurations. It helps with asset management. It helps understand how many AWS or Google Cloud instances are in the environments. I would rate Qualys TotalCloud a ten out of ten.
I definitely recommend other organizations to have this product in their environment. The price is a factor. Smaller organizations might find it unaffordable. However, there are different options depending on the budget, such as purchasing a smaller number of licenses. I highly recommend it. I work for LTI Mindtree, a large organization. Overall, I rate the product nine out of ten.
I recommend using it for posture management if a cloud agent is available. The cloud agent collects information for vulnerabilities and makes it accessible as a single source of information. I would rate Qualys TotalCloud a nine out of ten.
New users should know about the architecture of Qualys TotalCloud and its components and backend infrastructure. Understanding vulnerability detection, AI, threat intelligence, attack vectors, exposure, and risk management is key. They should also read the full user manual and insights from IT professionals. They should learn how to use this solution for threat management. I would rate Qualys TotalCloud an eight out of ten.
I would recommend TotalCloud from the posture management and integration perspectives, as these areas are strong. However, due to limitations in risk and inventory management, one might consider waiting until those features are improved. Overall, I would rate TotalCloud an eight out of ten.
I would rate Qualys TotalCloud ten out of ten. Qualys TotalCloud is deployed in multiple departments and utilized by over 100 users. Qualys TotalCloud is SaaS-based, so all maintenance is handled by Qualys. The agents update automatically, eliminating the need for user intervention. Reinstallation is only necessary in the rare event of agent corruption. I would definitely recommend Qualys to others. It is a strong competitor in today's market.
I would strongly recommend a Web Application Firewall (WAF) for any business or individual because it protects your information and prevents numerous risks associated with Internet use. I would rate Qualys TotalCloud a ten out of ten.
New users should have a deeper understanding of how to use the cloud API because the extensibility is based on that. If they do not understand how to use the API, it would not be effective for them. TotalCloud provides unified vulnerability and threat assessment across both IaaS and SaaS, but we do not use that. We do not have a use case for that. I would rate TotalCloud an eight out of ten.
I would rate Qualys TotalCloud eight out of ten. Qualys TotalCloud is deployed in one location, and we have two users. No maintenance is required. I recommend Qualys TotalCloud to others. It helps identify vulnerabilities present in the system and simplifies our work.
I would rate Qualys TotalCloud ten out of ten. Qualys TotalCloud is designed for continuous operation, eliminating the need for scheduled maintenance. It automatically synchronizes with your cloud environment, be it Azure, Amazon Web Services, or Google Cloud, to stay up-to-date. If you have a trusted partner familiar with Qualys, leverage their expertise. Also collaborate with the assigned Qualys Technical Account Manager. Don't hesitate to ask questions; both Qualys' TAMs and the Qualys community are valuable resources. Qualys offers free training and online documentation to help you with most tasks. I recommend Qualys TotalCloud to others.